Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Apps in the Kids Category are prohibited from transmitting personally identifiable information or device information to third parties, and third-party advertising and analytics are generally not permitted, with narrow exceptions requiring that analytics services do not collect the IDFA, identifiable information, location, or device data.
This analysis describes what Apple's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes strict data handling obligations for developers targeting children, restricting third-party data flows and advertising integrations that are common in other app categories, and requires compliance with applicable children's privacy laws globally.
The updated guidelines state that developers must ensure kids receive age-appropriate experiences within their apps and must remove user-generated content that violates the guidelines, terms of service, or community standards. Under the revised policy, if Apple identifies policy-violating content, the developer will be asked to remove it and provide a compliance improvement plan. Based on the developer's response, the app may be removed from the App Store until compliance is demonstrated. This establishes a formal escalation pathway where developer inaction or inadequate remediation can result in app suspension or removal.
View change record →Under this provision, apps designated in the Kids Category are required to limit data sharing with third parties, meaning children's identifiers, location, and personal information should not be transmitted to advertising or analytics vendors, subject to the narrow exceptions described.
Cross-platform context
See how other platforms handle Kids Category Third-Party Data and Advertising Restrictions and similar clauses.
Compare across platforms →Monitoring
Apple has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Kids Category apps may not send personally identifiable information or device information to third parties. Apps in the Kids Category should not include third-party analytics or third-party advertising. This provides a safer experience for kids. In limited cases, third-party analytics may be permitted provided that the services do not collect or transmit the IDFA or any identifiable information about children (such as name, date of birth, email address), their location, or their devices.Excerpt from Apple's App Store Review Guidelines
1) REGULATORY LANDSCAPE: This provision directly engages COPPA, which restricts the collection and disclosure of personal information from children under 13 without verifiable parental consent, enforced by the FTC. GDPR-K (protections for minors under GDPR) and equivalent laws in the UK, Canada, and other jurisdictions are also engaged. The provision's prohibition on IDFA transmission aligns with Apple's App Tracking Transparency framework. FTC enforcement of COPPA against app developers and SDK providers has resulted in significant penalties in documented cases. 2) GOVERNANCE EXPOSURE: High. Developers in the Kids Category must audit all third-party SDKs, ad networks, and analytics services for IDFA collection, identifiable data transmission, and location data practices. The guidelines hold the developer responsible for SDK compliance, meaning inadequate vendor vetting creates direct compliance exposure under both the App Review Guidelines and COPPA. 3) JURISDICTION FLAGS: The Kids Category restrictions apply globally, but COPPA creates specific US legal obligations for apps directed to children under 13. GDPR Article 8 and equivalent provisions in the UK, Canada, and Australia create additional consent and data minimization obligations. Illinois, California, and New York have state-level children's privacy statutes that may create heightened exposure for developers with US users. 4) CONTRACT AND VENDOR IMPLICATIONS: Third-party analytics and advertising vendor contracts should be reviewed for COPPA-compliant data processing terms. The guidelines permit limited third-party analytics only where vendors publicly document their Kids Category practices and conduct human review of ad creatives. Vendor agreements should reflect these documented practices and include representations about IDFA and identifiable data handling. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a full SDK audit for all Kids Category apps, mapping each third-party integration against the permitted data collection criteria. Advertising vendor agreements should be reviewed for age-appropriate content review processes. Privacy policies should accurately reflect the restricted data practices applicable to Kids Category apps. Where apps are available in multiple jurisdictions, compliance with local children's privacy laws beyond COPPA should be assessed.
This provision establishes strict data handling obligations for developers targeting children, restricting third-party data flows and advertising integrations that are common in other app categories, and requires compliance with applicable children's privacy laws globally.
Under this provision, apps designated in the Kids Category are required to limit data sharing with third parties, meaning children's identifiers, location, and personal information should not be transmitted to advertising or analytics vendors, subject to the narrow exceptions described.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Apple.