Under-14 PI is SPI. A teenage checkbox is not guardian consent.
PIPL treats personal information of minors under 14 as sensitive PI. Processing generally needs the guardian’s consent, a specific purpose, and heightened protection. CAC provisions on children’s PI add duties on notices, dedicated rules, and strict sharing. Age-gating that assumes every user is 18 is a product risk, not a legal strategy. EdTech, games, communities and UGC are in the blast radius. Under-14 is the SPI line; other minor protections can still apply above 14. Do not mix this page with the general SPI list — it is the children’s overlay.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Can users be under 14?
Games, education, UGC, family apps.
AgeHow is age actually checked?
Self-declare vs real gate.
GateWho is the guardian and how is consent captured?
Separate, verifiable.
GuardianIs sharing or export in play?
Stricter SPI plus CBDT.
ShareWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
What about 14–17 year olds?
They are not in the under-14 SPI bucket, but other youth and platform rules can still apply. Do not treat 16 as ‘adult’ for every product.
Is COPPA a substitute?
No. US COPPA does not replace PIPL or CAC children’s-PI rules for PRC users.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
