Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Designing For TV: Principles, Patterns And Practical Guidance (Part 2)

      September 5, 2025

      Neo4j introduces new graph architecture that allows operational and analytics workloads to be run together

      September 5, 2025

      Beyond the benchmarks: Understanding the coding personalities of different LLMs

      September 5, 2025

      Top 10 Use Cases of Vibe Coding in Large-Scale Node.js Applications

      September 3, 2025

      Building smarter interactions with MCP elicitation: From clunky tool calls to seamless user experiences

      September 4, 2025

      From Zero to MCP: Simplifying AI Integrations with xmcp

      September 4, 2025

      Distribution Release: Linux Mint 22.2

      September 4, 2025

      Coded Smorgasbord: Basically, a Smorgasbord

      September 4, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Drupal 11’s AI Features: What They Actually Mean for Your Team

      September 5, 2025
      Recent

      Drupal 11’s AI Features: What They Actually Mean for Your Team

      September 5, 2025

      Why Data Governance Matters More Than Ever in 2025?

      September 5, 2025

      Perficient Included in the IDC Market Glance for Digital Business Professional Services, 3Q25

      September 5, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      How DevOps Teams Are Redefining Reliability with NixOS and OSTree-Powered Linux

      September 5, 2025
      Recent

      How DevOps Teams Are Redefining Reliability with NixOS and OSTree-Powered Linux

      September 5, 2025

      Distribution Release: Linux Mint 22.2

      September 4, 2025

      ‘Cronos: The New Dawn’ was by far my favorite experience at Gamescom 2025 — Bloober might have cooked an Xbox / PC horror masterpiece

      September 4, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Disney to Pay $10M After FTC Finds It Enabled Children’s Data Collection Via YouTube Videos

    Disney to Pay $10M After FTC Finds It Enabled Children’s Data Collection Via YouTube Videos

    September 4, 2025

    Disney, DIsney COPPA Settlement, COPPA, Childrens Online Privacy Protection Act, FTC

    Disney has agreed to a $10 million settlement with the U.S. Federal Trade Commission (FTC) over violations of the Children’s Online Privacy Protection Act (COPPA), after improperly labeling some YouTube videos as “not made for kids” — enabling data collection from children under 13 without parental consent.

    According to the FTC, several YouTube videos featuring beloved franchises like Frozen, Toy Story, and The Incredibles were mislabeled due to Disney’s reliance on channel-level default settings instead of individually designating each video’s audience category. This oversight meant that child-directed content was often marked incorrectly, allowing personal data collection and targeted advertising in violation of federal law.

    The problem wasn’t mere negligence. YouTube had flagged over 300 such misclassified videos in mid-2020 — changing their status to “made for kids.” Despite this warning, Disney maintained channel-level defaults, meaning newly uploaded videos automatically inherited the incorrect labels. This practice persisted even on channels explicitly intended for younger audiences, such as Disney Junior, Mickey Mouse, and Pixar Cars.

    The FTC’s complaint cites that the mislabeling exposed young viewers to features YouTube restricted for kids, such as autoplay and personalized ads. Disney, which benefits from ad revenues generated on its YouTube content, reportedly used these defaults without sufficient oversight or individual review.

    What $10 Million Buys You

    Disney’s settlement isn’t just about the money, though $10 million is hardly pocket change even for a company that size. The real consequence is what Disney has to do going forward, and it’s fascinating because it points toward the future of protecting kids online.

    First, Disney has to follow the law—notify parents before collecting children’s data and get their permission first. Revolutionary concept, right?

    But here’s the interesting part. Disney also has to create a comprehensive review program for all their YouTube content unless YouTube implements something called “age assurance technology”—systems that can automatically determine how old someone is when they’re watching videos. Think of it as digital ID checking that happens in real-time.

    This is huge because it acknowledges that the current system—relying on companies to self-police their content labeling—is fundamentally broken. Instead, we might be heading toward a world where technology automatically protects children without depending on corporate good faith.

    The Bigger Picture

    FTC Chairman Andrew Ferguson put it bluntly: “Our order penalizes Disney’s abuse of parents’ trust.” But this case is about more than one company’s bad choices. It’s a symptom of a larger problem in how children’s privacy is treated online.

    The Children’s Online Privacy Protection Act (COPPA) was passed in 1998, when the biggest worry was kids giving out their home addresses in chat rooms. Now we’re dealing with sophisticated behavioral tracking, AI-powered content recommendation systems, and data brokers who can build detailed psychological profiles from seemingly innocent video viewing habits.

    This marks the first COPPA-related settlement brought against a YouTube content provider (as opposed to the platform itself) since the landmark 2019 $170 million YouTube-Google agreement. It shows that even well-established platforms and content companies must rigorously follow privacy requirements — especially when children are their target audience.

    The settlement creates some immediate improvements. Disney’s videos should be properly labeled going forward, which means better privacy protections when your kids watch Disney content on YouTube. But the bigger lesson is that parents can’t rely on companies—even ones with wholesome reputations—to automatically do the right thing when money is involved.

    Also read: Disney Data Breach Fears: Hackers Threaten Leak of Unreleased Projects

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleIranian Hackers Exploit 100+ Embassy Email Accounts in Global Phishing Targeting Diplomats
    Next Article Jaguar Land Rover Cyberattack Halts Global Operations and Retail Systems

    Related Posts

    Development

    How to Fine-Tune Large Language Models

    September 5, 2025
    Artificial Intelligence

    Scaling Up Reinforcement Learning for Traffic Smoothing: A 100-AV Highway Deployment

    September 5, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-7619 – WellChoose BatchSignCS Arbitrary File Write Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Software-Defined Radio: 9 Best Free Tools for Linux

    Linux

    I changed 8 settings on my Pixel phone to significantly improve the battery life

    News & Updates

    CVE-2025-28951 – CreedAlly Bulk Featured Image Unrestricted File Upload Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    CVE-2025-7620 – Digitware System Integration Corporation Cross-Browser Document Creation Remote Code Execution

    July 14, 2025

    CVE ID : CVE-2025-7620

    Published : July 14, 2025, 4:15 a.m. | 13 hours, 29 minutes ago

    Description : The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute arbitrary programs.

    Severity: 8.8 | HIGH

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    What Makes for a Good Stereoscopic Image?

    May 22, 2025

    CVE-2025-9705 – SourceCodester Water Billing System SQL Injection Vulnerability

    August 30, 2025

    Creating Scalable Apps with Modular Architecture in React Native⚙️

    April 24, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.