What is the Children’s Online Privacy Protection Act (COPPA) in the US?

Share:
Understand COPPA, the US law protecting children's online privacy, including 2025 rule changes, parental consent requirements, and business compliance obligations.

The Children’s Online Privacy Protection Act (COPPA) is a US federal law enforced by the Federal Trade Commission (FTC) that requires websites, apps, and online services directed at children under 13 to obtain verifiable parental consent before collecting, using, or sharing a child’s personal information. The FTC finalized major amendments to the COPPA Rule in 2025, expanding the definition of personal information, tightening parental consent and data retention rules, and giving companies until April 22, 2026, to comply.

Any business that runs a website, app, or online service that a child under 13 might use needs to understand COPPA. It’s one of the oldest privacy laws in the United States, but it’s far from static, the FTC just completed its first major overhaul of the rule since 2013. For companies handling children’s data, understanding what’s changed (and what hasn’t) is now a compliance priority, not a nice-to-have.

What is COPPA?

The Children’s Online Privacy Protection Act was enacted by Congress in 1998 and took effect in 2000. Its core purpose is simple: give parents control over what personal information websites and online services can collect from children under the age of 13.

COPPA applies to the following:

  • Operators of commercial websites and online services directed to children under 13.
  • General-audience websites or services that have actual knowledge they are collecting personal information from children under 13.
  • Mobile apps, connected toys, voice assistants, and IoT devices marketed to or used by children.
  • Third parties, such as ad networks or plug-in providers, that have actual knowledge they are collecting personal data through a child-directed site or service.

The law is enforced by the FTC, and the FTC has translated the statute into a detailed set of operational requirements known as the COPPA Rule (16 CFR Part 312).

What Counts as “Personal Information” Under COPPA

personal-information

COPPA’s protections hinge on what qualifies as personal information. Traditionally this included names, home addresses, email addresses, phone numbers, Social Security numbers, and persistent identifiers like cookies used to track a child across sites over time.

The 2025 amendments expanded this list further. Personal information now also explicitly includes government-issued identifiers and biometric identifiers, such as fingerprints, voiceprints, or genetic data, that can be used to recognize a specific individual, along with mobile telephone numbers under online contact information. This reflects how much data collection has evolved since the rule was last updated, from cookies to biometric scanning and connected devices. Organizations building a broader data protection program alongside COPPA compliance often pair this work with a formal GDPR compliance framework to align with international standards as well.

What are the Core Requirements for Operators

If your website or app falls under COPPA, you’re generally required to do the following:

  1. Post a clear, comprehensive privacy policy describing what data you collect from children, how it’s used, and how it’s disclosed.
  2. Provide direct notice to parents before collecting any personal information from a child, explaining your data practices.
  3. Obtain verifiable parental consent before collecting, using, or disclosing a child’s personal information (with limited exceptions).
  4. Give parents access to review the personal information collected from their child and the ability to request its deletion.
  5. Limit data collection to what’s reasonably necessary for the activity, a principle known as data minimization.
  6. Maintain the confidentiality, security, and integrity of the personal information collected.
  7. Retain data no longer than necessary to fulfil the purpose for which it was collected and delete it securely afterward.

Non-compliance is not a minor risk. The FTC has pursued significant enforcement actions in this area, including settlements involving major platforms accused of collecting data from children without proper parental notice or consent, resulting in multi-million-dollar penalties. A strong Data Protection Officer (DPO) as a service engagement can help organizations build the governance structure needed to manage these obligations continuously, rather than reactively.

What Changed in the 2025 COPPA Rule Amendments?

After a review that began in 2019 and drew more than 175,000 public comments, the FTC finalized amendments to the COPPA Rule, published in the Federal Register on April 22, 2025. The amendments took effect June 23, 2025, and organizations have until April 22, 2026 to fully comply. Key changes include:

  • Separate consent for third-party disclosures: Operators must now obtain distinct verifiable parental consent specifically for disclosing a child’s data to third parties for targeted advertising, rather than relying on one blanket consent for all data practices.
  • Expanded “personal information” definition: As noted above, biometric and government-issued identifiers are now explicitly covered.
  • Written information security program: Operators must implement, document, and annually review a data security program appropriate to the sensitivity of the children’s data they handle and the size and complexity of their business, a requirement similar in spirit to security frameworks organizations use for continuous security monitoring and compliance.
  • Defined data retention limits: Companies can no longer retain children’s personal information indefinitely; retention must be tied to the specific purpose for which the data was collected.
  • Greater Safe Harbor transparency: FTC-approved COPPA Safe Harbor programs must now publicly disclose their member lists and provide more detailed compliance reporting to the agency.
  • Updated “directed to children” analysis: The FTC clarified the evidence it may weigh, including marketing materials, audience composition, and comparable platforms’ user ages, when determining if a service is child-directed.

Notably, the FTC chose not to adopt some proposed changes, including a proposed express restriction on using engagement-enhancing techniques (like push notifications) under the “support for internal operations” exception, and did not codify separate rules for education technology providers, leaving existing guidance in place for now.

Who Requires Paying Attention?

COPPA compliance isn’t limited to companies that obviously market to kids. It also applies to general-audience platforms if they have actual knowledge that children under 13 are using their service and providing personal data, a category that has caught out social media platforms, gaming companies, and ed-tech providers in past enforcement actions. Mixed-audience services, connected toys, and voice-activated devices are all squarely within scope under the updated rule.

For organizations building or maintaining digital products used by families, schools, or general consumers, a proactive compliance review is far cheaper than an FTC investigation. This typically involves auditing data flows, updating privacy notices and consent mechanisms, and reviewing vendor and ad-tech relationships that touch children’s data, work that often overlaps with broader efforts suh as cloud security strategy reviews when children’s data is stored or processed in cloud environments.

To Conclude

COPPA remains one of the most consequential privacy laws for any business operating online in the US, and the 2025 amendments mark the most significant update to children’s privacy compliance obligations in over a decade. With the April 22, 2026 compliance deadline behind us as of this writing, the FTC’s enforcement expectations are firmly in effect, organizations still catching up on updated consent flows, data retention policies, and written security programs should treat this as an urgent priority rather than a future task.

Whether you’re a startup building your first app or an established platform reassessing your data practices, understanding COPPA’s requirements and building the governance to support them, protects both children’s privacy and your organization’s reputation.

Need help navigating COPPA, GDPR, CCPA, or other data privacy regulations? Ampcus Cyber’s privacy and compliance experts can assess your current data practices, close compliance gaps, and build a governance program that keeps pace with evolving regulations.

Talk to our compliance experts and turn regulatory complexity into a competitive advantage.

Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert