CNIL, ICO and GPEN Review Websites Aimed at Children During Internet Sweep
Time 2 Minute Read

On May 11, 2015, the French Data Protection Authority (“CNIL”) and the UK Information Commissioner’s Office (”ICO”) announced that they will participate in a coordinated online audit to assess whether websites and apps that are directed toward children, and those that are frequently used by or popular among children, comply with global privacy laws. The audit will be coordinated by the Global Privacy Enforcement Network (“GPEN”), a global network of approximately 50 data protection authorities (“DPAs”) from around the world.

In addition to the CNIL and the ICO, 27 other DPAs that are members of the GPEN will participate, including four German DPAs (the Federal Commissioner for Data Protection and Freedom of Information, the Data Protection Supervisory Authority of Bavaria, the Berlin Data Protection Commissioner and the Data Protection Commissioner of Hessen). View the full list of participating DPAs.

The joint effort will run from May 11 to 15, and will target child-directed websites and apps, such as gaming websites, social networking websites and educational websites. Specifically, the participating DPAs will verify whether the targeted websites and apps:

  • Seek parents’ consent before allowing children to use the services offered or provide personal data;
  • Raise public awareness regarding privacy;
  • Provide a privacy notice tailored to younger audiences (e.g., clear language, animated images, etc.); and
  • Facilitate the erasure of personal data provided by children.

As in prior years, the participating DPAs will use an analysis grid to obtain (1) a global picture of the privacy practices of child-directed websites and (2) details about practices common to particular jurisdictions. The DPAs intend to publish a combined report in Fall 2015.

The CNIL and the ICO have stressed that they could conduct further inspections and launch enforcement proceedings if their initial findings reveal serious breaches of applicable data protection law. Other DPAs participating in the joint audit may take similar action.

You May Also Be Interested In

Time 2 Minute Read

On March 25, 2026, the UK Information Commissioner’s Office and the UK Office of Communications released a joint statement addressing the intersection of online safety and data protection in relation to age assurance.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 3, 2026, the Virginia Attorney General appealed a federal court’s grant of a preliminary injunction barring the enforcement of a new Virginia law requiring age verification and a time limit on social media use by minors under the age of 16 pending a final determination on the merits.    

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page