TODAY, a child might learn to swipe on an iPad before they learn to walk. My little brother certainly did. By three, he could bypass a lock screen, navigate YouTube Kids and throw a staggering tantrum when the device was taken away.
He is 10 now, and things have genuinely changed, but only after our parents enforced strict screen-time limits. Today, he reads, plays outside and actually talks to us at the dinner table.
But not every child has parents who can intervene so effectively. More importantly, screen time is only the beginning.
Children are navigating digital spaces that were never designed primarily around their needs. Behind colourful apps and viral videos are data collection, harmful content, targeted advertising and people who may exploit young users.
This is not simply a parenting problem. It is a legal, ethical and regulatory challenge.
When the fun becomes a trap

Research has linked excessive screen use among children and adolescents with poorer sleep, reduced physical activity and other negative outcomes.
A systematic review of 50 studies involving more than 1.9 million adolescents also found associations between smartphone and social-media use and poorer mental wellbeing.
But the issue is not simply that children lack self-control. Many digital platforms are designed to maximise engagement, using recommendation systems and other features that encourage users to keep watching, scrolling and returning.
For children who are still developing impulse control, telling them to “just put the phone down” places much of the responsibility on the least powerful person in the equation.
The data problem
There is another danger that is harder to see: what happens to children’s data.
Every search, click and video watched can generate information about a user. Children may be unable to understand what they are agreeing to, let alone the long-term consequences of their information being collected and used.
The UN Convention on the Rights of the Child has been extended into the digital environment through General Comment No. 25, which stresses children’s rights to privacy, protection and access to digital technologies.
Malaysia’s Personal Data Protection Act 2010 does provide protections relating to the processing of personal data, including requirements around consent, but it was not designed as a comprehensive child-specific digital privacy framework.
Malaysia is now moving further in this direction through its broader online-safety regime.
The European Union’s General Data Protection Regulation offers one useful comparison. Under Article 8, when consent is the legal basis for processing personal data in online services offered directly to children, parental consent is required below an age set by each EU member state between 13 and 16.
It is therefore not accurate to say the GDPR simply requires parental consent for all processing of children’s data.
Malaysia has started acting
It would also be wrong to say Malaysia has no child-specific online-safety protections.
The Online Safety Act 2025 came into force this year, while its Child Protection Code and Risk Mitigation Code took effect on June 1.
The new framework requires platforms to take stronger measures against harmful content and protect children online. Malaysia has also introduced age-verification measures and restrictions preventing children under 16 from maintaining social-media accounts.
The question now is whether these measures will be effective in practice.
The UK’s experience offers one possible model. Its Age Appropriate Design Code requires services likely to be accessed by children to consider their best interests, use high-privacy settings by default, minimise data collection and assess risks associated with profiling and other features.
Protection cannot be left to parents

Parents still have an important role, but they cannot be expected to outsmart sophisticated platforms, understand complex privacy policies and monitor every digital interaction their children have.
Technology companies must be held responsible for designing safer environments, rather than treating child protection as an optional feature. Governments must ensure regulations are enforceable and keep pace with changing technology.
Schools also have a role. Digital literacy should not mean merely teaching children how to use technology. It should include understanding privacy, algorithms, manipulation, scams, harmful content and how to seek help.
Parents, meanwhile, need practical support in Bahasa Malaysia, Mandarin and Tamil, rather than being told simply to “take the tablet away”.
The goal should not be to lock children out of digital life. Children have a right to learn, communicate and participate online.
The goal is to make those spaces safe enough for them to do so.
Every child deserves protection that does not depend on luck, or on whether their parents happen to know how to navigate the digital world.
The devices are getting smarter.
Our laws, platforms and institutions need to get smarter about protecting the children who use them. ‒ Aug 19, 2026
The authors are from the Department of Science and Technology Studies, Faculty of Science, Universiti Malaya.
The views expressed are solely of the author and do not necessarily reflect those of Focus Malaysia.
Main image: Pexels/Ketut Subiyanto




