Skip to main content

Microsoft to pay $20M over Xbox child privacy violations

Microsoft has agreed to pay $20 million to U.S. regulators for violating the Children’s Online Privacy Protection Act (COPPA).

The breach involved the computer giant collecting and retaining personal information from children who set up an Xbox account prior to obtaining permission from their parents.

As part of the settlement with the Federal Trade Commission (FTC), Microsoft has agreed to enact measures aimed at enhancing privacy protections for children using its Xbox platform, such as rolling out a new account creation process and eliminating a glitch that resulted in data being retained for longer than it should have been.

Commenting on the case, Samuel Levine, director of the FTC’s Bureau of Consumer Protection, said its proposed measures “makes it easier for parents to protect their children’s privacy on Xbox, and limits what information Microsoft can collect and retain about kids.”

Levine added: “This action should also make it abundantly clear that kids’ avatars, biometric data, and health information are not exempt from COPPA.”

The FTC explained that to access and play games on an Xbox console or use any of the other Xbox Live features, users must first create an account. This requires the submission of personal information including first and last name, email address, and date of birth.

Until late 2021, even if a user indicated that they were under 13 years of age, they were also asked to provide a phone number and to agree to Microsoft’s terms and conditions, which until 2019 included a pre-checked box allowing the tech company to send promotional messages and to share user data with advertisers.

It was only after users gave this personal information that Microsoft required those indicating they were under 13 to ask a parent to finish the account creation process.

“From 2015-2020, Microsoft retained the data — sometimes for years — that it collected from children during the account creation process, even when a parent failed to complete the process,” the FTC said. “COPPA prohibits retaining personal information about children for longer than is reasonably necessary to fulfill the purpose for which it was collected.”

Responding to the case, Microsoft’s Dave McCarthy, CVP of Xbox Player Services, wrote in an online post: “Regrettably, we did not meet customer expectations and are committed to complying with the order to continue improving upon our safety measures. We believe that we can and should do more, and we’ll remain steadfast in our commitment to safety, privacy, and security for our community.”

Microsoft’s settlement follows an even bigger one involving Epic Games at the end of last year, which saw it pay the FTC $275 million over COPPA violations.

It also comes a few days after Amazon agreed to pay the FTC $25 million over allegations that it violated children’s privacy rights by keeping recordings of voice interactions with Alexa for years after they were made, along with location history.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Hitman, Tomba, and more classics get new revivals at Limited Run Games showcase
Hawk in a headset in the Fighting Force collection

Limited Run Games ran its annual showcase on Thursday, adding to its catalog of physical retro game releases for the next year. While many of the trailers were for already-announced titles, LRG managed to sneak in some big announcements, including the Beyond Good and Evil 20th Anniversary Edition, re-releases and remasters of some deep-cut retro games, and more.

The physical game publisher has also gotten into the world of broader video game publishing, with its Carbon Engine helping developers use emulation to port older games from in the pre-PlayStation 1 era over to modern platforms. It's also already released some projects this year, with Rocket Knight Adventures: Re-Sparked with Konami and being behind the Alan Wake 2 Collector's Edition. 

Read more
Try these 3 Xbox Game Pass horror titles this weekend (June 21-23)
Issac stands tall in the Dead Space remake.

Another weekend is upon us, and you're probably wondering which Xbox Game Pass games you should spend some time with over the next couple of days. Although Halloween is still several months away, the release of a new horror game this week means that I'm recommending some spooky titles from the Xbox Game Pass catalog this time around.

Of course, my first recommendation is that new game, which is developed by Amnesia: A Machine for Pigs developer The Chinese Room and is set on an oil rig. Once you beat that, I recommend you check out EA Motive's remake of a sci-fi horror game classic, as well as a newer title from Striking Distance Studio that was inspired by that same game.
Still Wakes the Deep

Read more
3 new PlayStation Plus games to check out this weekend (June 21-23)
Pagan Min attacks a soldier in Far Cry 4.

It's the middle of the month, so that means Sony just dropped a batch of new titles into the game catalog for PlayStation Plus Premium and Extra. While these additions aren't as high profile as some earlier months of the year, this group of new PS Plus games still has some winners that stand out as the cream of the crop. There are three games in particular that are worth hopping into this weekend.

First is a game from Capcom that will allow you to better understand the jump from Monster Hunter: World to Monster Hunter Wilds. Then, we have a classic Ubisoft open-world game that can get you primed for the release of Star Wars Outlaws and Assassin's Creed Shadows later in 2024. Finally, there's a PlayStation VR2 game about kayaking that offers a relaxing virtual experience for those looking for an excuse to put on the VR headset.
Monster Hunter Rise

Read more