Your child's first phone: equip them without spying, protect them without exposing them

Back to the blog
23 August 202612 min read

Introduction: the gift that opens ten accounts

There comes a moment, usually somewhere between the last year of primary school and the second year of secondary school, when the question lands at the dinner table. Everyone else has one. And the answer, whatever it is, commits far more than a budget.

Giving a child a phone is not handing over an object. It is opening up, in a single afternoon of setup, a permanent digital identity: a Google or Apple account, a phone number that will become their reference identifier for the next fifteen years, a location history that starts today and will never stop, and a place in the databases of a dozen advertising players who certainly did not wait until they turned thirteen.

Voting console built into a wooden desk with "Ja/Yes", "Nein/No" and "Enth./Abst." buttons

Public debate on the subject swings between two equally sterile poles. On one side, an outright ban — which solves the problem right up until the day the child borrows a classmate's phone, with no framework at all. On the other, the full parental surveillance arsenal: permanent location tracking, reading messages, automatic screenshots. This second option does not protect a child's privacy, it abolishes it — and it teaches, very effectively, that surveillance is the normal state of human relationships.

This guide proposes a third way, consistent with what this site stands for: reduce data collection at the source, explain rather than constrain, and keep the conversation open long enough that your teenager comes to you when things go wrong.


What a child's phone actually collects

Before talking about tools, we need a diagnosis. A smartphone taken out of its box and set up with "next, next, next" transmits, within the first hour:

  • The advertising identifier (AAID on Android, IDFA on iOS), which allows activity to be cross-referenced across apps;
  • Location, often continuously, sent up by the operating system, by weather apps, and by free games;
  • The list of installed apps, a surprisingly revealing piece of information about age, language, interests and sometimes health status;
  • The address book, hoovered up by any messaging app granted "Contacts" permission — which also exports the data of third parties who never asked for anything;
  • Communication metadata: who, when, for how long, from where. We have explained elsewhere why this metadata often says more than the content itself.

Add to this the specific issue of apps targeting minors. France's data protection authority, the CNIL, published eight recommendations on children's digital rights in 2021, and regularly points out that in France the consent of a minor under 15 must be obtained jointly with that of the holder of parental authority (article 45 of the French Data Protection Act, transposing article 8 of the GDPR). In practice, verification usually amounts to a tick box, and the Commission has fined several publishers for targeting advertising at minors.

An eleven-year-old who installs three free games in one evening has, statistically, transmitted more behavioural data than their parents emitted throughout their entire own adolescence.


Choosing the device: less surface, fewer leaks

The most structuring decision comes before any configuration.

Feature phone or smartphone?

For a child aged 9 to 12 whose real need is "being able to call my parents when I leave school", a feature phone with physical buttons meets the specification with a laughably small attack surface: no browser, no app store, no advertising identifier, a week of battery life. The social trade-off is real — the child will not be in their class group chats — but it is honest, explainable, and often better tolerated than a smartphone locked down on every side.

New, refurbished or handed down?

A refurbished device or one inherited from within the family is an excellent economic and ecological choice, on one imperative condition: a complete factory reset before handover. Otherwise, a phone handed down from a parent retains sessions, backups and an account that tie the child to the adult's digital identity. Also check that the model still receives security updates: a smartphone that will stop being updated in six months is a leak waiting to happen. A simple rugged protective case will, incidentally, extend the device's life far more reliably than any insurance policy.

The mobile plan

Go for a SIM card in a parent's name with a capped plan: no overage, no premium-rate numbers, no pay-per-use billing. It also avoids the child having to provide their own identity documents to an operator, meaning one less identifying piece of data in circulation.


Initial setup: the half hour that counts

Take thirty minutes, with the child beside you — not behind their back. Every setting you explain is a lesson in digital hygiene worth more than any lecture.

1. Create a dedicated child account. On Android via Family Link, on iOS via Family Sharing, with the real date of birth. Never reuse your own account: it mixes up histories, backups and recommendations.

2. Disable or reset the advertising identifier. Android: Settings → Privacy → Ads → Delete advertising ID. iOS: Privacy → Tracking → turn off "Allow Apps to Request to Track". Two minutes, immediate effect.

3. Review permissions app by app. The rule: location "only while using the app", microphone and camera denied by default, contacts access denied unless absolutely necessary. Turn on periodic permission reminders.

4. Choose a privacy-respecting search engine and browser. A browser that blocks trackers by default prevents most advertising profiling without breaking anything in day-to-day use.

5. Lock down app installation. Not to forbid, but to establish a conversation: every installation goes through a request, and therefore through a thirty-second exchange about what the app actually does.

6. Set lock screen notifications so they do not display message content. A phone left on a canteen table should not broadcast conversations to the whole room.


Parental controls: what really protects, what damages

The term covers very different realities, and the distinction is decisive.

FeatureReal usefulnessCost to the relationship
Adult content filtering (DNS/carrier)High, especially before age 13Almost nil
Time-of-day usage windowsHigh (sleep, homework)Low if negotiated
Install approvalGood (educational)Low
One-off location on requestReasonable when neededModerate
Permanent silent location trackingLowHigh
Reading private messagesVery lowVery high, often irreversible
Automatic screenshotsNoneBreakdown of trust

Since 2024, French law has required every connected device sold in France to offer a parental control system that can be activated free of charge at first use (the so-called Studer Act of 2 March 2022, brought into force by decree). Use it: it is the foundation. But a filtering system is not a spying system, and many commercial apps cheerfully cross that line.

Close-up of a smartphone screen showing the WhatsApp, Safari and Facebook app icons

One point that is rarely raised: these surveillance apps are themselves data collectors. You are entrusting a third-party publisher, often established outside the European Union, with a minor's real-time location, their conversations and their photos. Several "stalkerware" publishers have suffered massive breaches in recent years, exposing precisely the children's data they claimed to protect. The cure is sometimes worse than the disease.

The proportionality rule fits in a single sentence: do not collect anything on your child that you would refuse to let a government collect on you.


Explain rather than lock down: three conversations to have

1. "What you write does not disappear"

Children need to understand the difference between local deletion and real deletion: removing a message from their screen erases it neither on the recipient's device, nor on the host's servers, nor in the screenshot a classmate has already taken. It is the natural entry point into a discussion about photos, image-based blackmail and bullying.

2. "Free is paid for with you"

Explaining the advertising business model to a twelve-year-old is easier than it sounds: a free app makes money by selling its users' attention and information. Once the principle is understood, the child spots on their own the apps that ask for absurd permissions. An accessible book on digital privacy left on the living room table often has more effect than a parental sermon.

3. "There are things you don't say under your real name"

This site has long argued that discretion is not concealment. A teenager has legitimate reasons for wanting to ask a question without being identified: to a helpline, to a health service, to a trusted adult. In France, the Fil Santé Jeunes number (0 800 235 236) and 3018 for cyberbullying are anonymous and free, including from a mobile — and they do not appear on the itemised bill. Saying this out loud means offering an exit door before it is needed.


Hardware that helps without spying

A few accessories do more for a child's safety than any tracking app.

  • A privacy screen filter prevents side-angle reading on the bus or in class. Discreet, passive, no software.
  • An adhesive webcam cover for the family computer costs a few euros and removes an entire category of anxiety.
  • A compact power bank avoids the classic "my phone was dead, I couldn't let you know" scenario, which is the leading real cause of parental worry — well ahead of dramatic scenarios.
  • Wired headphones limit permanent Bluetooth pairing, an additional identifier continuously broadcast in public spaces.
  • A Bluetooth tracking tag slipped into the schoolbag solves the "know where the bag is" need without installing a snooping app on the child's phone.

That last point deserves a caveat: a tag on an object is not equivalent to tracking a person, but it comes very close if the object never leaves the child. Here too, transparency settles the matter: the child knows it is there, and can remove it.


The legal framework in brief

Three useful reference points for French parents:

  1. GDPR article 8 and article 45 of the French Data Protection Act: in France, a minor can consent alone to the processing of their data by an online service from the age of 15. Below that, consent is joint with the holder of parental authority.
  2. Image rights and a minor's privacy: the law of 19 February 2024 on guaranteeing respect for children's image rights writes the protection of a child's privacy into the exercise of parental authority. It targets in particular sharenting, the publication of photos of children by the parents themselves. In other words: a minor's digital privacy can also be asserted against their parents.
  3. Digital age of majority: the law of 7 July 2023 sets 15 as the age for signing up independently to social networks, with parental consent required below that. Its effective application remains dependent on age verification systems, a subject we have already shown raises serious privacy problems of its own.

The CNIL provides educational fact sheets for families on its website, and the Internet Sans Crainte programme, run by Tralalere on behalf of the French state, offers resources by age group. These are serious, free, French-language starting points.


A checklist for the big day

  • Device reset, still covered by security updates
  • Dedicated child account, exact date of birth
  • Advertising identifier deleted or reset
  • Location set to "while using the app" only
  • Contacts access denied by default
  • Content filtering enabled at DNS or carrier level
  • Notifications hidden on the lock screen
  • Encrypted backup configured (loss, theft, breakage)
  • Capped plan, premium-rate numbers disabled
  • Anonymous helpline numbers saved in contacts
  • Usage rules written together, on a sheet of paper, put up on display

That last point is not decorative. A written family agreement — screen time, places, what parents may look at and what they undertake not to look at — turns a surveillance relationship into a contractual one. It ages well: you renegotiate it at every birthday, loosening it gradually.


Conclusion: preparing an exit, not a prison

The goal of a first phone is not to keep a child under a glass dome until they turn eighteen. It is to bring them, over five or six years, to the point where they can manage on their own a device that collects data about them — because that is exactly the skill they will need for their entire adult life.

A child who has been told why microphone access is denied, why an advertising identifier is wiped, why some messages deserve to be sent without revealing their identity, will come out of adolescence with an instinct most adults have never acquired. It is an inheritance that can be passed on, and it costs no more than a few conversations.

Control, for its part, expires automatically at the age of majority. Understanding does not.

#Vie privée#Confidentialité#Sécurité#Cas d'usage#Anonymat#Cadre légal

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme