COPPA Compliance for Websites and Apps
Under COPPA, parents control the online collection of personal information from children under 13. A website, app, game, ecommerce store, social platform, learning tool, or software service directed to children under 13 must implement notice, parental consent, data minimization, security, and retention controls before collection begins.
COPPA also applies when a general audience service has actual knowledge that it's collecting personal information from a child under 13. Once a record identifies a specific user as under 13, the operator has that knowledge. Examples include a birthdate, user profile, support request, contest entry, chat message, uploaded file, or parent complaint.
Courts may impose a civil penalty of up to $53,088 per violation. In 2022, Epic Games agreed to pay a $275 million COPPA penalty involving Fortnite. On August 21, 2026, the Department of Justice announced a $400 million settlement with TikTok and ByteDance resolving the COPPA litigation filed in 2024. Under the settlement, TikTok will pay $300 million immediately and another $100 million if the court enters an order vacating an earlier consent decree. DOJ noted that the claims remained allegations and that the settlement included no determination of liability.
COPPA Applies in Three Situations
COPPA applies when your website or online service is directed to children under 13 and collects personal information from them. The FTC considers subject matter, visual content, animated characters, activities or incentives for children, music, audio content, model ages, child celebrities, language, advertising, marketing materials, user reviews, audience composition, and the ages of users on similar services.
COPPA also applies when your general audience service has actual knowledge that it's collecting personal information from a child under 13. Actual knowledge is narrower than a reason to know standard. If a user enters a birthdate showing age 11 during registration, the operator has actual knowledge that the user is a child.
COPPA also covers an advertising network, analytics provider, software development kit, or other embedded operator when it has actual knowledge that it's collecting personal information directly from users of a child directed website or service.
Neutral Age Screening for Mixed Audience Services
A mixed audience service is directed to children under the FTC's factors without targeting children as its primary audience. The COPPA Rule permits that service to identify users under 13 and apply COPPA protections to them.
The service must determine age before collecting personal information, except for collection permitted by a narrow consent exception. Its screening method must be reasonably calculated, in light of available technology, to determine whether a visitor is a child.
An age screen must remain neutral. It can't default to an adult age, preselect an answer, or tell the user which answer preserves access. A mixed audience service may provide different activities based on age, but it can't block children under 13 from participating altogether.
General audience services have a different starting point. COPPA doesn't require a general audience service to ask every user's age. A general audience service that chooses a neutral age screen may generally rely on the age information a user enters. If the operator later learns that a specific user is under 13, COPPA's notice and consent duties apply to that user.
Personal Information Includes More Than Names
COPPA personal information includes a child's first and last name, physical address, online contact information, screen name when it functions as online contact information, telephone number, government identifier, persistent identifier, and a photo, video, or audio file containing the child's image or voice. It also includes geolocation information sufficient to identify a street name and city or town, biometric identifiers, and information about the child or parent combined with one of those identifiers.
The FTC adopted amendments in January 2025, published them on April 22, 2025, and required full compliance by April 22, 2026. The amendments added government identifiers beyond Social Security numbers, including state identification cards, birth certificates, and passports. They also added biometric identifiers used for automated or partly automated recognition, including fingerprints, handprints, retina patterns, iris patterns, genetic data, voiceprints, gait patterns, facial templates, and faceprints.
Persistent identifiers require close review. Cookies, IP addresses, device identifiers, customer numbers, and similar identifiers are personal information when they recognize a user over time and across different websites or online services. The Rule treats internal operations differently. Authentication, security, analytics, contextual advertising, and advertising frequency limits may qualify for the internal operations exception. Behavioral advertising, contacting a specific child, and profiling don't qualify.
Verifiable Parental Consent Before Collection
Before collecting, using, or disclosing personal information from a child under 13, you must obtain verifiable parental consent unless a narrow COPPA exception applies. The method must be reasonably calculated, in light of available technology, to ensure that the person giving consent is the child's parent.
Approved methods include a signed consent form returned by mail, fax, or electronic scan and a payment system that notifies the primary account holder of each transaction. Other methods include a staffed toll free number, a video call with trained personnel, government identification checked against a database and promptly deleted, knowledge based authentication, and photo identification matched to a live image with prompt deletion.
Email plus and text plus provide additional methods for operators that don't disclose children's personal information as the Rule defines disclosure. Each method requires a confirming email or text, or confirmation by letter or telephone after collecting a postal address or telephone number. The operator must also tell the parent how to revoke consent.
If your service discloses personal information, including through public chat, profiles, comments, or message boards, email plus and text plus aren't available. You need another approved consent method.
Separate Consent for Third Party Disclosures
The amended Rule requires a separate parental choice before disclosing a child's personal information to a third party unless the disclosure is integral to the website or service. A disclosure is integral when it's necessary to provide the product or service the parent or child requested. Disclosures for advertising, payment or other consideration, or development of artificial intelligence aren't integral.
Consent to a nonintegral third party disclosure must be freely given, informed, specific, and expressed through an affirmative action distinct from consent to collection and internal use. If a parent refuses consent for behavioral advertising, the operator can't deny the child access on that basis, and behavioral advertising must remain off.
The Privacy Policy and Parent Notice Serve Different Purposes
Your online COPPA notice must identify the operators collecting or maintaining children's personal information through the service. It must provide their names, addresses, telephone numbers, and email addresses. One operator may provide the contact information and respond to inquiries if the notice names every operator. The notice must describe what you collect, how you use it, and whether children may make it public. It must also identify the third parties or specific categories of third parties that receive it, explain the purpose of each disclosure, state the retention policy, and explain how parents may review, delete, or stop further collection or use of their child's information.
Direct notice to a parent serves a different purpose. Before collection begins, the parent must receive notice explaining what information you intend to collect, how you'll use it, and whether you'll disclose it. If disclosure is planned, the notice must identify the recipients or specific categories of recipients and the purpose. It must also explain how the parent may provide consent and what happens if the parent doesn't consent within a reasonable time.
A privacy policy link alone doesn't supply verifiable parental consent. The parent must receive direct notice and complete the consent step before the child provides personal information beyond what the consent process or another COPPA exception permits.
Data Minimization, Security, and Retention
COPPA prohibits conditioning a child's participation in a game, prize offer, or other activity on disclosure of more personal information than is reasonably necessary. If an educational game needs a username and parent email address, it shouldn't require a home address, phone number, photo, and geolocation as conditions of play.
A covered operator must maintain a written information security program for children's personal information. At a minimum, you must designate one or more employees to coordinate the program, assess internal and external risks at least annually, implement safeguards for those risks, and test and monitor the safeguards. You must evaluate and update the program at least annually and whenever risks, test results, technology, or operations materially change.
Before another operator, service provider, or third party collects or maintains children's personal information on your behalf, you must take reasonable steps to assess its ability to secure the information. You must also obtain written assurances that it will use reasonable security measures.
Retention requires a written policy. Children's personal information can't be kept indefinitely. That policy must identify the purposes for collection, the business need for retention, and a deletion schedule. Include the policy in the online COPPA notice and delete the information when retention is no longer reasonably necessary for its stated purpose. During deletion, use reasonable measures to protect against unauthorized access to or use of the information.
FTC Protection for Age Verification
On February 25, 2026, the FTC issued an enforcement policy statement addressing age verification. The statement says the Commission won't bring a COPPA Rule enforcement action against a qualifying general audience or mixed audience operator solely because it collects, uses, or discloses personal information to determine a user's age without first obtaining parental consent. A service primarily directed to children doesn't qualify.
The policy requires the operator to limit the information to age verification, delete it promptly, obtain written security assurances from eligible vendors, provide notice, use reasonable safeguards, and assess the method's likely accuracy. The policy remains effective until the FTC publishes final rule amendments addressing age verification or withdraws the statement.
Once an age verification method identifies a user as under 13, a general audience operator has actual knowledge that the user is a child. The operator must then comply with COPPA before collecting other personal information from that user.
Age verification shouldn't become a separate data collection program. If you collect a face image, identification document, biometric signal, or other personal information to determine age, you should document the purpose, deletion trigger, vendor access, security controls, accuracy review, and notice before launch.
Safe Harbor Participation
The FTC approves COPPA safe harbor programs whose guidelines provide substantially the same or greater protections as the Rule. The FTC's current list identifies CARU, ESRB, iKeepSafe, kidSAFE, PRIVO, and TRUSTe.
An operator that complies with approved safe harbor guidelines is deemed to comply with the covered provisions of the Rule. Each program must review every member at least annually, update its public member list every six months, report to the FTC annually, and retain complaint, discipline, and assessment records for at least three years.
If your marketing claims safe harbor membership, the claim should match the FTC approved program, the certified product or service, and your current membership status. A stale seal or inaccurate membership claim may violate separate consumer protection laws.
COPPA in Product Design
You should determine whether COPPA applies before launch. Your review should cover the intended and actual audience, age screening, registration, chat, profiles, uploads, contests, analytics, advertising software, push notifications, parental consent, deletion requests, vendor contracts, security controls, and retention. Your compliance file should document the analysis, consent records, notices, vendor assurances, security program, retention policy, and deletion procedures.
A service primarily directed to children must provide COPPA protections to every visitor before collecting personal information. A mixed audience service may screen for age, but it must preserve access for children and obtain parental consent before collecting their personal information. A general audience service isn't required to ask every user's age. If it chooses to exclude children through an age screen, the screen should remain neutral and collection must stop when a user identifies as under 13.
COPPA compliance depends on product mechanics. Your privacy policy should document the system in operation, and the system must comply before collection begins.
Related practice area: Privacy Law
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry