Safer Phones for Kids: What Research and New Privacy Laws Reveal
The market for safer phones for kids is growing, and so is the risk of buying the wrong one. Some products restrict content appropriately. Others quietly harvest it. From a product listing, the difference is almost impossible to spot.
Two things have sharpened this problem recently: peer-reviewed research on which parental controls actually work, and the first update to federal children's privacy law since 2013. Together, they give parents a clearer picture of what protection looks like and what it doesn't. A genuinely protective device does three things: it applies controls matched to a child's age and developmental stage, it monitors transparently rather than covertly, and it minimizes data collection instead of monetizing it. The research suggests many products on the market fall short on at least one of those counts.
A nationally representative FOSI/Ipsos survey of 1,000 U.S. parents and 1,000 children ages 10–17, published last May, found that only about half of parents use formal parental controls. Most are managing their children's digital lives through household rules and open conversation which is exactly the gap the kid-safe phone market is rushing to fill.
Nearly nine in ten children in the same survey said they feel comfortable going to a parent when something online makes them feel unsafe (FOSI, May 2025). That number sits in productive tension with what the research says about which technical controls actually work.
What parents are worried about and why the concern holds
Video of the Day
The anxiety driving this market isn't manufactured. Between 3.2% and 16.4% of adolescents across countries meet the clinical threshold for full problematic social media use, according to JMIR research published last September. The severe cases are a minority. The at-risk group is not: roughly 34.7% of Dutch adolescents in the same dataset showed two to five symptoms, placing them in a category that carries many of the same negative outcomes as full problematic use.
Parents are already responding, primarily through what researchers call "restrictive mediation" rules about screen time, device location, and platform access (JMIR, September 2025). The FOSI survey shows families are also leaning on conversation and household norms, though the data doesn't tell us whether talk works as well as formal controls, or better.
The concern is also shifting. That same FOSI survey found growing parental awareness of AI features on children's devices (FOSI, May 2025). The kid-safe phone conversation has moved past social media filters into territory most current products haven't meaningfully addressed.
Video of the Day
The age problem: why controls that work for a ten-year-old can backfire for a sixteen-year-old

A prospective study tracking 315 adolescents across four data-collection waves found no statistically significant overall effect of parental internet-specific rules on whether children developed at-risk or problematic social media use (OR 0.959, 95% CI 0.60–1.54) (JMIR, September 2025). Blunt restriction, applied uniformly, does not reliably protect.
Age produces a sharp split in the findings. For children under roughly 12, stricter rules were associated with a lower likelihood of developing problematic social media behavior. For teens over roughly 15.7, the relationship reversed: heavier restrictions were associated with a higher likelihood of problematic use. The researchers described that outcome as potentially "counterproductive" from that age onward (JMIR, September 2025).
The product implication is direct. A phone with rigid, uniform controls may suit a preteen and actively work against a 16-year-old. Most child-safe phones and control apps apply a single feature set at parental discretion, with no mechanism for adjusting as the child develops. The design that fits the evidence is one that treats graduated autonomy as a goal, not an afterthought that arrives when the child leaves home.
Safer phones for kids: when "parental control" is really covert tracking

Age-appropriateness is one test. Transparency is the other and a portion of the studied market fails it badly, including apps sold through mainstream channels.
A PoPETs study published earlier this year examined 20 apps distributed outside the Google Play Store alongside 20 available in-store. Among the sideloaded apps, three transmitted sensitive user data without encryption, half carried no privacy policy at all, and eight of the twenty were flagged for stalkerware indicators behavioral signatures associated with covert surveillance rather than transparent monitoring (PoPETs, 2025). Of all 44 apps the researchers identified that were unavailable through Google Play, one in four were classified as outright stalkerware.
The problem isn't confined to sideloaded software. The same study found four apps currently available on Google Play Find My Kids, KidsGuard Pro, Life360, and mLite that met the study's stalkerware criteria (PoPETs, 2025). These are recognizable consumer brands, not obscure downloads.
The researchers drew a clear line between the two categories. Legitimate parental control software is visible to the child, operates with the child's knowledge, and carries a privacy policy describing how data is handled. Software in the other category conceals itself on the device, collects data without disclosure, and frequently has no stated policy on where that data goes.
One further complication worth noting: most child-safe smartphones are standard devices running a parental control layer on top. The safety of the hardware depends almost entirely on the integrity of that software. Evaluating a child-safe phone is, in practice, evaluating an app.
What the updated rules require and where they run out

The regulatory floor for child-safe products rose last year. The FTC finalized the first update to the Children's Online Privacy Protection Rule since 2013; the amended rule took effect June 23, 2025, with most compliance required by April 22, 2026 (Federal Register, April 2025).
The changes most relevant to parents evaluating products: parental disclosures must now name every individual third party receiving children's data, along with the purpose of each disclosure. Under the updated rule, as IAPP analyzed in January, any sharing of children's personal information with an undisclosed party would constitute a COPPA violation. Data retention policies must be made publicly available, and companies are explicitly prohibited from retaining children's data indefinitely (IAPP, January 2025).
Companies must also implement a formal security program, including designated staff, routine risk assessments, and ongoing monitoring, and must vet any third-party recipient by contract (IAPP, January 2025). Biometric identifiers now fall under the definition of personal information requiring parental consent. The Federal Register specifies these as data used for automated or semi-automated recognition of an individual, including fingerprints, handprints, retina patterns, iris patterns, genetic data, voiceprints, gait patterns, facial templates, and faceprints.
Those requirements give parents a practical baseline. If a product can't tell you exactly which companies receive your child's data, how long they keep it, and what security measures are in place, it isn't meeting the current federal standard.
The hard limit: COPPA covers children under 13. Extending equivalent protections to teenagers requires congressional action something lawmakers have promised to attempt as "COPPA 2.0" in the current Congress, but have not passed, according to IAPP. The adolescents the JMIR research identifies as most harmed by heavy-handed restrictions are largely the same teens who fall outside COPPA's reach entirely. The commercial market is operating in a regulatory gap that policy hasn't filled, and there's no deadline for when it will.
Three questions worth putting to any child-safe smartphone

The research reduces to a short checklist not from this article, but from the studies and regulatory record above.
Does the product adjust controls as the child ages? For preteens, structured limits appear protective. For teens over 15.7, the same controls are associated with worse outcomes (JMIR, September 2025). A device with no mechanism for graduating toward autonomy is applying a feature set that misfires precisely when it's most likely to be tested.
Is the monitoring transparent? Among the apps studied by PoPETs researchers, a meaningful share including some available through mainstream app stores used monitoring behaviors consistent with stalkerware, transmitted data without encryption, or operated without any stated privacy policy (PoPETs, 2025). A product that surveils a child covertly isn't a safer phone. It's a different kind of risk in different packaging.
Does it comply with updated data rules? Under the revised COPPA framework now in effect, any company handling under-13 data must disclose every third-party recipient, publish a retention policy, and demonstrate a formal security program. Parents of teens, who have no equivalent regulatory protection pending congressional action, have more reason to apply that standard themselves not less (Federal Register, April 2025).
With AI features becoming standard on consumer devices and COPPA 2.0 still unresolved, the definition of "safe" for children's phones will keep expanding. The gap between what the market claims and what the evidence supports isn't closing on its own.