Disney Fined $10M for Violating Children’s Privacy Laws on YouTube

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
In a major move to protect families online, the US Department of Justice (DoJ) announced on December 31, 2025, that Disney has agreed to pay a $10 million civil penalty. The settlement comes after a deep look into how the company handled its massive YouTube presence.

What Went Wrong?

Full Story:
 
Full Story:
The HackRead post is broadly consistent with the official filings, but it appears to be off by a day on the announcement date.

What actually happened (verified)
  • The U.S. Department of Justice (DoJ) announced on December 30, 2025 (not Dec 31) that a federal court entered a stipulated order resolving COPPA allegations against Disney entities, with a $10 million civil penalty.
  • The matter was investigated/negotiated by the FTC and then referred to the DoJ.
  • Core allegation: Disney allegedly failed to properly label some YouTube uploads as “Made for Kids”. The government said this allowed collection/use of children’s data for targeted ads without the required parental notice/consent under COPPA.
  • In addition to the penalty, the order includes an injunction and requires a compliance/review program for how Disney designates YouTube content (with some forward-looking language tied to possible “age assurance” on YouTube).

What this means for families (practical impact)
This is an enforcement action about how a content operator labels kid-directed content and how that interacts with data collection/ads on a major platform. It does not automatically mean any individual viewer can confirm their child’s data was “stolen” or that a device is infected—this is a privacy/compliance issue, not a malware incident.

If you want to reduce child tracking risk on YouTube regardless of this case, the safest/common-sense steps are:
  • Use YouTube Kids or a supervised experience for minors rather than a normal adult account.
  • Limit ad personalization: in Google account settings, reduce/disable ad personalization for the child profile (where available) and avoid sharing a parent’s logged-in account with a child.
  • Tighten content controls: Restricted Mode (not perfect), disable autoplay, and keep watch/search history minimal where appropriate.
  • Keep devices updated and run reputable security software, but treat this primarily as a privacy/settings issue rather than something an antivirus “fixes.”

Bottom line
The “$10M COPPA/YouTube labeling” settlement is real, but the official DoJ announcement date is December 30, 2025. For families, the best takeaway is to use kid-focused modes/supervision and privacy settings to reduce data collection exposure.

Sources
 
Industry Perspective (SANS / NIST)

From a security and privacy compliance perspective (referencing SANS Management 514 and the NIST Privacy Framework), this incident highlights a critical gap in Third-Party Risk Management (TPRM).

Asset Management (SANS CIS Control 1)

Organizations often catalogue internal servers but fail to catalogue "cloud assets" like social media channels. Each YouTube video is an asset that carries regulatory risk.

Privacy by Design

The settlement requires Disney to implement a "specific program" for compliance. In industry terms, this implies a mandatory governance layer where legal/compliance teams must verify metadata tags ("Made for Kids") before content publication.

The "Roblox" Parrallel

The Hackread article draws a parallel to Roblox. This establishes a clear trend, regulators are moving beyond static websites to police immersive platforms and video streams where data collection is passive and often invisible to the user.

Recommendations

For organizations and privacy-conscious users, the following actions are derived from this ruling.

For Organizations (Content Creators/Brands)

Audit Third-Party Footprint


Immediately review all corporate channels (YouTube, TikTok, Roblox) to ensure content settings match the target audience age group.

Enforce Classification

Update publishing Standard Operating Procedures (SOPs) to require a "Privacy Impact Assessment" (PIA) for new content channels.

Verify "Child-Directed" Status

If content subjects include animation, toys, or child-oriented activities, defaulting to "Made for Kids" (or equivalent) is the only safe harbor under COPPA.

For End Users (Parents)

Trust but Verify


Do not assume major brands automatically protect privacy. Use platform-level controls (e.g., YouTube Kids app) rather than relying on the content creator's settings.

Review Permissions

Regularly audit permissions for apps and platforms used by children, specifically looking for "advertising tracking" or "personalization" toggles.

References

SANS / CIS Critical Security Controls
CIS Controls v8.1

NIST Privacy Framework
NIST Privacy Framework Version 1.1.


Regulation

Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506

Related Precedent
FTC v. Google LLC and YouTube, LLC (2019) - $170M Settlement

Source Article
Disney Fined $10M for Violating Children’s Privacy Laws on YouTube - Hackread.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top