New Data Privacy Proposal Points the Way Toward Possible Compromise Between Tech Cos and Users

The News: A sweeping new data privacy proposal could point the way toward a possible comprise between tech companies and users. The Age Appropriate Design Code is a new British online data privacy proposal aimed at increasing protections for children online. Coming on the heels of the otherwise comprehensive 2018 Data Protection Act, this new proposal outlines new rules that specifically address online safety for minors. Per the New York Times:

“The rules will require social networks, gaming apps, connected toys and other online services that are likely to be used by people under 18 to overhaul how they handle those users’ personal information. In particular, they will require platforms like YouTube and Instagram to turn on the highest possible privacy settings by default for minors, and turn off by default data-mining practices like targeted advertising and location tracking for children in the country.”

A similar set of guidelines, dubbed COPPA (the 1998 Children’s Online Privacy Act), already exists in the United States but only applies to children under 13. The Age Appropriate Design Code is scheduled to go before British parliament for a vote sometime this year, and to be applied soon after.

Sweeping new data privacy proposal points the way toward possible compromise between tech companies and users

Analyst Take: It’s hard to argue against the fact that both the Age Appropriate Design Code and the 2018 Data Protection Act are important keys to providing protections for minors and keeping them safe online. That said, the chasm between what technology companies think is ‘the right thing to do’ and what users are comfortable with as it relates to personal data privacy, for themselves and their children is, in most instances, a deep one. Here’s a look at some of what I think the most important elements of this discussion, especially as it relates to the new data privacy proposal, include:

Protecting the rights and safety of children online is important, but not without issues

Some tech industry lobbyists have argued that while the objective of the proposal is noble, the rules themselves, or how they would require technology platforms to comply to data privacy rules, may run afoul of its intent, and may even cause more harm than they aim to correct. Age-gating for instance, could unnecessarily limit the types of services that a website or platform provides. Small companies may also no longer be able to provide or direct effective advertising services to young adults — from introducing them to content that specifically caters to their tastes, to notifying them of products and offers that would likely be of value to them. An argument can also be made that in order to ensure compliance with regard to age verification, platforms may have to collect more data from would-be users than they might have otherwise collected absent these rules.

Expanding the same protections to other vulnerable online users is possible — why not do it?

While tech companies and regulators work on data privacy details, what struck my eye about this proposal is twofold:

First, it hints at a possible expansion of data privacy and protection rules based on age where such data protections already exist but only apply to children under 13, instead of children under  18. This upward shift in age inclusion opens the door to the next logical question: If tech companies can do this for 13 and 18 year olds, why can’t they also do it for 25 year olds, 45 year olds, and 75 year olds? Or rather, why must basic data protection rules be predicated on age at all? Why not just make them universal? Is there a compelling reason why adult users of technology platforms deserve to be put at greater risk of stalking, harassment, hacking, doxing, and violence than their younger counterparts?

Second, many of the tools and practices to be set in place to protect children’s data online could presumably be used to protect adults as well. For instance, one tenet of the new code focuses on tech companies “thinking about the risks to children that would arise from collecting and processing of their personal data works equally well with adults.” Following the same logic, this premise could also be required to consider the risks to women, vulnerable communities, users living with disabilities, and the elderly that could arise from collecting and processing their personal data. If companies understand that children must be protected online because they are vulnerable to a plethora of threats, shouldn’t these same companies also understand that other users are vulnerable as well? And therefore, is there a rational reason why some vulnerable users should be protected but not others? From a regulatory or legislative standpoint, could it not be argued that it is in the public interest for these same companies to extend privacy and online safety protections to other vulnerable users besides children?

Taking that logic a step further, could it not be argued that since all users are inherently vulnerable to data theft, privacy abuses, stalking, fraud, harassment, and a plethora of unpleasantness and genuine threats, these same tech platforms have a responsibility to protect all users as best they can?

Expanding these protections to all users by default only makes sense

The Code’s 15 governing principles can almost all be expanded to adult users: “Best interest of the child” can just as easily become “best interest of the user.” The “data protection impact assessment” can also easily be applied to users of all ages. Data collection features being required to be set on the highest data privacy settings by default also doesn’t have to be limited to children. With regard to data sharing: “Do not disclose children’s data unless you can demonstrate a compelling reason to do so, taking account of the best interests of the child” can easily become “Do not disclose users’ data unless you can demonstrate a compelling reason to do so, taking account of the best interests of the user.” One can go down the list of all 15 principles and make the same observation each time.

There is a template here, for universal data privacy and online safety

This is the crux of what I see as a possible direction for data privacy regulations aiming to help tech companies and their users find a healthier balance than the one currently being debated around the world. Based on this latest effort, it would essentially look like this:

  1. A shift from an opt-out data privacy model (in which the default could be maximum data collection and the user must actively opt out of it) to an opt-in data privacy model (in which the default is minimum data collection, and the user has to opt in to more data collection in order to benefit from more data-dependent services).
  2. An emphasis on putting the best interest of the user front and center of all data collection and processing decisions, not just as a matter of culture but as a matter of law.
  3. Controls, some on the user side, some on the platform side, that allow users to determine what types of content they are comfortable with receiving or being exposed to, and in some cases, even be protected from.
  4. A deliberate restoration of trust in the platform-user relationship (further reinforced by policies of transparency and clear disclosure).

Because these principles, along with the tools and data privacy practices that will enable their execution, can be expanded to all age groups, and also because users and the governments they look to to protect them from exploitation, fraud, loss of privacy, and other threats have been actively looking to address the dual issue of digital privacy and digital security, I see in this proposal a template for what could become a model for universal data privacy and online safety requirements. Ideally, technology platforms would adopt this approach all on their own, but if they cannot, or will not, legislatures and regulatory bodies around the world may begin to feel growing pressure to step in and compel them to do so.

Futurum Research provides industry research and analysis. These columns are for educational purposes only and should not be considered in any way investment advice.

Other insights from the Futurum Research team:

IOT Cybersecurity Regulations Kick In With the Start of 2020

Facebook Doesn’t Really Care About Your Privacy — and This is Why It Hurts Libra

Why CMOs Need to Be Involved in Privacy Policy Creation

 

 

Author Information

Olivier Blanchard

Olivier Blanchard is Research Director, Intelligent Devices. He covers edge semiconductors and intelligent AI-capable devices for Futurum. In addition to having co-authored several books about digital transformation and AI with Futurum Group CEO Daniel Newman, Blanchard brings considerable experience demystifying new and emerging technologies, advising clients on how best to future-proof their organizations, and helping maximize the positive impacts of technology disruption while mitigating their potentially negative effects. Follow his extended analysis on X and LinkedIn.

Related Insights
Will Rapid7's 2026 PACT Program Redefine Partner-Led Cybersecurity Growth?
August 1, 2026

Will Rapid7’s 2026 PACT Program Redefine Partner-Led Cybersecurity Growth?

Rapid7 enhances its 2026 PACT Partner Program to boost co-sell execution and ecosystem alignment, capitalizing on surging demand as 82% of sellers expect significant growth....
Are TP-Link's New Vulnerabilities a Wake-Up Call for IoT Security?
August 1, 2026

Are TP-Link’s New Vulnerabilities a Wake-Up Call for IoT Security?

Forescout's research reveals critical vulnerabilities in TP-Link routers through Zero Touch Provisioning, exposing dangerous gaps between automated device management and enterprise security that demand immediate attention....
Thales's NATO Partnership Signals a New Era in Defense Technology
August 1, 2026

Thales’s NATO Partnership Signals a New Era in Defense Technology

Thales's successful strike system test strengthens its position as a sovereign defense integrator, enabling its cybersecurity portfolio to capture market share across government, infrastructure, and enterprise sectors....
Sofigate's ISO 27001 Certification: A Strategic Move in Cybersecurity
August 1, 2026

Sofigate’s ISO 27001 Certification: A Strategic Move in Cybersecurity

Sofigate's ISO 27001 certification strengthens its competitive position by validating robust information security practices that enterprise buyers demand for agentic AI deployments in the $762B software market....
AI-Driven Phishing Defenses Increase Costs for Security Teams
August 1, 2026

AI-Driven Phishing Defenses Increase Costs for Security Teams

AI-powered email defenses accelerate response times, yet AI-generated phishing attacks simultaneously inflate protection costs, challenging AI-native platforms' efficiency promise....
ClawArmor's Innovative Approach to Securing OpenClaw Instances
August 1, 2026

ClawArmor’s Innovative Approach to Securing OpenClaw Instances

OpenClaw's 247,000 GitHub stars in 60 days accelerated enterprise AI adoption. AccuKnox's ClawArmor addresses the 58.6% of organizations mandating automated verification for AI-generated code in a $344B market by 2028....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.