ONLINE PRIVACY CyberArtical Editorial Team

What parents can actually control about a child’s online footprint

A young child seen from behind, sitting at a laptop at a table

Advice for parents tends to arrive as a list of things to forbid. That is the least useful part of the problem, because the largest parts of a child’s data footprint are not created by the child. They are created by the apps on the devices you bought, by the operating system’s advertising identifier, by public records, and — awkwardly — by what the adults in their life post. This sorts the problem into what you can actually change.

The controls that exist

  • FTC: "Go to the privacy settings on your smartphone to see what information they can access from your device" — app permissions are set on the device, not in the app.
  • FTC: the phone "has a setting that lets you opt out of personalized ads from the company that makes the operating system". CISA’s version: "Disable your Ad ID."
  • A credit freeze is free, "lasts until you lift it", doesn’t affect a credit score, and means "nobody can open a new credit account in your name".
  • Opting a child out of prescreened offers needs "your child’s birth certificate, a copy of their Social Security card, and a copy of your driver’s license or other government-issued proof of identity".
  • Child identity theft is reported at IdentityTheft.gov, which produces a personal recovery plan and pre-filled letters.

Sorting the problem into three piles

Pile one is device and account configuration. This is entirely yours to set, it takes an evening, and it is where the largest reduction comes from.

Pile two is what your child does — what they post, who they talk to, what they install. This is a conversation, not a setting, and settings that pretend otherwise get worked around.

Pile three is what other people hold: public records, data brokers, and posts made by relatives. You have partial influence here and no control. The FTC’s own description of people-search sites is that they compile birth records, property records and the rest, and also "collect information from social media profiles that are public or viewable by everyone."

The device settings that come first

  1. On each device the child uses, open the operating system’s privacy settings and turn off personalised advertising. CISA states this plainly as disabling the Ad ID; the FTC describes it as opting out of personalised ads from the company that makes the operating system.
  2. In the same privacy menu, go through app permissions. The FTC’s instruction is to see what information apps can access from the device. Location, microphone, camera, contacts and photos are the ones worth being strict about.
  3. Set the browser’s privacy settings on that device — cookie limits and the personalised-ads preference. The FTC notes these settings "give you some control over the information websites collect".
  4. Repeat on every device and every browser. The FTC’s caveat applies to children’s devices as much as adults’: "If you opt out, be sure to opt out on each device and browser."
  5. Do the same on the household’s connected TV and streaming devices, which the FTC explicitly names as a place to review privacy settings.

Social accounts, and the setting that leaks the most

CISA’s Project Upskill privacy module names managing the settings on social media accounts as one of three core privacy actions, alongside disabling the advertising identifier and reducing the chance of tracking software being installed on the device.

The setting that matters most is whichever one governs what is visible to everyone rather than to friends. That is not just an exposure to strangers browsing; the FTC describes data brokers collecting from "social media profiles that are public or viewable by everyone." A public profile is an input to a commercial dataset, not merely a page.

Go through this with the child rather than for them. Settings changed behind someone’s back get changed back.

Your own posting is part of their footprint

This is the part parents find hardest to hear. A child who has never had an account can still have a searchable history of photographs, a school name, a home street and a birth date, assembled from adults’ posts over a decade.

There is no technical control for this. There is a habit: decide what you are willing to have permanently public about someone who cannot consent yet, and hold to it. Birth dates, school names, sports club locations and anything showing the front of the house are the standard regrets.

Freezing a child’s credit, and stopping prescreened offers

A child’s credit file is attractive precisely because nobody looks at it for eighteen years. The FTC’s freeze guidance describes the control in strong terms: it is free, it lasts until lifted, it does not affect a credit score, and while it is in place nobody can open a new credit account in that name.

The related step is opting out of prescreened credit and insurance offers. For a child this requires documentation — the FTC lists the child’s birth certificate, a copy of their Social Security card, and a copy of your driver’s licence or other government-issued proof of identity.

If you already suspect a child’s information has been misused, the route is IdentityTheft.gov, which produces a personal recovery plan, tracks progress and prints pre-filled letters to credit bureaus, businesses and debt collectors.

What none of this covers

Parental controls do not reach what a child does on a friend’s device, and they do not survive a determined teenager for long. Treat them as reducing accidental exposure rather than enforcing anything.

Nor does any of this remove information already in public records. The FTC is explicit that opting out of people-search sites "doesn’t delete your information from public records", that data "could re-appear for sale" when those records change, and that it "may still appear in the reports of your relatives, neighbors, or associates". Its advice is to check back periodically, which is a fair description of the whole job.

Sources: FTC — How to protect your privacy online · CISA Project Upskill, Module 6 · FTC — What to know about people search sites · FTC — Credit freezes and fraud alerts · FTC — What to know about prescreened offers

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC and CISA. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories