All Blog Posts

Understanding COPPA Compliance Requirements: A Guide to Safeguarding Children’s Online Privacy

Close
Read time
13 mins
Updated
Jul 13, 2026
Share
  • COPPA compliance is required from online services that collect personal data from children under 13 years old in the U.S. 
  • The Federal Trade Commission (FTC) introduced major amendments to COPPA that expanded the personal information definition and obligations and updated parental consent requirements.
  • COPPA amendments took effect on June 23, 2025; compliance deadline passed on April 22, 2026.
  • COPPA penalties can reach up to USD 53,088 per violation (as of June 2026); the FTC revises the figure periodically.
  • Verifiable parental consent is obligatory before collecting any personal information from children under 13 years old.
  • Cookiebot CMP by Usercentrics helps operators manage consent collection and data disclosure requirements that form part of a COPPA-compliant data governance program.

The Children’s Online Privacy Protection Act (COPPA) is a U.S. federal law that protects children’s data and privacy in digital spaces, with requirements for website and app owners. It requires operators of websites and online services directed at children to obtain verifiable parental consent before collecting personal information from those children.

Many state-level privacy laws also defer to COPPA regarding regulation of children’s information. Non-compliance can lead to serious legal and financial penalties. Our COPPA compliance checklist helps you navigate these requirements (including the FTC’s 2025 Rule amendments), avoid hefty fines, protect brand reputation, and build trust with families.

What is the Children’s Online Privacy Protection Act (COPPA)?

The Children's Online Privacy Protection Act (also referred to as Children's Online Privacy Protection Rule or COPPA Rule) is a U.S. federal law that was passed in 1998, took effect on April 21, 2000, and that has been substantially revised by the Federal Trade Commission (FTC) in 2013 and 2025.

COPPA focuses on safeguarding the privacy of children under 13 on the internet, and was introduced due to rising concerns about children's safety and privacy as internet use expanded. 

The COPPA Rule requires websites and online services that collect personal information from children to get verified consent from parents or guardians before doing so.

Under COPPA, website or online service definitions includes:

  • Network-connected games, social networking apps, and other apps that send or receive information online
  • Internet-enabled gaming platforms or location-based services
  • Plug-ins
  • Advertising networks or apps that deliver behaviorally-targeted ads 
  • Voice-over-internet protocol services
  • Connected toys or other Internet of Things devices

COPPA has been updated to keep up with evolving technologies and online practices, such as the proliferation of cell phone usage and social media platforms, some of which are specifically targeted to children. 

In January 2025, the FTC finalized amendments to COPPA, published in the Federal Register that April, that added a definition for 'mixed audience website or online service' to 16 C.F.R. Part 312 as those directed at children but are not exclusively child-directed. 

Previously existing in its FAQ materials only, the FTC codified and clarified how mixed audience services may determine user age and handle child-specific notice and parental consent obligations. 

The 2025 FTC amendments to COPPA took effect on June 23, 2025, with a compliance deadline of April 22, 2026. For full enforcement history, see the FTC's COPPA enforcement actions database.

Does COPPA Apply to You?

COPPA applies to you if you answer “yes” to any of the following questions:

  1. Do you collect personal information from website visitors or app users?
  2. Do you already have to obtain consent for collecting personal information from users?
  3. Is your content likely to attract children under 13?
  4. Are you aware that children under 13 are or could be using your service?
  5. Is your service directed at children even if it doesn't target them as the primary audience? 

Note that COPPA compliance requirements cover even foreign websites and services if they collect data from children in the United States. 

What Is Personal Information According to COPPA?

According to COPPA, personal information includes a broad range of data that can be used to identify a child under 13 years old. 

Specifically, § 312.2 COPPA defines personal information as:

  • First and last name
  • Home or physical address, including street name and city/town
  • Online contact information like email addresses
  • Screen names or usernames that function as online contact information
  • Telephone numbers
  • Government-issued identifiers, such as Social Security number or birth certificate
  • Persistent identifiers that can recognize a user over time and across different websites or online services, such as:
    • Customer numbers in cookies
    • IP addresses
    • Processor or device serial numbers
    • Unique device identifiers
  • Photos, videos, or audio files containing a child's image or voice
  • Geolocation information sufficient to identify street name and city/town
  • Information about the child or their parents that the operator collects from the child and combines with an identifier described above
  • Biometric identifiers, including fingerprints, faceprints, voiceprints, retinal scans, and genetic data

COPPA's definition of personal information is broad, covering both direct identifiers and information that could be used to recognize or track a child's online activities in combination with other information and/or over time.

COPPA parental consent is not required for collecting a child’s online contact information for one of the following limited purposes:

  • To obtain verifiable parental consent or provide direct notice to a parent
  • To respond to a one-time request from the child, without re-contacting the child
  • To protect the security or integrity of the website or online service
  • To support internal operations of the website or online service
  • To protect the child’s safety
  • When the website or online service is used by a school for educational purposes and the school has obtained parental permission.

Even if the case falls into one of these narrow exceptions, websites and online services must still comply with other COPPA compliance requirements, such as maintaining the confidentiality and security of any collected information.

COPPA Compliance Requirements Checklist

Download checklist

Publish a COPPA-Compliant Privacy Policy

Create a clear, detailed, and easily accessible COPPA privacy policy on your website or app. It can be a separate page or document or part of your broader privacy policy. Make sure it can be accessed on or from the home page or site footer, and wherever children's data is collected. 

What to include in a privacy policy for COPPA compliance:

  • Names, addresses, and contact details of all operators collecting data
  • Categories of personal data collected
  • How personal data is collected (including through tracking cookies and other technologies)
  • Purposes of data collection
  • Third parties (with explanations of how personal data is shared with them)
  • Parental rights explained in detail (including the ability to review, delete, and refuse further collection of their child's information) 

Ensure the policy is written in clear, understandable language without legal jargon.

Notify Parents

Implement a system to directly notify parents of your data collection practices before collecting any personal information from children. This notification should be separate from the privacy policy and include specific details about the types of information collected, including any use of Google cookies or similar website tracking technologies.

How to support notifications that are COPPA-compliant:

  • Update parents promptly if there are any significant changes to these practices.
  • Consider using email, push notifications, or in-app messaging for any direct communications. 
  • If data processing purposes change, parents must be notified and new consent to process children’s data must be obtained.

Develop a system to obtain verifiable consent from parents before collecting, using, or disclosing a child's personal information. Ensure your consent mechanism is designed to achieve, with as much confidence as possible, that the person providing consent is the child's parent or guardian.

Under 16 C.F.R. § 312.5(b), operators may choose from the following methods to obtain verifiable parental consent. This is evaluated against a "reasonable under the circumstances" standard. Document all consent obtained, including changes over time, and maintain these records securely in case of complaint or audit.

Signed consent form (returned by mail, fax, or electronic scan)

Credit card or debit card transaction linked to a verifiable adult account

Government-issued ID check against a database

Video conference verification or a toll-free call with a trained operator staff member

Knowledge-based authentication (KBA) using questions only the parent could answer

Facial recognition match against a government-issued photo ID

Confirmatory email or text message to the parent following receipt of consent (permitted only where the operator that does not “disclose” children's personal information)

Honor Parental Data Requests

Establish a clear, easily accessible, and user-friendly process for parents to review the personal information collected from their children. They should be able to withdraw consent and/or request the deletion of their child's data at any time.

Additionally, implement a system to verify the identity of parents making these requests to help ensure the security of children's data. Set up a dedicated team or point of contact to handle these requests promptly and efficiently.

Implement Data Protection Measures

Encryption of data in transit and at rest, strong access controls, and regular security audits are baseline COPPA compliance data security requirements.

Under 16 C.F.R. § 312.8, operators must:

  • Establish and maintain a written data security program appropriate to the volume and sensitivity of children's personal information collected
  • Designate a responsible staff member to coordinate the security program
  • Design, implement, and maintain technical, administrative, and physical safeguards to control risks identified through the risk assessments
  • Regularly test and monitor the effectiveness of the safeguards
  • At least annually, perform additional risk assessments to the confidentiality, security, and integrity of personal information
  • At least annually, evaluate and modify the information security program to address identified risks
  • Select and oversee service providers capable of maintaining appropriate security

The 2025 FTC revision makes the written data security program formal and obligatory for COPPA compliance.

Monitor Third-Party Data Practices

Carefully vet and regularly monitor any third-party service providers, including advertising networks and analytics platforms, you share data with to ensure they are also COPPA-compliant. Implement contractual safeguards with these third parties to ensure they handle children's data in a manner that meets COPPA compliance requirements.

Also, regularly audit their data practices and terminate relationships with non-compliant parties. Be particularly vigilant about third-party cookies and tracking technologies on your site or app.

Train Staff on COPPA Compliance Requirements

Conduct regular training sessions for staff on COPPA regulations, proper data handling practices, and procedures for obtaining parental consent. Monitor staff compliance regularly and create clear guidelines for staff on how to handle children's data and respond to parental inquiries or requests. 

For regulatory compliance, teams must implement data minimization, so only data that is explicitly needed to fulfill your company’s stated purposes is collected, stored, and processed.

Document Compliance Efforts

Maintain documentation of all your COPPA compliance efforts, including privacy policy updates, consent procedures, staff training records, security measures, and third-party agreements. Keep detailed logs of parental consent obtained (and any changes to it over time) and data access or deletion requests fulfilled. 

Consistent documentation will be crucial evidence in case of audits or investigations by regulatory authorities.

COPPA Fines and Violations for Non-Compliance

COPPA violations can lead to hefty fines for companies that don't comply. The FTC can issue civil penalties of up to USD 53,088 for each violation (as of June 2026), which means even a few infractions can add up quickly. 

The actual fine depends on factors like how severe the violation was, the number of children involved, and the misuse of their information. Some key COPPA fine cases include:

YouTube / Google (2019): USD 170 million, fined for collecting personal data from children through child-directed channels without obtaining verifiable parental consent.

TikTok / Musical.ly (2019): USD 5.7 million, required to delete personal data from children under 13 years old collected without a verifiable parental consent verification system.

Epic Games / Fortnite (2022): USD 275 million, largest COPPA fine to date, for collecting personal data from children without parental consent and for using dark patterns to bill users without authorization.

Amazon (2023): USD 25 million, fined for keeping kids' Alexa voice recordings beyond the period necessary to fulfil the stated purpose and for failing to honour parental deletion requests.

Disney (2025): USD 10 million, settled FTC allegations that it failed to properly designate child-directed YouTube videos as "Made for Kids," allowing personal data collection and targeted advertising to children without parental consent. A federal judge approved the settlement in December 2025.

Apitor Technology (2025): USD 500,000 (suspended), the China-based maker of robotic toy kits allegedly allowed a third-party SDK to collect children's geolocation data without parental notice or consent. The penalty is suspended due to the company's claimed inability to pay, but becomes payable in full if that claim is found false.

Iconic Hearts Holdings / "Sendit" (filed September 2025, pending): Penalty not yet determined, the FTC and DOJ allege the anonymous-messaging app knowingly collected personal data from over 116,000 self-declared under-13 users without parental consent, alongside deceptive practices including fabricated messages and undisclosed recurring subscription charges. Notable as a case combining COPPA violations with FTC Act unfairness and ROSCA claims.

Beyond fines, companies might be required to introduce new privacy measures, delete improperly collected data, and revise their practices. 

The reputational damage from violating COPPA rules can be just as serious as the financial penalties. Public trust is hard to rebuild once lost, and companies found guilty of mishandling children's data and violating child privacy laws can face consumer backlash, negative media coverage, and long-lasting damage to their brand. This erosion of trust can impact customer loyalty, deter potential partnerships, and even affect a company's market value over time.

COPPA vs. GDPR: How Child Data Protection Rules Compare

Both COPPA and the EU General Data Protection Regulation (GDPR) regulate the protection of children’s privacy and data, but they have differences in jurisdiction, age threshold, consent requirements, enforcement body, and penalties.

CriterionCOPPAGDPR (Art. 8)
JurisdictionU.S. operators and foreign operators collecting U.S. children's dataControllers/processors offering information-society services to children in the EU, including foreign organizations that target or monitor EU residents
Age ThresholdUnder 13 years oldUnder 16 years old (member states may lower the threshold to no less than 13)
Consent RequirementsVerifiable Parental Consent (VPC) from parent or guardian before data collection from a child under 13Consent from parent or guardian for data processing (made with reasonable efforts and verified via available technology) where the child is below the applicable national threshold
Enforcement BodyFTC and state attorneys generalNational data protection and supervisory authorities in the EU
PenaltiesUp to USD 53,088 for each violation (as of June 2026)Up to EUR 20 million or 4 per cent of global annual turnover

While COPPA is a standalone regulation that applies to data collection, GDPR-K (the common term for the parts of the GDPR focused on children’s privacy) is part of a larger piece of legislation that applies to all personal data processing, including profiling and decision-making.

U.S. State Laws on Child Data Privacy Beyond COPPA (2026)

While COPPA is a federal law that regulates data collection from children under 13, U.S. state laws passed to date also protect teens under 18, and some provide additional age thresholds, requirements, and safeguards:

  • California Privacy Rights Act (CPRA): Requires opt-in consent for selling or sharing the data of children aged between 13 and 15.
  • California Age-Appropriate Design Code Act: (Partially enforced as of April 2026) mandates high-privacy default settings, age-appropriate disclosures, and age estimation for services likely to be accessed by minors under 18. The Ninth Circuit lifted the injunction on most of the law in March 2026, and it took effect April 3, 2026. Only the DPIA requirement, data-use restrictions, and the 'dark patterns' provision remain blocked pending further litigation.
  • Maryland Age-Appropriate Design Code: Like California Age-Appropriate Design Code Act, defines minors under 19 and requires DPIAs, but does not mandate age verification and broadly defines data processing as “collecting, using, storing, disclosing, analyzing, deleting, or modifying personal data.” 
  • Vermont Age-Appropriate Design Code Act: (Takes effect January 1, 2027) defines minors as children aged under 18, imposes a minimum duty of care on the service design, and allows individuals to sue services.
  • Texas Securing Children Online through Parental Empowerment (SCOPE) Act: (Partially enforced) requires blocking targeted advertising to minors under 18 and obtaining parental consent for data sharing, with blocked monitoring and filtering requirements and age verification obligation as of June 2026.

The Kids Online Safety Act (KOSA) is a federal law targeting social media platform safety for kids under 17. It has been folded into the Kids Internet and Digital Safety (KIDS) Act (H.R. 7757), a broader package drawn from 14 separate children's safety bills. The House passed the KIDS Act on June 29, 2026.

The House version, however, is notably weaker than what the Senate previously approved. It omits KOSA's "duty of care" provision, which would have required platforms to take reasonable steps to prevent harms such as eating disorders, suicide, substance use, and sexual exploitation. The legislation’s co-authors have called the House bill "dead in the Senate" on those grounds. 

The House package also imposes heavy focus on platform design and safety more broadly, covering age verification, AI chatbot safeguards, restrictions on minors' data use for targeted advertising, and limits on private messaging for under-13s.

Senate leaders on both sides want the duty-of-care language restored, and there's disagreement over whether the final law should preempt stronger state-level protections. No timeline for Senate action or reconciliation between the two chambers has been set as of early July 2026.

How Cookiebot™ Supports COPPA Compliance

Cookiebot CMP by Usercentrics, supports compliance with COPPA data disclosure requirements through automated cookie scanning on websites that helps keep consent banner information about data processing services and privacy notices up to date. It enables you to display customized, geotargeted consent banners to notify visitors and obtain informed consent. And it records and securely stores audit-ready consent logs over time. 

The Privacy Policy Generator presents targeted questions about your business and data 

processing activities to help you create an accurate and customized privacy policy for your business activities. We make it easy to add it to your website.

Frequently asked questions

The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law that safeguards the online privacy of children under 13 years old. It requires websites, apps, and online services to obtain verifiable parental consent before collecting personal information from children, publish clear privacy policies, and implement measures to protect children's data.

COPPA was created to protect children's online privacy and prevent companies from collecting and using personal information of children under 13 without proper consent. It was established in response to the proliferation of internet use and growing recognition that children's personal information is more sensitive than that of adults. It also recognizes that children may have difficulty understanding the potential consequences of sharing their data online.

COPPA compliance refers to adhering to the requirements set forth by the Children's Online Privacy Protection Act, which aims to safeguard online privacy and protect the personal data of children under 13 years old. 

Codified at 16 C.F.R. Part 312, it requires operators of websites and online services to obtain verifiable parental consent before data collection, publish a detailed privacy policy disclosing data collection practices, allow parents to review and delete their children's information, and implement reasonable security measures. The 2025 FTC amendment codified the “mixed audience” definition and requires a written data security program.

In January 2025, the Federal Trade Commission (FTC) finalized the first major amendments to the Children's Online Privacy Protection Rule (16 C.F.R. Part 312) since 2013. 

Effective June 23, 2025, with a compliance deadline of April 22, 2026, the 2025 Rule introduced expanded personal information definition (biometric and government-issued identifiers), updated parental consent methods (knowledge-based authentication and facial recognition), mandatory verifiable parental consent (VCP), written data security programme and data retention policy obligation, and codified “mixed audience” definition to COPPA.

COPPA compliance is primarily enforced by the Federal Trade Commission, which investigates potential violations and takes legal action against companies that fail to comply with the regulations. The FTC can initiate investigations based on complaints from the public, which can be submitted online or through their toll-free number.

In addition to the FTC's efforts, state attorneys general have the authority to bring COPPA enforcement actions within their jurisdictions. Certain federal agencies, such as the Office of the Comptroller of the Currency and the Department of Transportation, also play a role in enforcing COPPA compliance for specific industries they regulate.

Enforcement actions typically involve legal proceedings and may result in companies being required to implement new privacy policies and procedures to ensure future compliance with COPPA.

The Children's Online Privacy Protection Act (COPPA) applies to children under 13 years of age.

Several state laws add further protections for minors beyond COPPA, including California's CPRA, the Age-Appropriate Design Code laws in California, Maryland, and Vermont, and Texas's SCOPE Act. 

At the federal level, the House passed the Kids Internet and Digital Safety (KIDS) Act on June 29, 2026, folding in KOSA and COPPA 2.0's expanded age bands. It has not yet moved through the Senate, as of July 2026.