COPPA Compliance for Websites and Apps
COPPA gives parents control over personal information collected online from children under 13. If your website, app, game, ecommerce store, social platform, learning tool, or software service targets children under 13, the product needs notice, parental consent, data minimization, security, and retention controls before collection begins.
COPPA also applies when a general audience service has actual knowledge that it collects personal information from a child under 13. A birthdate field, support ticket, user profile, contest entry, chat message, uploaded content, or parent complaint can provide that knowledge about a specific user.
The FTC currently lists a maximum civil penalty of $53,088 per violation. In 2022, Epic Games agreed to a $275 million COPPA penalty involving Fortnite, the largest to date. In August 2024, the Department of Justice filed a COPPA lawsuit against TikTok and ByteDance on the FTC's behalf. The FTC case materials list that action as pending. The Commission's public case list shows continued COPPA enforcement through 2025 and 2026, including Disney and NGL matters.
COPPA Applies in Three Situations
COPPA applies when your website or online service is directed to children under 13 and collects personal information from them. The FTC looks at subject matter, visual content, animated characters, child oriented activities or incentives, music, audio content, model ages, child celebrities, language, advertising, marketing materials, user reviews, audience composition, and the ages of users on similar services.
COPPA also applies when your general audience service has actual knowledge that it's collecting personal information from a child under 13. Actual knowledge is narrower than a "reason to know" standard, but facts inside your own product can create it. If a user enters a birthdate showing age 11 during registration, COPPA applies to that user.
Third party services can also trigger COPPA. An ad network, analytics provider, plug in, SDK, or other embedded service may become covered when it has actual knowledge that it's collecting personal information directly from users of a website or service directed to children.
The Neutral Age Screen for Mixed Audience Services
A mixed audience service targets children under the FTC's factors without targeting children as its primary audience. The COPPA Rule permits that service to use an age screen and apply COPPA protections to users identified as under 13.
Neutrality controls the age screen. It cannot default to an adult age, preselect an answer, or tell the user which answer preserves access.
General audience services have a different starting point. COPPA doesn't require a general audience service to ask every user's age, and the FTC has said a general audience service that uses a neutral age screen may generally rely on the age information users provide. If the operator subsequently learns that a specific user is under 13, COPPA's notice and consent duties attach for that user.
Personal Information Includes More Than Names
COPPA personal information includes a child's first and last name, physical address, online contact information, screen name when it functions like online contact information, telephone number, government identifier, persistent identifier, photo, video, audio file containing the child's image or voice, precise geolocation, biometric identifier, and information about the child or parent that is combined with one of those identifiers.
The 2025 COPPA amendments, finalized in January 2025 with full compliance required since April 22, 2026, added government identifiers beyond Social Security numbers, including state identification cards, birth certificates, and passports. They also added biometric identifiers used for automated or partly automated recognition, including fingerprints, handprints, retina patterns, iris patterns, genetic data, voiceprints, gait patterns, facial templates, and faceprints.
Persistent identifiers are a common trap. Cookies, IP addresses, device IDs, customer numbers, and similar identifiers can count as personal information when they recognize a user over time or across websites and online services. The Rule treats internal operations differently. Authentication, security, analytics, contextual advertising, and ad frequency capping may fit the internal operations exception, but behavioral advertising, contacting a specific child, and profiling don't.
Verifiable Parental Consent Comes First
Before collecting, using, or disclosing personal information from a child under 13, you must obtain verifiable parental consent unless a narrow COPPA exception applies. Verifiable parental consent means a method reasonably calculated, in light of available technology, to ensure the person giving consent is the child's parent.
Approved methods include a signed consent form returned by mail, fax, or electronic scan, a payment method that notifies the account holder of each transaction, a staffed toll free number, a video conference with trained personnel, government identification checked against a database and promptly deleted, knowledge based authentication, and a photo ID matched to a live image through trained personnel with prompt deletion.
A lower tier method exists for operators that keep children's information internal. Practitioners call it email plus, meaning consent obtained by email and coupled with an additional confirming step such as a confirmatory email, postal address confirmation, or telephone confirmation. Email plus is available only when you don't disclose children's personal information. If your service discloses personal information, including by making it publicly available through chat, profiles, comments, or message boards, you need one of the stronger consent methods.
