
The minimum viable compliance trap in children's privacy, and why it quietly creates security risk
Products that technically satisfy children's privacy laws while preserving the same extractive architecture that made regulation necessary. Why minimum viable compliance is a security problem, not just a privacy one.
There is a pattern that keeps repeating in children's privacy law, regardless of jurisdiction. We write rules to protect children. Industry responds by doing exactly what is required. And almost nothing more.
The result is what I think of as minimum viable compliance. Products that technically satisfy the letter of children's privacy laws while preserving the same underlying data extraction, profiling incentives, and architectural fragility that made regulation necessary in the first place.
This is not a moral failing. It is a predictable systems outcome.
We see it clearly in how companies comply with regimes like COPPA in the United States and GDPR-K in Europe. Age gates are added. Consent flows are redesigned. Parents are looped in through dashboards and notices. But the core product architecture often remains unchanged. Data is still centralised. Identifiers still exist. Behaviour is still logged. The difference is that the flows are now wrapped in legal ceremony.
From a legal standpoint, this often passes. From a security standpoint, it is a quiet regression.
Australia is heading into the same terrain.
Australia's Privacy Act reforms and the development of a Children's Online Privacy Code are rightly focused on fairness, transparency, and harm reduction. The intent is sound. But intent does not determine outcome. Architecture does.
If compliance is achieved by adding process around fundamentally extractive systems, the risk profile does not meaningfully improve. In some cases, it gets worse.
Here is why this becomes a cyber security issue, not just a privacy one.
Minimum viable compliance tends to increase data complexity. Age verification services are bolted on. Consent records are stored separately. Parental identity data is introduced where none existed before. Exceptions and overrides multiply. Each of these elements becomes another data store, another interface, another dependency.
Attack surface grows, even as risk is claimed to be reduced.
Worse, compliance theatre creates false confidence. When a product is declared "compliant", internal scrutiny often drops. Controls are assumed to be sufficient because legal thresholds are met. Security investment shifts elsewhere. Meanwhile, the underlying system is still optimised for data collection, retention, and reuse.
Children's data is not just sensitive because of who it belongs to. It is sensitive because it often persists for decades. Decisions made about identity, behaviour, and categorisation can follow someone into adulthood. That makes integrity failures and secondary use far more damaging than a typical breach.
Australia's regulatory framing increasingly acknowledges this. The language is moving toward best interests, proportionality, and harm prevention. But regulation still largely operates at the level of obligation, not design.
This is where minimum viable compliance becomes dangerous.
A system engineered to comply at the margins will meet audit questions today while storing up risk for tomorrow. When an incident occurs, the organisation will not be asked whether it technically complied. It will be asked whether the system was appropriate for the risk it carried.
That is a different standard.
There is also a national security and trust dimension that rarely gets discussed. Children's platforms generate identity data, behavioural data, and social graphs at scale. When these systems rely on opaque vendors, offshore processing, or poorly governed analytics pipelines, the risk is not just individual harm. It is systemic exposure.
Australia already understands this logic in other domains. We apply it to critical infrastructure. We apply it to identity systems. We are slowly applying it to AI. Children's data ecosystems should not be exempt simply because compliance boxes were ticked.
The uncomfortable truth is that many companies do not set out to exploit children's data. They set out to build products quickly within commercial constraints. Compliance frameworks that reward procedural adherence over architectural restraint steer them toward legal minimalism, not safety.
Security teams sit uncomfortably in the middle of this.
They are asked to secure systems whose core purpose conflicts with minimisation. They are asked to protect data that did not need to be collected. They are asked to defend architectures whose risk was accepted upstream for commercial reasons.
Calling this out is not anti-business. It is pro-reality.
If Australia wants children's privacy reform to reduce harm rather than redistribute liability, we need to look past whether a system is compliant and ask whether it is necessary, proportionate, and defensible under failure conditions.
Compliance theatre feels safe because it is measurable. Security reality is harder because it asks different questions.
Minimum viable compliance keeps lawyers comfortable. It does not keep children safe. And it quietly hands security teams a risk profile they did not design and cannot meaningfully control.
Free CyberSafety training for every Australian family
Video lessons, downloadable guides and completion certificates — all free, forever.
Start free training