Children spend hours online every day. Meanwhile, apps, games, and websites collect data about them. Consequently, Congress built a federal shield in 1998. At the center of that shield still sits the Children’s Online Privacy Protection Act. Moreover, the law has changed fast over the past two years. New amendments reached full force in April 2026. Likewise, regulators keep securing multimillion-dollar settlements.
This guide explains the law in plain words. First, you will learn who must comply. Next, you will see what the rules demand. Finally, you will get a practical checklist. Whether you run a startup, a media channel, or a mobile game, the roadmap applies to you. We built it from primary sources, including the statute, the FTC rule, and court-approved orders.
Why Children’s Online Privacy Protection Act Matters Today
The Stakes for Parents
Parents rarely see how much data a child shares. A single game session can reveal a location, a voice, and a device ID. Children’s Online Privacy Protection Act gives parents a veto over that flow. Moreover, it forces companies to explain themselves before collection begins. Consequently, families gain a clear point of control.
The Stakes for Businesses
Companies face a different picture. Investors and partners now ask about children’s privacy during due diligence. Meanwhile, app stores and ad platforms expect proof of compliance. Therefore, a weak program can slow funding, launches, and partnerships. In contrast, strong compliance with the Children’s Online Privacy Protection Act works as a trust signal.
The Stakes for Regulators
Regulators treat children as a priority group. The FTC has repeatedly pledged to keep enforcing the law. Accordingly, Children’s Online Privacy Protection Act enforcement has stayed active across administrations. Additionally, record penalties show that size offers no shelter.
What Is Children’s Online Privacy Protection Act (COPPA)?
Quick Definition
Children’s Online Privacy Protection Act (COPPA) is a U.S. federal law. It limits how websites, apps, and online services collect personal information from children under 13. First, operators must tell parents what they collect. Then, they must obtain verifiable parental consent before collection begins. The Federal Trade Commission (FTC) enforces the Children’s Online Privacy Protection Act. In short, parents decide what happens to a young child’s data, not companies.
Where the Law Comes From
Congress passed the statute in 1998. It is codified at 15 U.S.C. §§ 6501–6506. Its short title is the “Children’s Online Privacy Protection Act of 1998.” The statute then directed the FTC to write detailed regulations. Accordingly, the agency issued the COPPA Rule in November 1999. That Rule took effect on April 21, 2000. Later, the FTC updated it in 2013 and again in 2025. Today, the Children’s Online Privacy Protection Act (COPPA) remains the main federal privacy law for children’s data online.
Statute Versus Rule
Many people mix up the two. However, they play different roles. The statute sets the framework, while the Rule, found at 16 C.F.R. Part 312, supplies the operational detail. Therefore, compliance teams read both. A violation of the Rule counts as an unfair or deceptive practice under the FTC Act. That link gives the agency its enforcement power.
Who Must Follow Children’s Online Privacy Protection Act?
Child-Directed Websites and Apps
The Rule covers operators of commercial websites and online services directed to children under 13. To decide, the FTC weighs many factors. For example, it reviews subject matter, visual content, animated characters, and music. It also considers the age of models, the language used, and advertising aimed at children. Additionally, it examines audience composition and evidence of the intended audience. Therefore, a self-described teen product can still fall under the Children’s Online Privacy Protection Act.
General Audience Sites With Actual Knowledge
Not every service covered by the Children’s Online Privacy Protection Act targets kids. A general audience site must also comply when it has actual knowledge that it collects personal information from a child under 13. For instance, a sign-up form may ask for a birth date. If a user enters a date that shows age 12, the operator now knows. Similarly, a parent’s email complaint can create actual knowledge. Consequently, operators should plan for these moments before they happen.
Mixed Audience Services
Some services attract both children and adults. The FTC calls them mixed audience services. Amendments in 2025 added a formal definition of that term. In practice, such a service may screen users by age before it collects data. However, it must treat every user who identifies as under 13 as a child. Otherwise, the age screen offers no protection at all.
Third Parties, Plug-ins, and Ad Networks
Liability also reaches behind the scenes. The Rule deems a service child-directed when it has actual knowledge that it collects personal information from users of another child-directed service. Thus, an ad network or software development kit provider can face duties of its own. Children’s Online Privacy Protection Act therefore reaches the whole data supply chain. Meanwhile, the host service must understand what its vendors collect. Indeed, the Disney order shows how a content owner can answer for data that a platform gathers from its videos.
What Counts as Personal Information Under COPPA?
The Core Data Types
The definition is broad. According to FTC guidance, personal information includes a child’s full name, home address, phone number, and email address. In addition, a child’s physical location counts. Photos, videos, and audio recordings of the child also qualify. Likewise, government identifiers, such as a Social Security number, fall inside the definition. As a result, even a simple registration form can trigger the Children’s Online Privacy Protection Act.
Persistent Identifiers and Biometric Data
The list does not stop with names and contact details. Persistent identifiers, such as IP addresses, count when they track a child over time and across sites. Biometric identifiers now appear in the Rule’s definition as well. Therefore, fingerprints, voiceprints, and facial templates demand the same care as a name.
Why the Definition Matters in Practice
A broad definition means broad coverage. For example, a game that collects only a device identifier for ad targeting still collects personal information. Consequently, a team cannot rely on the claim that it never asks for names. Instead, it must map every data flow. That map should include analytics tools, advertising code, and cloud vendors. After that, the team can decide which flows need consent.
Core Duties Under Children’s Online Privacy Protection Act (COPPA)
Operators must meet six core duties. Each one comes from the statute and the Rule. Together, they form the backbone of Children’s Online Privacy Protection Act (COPPA) compliance.
Post a Clear Privacy Policy
Every covered operator must post a clear and complete privacy policy. The policy must describe how the operator handles personal information collected from children under 13. Furthermore, a link must appear on the home page and wherever the operator collects children’s data. Plain language matters here. Dense legal text invites regulatory attention. Therefore, write the notice for a busy parent, not for a lawyer.
Give Direct Notice to Parents
Before collecting data, operators must notify parents directly. The notice must explain what the operator wants to collect and why. It must also describe how the parent can give consent. Since the 2025 amendments, the required content has grown. For instance, operators must now say more about third-party disclosures. Accordingly, old notice templates need a fresh review.
Obtain Verifiable Parental Consent
Consent sits at the heart of the Children’s Online Privacy Protection Act (COPPA). Operators must make reasonable efforts, given available technology, to make sure a parent approves the collection. Approved methods appear in the Rule. Examples include a signed consent form, a payment card transaction that notifies the account holder, a call to trained staff, a video conference, and a check of government-issued ID. The FTC does not mandate any single method. Meanwhile, companies may ask the FTC to approve new methods.
Honor Parental Review and Deletion Rights
Parents keep control after consent. On request, an operator must show a parent the personal information it holds about the child. Moreover, parents may refuse further collection and direct the operator to delete the data. Operators therefore need a process that verifies the requester is the parent. Otherwise, they risk handing a child’s data to a stranger. A written, tested workflow solves this problem.
Secure Data and Limit Retention
Operators must keep children’s data confidential, secure, and intact. They must also avoid indefinite retention. Under Section 312.10, an operator may keep personal information only as long as reasonably necessary for the purpose it was collected. After that, it must delete the data securely. Additionally, the amended Rule requires a written retention policy that appears in the online notice.
Never Condition Participation on Data Collection
Finally, operators cannot force children to hand over more data than necessary. Section 312.7 bars conditioning a child’s participation in a game, prize offer, or similar activity on disclosing extra personal information. For example, a quiz should not demand a home address to unlock a level. Consequently, product teams should collect only what a feature truly needs.
Exceptions and Special Rules in Children’s Online Privacy Protection Act (COPPA)
Narrow Consent Exceptions
The Rule allows limited exceptions to prior consent. Operators may collect contact information once to respond to a direct request from a child. They may also use contact details to protect a child’s safety. In addition, the FTC treats certain internal-operations uses differently. However, these exceptions stay narrow. Therefore, read Section 312.5 closely before relying on any of them.
Voice Recordings
Voice features raise special questions under the Children’s Online Privacy Protection Act (COPPA). In 2017, the FTC issued guidance on audio recordings. Put simply, the agency said it would not act when an operator collects a child’s voice only to replace typed text, deletes it right away, and describes the practice in its privacy policy. Even so, operators must follow those conditions strictly. Moreover, using voice data for any other purpose triggers the full consent duties.
Schools and Education Technology
Schools sometimes consent on behalf of parents. The FTC has long allowed this in limited school contexts. Operators may then use the data only for the school’s educational purpose. Furthermore, it cannot use the data for commercial purposes such as advertising. Because the FTC left education technology amendments out of the 2025 Rule, existing guidance still matters.
Safe Harbor Programs Under Children’s Online Privacy Protection Act
What a Safe Harbor Program Does
Children’s Online Privacy Protection Act lets industry groups seek FTC approval of self-regulatory guidelines. Operators that follow approved guidelines can receive safe harbor treatment. Therefore, joining a program offers structured oversight and a measure of regulatory comfort. Examples include programs run by the Children’s Advertising Review Unit and the Entertainment Software Rating Board. Still, a safe harbor is not immunity. The FTC can revoke its approval of a program.
New Transparency Duties
The 2025 amendments increased transparency for these programs. Each program must publicly list its member operators and certified services, and it must update that list every six months. In addition, programs must report more information to the FTC. Consequently, parents and operators can see who holds certification.

What Changed in the 2025 Amendments to Children’s Online Privacy Protection Act?
Key Dates
The FTC approved the amendments to the Children’s Online Privacy Protection Act on January 16, 2025. Publication in the Federal Register followed on April 22, 2025. They became effective on June 23, 2025. Operators then had until April 22, 2026, to comply fully. That deadline has now passed. Therefore, the FTC can enforce the new requirements today. Safe harbor programs faced earlier deadlines.
Separate Consent for Third-Party Disclosure
The biggest change targets data sharing. Operators must now obtain separate verifiable parental consent before disclosing a child’s personal information to third parties. This rule covers targeted advertising and other purposes. As a result, a single bundled consent no longer works. Parents must get a distinct choice about sharing.
Written Retention and Security Programs
The Rule now ties retention to a written policy. It also pushes operators toward more formal security practices. In particular, operators must maintain a written information security program suited to the size and complexity of their business. Furthermore, they must secure written assurances from vendors that receive children’s data. Thus, documentation matters as much as technology.
Expanded Definitions and New Consent Methods
Biometric identifiers now count as personal information. The Rule also lets operators use a mobile phone number to send text messages in limited cases. Additionally, the FTC added new consent methods, such as knowledge-based authentication and facial recognition matched to a government ID. Together, these updates modernize the Rule for current technology.
Proposals the FTC Left Out
Not every proposal survived. The FTC chose not to adopt amendments on education technology and push notifications. Nevertheless, operators should watch both topics. Past FTC guidance on education technology remains a useful reference.
Enforcement and Penalties Under Children’s Online Privacy Protection Act
Who Enforces the Law
The FTC leads federal enforcement of the Children’s Online Privacy Protection Act. It often works with the Department of Justice, which files complaints in federal court. State attorneys general can also bring actions under the statute. For example, New York joined the YouTube case. Notably, the statute gives individuals no private right of action.
Penalty Amounts
Violations can cost up to $53,088 each. The FTC set that figure in its January 2025 inflation adjustment. Because of a missing data point, the agency announced that its 2026 amounts remain unchanged. Moreover, penalties can multiply across violations. Therefore, exposure grows fast. Orders also impose deletion duties and long compliance programs.
Beyond Fines: Other Consequences
Money is only part of the story. Orders often run for many years. For example, Disney must operate its review program for a decade. Settlements can also require data deletion, staff training, and regular reports to the FTC. Meanwhile, public settlements damage brand trust. Therefore, count operational and reputational costs alongside the headline penalty.
The YouTube Settlement
In 2019, Google and YouTube agreed to pay $170 million. Of that sum, $136 million went to the FTC and $34 million to New York. The agencies alleged that YouTube collected persistent identifiers from viewers of channels it knew were directed to children. YouTube then used them for targeted advertising without parental consent. Additionally, the order required a system for channel owners to designate child-directed content. This case set the template for platform liability.
The Epic Games Settlement
In December 2022, Epic Games agreed to a $275 million penalty over Fortnite. The FTC alleged that Epic collected personal information from children under 13 without notifying parents or obtaining consent. At that time, the amount was the largest penalty ever obtained for violating an FTC rule. Beyond the penalty, Epic agreed to $245 million in refunds tied to separate dark-pattern claims. Epic’s order also pushed stronger privacy defaults. Therefore, game studios cannot assume a Teen rating protects them.
The Disney Settlement
In September 2025, Disney agreed to pay a $10 million civil penalty. The complaint alleged that Disney mislabeled child-directed YouTube videos as “Not Made for Kids.” As a result, data collection and targeted advertising allegedly proceeded without parental consent. A federal court approved the order, and the FTC announced the final approval on December 31, 2025. Additionally, Disney must run a ten-year program to review each video it publishes to YouTube. Consequently, content owners now face video-by-video accountability.
Other Recent Actions and Lessons
Toy maker Apitor also settled in 2025. It agreed to a $500,000 penalty, suspended because of its financial condition, and to ensure that third-party software complies. Taken together, these cases teach four lessons. First, audience labels must match reality. Second, default settings matter. Third, vendor code is your responsibility. Fourth, documentation protects you when regulators ask questions.
The 2026 Age Verification Policy Statement
What the FTC Announced
On February 25, 2026, the FTC issued a policy statement on age verification technology. The agency said it will not bring enforcement actions against certain operators that collect, use, or disclose personal information solely to determine a user’s age. Consequently, general audience and mixed audience services can test stronger age checks with less fear. Importantly, the statement targets reliable tools, not simple self-declared birth dates.
Conditions Operators Must Meet
The relief has limits. Operators must use the data only for age verification and delete it promptly. They must notify parents and children about the collection, and they must use reasonable security safeguards. Finally, they must take reasonable steps to confirm that the method produces accurate results. Meanwhile, the statement does not change what the Children’s Online Privacy Protection Act requires. Separately, the FTC said it plans a formal review of the Rule on age verification.
Pending Federal Bills: COPPA 2.0 and the KIDS Act
COPPA 2.0
Congress is weighing a major expansion of the Children’s Online Privacy Protection Act. In March 2026, the Senate unanimously passed the Children and Teens’ Online Privacy Protection Act, known as COPPA 2.0. The bill would extend protections to users under 17. It would also restrict targeted advertising to those users.
The KIDS Act
Meanwhile, the House passed the Kids Internet and Digital Safety (KIDS) Act, H.R. 7757, on June 29, 2026. The package folds in a House version of COPPA 2.0 and the Kids Online Safety Act. However, Senate sponsors object to its omission of a duty of care. Therefore, the final outcome remains uncertain. Neither measure had become law when this article was published.
What to Do While Congress Decides
Smart teams build to the higher bar now. For instance, they can limit teen data collection, avoid targeted ads for minors, and honor deletion requests quickly. Moreover, these steps already help under several state laws. Accordingly, early investment avoids a costly redesign later.
Step-by-Step Compliance Checklist for Children’s Online Privacy Protection Act (COPPA)
Use this checklist to audit your product against the Children’s Online Privacy Protection Act. Work through the steps in order.
- Decide whether your service is child-directed, mixed audience, or general audience.
