Frameworks

What is COPPA?

COPPA is the FTC’s Children’s Online Privacy Protection Rule, 16 CFR Part 312, implementing the Children’s Online Privacy Protection Act of 1998 and amended in 2025. It binds operators of websites and online services directed to children under 13, and any operator with actual knowledge it is collecting or maintaining personal information from a child, requiring notice to parents, verifiable parental consent before collection, a parent’s right to review and delete, and a written children’s information security programme.

Definition

COPPA is a United States federal rule governing the online collection of personal information from children under 13. It applies to an operator of a website or online service directed to children, and to any operator with actual knowledge that it is collecting or maintaining personal information from a child, and it conditions that collection on notice to the parent and the parent’s verifiable consent.

Background

The Children’s Online Privacy Protection Act was passed in 1998 (15 U.S.C. 6501 et seq.); the operative detail lives in the FTC’s implementing rule, 16 CFR Part 312, which was amended in 2025. Part 312 has thirteen sections, but only some of them impose duties on an operator — scope, definitions, enforcement, safe harbor programmes and the Commission’s own procedures do not. The duties that do bind an operator run from notice (both a direct notice to the parent and a posted online notice), through verifiable parental consent and a defined set of exceptions to it, to the parent’s right to review collected information and refuse its further use, a prohibition on conditioning a child’s participation on excess collection, a written children’s information security programme, and a retention-and-deletion duty with a written retention policy. The 2025 amendments widened the definition of personal information — biometric identifiers and government-issued identifiers among the additions — and added a defined term for a mixed audience website or online service. Importantly, a persistent identifier such as an advertising ID is personal information under the Rule, which puts a great deal of ordinary SDK behaviour inside its scope.

Why it matters

COPPA is enforced by the FTC, and a violation is treated as an unfair or deceptive act or practice under the FTC Act. But the more common practical trigger is the second prong: a general-audience product with no interest in children can land inside the Rule the moment it acquires actual knowledge that a particular user is under 13. Separately, if you ship a mobile app, COPPA is only part of the problem — Apple, Google Play and Amazon each run their own children’s programme rules, each is stricter than COPPA in places, and removal from a store is a commercial outcome that does not wait for a regulator.

Step by step

  1. Determine scope against both triggers separately: whether the service is directed to children under 13, and where you could acquire actual knowledge that a user is a child.
  2. Inventory what personal information you collect from children, remembering that a persistent identifier counts.
  3. Write the direct notice to parents and post the online notice of your children’s information practices, in every area where you collect from children.
  4. Obtain verifiable parental consent before collection, use or disclosure — or confirm that a specific exception in the Rule applies, and meet its conditions and its notice duty.
  5. Give parents a reasonable means to review what was collected and to refuse its further use or maintenance.
  6. Stand up the written children’s information security programme, and a written retention policy with secure deletion.
  7. If you ship to app stores, run each store’s children’s policy as a separate assessment — COPPA compliance does not satisfy any of them.

Examples

  • A mobile game aimed at under-13s obtains verifiable parental consent before collecting any personal information, and posts its children’s notice on the screens where collection happens.
  • A general-audience service adds a support workflow for the case where a parent reports that an account holder is nine years old, because that report creates actual knowledge and changes the service’s obligations for that user.
  • An app that collects only a persistent identifier, solely to support the internal operations of the service, relies on that exception and posts the notice describing precisely which internal operations and how the identifier is kept from being used to contact or profile anyone.

Common mistakes

  • Treating "we are not a kids app" as the whole scope analysis, and never considering the actual-knowledge trigger.
  • Assuming COPPA covers teenagers. Its "child" is a person under 13; other regimes reach further, and Amazon’s Appstore policy treats a child as under 16 in the EU, Australia and Japan.
  • Forgetting that a persistent identifier is personal information, and so treating an advertising ID as outside the Rule.
  • Relying on the internal-operations exception while collecting other personal information alongside the identifier, or using the identifier for a second purpose — either collapses the exception.
  • Confusing an age screen or an Apple parental gate with verifiable parental consent. They are different mechanisms with different purposes, and Apple says its gate is generally not the consent those statutes require.
  • Assuming COPPA compliance clears app-store review. The stores run separate contractual rules and are stricter in places.

FAQ

Who does COPPA apply to?

An operator of a website or online service directed to children under 13, and separately any operator with actual knowledge that it is collecting or maintaining personal information from a child. The two triggers are independent, so a general-audience service can be outside the first and inside the second.

What is verifiable parental consent?

Consent obtained from the child’s parent, by a method the Rule recognises as verifiable, before personal information is collected, used or disclosed. The Rule sets out the acceptable methods rather than leaving it to be asserted, and it defines a set of exceptions where prior consent is not required — each with its own conditions and, in several cases, its own notice duty.

Does COPPA apply outside the United States?

COPPA is US federal law. Other jurisdictions have their own regimes — the GDPR provisions on a child’s consent, and state age-appropriate-design statutes among them — and they are not folded into COPPA. A programme scoped to COPPA alone is under-scoped for a product with users elsewhere.

Is COPPA the same as the app-store children’s rules?

No. COPPA is law; the Apple, Google Play and Amazon children’s rules are programme terms inside a developer agreement, each revisable in place without notice and each stricter than COPPA in places. Amazon, for example, bars its own advertising and affiliate programmes from child-directed apps and says parental consent does not lift that. You need COPPA and the policy of every store you ship to.

Related

COPPA in Keel → Does COPPA apply to my app? → Can I show ads in a kids app? → Do I need a parental gate? → What is GDPR? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free