---
title: "Pixalate’s State of Children's Privacy on Mobile Apps: APAC"
description: "Pixalate’s State of Children's Privacy on Mobile Apps Report: APAC highlights app developers’ potential violation risks under the COPPA act."
image: https://www.pixalate.com/hubfs/STATE%20OF%20CHILDREN%E2%80%99S%20PRIVACY%20ON%20MOBILE%20APPS_%20APAC%20-%20Q3%202025.png
---

[![pixalate-logo-red-small](https://www.pixalate.com/hs-fs/hubfs/2018NewTemplate/pixalate-logo-red-small.png?width=150&height=46&name=pixalate-logo-red-small.png "pixalate-logo-red-small")](https://www.pixalate.com/?hsLang=en)

# **State Of Children’s Privacy On Mobile Apps Report: Asia-Pacific (APAC)**

Pixalate’s **Q3 2025 State Of Children’s Privacy On Mobile Apps Report: Asia-Pacific (APAC)** is part of its COPPA Violation Risks in Mobile Apps series, highlighting APAC-registered app developers that have likely child-directed apps downloadable from the Google Play Store and the Apple App Store that are at risk of violating the United States’ Children’s Online Privacy Protection Act (COPPA).

**Download the Q3 2025 report, along with two complete lists of APAC-registered, child-directed apps:**

- Apps in violation of the COPPA Rule
- Apps identified as likely failing to obtain a Verifiable Parental Consent (VPC)

### Download Report

*By clicking Download and entering your email address, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms?hsLang=en) and have read and acknowledge our [Privacy Policy](https://www.pixalate.com/privacy-policy?hsLang=en).*

## **Key Q3 2025 takeaways:**

- Pixalate flagged 1,248 APAC-registered, child-directed apps for **likely violating COPPA**.
- These apps unlawfully processed the personal information of an estimated **117 million U.S.-based Lifetime App Users**–the majority likely children.
- 1,198 likely shared U.S. child app users’ **Device IDs in the advertising bid stream**.
- 962 apps **failed to provide the ‘Children's Privacy’ disclosure** required under the COPPA Rule, as measured by Pixalate.
- Of 1,003 ad-enabled APAC-registered child-directed apps analyzed, **1,001 failed to obtain Verifiable Parental Consent (VPC)** before collecting personal information, per Pixalate’s findings.

## **About: ‘State Of Children’s Privacy On Mobile Apps Report: Asia-Pacific (APAC)’**

This report investigates and discusses several privacy violations of the United States’ [Children’s Online Privacy Protection Act (COPPA)](https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa) by mobile app developers registered within the Asia Pacific (APAC) market (e.g. Singapore, People’s Republic of China, Vietnam, Japan, South Korea and others). Although the identified app developers are based outside of the United States (U.S.), their child-directed mobile apps are offered to and accessed by app users–the majority of whom are children–within the U.S.

Based on COPPA’s scope and a thorough application of data privacy compliance analysis, Pixalate identified **1,248** APAC-registered and child-directed apps that are violating the COPPA Rule, especially provisions addressing the collection, use, sale, and disclosure of personal information of U.S.-based child app users under the age of 13.

Pixalate also observed that from a dataset of **1,003** APAC-registered and child-directed apps, **1,001** apps violated the requirement of obtaining a Verifiable Parental Consent (VPC) under COPPA.

For this report, Pixalate’s legal and data science teams analysed the privacy policies* of around **23,097** child-directed apps with ads** that were** **downloadable from the Google Play Store and Apple App Store in **Q3 2025**. From this number, **7,524** child-directed apps were determined to be registered in the APAC region and **1,248 **of these were likely violating COPPA. The data in this report is derived from conducting manual assessments and systematic browsing or ‘crawls’ of the Google Play and Apple App Stores, performed via Pixalate’s proprietary technologies and detection systems.