- Map every data flow, including vendors and software development kits.
- Remove any data field you do not truly need.
- Draft a clear privacy policy and a direct parental notice.
- Choose a verifiable parental consent method that fits your risk level.
- Build separate consent for third-party disclosure.
- Publish a written retention policy and delete data on schedule.
- Adopt a written information security program and vet your vendors.
- Create a workflow for parental review and deletion requests.
- Train staff, document decisions, and audit twice a year.
Practical Scenarios Under Children’s Online Privacy Protection Act (COPPA)
A Kids’ Drawing App
Imagine a drawing app for ages six to ten. It is clearly child-directed. Therefore, it needs parental notice and consent before collecting even a device identifier for advertising. Better yet, the team can limit itself to basic functions that qualify for the internal-operations exception, while meeting its new conditions.
A General Audience Social App
Consider a photo-sharing app for everyone. Its team asks for a birth date at sign-up. One user enters a date that makes them 11. The operator now has actual knowledge. Accordingly, it must either obtain verifiable parental consent or stop collecting and delete the information.
A Video Channel Owner
A family-entertainment brand uploads videos to a video platform. Some videos target young children. Under the Disney order, the brand must review videos individually rather than assume the channel label applies. Thus, a single mislabeled video can create exposure.
An Education Quiz Tool
A school adopts a quiz platform for classroom use. The school may authorize collection for educational purposes. However, the vendor may not repurpose the data for advertising. Therefore, the contract should lock in those limits.
How State Laws and Children’s Online Privacy Protection Act Work Together
Federal Floor and State Layers
Children’s Online Privacy Protection Act (COPPA) sets a federal baseline. It also limits state laws that conflict with its treatment of covered activities. Meanwhile, many states have passed their own children’s and teen privacy or design laws. Some cover teens up to age 17. Others require age-appropriate design or restrict certain features. As a result, a compliant federal program may still miss state duties. Several state laws also face court challenges, so teams should monitor each one.
A Unified Approach
Many companies choose one high standard for all minors. This approach limits engineering complexity. Furthermore, it prepares teams for the Senate-passed COPPA 2.0 bill.
Building a Strong Children’s Online Privacy Protection Act (COPPA) Compliance Program
Assign Clear Ownership
Name one accountable leader. That person should coordinate legal, product, engineering, and marketing teams. In addition, they should brief senior management twice a year. Children’s Online Privacy Protection Act compliance fails when responsibility spreads too thin.
Train and Test
Train every team that touches children’s data. Next, test your consent flow with real users. Then, review logs to confirm that deletion jobs actually run. Finally, rehearse a response plan for a data incident involving children.
Document Everything
Keep records of audience research, consent methods, vendor reviews, and retention schedules. Regulators reward documented good faith. Likewise, a clean paper trail shortens investigations. Under the Children’s Online Privacy Protection Act (COPPA), documentation is your best evidence.
Common Children’s Online Privacy Protection Act (COPPA) Mistakes to Avoid
Relying on a Weak Age Gate
A pop-up asking for a birth date feels safe. However, regulators enforcing the Children’s Online Privacy Protection Act look at what you know and what you should know. Therefore, pair age screening with content review and real audience data.
Ignoring Third-Party Code
Analytics tools and ad libraries often collect identifiers silently. Consequently, one forgotten script can create liability under the Children’s Online Privacy Protection Act. Audit every library before each release.
Copying Another Company’s Policy
Templates save time. Yet a copied policy rarely matches your actual practices. As a result, it can become evidence of a deceptive statement. Write your own and keep it accurate.
Accepting a Simple Checkbox as Consent
Some teams accept a box labeled “I am a parent.” However, a checkbox rarely meets the standard for verifiable consent. Therefore, choose a method that gives real assurance that a parent approved the collection.
Keeping Data Forever
Old data feels harmless. In fact, indefinite retention violates the Rule. So, set deletion dates, then automate them.
How Children’s Online Privacy Protection Act Compares With India’s DPDP Act
Different Age Thresholds
Indian readers should note a sharp contrast. Children’s Online Privacy Protection Act protects children under 13. By contrast, India’s Digital Personal Data Protection Act, 2023 treats anyone under 18 as a child. Consequently, a service that is lawful for a 15-year-old in the United States may need parental consent in India.
Similar Consent Logic
Both regimes rely on verifiable parental consent. Section 9 of the Indian Act requires it before a fiduciary processes a child’s data. The Act also bars tracking, behavioral monitoring, and targeted advertising aimed at children. Furthermore, Rule 10 of the DPDP Rules, 2025 explains how verification should work. Notification of those Rules came in November 2025.
Takeaway for Global Businesses
Global products should not pick one standard. Instead, they should map each market’s age line and consent rules. In addition, they should design one flexible consent system. Doing so reduces rework when laws change.
Conclusion: Build Children’s Online Privacy Protection Act Into Product Design
Compliance works best at the design stage. Therefore, treat children’s privacy as a product feature, not a legal afterthought. Children’s Online Privacy Protection Act gives parents control, and the FTC now enforces that promise with real force. Meanwhile, the 2025 amendments raised the bar on consent, retention, and security. Likewise, new age verification guidance and pending bills signal more change ahead for the Children’s Online Privacy Protection Act (COPPA).
Start with a data map. Then, fix consent, retention, and vendor controls. Finally, document every decision. Because regulators reward good records, this habit pays off. Please note that this article offers general information, not legal advice. Consult a qualified attorney before you rely on it for a specific product.
References
- Cornell Law School, Legal Information Institute. “15 U.S. Code § 6501 – Definitions.” https://www.law.cornell.edu/uscode/text/15/6501
- DPDP Act Resource. “Rule 10, Digital Personal Data Protection Rules, 2025: Verifiable Consent for Processing of Personal Data of Child.” https://www.dpdpa.com/dpdparules/rule10.html
- Electronic Code of Federal Regulations. “16 CFR Part 312 – Children’s Online Privacy Protection Rule (COPPA Rule).” https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-312
- Federal Register. “Children’s Online Privacy Protection Rule” (final rule, April 22, 2025). https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule
- Federal Trade Commission. “Children’s Online Privacy Protection Rule: A Six-Step Compliance Plan for Your Business.” https://www.ftc.gov/business-guidance/resources/childrens-online-privacy-protection-rule-six-step-compliance-plan-your-business
- Federal Trade Commission. “Complying with COPPA: Frequently Asked Questions.” https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions
- Federal Trade Commission. “Children’s Online Privacy Protection Rule: Not Just for Kids’ Sites.” https://www.ftc.gov/business-guidance/resources/childrens-online-privacy-protection-rule-not-just-kids-sites
- Federal Trade Commission. “Verifiable Parental Consent and the Children’s Online Privacy Rule.” https://www.ftc.gov/business-guidance/privacy-security/verifiable-parental-consent-childrens-online-privacy-rule
- FTC Consumer Advice. “Protecting Your Child’s Privacy Online.” https://consumer.ftc.gov/articles/protecting-your-childs-privacy-online
- Federal Trade Commission. “FTC Finalizes Changes to Children’s Privacy Rule Limiting Companies’ Ability to Monetize Kids’ Data” (January 2025). https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data
- Federal Trade Commission. “Google and YouTube Will Pay Record $170 Million for Alleged Violations of Children’s Privacy Law” (2019). https://www.ftc.gov/news-events/news/press-releases/2019/09/google-youtube-will-pay-record-170-million-alleged-violations-childrens-privacy-law
- Federal Trade Commission. “Fortnite Video Game Maker Epic Games to Pay More Than Half a Billion Dollars over FTC Allegations of Privacy Violations and Unwanted Charges” (2022). https://www.ftc.gov/news-events/news/press-releases/2022/12/fortnite-video-game-maker-epic-games-pay-more-half-billion-dollars-over-ftc-allegations
- Hintze Law. “Disney to Pay $10 Million for COPPA Settlement.” https://hintzelaw.com/blog/2026/1/2/disney-to-pay-10-million-for-coppa-settlement
- Federal Register. “Adjustments to Civil Penalty Amounts” (January 17, 2025). https://www.federalregister.gov/documents/2025/01/17/2025-01361/adjustments-to-civil-penalty-amounts
- U.S. Government Publishing Office. “Civil Penalty Inflation Adjustments,” 91 Fed. Reg. (September 15, 2026). https://www.govinfo.gov/content/pkg/FR-2026-09-15/html/2026-18853.htm
- Mayer Brown. “FTC Issues Policy Statement on Age Verification Technologies Under COPPA” (February 2026). https://www.mayerbrown.com/en/insights/publications/2026/02/ftc-issues-policy-statement-on-age-verification-technologies-under-coppa
- Davis Polk. “FTC Prioritizes COPPA Enforcement as New Compliance Obligations Take Effect.” https://www.davispolk.com/insights/client-update/ftc-prioritizes-coppa-enforcement-new-compliance-obligations-take-effect
- Congress.gov, Congressional Research Service. “The House Passes the KIDS Act.” https://www.congress.gov/crs-product/LSB11465
- Senator Edward J. Markey. “Senator Markey Celebrates Unanimous Senate Passage of His Bipartisan Children and Teens’ Online Privacy Protection Legislation” (March 5, 2026). https://www.markey.senate.gov/news/press-releases/senator-markey-celebrates-unanimous-senate-passage-of-his-bipartisan-children-and-teens-online-privacy-protection-legislation
FAQs about the Children’s Online Privacy Protection Act
- 1. What is the Children's Online Privacy Protection Act?
The Children’s Online Privacy Protection Act is a U.S. federal privacy law that protects children under 13 from certain online data collection practices. It requires covered website and online service operators to provide notice to parents and, in most covered situations, obtain verifiable parental consent before collecting, using, or disclosing a child’s personal information. The law applies to child-directed services and can also apply to general-audience services that have actual knowledge that they are collecting information from children under 13.
- 2. Who must comply with the Children's Online Privacy Protection Act (COPPA)?
The Children’s Online Privacy Protection Act (COPPA) generally applies to operators of websites and online services directed to children under 13 that collect personal information. It can also apply to general-audience services when they have actual knowledge that they are collecting information from a child. Third-party services, including certain advertising networks and plug-ins, may also have obligations when they collect information through covered services. Businesses should therefore examine their audience, data practices, and third-party technologies before determining whether the law applies.
- 3. What information does the Children's Online Privacy Protection Act protect?
The Children’s Online Privacy Protection Act covers various categories of personal information collected from children. Depending on the circumstances, this can include names, contact information, persistent identifiers, photographs, videos, audio recordings, geolocation information, and other identifiers. Regulatory changes have also expanded the definition to address certain biometric and government-issued identifiers. Companies should therefore review all data collected through websites, applications, games, connected devices and other online services.
- 4. Is parental consent required under the Children's Online Privacy Protection Act (COPPA)?
Generally, yes. The Children’s Online Privacy Protection Act (COPPA) requires covered operators to obtain verifiable parental consent before collecting, using or disclosing personal information from children under 13, unless a specific regulatory exception applies. The consent mechanism must provide reasonable assurance that the person giving permission is the child’s parent. Businesses should document the consent method and maintain procedures for parental review, deletion, and withdrawal of consent.
- 5. What are the penalties for violating the Children's Online Privacy Protection Act?
Violations of the Children’s Online Privacy Protection Act can lead to FTC enforcement and significant civil penalties. Businesses may also face requirements involving data deletion, privacy programs, security controls, parental rights, and future compliance. Therefore, companies serving children should conduct regular privacy assessments, review third-party vendors, limit unnecessary data collection, establish retention periods, and maintain appropriate security safeguards.
