Z6.04.3Data minimizationdesignresearch

Children and visitors need minimal collection by default

Aliases: default minimal collection · least privilege for data

What it is

For the two classes of people who cannot consent effectively — children (autonomy still developing, and the records follow them for life) and visitors (no standing, no account, brief presence) — the collection default should be the minimum the stated function needs, with expansion requiring explicit action rather than discovery-and-disable by the user. Data minimization is a principle in general privacy law; here it is a default-value design: the factory state is the minimum.

Why it happens

Defaults are sticky: the behavioural-economics literature on the default effect and status quo bias shows, repeatedly, that whatever ships as the default persists untouched for most users. "Fully on by default" therefore means all-collection on children and visitors is effectively irreversible; setting the minimum as the factory state is the only position that protects those without a voice, given how defaults behave.

For children the stakes compound over time: behaviour, voice, and location recorded at age 8 still exist somewhere at 30 — a lifecycle-scale exposure whose subject could neither assess the consequences at the time nor ever withdraw. For visitors: the configuration interface contains no representative of the visitor's interests — the owner configures for the household's convenience and the visitor's voice is absent; the minimal default substitutes for that absent voice.

"Minimal" is defined by function, not by technology: a motion-triggered light needs "someone is present", not "who"; a speaker needs the wake word, not cloud archival of all audio. The gap between what the function needs and what ships as default is a product decision, not a technical necessity — that sentence is itself the evaluation standard.

Studying it

  • Default-effect research (behavioural economics crossing into privacy settings, described generically): defaults decisively shape long-run distributions, verified across organ donation, pension enrolment, and privacy settings; privacy-default studies show far more users keep sharing under "shared by default" than under "private by default" — the gap is large enough that the default itself becomes a policy instrument.
  • Children's-data research (described generically): audits of connected toys and child-facing devices repeatedly find collection beyond functional need — always-on microphones, long-term cloud retention; the lifecycle risk of children's data (irreversibility and permanence of records) is a core topic in children's privacy research.
  • Variables: the set difference between factory defaults and functional need (audit method), default retention periods, accuracy of parents' understanding of the defaults.

Where it stops holding

  • Minimal defaults genuinely trade against function quality: presence-only sensing cannot drive per-person automations — and per-person automation is what some households actually want. Minimal defaults do not forbid collection; they move the decision to expand from the factory to setup time.
  • Safety cases justify exceptions: baby monitors and wandering alerts need more than minimal collection — the requirement there is scope limited to the safety function (a wandering alert needs location at the door, not location history), not zero.
  • "Children" spans ages 0–17, and a single child tier becomes regimentation by puberty: what is needed is a ladder that unlocks with age; the minimal default is only the ladder's starting point. Note also that children's-data rules in some jurisdictions (COPPA-style children's online protection regulations) already turn minimization from design preference into legal duty — designing to the strictest jurisdiction is the pragmatic route.

Applying it

  • Ship interior sensing at presence granularity (someone / no one); identity granularity requires explicit enabling with its purpose explained.
  • Default retention short — days, not years; upgrading is an explicit action. Child-linked profiles collect no behavioural data by default; safety features collect only the safety signal itself.
  • Switch to a minimal posture while guests are present: interior cameras pause, audio is not written to storage; resuming requires an explicit owner action, not a timed auto-restore.
  • How to check: for each data type, ask "with this off by default, which declared function breaks?" — a type with no breaking function ships off. Walking through the types one by one yields the minimal-default inventory.

Related

  • Same group: Z6.04.1 Guests enter the sensing field without ever consenting · Z6.04.2 Sensing needs visible notice
  • Nearby: Z6.05 Sensors and cameras in the home · Z6.06 Awareness of passive collection
  • Search terms: data minimization · default effect · children's privacy · COPPA

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Z6.04.3