Your Kid Already Has a Digital Footprint. Most of It Wasn't Their Choice.

Children have 1,300+ images online by age 13 — most posted by parents. Here's what your kid's digital footprint actually looks like in 2026, why it matters, and what you can do about it now.

My daughter was nine when she asked me to take down a photo. It was a bath picture from when she was two — rubber ducks, bubbles, huge grin. I'd posted it the day I took it and hadn't thought about it since. Seven years it sat on my profile. Three hundred likes. Comments from people I haven't spoken to in a decade.

She didn't find it funny. She found it mortifying. And she was right to, because that photo had been publicly accessible for seven years, indexed by search engines, scraped by data brokers, and visible to anyone with a browser. I had not asked a two-year-old for permission because two-year-olds cannot give it. That was the problem.

Your kid's digital footprint is already bigger than you think. And if you're like most parents, you built the foundation yourself.

The footprint starts before they can walk

Ninety-two percent of American children under two already appear in online photos, according to research cited by Dark Reading. By age five, parents have posted an average of 1,000 images of their children. By thirteen, that number climbs past 1,300 photos and videos — a visual archive assembled entirely without the subject's consent.

This isn't a lecture about posting birthday photos. It's a question of scale. One thousand images contain metadata: timestamps, GPS coordinates, facial geometry. They contain information about your child's school uniform, their bedroom, their neighborhood park, their friends' faces. Data brokers don't see a cute bath photo. They see a dataset.

And that's just what parents post voluntarily. The involuntary side is worse.

The PowerSchool breach changed the math

In January 2025, a hacker accessed PowerSchool, a cloud-based student information system used by school districts across the country. The breach exposed over 62 million student records and nearly 10 million teacher records — the largest compromise of children's data in U.S. history.

What was in those records? Names, addresses, dates of birth, Social Security numbers. But also medical conditions, disability accommodations, individualized education plans, disciplinary histories, and family income data linked to free and reduced lunch programs. The Texas Attorney General's lawsuit against PowerSchool highlighted that even bus stop information was exposed — data that could be used to physically locate a child.

The attacker, a nineteen-year-old Massachusetts college student, demanded $2.85 million in ransom. He was eventually sentenced to four years. The 62 million children whose records were exposed got credit monitoring.

Here's what most parents miss: for those kids, the breach isn't over. It will never be over. An exposed Social Security number doesn't expire. A child whose SSN was leaked at age seven will carry that vulnerability into every credit application, apartment lease, and job background check for the rest of their life.

Children are 51 times more likely to have their identity stolen

That number comes from AZFamily's reporting on identity theft research released in May 2026. Roughly 1.25 million children are victims of identity theft each year. The damage totals an estimated $2.6 billion annually.

Why children? Because nobody checks. A seven-year-old doesn't apply for credit cards. A twelve-year-old doesn't file taxes. A stolen child identity can be used for years — to open credit accounts, purchase homes, secure employment — before anyone notices. Most victims don't discover the theft until they're adults, often when they apply for their first student loan or apartment and find a credit history they never created.

Sixty percent of child identity theft is committed by someone the child knows. A family member. A parent's partner. Someone with access to the mailbox or the filing cabinet. But the other forty percent? That's PowerSchool. That's data brokers. That's the apps your eight-year-old taps "accept" on without reading a word.

Your kid is tapping "accept" on things you haven't discussed

The UK's Information Commissioner's Office (ICO) published a survey in April 2026 based on 1,000 parents of children aged four to eleven. Seventy-five percent of parents said they feared their child couldn't make safe online privacy choices. That fear is well-founded: the survey revealed that a single tap on "accept" in an app or game can expose friendships, interests, mood patterns, and even sleep data.

But here's the part that got me: twenty-one percent of parents had never spoken to their children about online privacy. Not once. And thirty-eight percent discussed it less than once a month. Meanwhile, ninety percent had talked about screen time in the past month.

We've been obsessing over how long kids are online and almost completely ignoring what they're giving away while they're there.

Proton's March 2026 survey of 1,216 U.S. parents confirmed the pattern. Seventy-eight percent were concerned about their child's online privacy. Fifty-eight percent feared their child's identity could be stolen before adulthood. Sixty-five percent believed tech companies are failing to protect children's privacy. Sixty-three percent said Big Tech is actively profiting from their child's data.

They're right. And knowing it doesn't fix it without action.

Sharenting isn't a parenting failure. But it is a data problem.

I want to be careful here. Posting photos of your kids isn't inherently dangerous, and framing it that way is unhelpful. Parents share because they're proud, because grandparents live far away, because community matters. Shaming parents for sharenting misses the point entirely.

The point is that most parents don't understand what happens to the content after they post it. Research on sharenting has documented risks including digital kidnapping (where strangers download and repost children's photos as their own), identity theft from exposed personally identifiable information, and the creation of facial recognition profiles that will follow children into adulthood. One study found that children's digital footprints typically begin before their first birthday — usually with an ultrasound image or birth announcement.

And children, when they're old enough to have opinions, tend to have strong ones. Research consistently shows that kids feel uncomfortable when they discover the extent of their online presence. They didn't consent. They couldn't have. That gap between a parent's intent and a child's experience is worth sitting with.

Sixty-two percent of parents in Proton's survey said they would choose to erase their child's entire online history and start fresh if they could. That's not guilt. That's recognition.

What actually works

I've read enough "ten tips to protect your child's digital footprint" articles to know that most of them are useless. They tell you to "be mindful" and "think before you post," which is the online safety equivalent of telling someone to "just eat less."

Here's what I've found actually changes something:

Audit what's already out there. Search your child's full name in Google, in quotes. Check image results. Check your own social media going back to when they were born. You will find things you forgot about. Some of them will make you uncomfortable. That discomfort is useful.

Lock down the metadata. Before posting any photo, strip the location data. On iPhones, go to the photo, tap the info button, tap the location, and select "Remove Location." On Android, it's in the photo details. This takes four seconds and prevents your child's school, home, and daily routine from being mapped by anyone with access to the image file.

Have the privacy conversation, not just the screen time conversation. The ICO's data shows we've gotten good at talking to kids about how long they're online. We need to get equally good at talking about what information they're giving away. Ask them: "What did that app ask you for when you signed up? Did it want your real name? Your birthday? Your school?" If they don't know, help them find out.

Freeze your child's credit. This is the single most effective protection against child identity theft, and almost nobody does it. You can freeze a minor's credit with all three bureaus — Equifax, Experian, and TransUnion — for free. It takes about fifteen minutes per bureau. A frozen credit file means nobody can open accounts in your child's name, even if they have the Social Security number. When your child turns eighteen, they can unfreeze it themselves.

Remove stored personal information from apps. Go through every app your child uses. Check what permissions each one has. Does a game need access to contacts? Does a drawing app need location services? Revoke everything that isn't essential to the app's core function. Then check again in three months, because app updates quietly re-enable permissions.

Talk to your child's school about data practices. After PowerSchool, this isn't optional. Ask: What student information system does the school use? Has it been audited? Does it require multi-factor authentication? What data is collected beyond what's educationally necessary? You have a right to this information under FERPA, and schools are required to provide it.

The system is broken. You shouldn't have to do this alone.

I want to be honest about something: the fact that parents need a six-step action plan to protect their child's basic privacy is itself a failure. It shouldn't require a credit freeze to keep a seven-year-old's identity safe. It shouldn't require stripping metadata from a birthday photo to keep your address private. These are structural problems that require structural solutions.

The Kids Online Safety Act is working its way through Congress again. The ICO has issued open letters to tech firms demanding stronger age verification. States are expanding children's online safety laws to cover AI chatbots. COPPA was updated in June 2025 to require separate parental consent for third-party data sharing. These are real steps.

But legislation moves slowly, and data breaches don't wait. Your child's digital footprint is being assembled right now, from multiple sources, by multiple parties, with or without your knowledge. Some of it you created. Some of it their school created. Some of it they created themselves by tapping "accept" on a permission screen designed to be ignored.

The good news: you can start reducing that footprint today. Not by going offline — that ship sailed — but by understanding what's out there, closing the gaps you can close, and teaching your child to ask questions before they tap.

At Digipalz, our Digital Citizenship curriculum teaches kids to understand their digital footprint before someone else uses it against them. Because the goal isn't to make kids afraid of the internet. It's to make sure the internet doesn't know more about them than they know about themselves.

If you suspect your child's identity has been stolen: