All Blog Posts

COPPA Compliance with Checklist: What U.S. Website Operators Need

Close
Read time
10 mins
Updated
Sep 2, 2026
Share
  • The FTC's 2025 COPPA Rule amendments are now fully enforceable. The compliance deadline passed on April 22, 2026, so operators are held to the updated standard today, not a future one.
  • Civil penalties currently reach $53,088 per violation, adjusted for inflation as of January 2025. Older figures circulating online (such as $50,120) are out of date.
  • A written data security program and a data retention policy are now mandatory, not best practice. Indefinite retention of children's data is no longer permitted.
  • FTC-approved Safe Harbor programs face stricter oversight, including mandatory security reviews and public membership disclosure. If you rely on one, confirm it has updated its own compliance program.
  • State children's privacy laws now layer on top of COPPA for many U.S. operators, including California's Age-Appropriate Design Code Act, Maryland's and Vermont's counterparts, and the Texas SCOPE Act.
  • Federal reform is moving but not finished. COPPA 2.0 and the Kids Online Safety Act are both active in Congress, but neither is law yet.

If your website, app, or online service has any realistic chance of reaching a child under 13 in the United States, the Children’s Online Privacy Protection Act already applies to you. Since April 22, 2026, that means meeting the Federal Trade Commission's updated rule, not the version of COPPA many compliance guides still describe. This checklist walks through what changed, what's still required, and where the law is headed next.

What Is COPPA and Who Enforces It?

The Children's Online Privacy Protection Act (COPPA) is the U.S. federal law governing how operators collect, use, and disclose personal information from children under 13. Congress passed it in 1998, and it took effect April 21, 2000. The Federal Trade Commission (FTC) implements COPPA through its COPPA Rule, codified at 16 C.F.R. Part 312, and is the law's primary enforcer, alongside state attorneys general and a handful of sector-specific federal regulators.

The FTC substantially revised the Rule twice: once in 2013, and again in January 2025, when it finalized the most significant COPPA update in over a decade. Those 2025 amendments took effect June 23, 2025, with a one-year runway for operators to comply. That runway closed on April 22, 2026. In practical terms, every operator covered by COPPA is now expected to already meet the updated standard, including the new data security, retention, and Safe Harbor provisions covered below.

Does COPPA Apply to Your Website?

COPPA isn't limited to platforms built for kids. Answer "yes" to any of the following, and COPPA compliance requirements likely apply to your operation:

Does COPPA Apply?

Does COPPA Apply?
1

Do you collect personal information from website visitors at all?

2

Are you already legally required to obtain consent to collect that information from anyone?

3

Is any part of your site or content likely to attract or be accessed by children under 13?

4

Do you know, or have reason to know, that children under 13 use your service?

5

Is your service directed at children, even if adults are your primary audience?

COPPA also reaches beyond U.S. borders. If your company is based outside the United States but knowingly collects personal information from children located in the U.S., the same obligations apply. If there's any ambiguity about whether your service is "directed to children" under the FTC's multi-factor test, that's a question for legal counsel, not a compliance checklist.

What Counts as a Child's Personal Information Under COPPA?

COPPA's definition of personal information is broad by design, covering direct identifiers and anything that could be combined with other data to identify or track a child over time. Under 16 C.F.R. Section 312.2, it includes:

  • First and last name
  • Home or physical address, including street name and city or town
  • Online contact information, such as email addresses
  • Screen names or usernames that function as online contact information
  • Telephone numbers
  • Government-issued identifiers, including Social Security numbers or birth certificate numbers
  • Persistent identifiers that recognize a user across sites or services over time, such as cookie-based customer numbers, IP addresses, device serial numbers, and unique device identifiers
  • Photos, videos, or audio files containing a child's image or voice
  • Geolocation data precise enough to identify a street name and city or town
  • Biometric identifiers, including fingerprints, faceprints, voiceprints, retinal scans, and genetic data
  • Any information about the child or their parents that an operator collects from the child and links to one of the identifiers above

The biometric identifier category and the government-issued identifier language were both added by the 2025 Rule amendments. Earlier compliance guides written before mid-2025 may not reflect them.

Do you know what your site is tracking?

Start your free website scan and find out in minutes what cookies and trackers are active. Get your customized privacy compliance risk report.

COPPA Compliance Checklist for U.S. Operators

Use this as a working list, not a substitute for legal review. Each item below reflects the current COPPA Rule, including the 2025 amendments.

1. Confirm Your Safe Harbor Status, If You Have One


If you participate in an FTC-approved Safe Harbor program, confirm that the program itself has updated to reflect the 2025 Rule. Safe Harbor reviews must now cover security as well as privacy practices, and programs must publicly disclose their full membership lists. A Safe Harbor seal that hasn't been refreshed for these changes doesn't protect you from FTC action.

2. Publish a COPPA-Compliant Privacy Policy


Create a clear, detailed privacy policy that's easy to find on your homepage, site footer, and anywhere children's data is collected. Cover the operators collecting data (with names and contact details), what's collected and how (including through tracking cookies), why it's collected, whether it's shared with third parties, and how parents can review, delete, or refuse further collection of their child's information. Skip the legal jargon.

3. Notify Parents Directly, Separately from Your Privacy Policy


Parents need a standalone notice describing what data you collect from children and how, before you collect it. Update that notice whenever your data practices change materially, and get fresh consent if the purpose of processing changes.


Under 16 C.F.R. Section 312.5(b), acceptable verification methods include:

  • Signed consent form
  • Credit or debit card transaction tied to a verifiable adult account
  • Government-issued ID check
  • Video call or toll-free call with trained staff
  • Knowledge-based authentication
  • Facial recognition match against a government photo ID
  • Confirmatory email (in narrow circumstances)

The standard is "reasonable under the circumstances," not a single mandated method. Document every consent obtained, and keep those records secure.

5. Set a Written Data Retention and Deletion Policy


This is new under the 2025 Rule: operators can no longer retain children's personal information indefinitely. You need a written policy specifying how long you keep data, why that period is necessary, and how you delete or anonymize it once it's no longer needed.

6. Build a Formal, Written Data Security Program


16 C.F.R. Section 312.8 now requires a documented program, not just reasonable security measures in general. That program must designate a responsible staff member, address risks identified through regular assessments, apply technical and administrative safeguards, undergo at least annual testing and review, and vet any service provider with access to the data.

7. Give Parents a Working Way to Review, Revoke, and Delete


Parents need an accessible process to review what's been collected from their child, withdraw consent, and request deletion, plus a way to verify that the person making the request is actually the parent.

8. Vet and Monitor Third Parties with Access to Children's Data


Advertising networks, analytics vendors, and other processors need contractual COPPA obligations, and you need to actually audit them, not just sign the contract and move on. Pay particular attention to third-party cookies and tracking scripts running on pages likely to be seen by children.

9. Train Staff and Keep Documentation Current


Regular training on COPPA obligations and data minimization principles, paired with a documentation trail of policy updates, consent records, and third-party agreements, is what stands between "we tried" and "we can prove it" during an FTC inquiry.

A handful of narrow exceptions exist. Consent isn't required when an operator collects a child's contact information solely to obtain parental consent or provide notice, to respond to a one-time request without storing the data, to protect the security or integrity of the service, to support internal operations, to protect the child's safety, or when a school has arranged for educational use and already obtained parental permission. Even inside these exceptions, every other COPPA obligation, including data confidentiality and security, still applies.

FTC Enforcement and Penalties: What COPPA Violations Actually Cost

Civil penalties for COPPA violations currently reach USD 53,088 per violation, a figure the FTC revises annually for inflation. Actual penalties scale with the severity of the conduct, the number of children affected, and how the data was used or shared. Recent cases give a sense of range:

  • YouTube/Google (2019): USD 170 million for collecting data from children on child-directed channels without parental consent.
  • Epic Games/Fortnite (2022): USD 275 million, the largest COPPA penalty to date, for collecting children's data without consent and using dark patterns to bill users.
  • Amazon (2023): USD 25 million for retaining children's Alexa voice recordings beyond what was necessary and for failing to honor parental deletion requests.
  • Disney (2025): USD 10 million, settled after allegations that Disney failed to mark child-directed YouTube videos as "Made for Kids," allowing targeted ad data collection from children. A federal judge approved the settlement in December 2025.
  • Iconic Hearts Holdings ("Sendit") (filed September 2025, pending): The FTC and DOJ allege the anonymous-messaging app knowingly collected data from more than 116,000 self-declared under-13 users without consent, alongside deceptive subscription practices.

Beyond the penalty itself, enforcement typically forces new privacy procedures, deletion of improperly collected data, and public disclosure that can outlast the fine in terms of reputational cost.

How COPPA Interacts With U.S. State Children's Privacy Laws

COPPA sets a federal floor, but it isn't the only children's privacy law U.S. operators need to track, and it stops at age 13. Several state laws extend protections to teens and add obligations COPPA doesn't cover:

  • California Privacy Rights Act (CPRA): Requires opt-in consent before selling or sharing the personal data of anyone aged 13 to 15.
  • California Age-Appropriate Design Code Act: After a March 2026 Ninth Circuit ruling narrowed a lower court's injunction, several provisions, including the coverage definition and the age-estimation requirement, took effect April 3, 2026. The data-use restrictions and the "dark patterns" prohibition remain enjoined pending further litigation, so check current enforcement status before assuming the full law applies to you.
  • Maryland Age-Appropriate Design Code: Covers anyone under 18, requires data protection impact assessments, but doesn't mandate age verification.
  • Vermont Age-Appropriate Design Code Act: Takes effect January 1, 2027, and allows individuals to sue for violations, a private right of action COPPA itself does not provide.
  • Texas SCOPE Act: Partially enforced, restricting targeted advertising to minors under 18 and requiring parental consent for data sharing, with some monitoring, filtering, and age-verification provisions still on hold.

If your operation is U.S.-only, this state layer, not the international comparisons some guides lead with, is usually the more immediate compliance gap worth closing.

Where Federal Reform Stands: COPPA 2.0 and the KIDS Act

Federal law hasn't caught up to these state moves yet, but Congress is actively working on it. Here's where things stood as of early September 2026:

The Senate passed a standalone version of COPPA 2.0 by unanimous consent in March 2026. It would extend COPPA-style protections to teens aged 13 to 16 for the first time, replace COPPA's "actual knowledge" standard with a broader "knowledge fairly implied" test, and add data deletion rights for both age groups.

The House took a different route. Rather than voting on COPPA 2.0 as a standalone bill, it folded a COPPA 2.0 rewrite into a larger package, the Kids Internet and Digital Safety (KIDS) Act (H.R. 7757), and passed that package in June 2026. The House version reaches similar ground on teen protections but was criticized by Senate sponsors for dropping the Kids Online Safety Act's "duty of care" provision.

The Senate has since advanced its own separate slate through committee, including a version of the Kids Online Safety Act with the duty of care provision restored, plus companion bills on AI chatbot safety and youth data privacy. None of this has reached a full Senate floor vote or a House-Senate conference as of this writing.

What this means for your compliance planning: nothing here is law yet. Current obligations remain governed by original COPPA and the FTC's 2025 Rule. Treat any claim that COPPA "now covers teens" or "now requires a duty of care" as premature, and revisit this section before republishing, since this is one of the fastest-moving corners of U.S. privacy law right now.

Children's Privacy Rules Outside the U.S.

If your audience extends beyond U.S. borders, COPPA compliance alone won't cover you. The EU's GDPR sets its own children's consent age (13 to 16, depending on the member state). The UK's Children's Code applies to any service likely to be accessed by under-18s, and countries including Brazil, China, and India each set their own thresholds and requirements.

How Cookiebot Supports COPPA Compliance

Cookiebot™ CMP helps website operators manage the consent and disclosure side of COPPA compliance. It scans your site to keep consent banner information about data processing services current, displays customized consent banners so parents can make informed choices, and keeps audit-ready consent logs over time. Our privacy policy generator pairs with it to produce a COPPA-aligned policy tailored to your specific data practices.

Cookiebot doesn't replace the judgment calls a Safe Harbor program, qualified legal counsel, or your own compliance team need to make, but it does the ongoing scanning and record-keeping so those calls are backed by accurate data.

Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.

Frequently asked questions

Original COPPA and the FTC's 2025 Rule are the current, enforceable law. COPPA 2.0 has passed the Senate as a standalone bill and, in a different form, the House as part of the KIDS Act, but neither chamber's version is law. Compliance planning should be based on today's rule, not the pending one.

The 2025 Rule, fully enforceable since April 22, 2026, added a formal "mixed audience" service definition, expanded personal information to include biometric and government-issued identifiers, added new parental consent verification methods, and made a written data security program and a data retention/deletion policy mandatory rather than optional.

Up to USD 53,088 per violation, as adjusted for inflation in January 2025. Actual penalties depend on the severity of the violation, the number of children affected, and how the data was used.

Yes, if you knowingly collect personal information from children located in the United States. Location of your headquarters doesn't exempt you.

It's optional, not required, but if you already participate in one, confirm it has updated its own reviews to cover the 2025 Rule's security requirements and public membership disclosure obligations. An outdated Safe Harbor seal won't protect you in an FTC action.

California's CPRA and Age-Appropriate Design Code Act, Maryland's Age-Appropriate Design Code, Vermont's Age-Appropriate Design Code Act (effective 2027), and the Texas SCOPE Act all extend obligations beyond COPPA's under-13 scope, typically covering teens as well.

The Federal Trade Commission (FTC) is the primary enforcer, with authority to bring civil actions and negotiate settlements. State attorneys general can also bring COPPA actions within their jurisdictions, and select federal agencies enforce it for industries they separately regulate.

COPPA, in force since 2000, covers children under 13. COPPA 2.0, still pending in Congress, would extend similar protections to teens 14 to 17, tighten the knowledge standard operators are held to, and add a right to deletion for both age groups. It is not currently in effect.

The Children's Online Privacy Protection Act (COPPA) is a US federal law that safeguards the online privacy of children under 13 years old. It requires websites, apps, and online services to obtain verifiable parental consent before collecting personal information from children, publish clear privacy policies, and implement measures to protect children's data.

COPPA is a federal law that applies to online services directed to children under 13, or general-audience services with actual knowledge of users under 13. It requires verifiable parental consent before collecting personal information from those users.

The CAADC extends to all users under 18, applies to any general-audience service children are likely to access (not just services directed at them), and imposes design-level requirements — privacy by default, no dark patterns, impact assessments — that go well beyond COPPA's consent requirements. The two laws overlap for users under 13 but address distinct populations and obligations.

COPPA requires websites and online services to obtain verifiable parental consent before collecting personal information from children under 13. It also mandates that these services provide clear privacy policies, allow parents to review and delete their children's information, and implement measures to protect the confidentiality and security of children's data.

Websites and online services must get verifiable parental consent before collecting personal data from children under 13. They must also have a clear privacy policy, protect children's data, allow parents to review and delete it, and limit data collection to what's necessary for the service.