Roblox Corporation, one of the world's largest gaming platforms with over 70 million daily active users, faces mounting scrutiny over its data privacy practices—particularly regarding the collection, storage, and monetization of children's personal information. As a platform where approximately half of all users are under the age of 13, Roblox occupies a uniquely sensitive position in the digital landscape: it is simultaneously a playground for children and a data-driven advertising business.
This report examines the full scope of Roblox's data privacy violations, from noncompliance with the Children's Online Privacy Protection Act (COPPA) to the opaque handling of biometric data through third-party age verification systems. The findings reveal a pattern of expansive data collection that far exceeds what is disclosed in the company's privacy policy, a series of policy revisions that may amount to cosmetic changes rather than substantive reform, and significant risks posed by third-party data sharing arrangements.
The stakes are enormous. Under COPPA, penalties can reach $50,120 per violation. With tens of millions of children using the platform, the potential liability runs into the billions. More importantly, the long-term consequences for the children whose data is collected, analyzed, and shared remain poorly understood and largely unregulated.
The Children's Online Privacy Protection Act (COPPA) is a federal law enacted in 1998 that imposes requirements on operators of websites and online services directed at children under 13, or that have actual knowledge of collecting personal information from children under 13. The law requires:
COPPA is enforced by the Federal Trade Commission (FTC), which has the authority to bring enforcement actions and impose civil penalties.
Despite its massive child user base, Roblox has been subject to significant criticism—and regulatory action—over its COPPA compliance.
The FTC investigated Roblox for collecting geolocation data, chat logs, behavioral data, and device identifiers from millions of children under the age of 13. This investigation revealed a stark disconnect between what Roblox's privacy policy claimed and what the platform actually did in practice.
Roblox's privacy policy has historically stated that it only collects limited information from users under 13:
However, the FTC's findings indicated that Roblox's actual data collection practices were far more expansive. The platform collected:
This discrepancy between stated policy and actual practice is a hallmark of COPPA noncompliance. The FTC has consistently held that privacy policies must accurately describe data collection practices, not merely list a minimal set of data points while collecting far more.
Under COPPA, the FTC can impose penalties of $50,120 per violation as of 2023 adjustments. Given that Roblox has had tens of millions of child users, the theoretical maximum penalty is staggering. However, FTC settlements typically involve negotiated amounts far below the statutory maximum.
The FTC has been increasingly aggressive in COPPA enforcement in recent years, setting a clear trajectory toward harsher penalties:
| Company | Year | Fine | Key Violation |
|---|---|---|---|
| Epic Games (Fortnite) | 2022 | $520 million | COPPA violations and dark patterns |
| Microsoft (Mojang) | 2023 | $20 million | Failure to obtain parental consent |
| Disney | 2023 | $10 million | Data collection without consent on child-directed content |
| HoYoverse (Genshin Impact) | 2024 | $20 million | Violating children's privacy rules |
The Epic Games settlement is particularly instructive. Epic was fined $520 million—comprising a $275 million COPPA penalty and $245 million for dark patterns—for practices remarkably similar to those alleged against Roblox: collecting children's data without consent and exposing children to potentially harmful communications.
This trajectory suggests that any future FTC action against Roblox would likely result in a settlement in the hundreds of millions, if not billions, of dollars—particularly given Roblox's larger child user base compared to most of the companies listed above.
Roblox's data collection extends far beyond the limited information disclosed in its child-facing privacy policy. A comprehensive analysis of the platform's data practices reveals extensive collection across multiple categories:
Beyond directly collected data, Roblox also generates inferred data about its users:
In late 2025, Roblox introduced a third-party age verification system operated by Persona, a digital identity verification company. While framed as a safety measure, this system introduces significant new privacy risks.
The Persona age verification system collects:
Perhaps most concerning are Persona's data retention and usage practices:
This means that children's facial biometrics—arguably the most sensitive category of personal data—are being collected, stored for years, and used for purposes that extend beyond simple age verification, all through a third party whose privacy practices most parents have never reviewed.
Roblox's privacy policy explicitly acknowledges sharing data with:
Under the broad definition of "sale" in the California Consumer Privacy Act (CCPA), certain data sharing practices may constitute a sale of children's data. The CCPA defines "sale" broadly as "selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's personal information by the business to a third party for monetary or other valuable consideration."
Given that Roblox shares user data with advertising partners—and derives advertising revenue from this practice—the sharing of children's behavioral data may constitute a sale under CCPA, which carries additional requirements and penalties.
Roblox has made several notable changes to its privacy policy in recent years, particularly in response to increased regulatory scrutiny and public pressure.
In May 2026, Roblox updated its privacy policy to restrict personalized advertising for users under 18. This change represented a significant shift from previous practice, where behavioral data from minors was used to serve targeted advertisements.
However, the practical impact of this change remains questionable:
In March 2026, Roblox clarified that parent email addresses constitute the only category of COPPA-covered personal information collected from children under 13. This clarification was notable for its narrowness—it essentially confirmed that Roblox's official position is that the only regulated personal information it collects from children is the parent's email address used for consent.
This position is difficult to reconcile with the FTC's findings regarding extensive behavioral and device data collection.
Roblox's privacy policy changes follow a pattern common in the technology industry: cosmetic revisions that address the most visible criticisms without fundamentally altering data practices. Key indicators of this pattern include:
Previous versions of the privacy policy contained more ambiguous language about the use of data for advertising, which may have been intentional to allow maximum flexibility in data monetization.
Roblox's child user base is enormous:
Children's behavioral data is used to optimize engagement—a practice that raises significant ethical concerns:
Children's data informs broader advertising strategies:
A BBC investigation into Roblox's age verification practices revealed inadequate safeguards:
This investigation demonstrated that Roblox's age-based privacy protections are undermined by the platform's failure to verify user ages accurately.
The core issue is one of informed consent. Children under 13 cannot legally consent to data collection, and parents often lack the technical understanding to evaluate the scope of data being collected from their children. Roblox's privacy policy—while technically available to parents—uses language and concepts that are difficult for non-technical users to evaluate.
Moreover, the platform's design encourages children to engage deeply with its features, generating vast quantities of behavioral data that the children (and often their parents) are unaware is being collected.
Roblox shares user data with advertising partners, creating a chain of data custody that extends well beyond the platform itself:
Each of these transfers represents a point at which children's data may be exposed to additional parties, each with their own data retention and sharing practices.
Beyond advertising, Roblox's platform includes various forms of third-party tracking:
Roblox data may be combined with data from other platforms and services:
The third-party age verification tool operated by Persona represents a particularly acute third-party risk:
The European Union's General Data Protection Regulation (GDPR) imposes strict requirements on the processing of children's personal data:
Roblox's expansive data collection practices may violate multiple GDPR provisions, particularly:
Per Roblox's policy, information from EEA child accounts is not used or shared without parental consent. However, this policy faces several credibility challenges:
Multiple countries are investigating Roblox's data practices:
In late 2025, Roblox introduced an AI-powered age estimation system as an alternative to traditional age verification. This system represents a fundamental tension between child safety and data privacy.
Privacy advocates have raised serious concerns about this system:
Biometric Data Collection from Children
Third-Party Storage
Retained for Three Years
Watchlist Comparison
The age verification dilemma represents one of the most difficult challenges in children's digital policy:
The age verification system raises a question that Roblox has not adequately answered: Is the collection and long-term storage of children's facial biometrics a proportionate response to the age verification problem?
Given that Roblox already collects date of birth from all users—and that the BBC investigation demonstrated the platform's age-gating is easily circumvented regardless—it is unclear whether biometric age verification actually improves child safety in practice, while the privacy costs are well-documented and severe.
Roblox's data privacy practices represent a systemic failure to protect children's personal information. The platform collects far more data than its privacy policy discloses, shares this data with third parties whose practices are opaque to parents, and has introduced a biometric age verification system that subjects children to facial scanning and long-term data retention by external companies.
The regulatory landscape is tightening. The FTC's recent enforcement actions against Epic Games, Disney, and other platforms signal that penalties for COPPA violations are entering the hundreds of millions of dollars. The GDPR's enhanced protections for children's data create additional liability in European markets. And public awareness of children's data privacy is growing.
Roblox's privacy policy changes—while presented as reforms—appear to address specific criticisms without fundamentally altering the company's data-driven business model. The May 2026 restriction on personalized advertising for minors and the March 2026 clarification about parental emails are narrow adjustments that leave the core data collection infrastructure intact.
The most concerning development is the Persona age verification system, which introduces a new category of risk—children's biometric data held by third parties for years—under the guise of child safety. This system epitomizes the paradox at the heart of Roblox's approach to data privacy: the company collects more and more data about children in the name of protecting them, while doing less than is necessary to safeguard the data it already holds.
For parents, regulators, and child advocates, the message is clear: Roblox's data practices require sustained scrutiny, and the gap between the company's stated policies and its actual behavior remains dangerously wide.
This report was compiled from publicly available regulatory filings, news investigations, privacy policy documents, and third-party analyses. All claims are sourced from publicly reported information. This document is intended for informational and research purposes.
Document Version: 1.0
Last Updated: August 2026
Classification: Public