**References to ‘no privacy policy/policies’ or ‘no privacy policy/policies detected’ indicate that Pixalate’s proprietary systems were unable to detect or identify a purported privacy policy/notice URL or the requisite disclosures at the time of crawling the App Stores, pursuant to Pixalate’s proprietary privacy policy detection and classification system. To learn more, please refer to the Methodology section.  
****Having programmatic traffic, with ad impressions in the United States. For a detailed explanation, please refer to the Methodology section.

*

## **COPPA: Applicability of COPPA in APAC**

### **What is the Children’s Online Privacy Protection Act (COPPA)?**

The Children’s Online Privacy Protection Act (COPPA) was enacted in 1998 in the U.S. to protect the privacy of children under the age of 13 in the digital online environment. COPPA is enforced by a consumer protection U.S. government agency, the Federal Trade Commission (FTC).

The FTC conducts investigations and takes rigorous legal actions by imposing hefty fines against numerous national and international businesses, including app developers, that are found to be violating COPPA’s requirements when collecting, using, sharing or selling children’s personal information.

### **Are you subject to COPPA?**

APAC-registered app developers are likely subject to COPPA if they are ‘Operators’ of ‘child-directed’ apps and are collecting personal information* via such apps from U.S.-based children under the age of 13.

**individually identifiable information about an individual collected online - See 16 CFR 312.2 “Personal information”* 

#### **What is an Operator?**

Any person who operates a website or online service and collects, maintains, or uses personal information of U.S.-based children under 13. Examples:

- Mobile App Developers
- Businesses with child-directed website(s) 
- Online platforms accessible and used by children

#### **What is Child-Directed?**

Under COPPA, the FTC relies on 10 factors to determine if your app or online services are directed towards children. These factors range between: subject matter, visuals, animation usage, music/audio content, age of characters & more.

#### **As an app developer, COPPA applies to you if:**

You operate apps that are targeted towards and accessible by U.S.-based children aged under 13, and collect, use, or disclose personal information of U.S.-based children. If both conditions apply, the app developer qualifies as an ‘Operator’ and their apps would be deemed by the FTC as ‘covered’ child-directed apps.

**Your apps will also qualify as ‘covered’ apps subject to COPPA if:**

1. You operate apps that can qualify as **‘general audience’** apps i.e. apps designed for a broader adult audience, but you have **actual knowledge** that you are collecting, using, or disclosing personal information from U.S.-based children aged under 13; or
2. You operate apps that may not specifically target children under age 13 as their primary audience, but are designed to target younger teens and adults.*  These types of apps are called** ‘Mixed Audience’** apps and are a subcategory of child-directed apps, or
3. You have actual knowledge that your apps are collecting personal information directly from users of another website/online service that is directed to U.S.-based children, ([16 C.F.R. § 312.3](https://www.ecfr.gov/current/title-16/part-312#p-312.3(General%20requirements))).

**According to the FTC, ‘mixed audience’ websites and online services are a subcategory of those operators that are deemed ‘child-directed.’ This includes apps that do not “target children children as its primary audience,” meaning it can cover apps that also target older teens and adults.*

 

**See also:**

- … [Verifiable Parental Consent (VPC) Failures under COPPA in Mobile Apps](https://www.pixalate.com/verifiable-parental-consent-vpc-failures-under-coppa-in-mobile-apps?hsLang=en)
- … [GDPR-K & UK Children’s Code Privacy Violations Report](https://www.pixalate.com/gdpr-k-uk-childrens-code-privacy-violations-report?hsLang=en)
- ... [Made-for-Advertising (MFA) Benchmarks](https://www.pixalate.com/made-for-advertising-mobile-report?hsLang=en)
- ... [IVT & Ad Fraud Benchmarks Report](https://www.pixalate.com/invalid-traffic-benchmarks-report-global?hsLang=en)

 

### **About Pixalate**

*Pixalate is a global platform for privacy compliance, ad fraud prevention, and data intelligence in the digital ad supply chain. Founded in 2012, Pixalate’s platform is trusted by regulators, data researchers, advertisers, publishers, ad tech platforms, and financial analysts across the Connected TV (CTV), mobile app, and website ecosystems. Pixalate is MRC-accredited for the detection and filtration of Sophisticated Invalid Traffic (SIVT).*

### Schedule a Demo

![pixalate-logo-red-small](https://www.pixalate.com/hs-fs/hubfs/2018NewTemplate/pixalate-logo-red-small.png?width=208&name=pixalate-logo-red-small.png "pixalate-logo-red-small")

**

 By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms?hsLang=en) and [Privacy Policy](https://www.pixalate.com/privacypolicy?hsLang=en)

Products

[Analytics](https://www.pixalate.com/products/analytics?hsLang=en) [Blocking](https://www.pixalate.com/products/blocking?hsLang=en) [Media Rating Terminal](https://www.pixalate.com/products/mrt?hsLang=en) [Publisher Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex&hsLang=en) [Seller Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex&hsLang=en) [IoT Device Rankings](https://www.pixalate.com/rankings/?group=app&reportId=iotDeviceReach&hsLang=en)

Resources

[Blog](https://blog.pixalate.com/?hsLang=en) [Press](https://www.pixalate.com/press?hsLang=en) [Careers](https://www.pixalate.com/jobs?hsLang=en) [Team](https://info.pixalate.com/pixalate-leadership-team?hsLang=en)

Contact

Email

[** sales@pixalate.com ](mailto:sales@pixalate.com)

[** privacy@pixalate.com ](mailto:privacy@pixalate.com)

US:

[** +1 888 749 2528 ](tel:+1%20888%20749%202528)

EU:

[** +44 (0)800 011 2050 ](tel:+44%20(0)800%20011%202050)

Slack:

[Join ATSAPI Slack Channel ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

Offices

Global Offices

US

1775 Greensboro Station Place, Suite 425, McLean, VA 22102

UK

20 North Audley Street   
London, W1K 6WE, United Kingdom

EU

10 Earlsfort Terrace   
Dublin 2, D02 T380, Ireland

Singapore

10 Anson Road, #22-02 International Plaza, Singapore 079903

[![facebook](https://www.pixalate.com/hubfs/footer/icons/facebook.png) ](https://www.facebook.com/pixalate) [![x](https://www.pixalate.com/hubfs/footer/icons/twitter-x.png) ](https://twitter.com/pixalateinc) [![linkedin](https://www.pixalate.com/hubfs/footer/icons/linkedin.png) ](https://www.linkedin.com/company/pixalate) ![wechat](https://www.pixalate.com/hubfs/footer/icons/wechat.png) [![slack](https://www.pixalate.com/hubfs/footer/icons/slack.png) ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

[Terms of Use](https://www.pixalate.com/terms?hsLang=en) [Privacy Policy](https://www.pixalate.com/privacypolicy?hsLang=en) [GDPR Compliance](https://www.pixalate.com/gdpr?hsLang=en) Disclaimer

Copyright © 2025 Pixalate

[Back to top **](https://www.pixalate.com/pixalates-state-of-childrens-privacy-on-mobile-apps-apac#)

# Disclaimer

 Disclaimer: The content of this page reflects Pixalate’s opinions with respect to the factors that Pixalate believes can be useful to the digital media industry. Any proprietary data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate’s opinions are just that - opinion, not facts or guarantees.

 Per the MRC, “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes. Also per the MRC, “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”

**

**

*By clicking Download and entering your email address, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms?hsLang=en) and have read and acknowledge our [Privacy Policy](https://www.pixalate.com/hubfs/2024-08-20_Pixalate_Privacy_Policy.pdf?hsLang=en).

*Copyright © 2025 Pixalate** *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

*

×

## Subscribe to the Pixalate Blog

The first step in ad fraud prevention.

Loading...

 By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms?hsLang=en) and [Privacy Policy](https://www.pixalate.com/privacypolicy?hsLang=en).

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Contact Us12

Loading...

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Download GSTI

Loading...

Schedule your demo today

Please complete all fields

Loading...

By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms?hsLang=en) and [Privacy Policy](https://www.pixalate.com/privacypolicy?hsLang=en).

*

* *

* *