Marketing to kids and vulnerable audiences without crossing the line
In September 2019 Google paid $170 million to settle claims from the FTC and the New York Attorney General that YouTube had collected persistent identifiers from viewers of toy-unboxing and nursery-rhyme channels and used them for behavioural advertising, with no parental consent anywhere in the chain. Those channels were child-directed by any sensible reading. The ad stack did not know it, because nothing connected the content label to the targeting logic.
The settlement was the cheap part. From January 2020 YouTube made every creator mark each upload as made for kids or not, and on anything so marked it switched off personalised ads, comments and several monetisation features. Children's channels absorbed the revenue hit, not Google. That is the recurring shape of this work: the fix lands on the people making the content, months after the lawyers have moved on, and nobody budgeted for it.
Why this audience is legally different
Children are the clearest case, but the protected set is wider: people with cognitive impairment, problem gamblers, people in financial distress. Regulators suspend the "reasonable consumer" test for them, on the assumption they cannot price the persuasion or the data trade being put in front of them.
Three obligations change:
- Consent below the statutory age comes from a parent and has to be verifiable. A checkbox reading "I confirm I am over 18" verifies nothing.
- Behavioural profiling for ad targeting is restricted for under-13s in the US and banned for minors on platforms operating in the EU.
- The age rating has to match the delivered audience, not the intended one. A 15-rated trailer whose real delivery skews to 11-year-olds is a problem even when the creative is impeccable.
None of these groups identify themselves. You infer them, and the inferenceinferenceThe moment a trained AI model is put to work: it takes a new input and produces an answer, prediction or generated output.View full definition → is where teams get careless.
The core legal frameworks
United States: COPPA (Children's Online Privacy Protection Act). Covers services directed to children under 13, and any service with actual knowledge it is collecting data from an under-13. That second trigger catches general-audience media: actual knowledge can arrive as one support email saying "my nine-year-old uses this", and from that moment the obligation is live. The FTC finalised amendments to the COPPA Rule in 2025 requiring separate parental opt-in before children's data goes to third parties for targeted advertising. See the FTC's COPPA business guidance for current thresholds and compliance dates.
European Union: GDPR Article 8 sets the digital consent age at 16 and lets member states drop it as low as 13. They have, unevenly: Ireland and France stayed at 16, Denmark and Sweden went to 13. A pan-European campaign running one consent age is wrong in a good half of the union.
United Kingdom: the Age Appropriate Design Code (the Children's Code), in force since September 2021 and overseen by the ICO. Its scope test is "likely to be accessed by children", which is far wider than "aimed at children". A general-audience streaming service with a real teen audience sits inside it, and the Code wants high-privacy defaults, profiling off unless justified, and no nudges toward weaker settings.
EU Digital Services Act: Article 28 bans profiling-based advertising to users a platform knows with reasonable certainty are minors, whatever the platform says its audience is.
Gambling-adjacent work stacks the CAP Code and the Gambling Act on top, policed by the watchdog the module's first lesson covers.
Case study: loot-box promotions and the gambling question
A loot box is a paid in-game item granting randomised rewards. Regulators have argued about it for the better part of a decade without converging.
Belgium's Gaming Commission concluded in 2018 that paid loot boxes fall under national gambling law, and publishers stripped real-money mechanics from Belgian builds rather than seek licences.
The Netherlands went the other way in the end. The Dutch gambling authority fined Electronic Arts €10 million over FIFA packs, and in March 2022 the Trade and Industry Appeals Tribunal quashed it, holding the packs were part of a game of skill rather than a standalone gambling product. Worth remembering when someone tells you a regulator's position is settled law.
The UK declined to reclassify and settled in 2023 for industry-led principles via DCMS: spend controls, odds disclosed before purchase, parental controls, implemented across 2024.
The marketing exposure sits below the legal question. Promoting a perfectly legal loot box through unboxing videos whose comment sections read like a Year 6 classroom, or through pop-ups timed to the first app open of the day, invites an unfairness case regardless of how the mechanic is classified. Test the audience, not the product.
Case study: age-gating failures
Age assurance runs on a ladder: self-declared birthdate at the bottom, then inference from behavioural and account signals, then documentary or biometric checks at the top. Most media companies stop on the bottom rung and hope.
TikTok shows what the middle of the ladder costs. The ICO fined it £12.7 million in April 2023, finding roughly 1.4 million UK children under 13 were using the platform in 2020 in breach of TikTok's own minimum age, with checks inadequate to keep them out. Five months later the Irish Data Protection Commission added €345 million over children's accounts being public by default and weaknesses in family pairing. TikTok had age rules. It did not have age assurance.
The direction of travel is estimation rather than declaration. Google has moved to machine-learning age estimation for signed-in users in the US, inferring whether an account belongs to an under-18 and applying teen protections without asking. Expect your own DPO to raise the counter-argument: age assurance collects more data about children than doing nothing. The ICO's answer is proportionality, match the strength of the check to the risk of the content, and it will not accept biometric estimation on a service that could have solved the problem by turning profiling off for everybody.
The failure mode is rarely the gate itself. It is the disconnection Google paid for in 2019: a classification field that exists and does not control the ad pipelinepipelineAll active sales opportunities across the stages of the sales process, together with their combined potential value and probability of closing.View full definition →.
Audience checks to fold into the sign-off
These are the child-audience additions to the sign-off sequence another lesson in this module sets out, not a replacement for it.
- Classification match: does the age rating (PEGI, ESRB, BBFC) match who the buy will actually reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.View full definition →, judged on delivered data rather than the plan?
- Data flowData flowAn automated sequence of steps that moves data from source to destination: ingestion, transformation, validation, and loading, so it arrives clean and ready to use.View full definition → audit: does the stack drop persistent identifiers on any surface flagged child-directed? Under COPPA a device ID is personal data with no name attached.
- Lookalike seeds: a lookalike built from the top 1% of spenders on a gambling or gacha title is a model of compulsive spending, and it will find vulnerable people efficiently. Inspect the seed list before the model runs.
- Mid-flight drift: automated bidding hunts cheap inventory, and child-heavy inventory is cheap. A campaign clean at launch can be delivering a third of impressionsimpressionsThe total number of times an ad or piece of content is displayed, regardless of clicks. Each display counts as one impression, even to the same person.View full definition → against kids' channels by week three. Set exclusions at account level and re-audit delivery weekly, not at wrap.
- Strictest-market default: apply Belgium's loot-box position and the highest consent age in the buy rather than one global setting.
Knowledge check
1. The Google/YouTube enforcement action illustrates a compliance gap that companies should close before launch. What was the core failure?
2. Why do regulators apply different legal standards to marketing aimed at children versus the general 'reasonable consumer' standard?
3. A mobile game is rated for general audiences but a marketing team discovers, through engagement data, that a large share of active users are under 13. Under the logic described in the lesson, what does this trigger?
4. Select ALL correct answers about how marketing obligations change when the audience includes children or other vulnerable groups.
Select all the correct answers.
5. Select ALL correct answers about who counts as a 'vulnerable audience' requiring special marketing protections, per the lesson's framing.
Select all the correct answers.
What "good" looks like in practice
The pattern regulators are pushing: classify first, and let classification gate the ad tech. YouTube Kids carries no personalised advertising and restricts ad formats and categories; TikTok runs a separate limited experience for younger US users with no personalised ads and no messaging. Both accept a worse product in exchange for a narrower liability.
Two consequences to plan for. Contextual-only inventory pays less, so kids' content drifts toward sponsorship and integration, which lands squarely under advertising rules including the CAP restriction on direct exhortation to children (pester power). And without identifiers you lose frequency capping and deduplicated reach, so a child can see the same spot thirty times in an afternoon and your measurement falls back on panels. Decide the acceptable exposure count before the buy, because the platform will not cap it for you.
🎬 [VIDEO: "How COPPA Works and Why It Matters" - youtube.com - FTC-adjacent explainer on children's online privacy law and advertising restrictions, useful as a primer before auditing your own ad stack]
Key takeaways
- COPPA's actual-knowledge trigger and the Children's Code's "likely to be accessed by children" test both catch general-audience media. Neither asks what your app store category says.
- One consent age across Europe is wrong somewhere: Article 8 leaves the threshold anywhere between 13 and 16 depending on the member state.
- Age rules are not age assurance. TikTok's £12.7 million ICO penalty and €345 million from the Irish DPC turned on 1.4 million under-13s getting past a policy that existed on paper.
- Vulnerability targeting usually happens by proxy, through a high-spender lookalike seed or an auto-optimising bid that finds cheap child-heavy inventory mid-flight. Audit seeds and delivery, not just creative.
- The compliance fix has a revenue tail: switching off personalised ads on children's content moved the cost onto creators after the 2019 YouTube settlement, and it will move onto your content P&L too. Budget for it before you promise the classification.