Beyond usability, laws in multiple jurisdictions constrain what products can do around minors
Aliases: age-appropriate design code · minors protection · default privacy for minors
What it is
Beyond the usability findings rooted in cognitive and motor development covered elsewhere, products aimed at or reachable by children face a constraint of an entirely different nature: multiple jurisdictions maintain age-appropriate design guidance and minors-protection rules governing data collection, content presentation, and engagement-driving design aimed at young users. This layer is different in kind from the others: the earlier ones are about "what makes the experience better"; this one is about practices that aren't permitted even when they'd be defensible on experience grounds — an externally imposed compliance obligation, not a design preference a team gets to weigh against user experience.
Why it happens
The rationale for these rules is exactly the set of facts established elsewhere: children lack the judgment to weigh long-term consequences and lack the ability to recognize obscure terms and manipulative design, meaning the assumption underlying ordinary voluntary consent in a product — that the user will weigh whether to agree — doesn't hold for underage users. Because a product's own incentives around engagement and revenue don't always align with protecting its underage users, relying on the product's own judgment of where to draw the line isn't reliable. External rules therefore substitute a single, uniform protective floor for "letting the product decide the appropriate degree" — that floor typically shows up as: defaults starting from the most protective option, data collection limited to what's functionally necessary, and avoiding interaction designs that exploit known psychological vulnerabilities of minors.
Studying it
Determining whether a product falls under this kind of constraint can't rely on the product's stated target age alone — actual audience composition matters just as much. If a product is nominally aimed at adults but usage data shows a meaningful share of actual users are minors, most age-appropriate protection rules still treat the product as carrying the corresponding obligations. The standard way to verify actual audience composition is behavioral analysis (active hours, content preferences, the plausibility of registration information) rather than relying on a self-reported age field, since underage users misreporting their age at signup is common and self-reported data alone isn't reliable.
Where it stops holding
These rules differ across jurisdictions and continue to be revised over time; a specific practice compliant in one jurisdiction isn't necessarily compliant in another, and there is no single fixed checklist that applies everywhere. More importantly, meeting this compliance layer and being genuinely usable for children are separate matters: a product can be fully compliant on data collection and default settings while still being poor on cognitive and motor usability dimensions like touch target size or task chunking — compliance is a floor requirement, not a substitute for the developmentally grounded usability design covered elsewhere.
Applying it
- Bring age-appropriate protection requirements into the design phase as a constraint on par with technical feasibility, rather than leaving them to a pre-launch compliance review — retrofitting is almost always far more expensive than accounting for them during initial design.
- Any default setting touching minors' data should start from the most protective option available, requiring the user to actively loosen it rather than actively tighten it; interaction design aimed at minors should avoid sustained-engagement techniques that would be acceptable for adult users but exploit a minor's psychological vulnerabilities.
- Verification: periodically check the product's actual user age composition (based on behavioral signals, not self-reported fields). The moment the share of underage users reaches a level that triggers protective obligations, launch a review of the corresponding defaults and data-collection scope proactively, rather than waiting for an external audit to surface the problem.
Related
- Same group: A11.02.5 Exploratory manipulation outpaces consequence assessment · A11.02.8 Preschool, school-age, and adolescent users cannot be merged into one group
- Adjacent: O1.04 Privacy by default · O1.05 The usability dilemma of informed consent
- Search:
age-appropriate design·minors protection·default privacy settings
Cards in the same group
- A11.02.1Smaller fingertips don't mean children need smaller touch targets — aiming precision does
- A11.02.2A child's still-developing motor control makes drags and long presses fail far more than taps
- A11.02.3Interfaces built on the assumption of reading fail children who can't read yet
- A11.02.4A floppy-disk save icon means nothing until a child's grasp of metaphor catches up
- A11.02.5Children explore an interface by tapping everything, before they can judge the consequences
- A11.02.6How long a task should take needs to shrink with a younger child's attention span
- A11.02.7Children mis-tap far more than adults, which makes reliable undo more urgent for them
- A11.02.8Preschoolers, school-age kids, and teenagers need three different designs, not one kids bucket