Separate Consent for Advertising Disclosures
The amended Rule requires a separate parental choice for covered disclosures of children's personal information to third parties, including targeted advertising disclosures, unless the disclosure is integral to the website or service.
The parent's consent to third party disclosure must be specific, informed, and given through an affirmative action separate from consent to collection and internal use. When a parent refuses a nonintegral advertising disclosure, the operator cannot deny the child access on that basis.
The Privacy Policy and Parent Notice Do Different Jobs
Your online COPPA notice must identify each operator collecting or maintaining children's personal information through the service. It must describe what you collect, how you collect it, how you use it, whether you disclose it, who receives it, how long you retain it, and how parents can review, delete, or stop further collection or use of their child's information.
Direct notice to a parent does a different job. Before collection begins, the parent must receive notice that explains what information you collected from the parent or child to obtain consent, what additional information you intend to collect from the child, how you will use it, whether you may disclose it, how the parent can give consent, and what happens if the parent doesn't consent within a reasonable time.
A privacy policy link alone doesn't supply verifiable parental consent. The parent must receive the direct notice and complete the consent step before the child provides personal information beyond what is allowed for the consent process or another COPPA exception.
Data Minimization Controls the Product
COPPA prohibits conditioning a child's participation in a game, prize offer, or other activity on the child's disclosure of more personal information than is reasonably necessary. If an educational game needs a username and parent email to operate, it shouldn't require a home address, phone number, photo, and precise geolocation as a condition of play.
Written security program requirements arrived in the same 2025 amendments. At a minimum, a covered operator must maintain a written information security program for children's personal information, designate one or more employees to coordinate it, assess internal and external risks at least annually, design safeguards tied to those risks, test and monitor those safeguards, and adjust the program when risks, test results, technology, or operations change.
Retention now requires a written policy. Children's personal information may not be kept indefinitely. Your data retention policy must identify the purposes for collecting children's personal information, the business need for retaining it, and a timeframe for deletion. The policy must appear in the online COPPA notice, and the information must be deleted when retention no longer fits the stated purpose and business need.
Age Verification Holds Narrow FTC Protection
On February 25, 2026, the FTC issued an enforcement policy statement addressing age verification technologies. The statement says the Commission will not bring a COPPA Rule enforcement action against qualifying general audience and mixed audience operators that collect, use, or disclose personal information solely to determine a user's age without first obtaining parental consent. Services primarily directed to children do not qualify.
The policy requires purpose limitation, prompt deletion, vendor security assurances, notice, reasonable safeguards, and reasonable accuracy checks. It leaves the COPPA Rule unchanged and provides no substantive rights. It remains effective until the FTC publishes rule amendments addressing age verification or withdraws the statement, and the Commission has announced its intent to open that review.
Age verification shouldn't become a new data collection program. If you collect a face image, ID, biometric signal, or other personal information to determine age, you should document the purpose, deletion trigger, vendor access, security controls, and parent notice before launch.
Safe Harbor Programs Are Specific
FTC approved COPPA safe harbor programs provide self regulatory guidelines that meet or exceed the Rule's protections. As of July 2026, the FTC's public list identifies CARU, ESRB, iKeepSafe, kidSAFE, PRIVO, and TRUSTe.
Safe harbor participation helps only while the operator follows the approved guidelines. The amended Rule requires approved safe harbor programs to publish member lists, report more information to the FTC, keep records, and update guidelines for the 2025 amendments.
If your marketing claims safe harbor membership, the claim should match the FTC approved program and your current membership status. A stale seal or inaccurate safe harbor claim can become its own consumer protection problem.
COPPA Belongs in the First Product Decision
Determine whether COPPA applies before launch. The product review needs to address audience, age screens, registration, chat, profiles, uploads, contests, analytics, advertising software development kits, push notifications, parental consent, deletion requests, vendor contracts, security controls, and retention.
A child directed service needs its COPPA system before collection begins. A general audience service that does not support users under 13 needs a neutral age screen, a process that refuses account creation for users under 13, and a process that stops collection when later facts establish actual knowledge.
COPPA compliance is built from product mechanics. The privacy policy documents the system, but the system has to work first.
Related practice area: Privacy Law
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry