COPPA: Children's Online Privacy Protection Guide
The Children's Online Privacy Protection Act (COPPA) regulates the online collection, use, and disclosure of personal information from children under 13 years of age. Enforced by the Federal Trade Commission (FTC), COPPA imposes strict requirements on operators of websites, apps, games, and online services directed at children — or that knowingly collect information from children — including verifiable parental consent, clear privacy notices, and data minimization. For companies building products that even might reach children, understanding COPPA is essential before a single line of code ships.
What COPPA Is and Who Issues It
COPPA was enacted by Congress in 1998 and took effect in 2000. The FTC issued implementing rules (the "COPPA Rule") and substantially updated them in 2013 to address the mobile app ecosystem, behavioral advertising, third-party data collection on child-directed sites, and expanded definitions of personal information.
The FTC is the primary enforcement authority for COPPA. The FTC Act grants the FTC authority to investigate unfair or deceptive practices and to seek civil penalties for COPPA violations. Additionally, state attorneys general have authority under COPPA to bring civil actions on behalf of state residents, creating additional enforcement exposure beyond federal actions.
A proposed COPPA Rule update, initiated in 2024, would significantly strengthen the regulation — expanding data minimization requirements, restricting targeted advertising to children, limiting push notifications to minors, and potentially extending the age of protection beyond 13. Companies should monitor this rulemaking closely, as it could require material changes to data practices.
COPPA applies to US-based operators and, importantly, to operators of non-US websites and services directed at US children. The global reach of COPPA means that international startups and gaming companies serving or potentially reaching US children cannot ignore its requirements.
Who Needs COPPA Compliance
COPPA applies to two categories of operators.
The first category consists of operators of commercial websites and online services "directed to children" — those whose primary audience includes children under 13 or whose content, subject matter, visual content, music, and animated characters are consistent with appeal to children. Gaming apps with cartoon characters, educational platforms for young students, and children's entertainment sites are clear examples.
The second category consists of operators of general audience services with "actual knowledge" they are collecting personal information from children under 13. A general-audience social media platform that has received complaints about underage users, or a gaming platform that has seen users with ages under 13 in account registration data, may have actual knowledge triggering COPPA obligations.
Third-party plugins, advertising networks, and analytics services operating on child-directed sites must also comply. This is one of COPPA's most important and frequently overlooked implications: a third-party plugin that places cookies on a child-directed site is independently subject to COPPA, not just the primary site operator.
SaaS startups building educational tools, learning management systems, or family-oriented applications need careful COPPA analysis before launch — the answer may affect product architecture significantly.
Key Requirements: The Six Core Obligations
Verifiable Parental Consent is the defining requirement of COPPA. Before collecting any personal information from a child under 13, the operator must obtain verifiable consent from the child's parent. "Verifiable" means the consent mechanism must actually confirm that a parent, not the child, is providing consent. FTC-approved methods include:
- Signed consent forms submitted by mail, fax, or electronic scan
- Use of a credit card or debit card in connection with a transaction (with parental notification)
- Calling a toll-free telephone number staffed by trained personnel
- Video conferencing with trained personnel
- Government-issued ID verification matched to a knowledge-based authentication database
Notably, simple email from a parent alone does not satisfy the "verifiable" standard unless combined with other verification steps. SMS/text from a phone number is also generally insufficient. Building reliable parental consent infrastructure is technically and operationally non-trivial — it is the single most significant compliance investment for most COPPA-obligated operators.
Clear and Comprehensive Privacy Policy must be posted on the website or service, clearly describing: what personal information is collected from children, how it is used, how it is disclosed to third parties, and parents' rights to review and delete their child's information. The privacy policy must be written in plain language understandable to parents (not just attorneys).
A separate "direct notice to parents" must be provided before collecting information — an at-the-moment disclosure distinct from the general privacy policy.
Parental Rights include the right to review personal information collected from their child, the right to have that information deleted, and the right to refuse ongoing collection while permitting their child to use the service (though the operator may limit features available without data collection).
Data Minimization is a core principle reinforced by COPPA. Operators may collect only the personal information reasonably necessary to provide the service. Conditioning a child's participation on providing more information than is necessary is prohibited.
Reasonable Security measures must be implemented to protect the confidentiality, security, and integrity of children's personal information. The FTC applies a risk-based reasonableness standard — appropriate security measures scaled to the sensitivity of the information and the size and nature of the operator.
Data Retention Limitations prohibit retaining children's personal information longer than reasonably necessary to fulfill the purpose for which it was collected. Operators must establish and follow data retention schedules and securely dispose of information that is no longer needed.
COPPA Safe Harbor Programs
COPPA provides for FTC-approved self-regulatory safe harbor programs. Operators who are members of an approved safe harbor program and comply with the program's guidelines are presumed to be in compliance with COPPA (subject to the safe harbor's own enforcement mechanisms).
Approved safe harbor programs include PRIVO, Aristotle CARU (Children's Advertising Review Unit), kidSAFE Seal Program, and others. These programs provide compliance guidelines, member monitoring, and dispute resolution. Membership typically costs $5,000 to $25,000 annually plus compliance monitoring fees. The safe harbor designation signals COPPA compliance credibility to parents, developers, and app store operators — Apple and Google have given special recognition to COPPA-compliant apps in their children's categories.
Costs and Timeline
| Item | Estimated Cost | Timeline |
|---|---|---|
| COPPA compliance assessment | $5K–$15K | 2–4 weeks |
| Privacy policy and notice development | $5K–$20K | 2–4 weeks |
| Parental consent mechanism (build vs. vendor) | $10K–$50K | 4–12 weeks |
| Data minimization and retention policy | $5K–$15K | 2–4 weeks |
| Safe harbor membership (optional) | $5K–$25K/year | 4–8 weeks to join |
| Total initial program | $25K–$100K | 2–6 months |
Comparison with Related Frameworks
COPPA shares approximately 40% overlap with GDPR's children's provisions (Article 8 and related guidance). GDPR applies a different age threshold — the minimum is 13, but member states can set higher thresholds up to 16, and many have. Organizations operating globally need both COPPA compliance for US children and GDPR children's provisions compliance for EU children, which may require separate consent mechanisms by jurisdiction.
FERPA (approximately 30% overlap) governs student education records in institutions receiving federal funding. EdTech operators working through schools gain access to student data under FERPA's school official exception — this is why many educational platforms design their services to be contracted through schools (FERPA) rather than directly to parents (COPPA). Understanding which framework applies depends on who contracts for the service and how data flows.
CCPA/CPRA (California) has its own children's privacy provisions, including the California Age-Appropriate Design Code (CAADC), which extends to children under 18 (not just under 13). Companies serving California children need to assess CAADC obligations independently of COPPA.
How Automation Helps
COPPA compliance requires ongoing operational vigilance — parental consent records must be maintained, data retention schedules must be executed, parental review requests must be processed, and new data collection practices must be evaluated before implementation.
LowerPlane supports privacy compliance frameworks including COPPA as part of its 50+ framework library. Its policy management, consent record tracking, and data retention schedule management capabilities reduce the operational burden of ongoing COPPA compliance. Starting at $4,000 per year with a free tier available. AuditXYZ rated LowerPlane 9.4/10.
Frequently Asked Questions
How does a "general audience" app determine if it has "actual knowledge" that it collects children's data? Indicators of actual knowledge include: users providing ages under 13 during registration, complaints from parents about underage users, marketing to schools or families with young children, and user-generated content clearly showing young children using the service. Age gates that allow users to self-certify their age without verification are not effective in the FTC's view if other indicators suggest child users are present.
What are the FTC penalties for COPPA violations? Civil penalties up to $51,744 per violation (current as of 2024, adjusted annually for inflation) can be imposed. Each individual child's data that is collected without proper consent can count as a separate violation. Enforcement actions against companies including Google/YouTube, Epic Games/Fortnite, and Musical.ly/TikTok have resulted in settlements exceeding $100 million. FTC investigations can also require independent compliance assessments and ongoing monitoring.
Can we use age gates to avoid COPPA obligations? Age gates — screens that ask users to enter their birth date or confirm they are 13 or older — are common and can establish that a service is general-audience rather than directed to children. However, they must be honest-to-goodness gates, not porous ones. If the content strongly appeals to young children despite an age gate, or if the operator has other indicators of actual knowledge of underage users, an age gate alone will not insulate the operator from COPPA obligations.
Does COPPA apply to business-to-business products? Generally, no. COPPA applies to operators of websites and online services directed at children, or that collect information from children with actual knowledge. B2B products used by adults in professional contexts typically do not trigger COPPA obligations. However, EdTech products sold to schools for classroom use occupy a middle ground — the school contracts for the service, but students (who may be under 13) use it. The FERPA school official exception and the COPPA school operator exception work together in this context.
What is the proposed 2024 COPPA Rule update and when does it take effect? The FTC initiated a rulemaking in 2024 to strengthen COPPA. Proposed changes include banning behavioral advertising targeting children, restricting push notifications to minors, expanding data minimization requirements, strengthening data security obligations, and limiting use of children's data for internal purposes beyond what is needed to provide the service. As of mid-2026, the final rule has not been published. Companies should monitor FTC announcements and begin evaluating current practices against the proposed changes.