Skip to main content

Websites and online services that are directed to, or know they’re collecting information from, children under 13 are required by law to notify the parents directly and get their permission before they collect that child’s information. The FTC says Microsoft’s Xbox Live failed to do so.

As part of a settlement, Microsoft agreed to comply with the law to protect children’s privacy on Xbox Live and to get parental consent for the personal information it collected from children’s accounts created before May 2021. The company also will tell adult Xbox Live users about its privacy settings to protect children.

If you have a child that plays on your Xbox Live account, you may create a child account, which gives your child some privacy protections they don’t get on an adult account. For example, a child account limits how Microsoft shares your child’s information. And your child may only communicate with friends that you approve. To review and adjust your child’s privacy settings, go to your Microsoft Privacy Dashboard.

Before a website or online service collects personal information from your child, it has to notify you and get your permission. The notice must

  • tell you what information the site will collect about your child,
  • tell you how it will use the information,
  • tell you how to give — or withhold — your consent, and
  • include a link to the privacy policy with more details.

If you give consent, that’s not the end of the story. You have the right to review the information that the website or service collects about your child, and delete it if you choose. You also have the right to revoke your consent at any time.

To learn more, check out the FTC’s advice about protecting your child’s information online.

Search Terms

It is your choice whether to submit a comment. If you do, you must create a user name, or we will not post your comment. The Federal Trade Commission Act authorizes this information collection for purposes of managing online comments. Comments and user names are part of the Federal Trade Commission’s (FTC) public records system, and user names also are part of the FTC’s computer user records system. We may routinely use these records as described in the FTC’s Privacy Act system notices. For more information on how the FTC handles information that we collect, please read our privacy policy.

The purpose of this blog and its comments section is to inform readers about Federal Trade Commission activity, and share information to help them avoid, report, and recover from fraud, scams, and bad business practices. Your thoughts, ideas, and concerns are welcome, and we encourage comments. But keep in mind, this is a moderated blog. We review all comments before they are posted, and we won’t post comments that don’t comply with our commenting policy. We expect commenters to treat each other and the blog writers with respect.

  • We won’t post off-topic comments, repeated identical comments, or comments that include sales pitches or promotions.
  • We won’t post comments that include vulgar messages, personal attacks by name, or offensive terms that target specific people or groups.
  • We won’t post threats, defamatory statements, or suggestions or encouragement of illegal activity.
  • We won’t post comments that include personal information, like Social Security numbers, account numbers, home addresses, and email addresses. To file a detailed report about a scam, go to ReportFraud.ftc.gov.

We don't edit comments to remove objectionable content, so please ensure that your comment contains none of the above. The comments posted on this blog become part of the public domain. To protect your privacy and the privacy of other people, please do not include personal information. Opinions in comments that appear in this blog belong to the individuals who expressed them. They do not belong to or represent views of the Federal Trade Commission.

Ezrway
June 07, 2023

To me, part of protecting my child's privacy is when I set up an account for them I make sure I set it as a child's account.

Then I review the access and privacy settings with my wife to make sure she agrees with my choices.

Microsoft Xbox One and Microsoft Xbox Live instructions were clear enough for us to understand what information would be collected and how we could limit the information that was shared.

Josh
June 14, 2023

I would like to deeply thank the individuals out there standing up and fighting for humanity's basic rights as they evolve before us. Besmirched in shame are the names of interested parties who would subvert what is universally right for any profit or competitive edge. This world, our time, is all shared. We 'ought to play nice.

Bonnie futch
October 04, 2023

In reply to by Josh

It is very unfortunate that corporations like these can be so irresponsible, and careless about keeping up with there own contract agreement. I have two children who were deeply aggressive and not once have I ever seen one email. It's unacceptable and they are responsible period. I will stand strong for my family and everyone else who was affected not notified by the entitled corporation.

Kaniack
November 02, 2023

Microsoft blocked my account access for “security” purposes and said I had the wrong login info when trying to get into my Xbox live account. I have tried many many times to use the backup info to reset the password and get rejected saying I need to provide more and more information at which time the site will pop up a error saying to try another way to access etc and I’ve been locked out for over a year now and Microsoft states very bluntly “oh well, make another account.