Corporations

Amazon: The Echo Maker Kept Children's Voice Recordings and Location Data Years After Parents Requested Deletion

Amazon retained children's voice recordings and associated location data for years after parents requested that the data be deleted — systematically overriding parental deletion rights and using the retained data to train Alexa's voice recognition algorithms in violation of children's privacy law.

Amazon.com Inc. agreed to pay $25 million to resolve findings that it had retained children's voice recordings and location data collected through its Alexa voice assistant for years after parents requested deletion of that data — failing to honor parental deletion rights required under the Children's Online Privacy Protection Act and the company's own privacy promises, and using the retained children's data to improve Alexa's voice recognition algorithms in ways that the retention was designed to facilitate.DOCUMENTED

Alexa's voice data is central to Amazon's artificial intelligence development — each voice interaction that is processed and retained improves the accuracy and personalization of the voice assistant's responses. Amazon's systems were designed to retain voice recordings and associated data to serve this development purpose, and the investigation found that this retention objective was prioritized over the parental deletion rights that COPPA grants to parents of children whose data is collected by a service.DOCUMENTED

Key facts
  • Amazon retained children's voice recordings years after parents requested deletion through available deletion mechanisms
  • In some cases, deletion requests erased the voice recording from the user-facing interface while the underlying data remained in Amazon's back-end systems
  • Children's geolocation data linked to Alexa interactions was also retained beyond parental deletion requests
  • Amazon used the retained children's voice data to train Alexa's voice recognition and language models
  • $25 million civil penalty — the largest ever assessed in a children's privacy case at the time of the settlement

The Deletion Request Problem

COPPA requires that operators of child-directed services honor parental requests to review and delete their child's personal information. The deletion right is fundamental to parental control — it allows parents who discover that data has been collected from their child to remove that data from the operator's systems. When an operator accepts a deletion request but fails to actually delete the data from all systems where it is stored, the deletion right is illusory: the parent believes the data has been removed when in fact it remains accessible to the company.REVIEWED

Amazon's deletion failure operated on multiple levels. In some cases, parental deletion requests through the Alexa app removed the voice recording from the user-visible history while leaving the underlying audio data and transcription in Amazon's internal systems used for AI training. In other cases, the deletion process was not propagated consistently across all systems where the child's data was stored, so data deleted from one system remained in others. The result was that parents who believed they had exercised their legal right to delete their child's data had not actually achieved that deletion.DOCUMENTED

Geolocation and Children's Privacy

The settlement also addressed Amazon's retention of geolocation data associated with children's Alexa interactions. Alexa-enabled devices can collect and store location information that is linked to voice interactions — information that reveals the child's home location, school, and daily movement patterns. This geolocation data is particularly sensitive for children because it enables tracking of a minor's physical location and routine, creating safety risks if the data were accessed by unauthorized parties. Amazon retained this geolocation data beyond parental deletion requests under the same AI development rationale that governed voice recording retention.DOCUMENTED

Regulators found that Amazon had not adequately disclosed to parents how children's voice and location data would be used for AI training purposes or how long the data would be retained for those purposes — information that parents would need to make informed decisions about whether to allow their children to use Alexa-enabled devices in their homes. The retention of sensitive children's data for commercial AI development purposes that were not adequately disclosed is a core COPPA concern, because it allows companies to use children as a source of AI training data without the meaningful parental consent and control the law requires.DOCUMENTED

Amazon's systems erased children's voice recordings from the user-visible history while keeping the underlying audio data in AI training systems — giving parents the appearance of having exercised their deletion rights without the substance.

The AI Training Incentive for Data Retention

The Alexa case illustrates a structural tension in AI-dependent consumer technology: the same data that is valuable for improving AI systems is also the data that privacy laws protect and that users have the right to delete. Voice-activated AI assistants improve their accuracy and personalization through exposure to more voice data — meaning that every deletion request, from the AI system's perspective, removes a data point that could have improved the model. When a company's systems are designed to optimize for AI training quality rather than for privacy compliance, deletion requests become obstacles to be managed rather than rights to be honored.REVIEWED

Consumer technology advocates have argued that this structural tension requires regulatory requirements that go beyond process compliance — requiring that AI systems be designed with privacy rights as a primary design constraint rather than a compliance overlay. The principle of privacy by design would require that deletion propagate completely across all systems the moment a deletion request is received, rather than being implemented only in user-facing systems while AI training systems retain the data.REVIEWED

Settlement Requirements

The settlement requires Amazon to delete all children's voice and geolocation data collected during the violation period, to honor deletion requests completely across all internal systems rather than only in user-facing interfaces, and to implement enhanced disclosure of data collection and retention practices for children's accounts. Amazon must also implement a data retention schedule that limits how long children's voice and location data can be retained for any purpose and must obtain affirmative parental consent for any use of children's data beyond the provision of the immediate service. The $25 million penalty was the largest ever assessed in a COPPA enforcement action at the time of the settlement.DOCUMENTED

Managing Your Children's Smart Device Privacy

Parents who have Alexa-enabled devices in their homes can take several practical steps to manage the privacy of their children's voice data. Amazon provides a setting in the Alexa app to enable the "children's" designation for voice profiles, which applies additional COPPA-required protections to data collected from that profile. Parents should regularly review and delete voice recording history in the Alexa app, verify that deletion is being processed across all systems rather than only in the user-facing history, and review the privacy settings in their specific device model. Parents who want to eliminate the data collection risk entirely can disable the microphone on Alexa devices when children are present. Smart home devices that use always-on microphones represent a category of ambient data collection that parents should evaluate carefully relative to the household privacy that children are entitled to expect in their home environment.

Have documents relevant to this story? Reach us through our tips channel.

Every Watchdog Journal investigation is built on primary documents and classified under our evidence standard.

Browse All Investigations →