What Is COPPA and Why It Matters

The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law that protects the privacy and personal information of children under 13. The FTC enforces it through the COPPA Rule, which was substantially amended effective June 23, 2025, with compliance for most new provisions required by April 22, 2026.

COPPA regulates how businesses collect, use, store, and disclose children's personal information - and it applies far more broadly than many organizations realize. It reaches not only children's websites and apps, but platforms, services, and tools that knowingly collect data from children or are directed toward a child audience.

For businesses, COPPA is not just a legal requirement. It is a trust and risk issue that runs directly through IT systems, data security, consent mechanisms, and vendor oversight.

What It Is

COPPA is a consent-first law: before collecting personal information from a child under 13, an operator owes parents clear notice and must obtain verifiable parental consent.

The 2025 amendments sharpened the Rule in ways that matter operationally (Federal Register, April 22, 2025):

  • A written information security program is now explicitly required.
  • A written data retention policy is required, with retention limited to as long as reasonably necessary - indefinite retention is off the table.
  • Separate verifiable parental consent is required before disclosing children's personal information to third parties, including for targeted advertising.
  • A mixed-audience category was defined, with age-screening requirements for services that appeal to children and adults alike.

The FTC also approves safe harbor programs (16 CFR 312.11): an operator participating in an approved program is deemed in compliance with the Rule - a practical route worth knowing exists.

Who It Applies To

COPPA applies to:

  • Websites and online services directed to children under 13: judged by subject matter, visuals, language, and audience evidence.
  • Operators with actual knowledge: any online service that knowingly collects personal data from children, even if not child-directed.
  • Third-party vendors: analytics, advertising, and plugin providers collecting data through child-directed services.
  • Foreign businesses: operators outside the U.S. are covered when they collect data from U.S. children.
  • Mixed-audience services: under the 2025 Rule, services appealing to both children and adults need effective age screening.

In practice that includes educational platforms and edtech providers, gaming and entertainment apps, children's streaming and content platforms, healthcare-adjacent platforms serving minors, toy and media companies with child-focused digital experiences, and SaaS platforms used in schools or by children.

What Information Is Regulated

COPPA defines personal information broadly when it relates to children:

  • Full name
  • Home or email address
  • Phone number
  • Username or online identifier
  • IP address or device identifiers
  • Geolocation data
  • Photos, videos, or audio recordings of a child
  • Persistent identifiers used for tracking (cookies, advertising IDs)
  • Biometric identifiers - added by the 2025 amendments: fingerprints, handprints, retina and iris patterns, voiceprints, facial templates, gait patterns, and DNA (16 CFR Part 312)
  • Any information that can identify or contact a child

From an IT perspective, even metadata and tracking technologies can trigger COPPA obligations. A single embedded analytics script can put a service in scope.

Relation to Other Frameworks

COPPA is often treated as a niche regulation, but its required controls align closely with broader frameworks:

  • **FERPA:** governs student education records; edtech serving schools frequently answers to both.
  • **CCPA/CPRA:** California adds opt-in rules for minors' data and a higher penalty tier for violations involving consumers under 16.
  • **GDPR:** the EU applies its own children's data protections, with parental consent thresholds by member state.
  • **NIST CSF, ISO 27001, and SOC 2:** the security management structures that make COPPA's written security program real.

Investments made for COPPA strengthen your overall security posture, not just child-focused services.

IT Requirements

COPPA requires reasonable procedures to protect children's data - and, under the 2025 amendments, a written information security program and a written data retention policy. Key expectations:

Parental notice and verifiable consent. Clear notice of data collection practices, verifiable parental consent before collection, separate consent before disclosing to third parties (including targeted advertising), and secure storage of consent records.

Data minimization. Collect only what is necessary. Avoid persistent identifiers where possible, and disable unnecessary tracking and analytics - especially third-party scripts.

Strong security safeguards. The written security program in practice: access controls and least-privilege permissions, encryption at rest and in transit, secure cloud and application configurations, and logging and monitoring of access.

Data retention and deletion. A written retention policy, retention limited to as long as reasonably necessary, and secure deletion when data is no longer needed. Indefinite retention is not permitted.

Vendor and third-party oversight. Ensure embedded third-party services comply, restrict vendor data use, and maintain contracts and documentation. COPPA failures often start in a plugin nobody audited.

Why this lands on IT and security teams

COPPA compliance often fails not because of intent, but because of how systems are configured. Common risk areas: analytics or ad tools collecting persistent identifiers, inadequate age-gating, weak parental consent workflows, over-collection, poor access control or retention practices, and third-party plugins collecting data outside your visibility. FTC enforcement actions have cited technical misconfigurations, not just policy failures.

Why It Matters

The penalties are per violation, and they add up. COPPA violations carry FTC civil penalties currently up to $53,088 per violation (16 CFR 1.98, figure effective January 17, 2025; adjusted annually for inflation). Each child's data, mishandled, is its own violation - multiply across a user base and the number gets serious fast.

The 2026 compliance deadline is real. The amended Rule took effect June 23, 2025; compliance with most new provisions is required by April 22, 2026. Operators still running pre-amendment practices - no written security program, no retention policy, no separate disclosure consent - are now out of date.

Children's data raises the stakes on everything. Regulators, parents, school districts, and press treat children's privacy failures differently. The reputational cost of an enforcement action routinely exceeds the fine.

Safe harbor exists. Participation in an FTC-approved safe harbor program is deemed compliance - one structured path to reducing enforcement risk.

How It Fits Into Cyber Risk Management

COPPA's written security program requirement is a program requirement - exactly what a structured approach delivers.

Governance, Risk & Compliance maintains the written policies, consent records, and documentation the amended Rule demands. Cyber Risk Management hardens the systems handling children's data and keeps tracking technologies visible and intentional. Third-Party Assessments audit the analytics, advertising, and plugin vendors where COPPA violations most often originate.

COPPA does not invent new security - it raises the stakes when children's data is involved.

How We Help With COPPA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment traces every point where children's data enters your systems - including third-party scripts - and tests your consent workflows, security program, and retention practices against the amended COPPA Rule.

How to Prepare

  1. 01Identify child-related data flows

    Document where children's data is collected, which systems store it, who has access, and which vendors receive it. Include the third-party tools embedded in your services - they are part of your data flow whether you chose them deliberately or not.

  2. 02Review age-gating and consent mechanisms

    Confirm age screening is effective (including for mixed-audience services), parental consent is verifiable, separate consent exists for third-party disclosures, and consent records are stored securely.

  3. 03Harden systems handling children's data

    MFA for administrative access, encryption, secure APIs and integrations, and logging and monitoring. This is the substance behind the written information security program the Rule now requires.

  4. 04Write the required documents

    The 2025 amendments require a written information security program and a written data retention policy with defined limits. Draft them to match what your systems actually do - then fix whichever side of that comparison is wrong.

  5. 05Review third-party tools

    Audit analytics platforms, advertising tools, embedded plugins, and cloud providers. Many COPPA violations stem from third-party data collection the operator never saw.

  6. 06Train staff

    Employees should understand COPPA basics, data handling restrictions, incident reporting procedures, and why children's data requires extra care.

Frequently Asked Questions

Does COPPA apply to my business?

Yes, if your website or online service is directed to children under 13, or if you have actual knowledge you collect personal data from children - including through embedded third-party tools. Mixed-audience services need age screening under the 2025 Rule. Foreign operators collecting U.S. children's data are covered too.

What happens if we're not compliant with COPPA?

FTC civil penalties currently run up to $53,088 per violation, adjusted annually for inflation - and each affected child can represent a separate violation. Enforcement actions also bring consent decrees, mandated audits, and reputational damage that outlasts the fine.

How long does it take to become COPPA compliant?

The assessment runs two to four weeks; most operators then need a few months to fix consent workflows, write the required security program and retention policy, and clean up third-party trackers. Compliance with most 2025 Rule provisions is required by April 22, 2026 - build the timeline backward from that date.

What does COPPA compliance cost?

It depends on how many services touch children's data and how much third-party cleanup is needed. We publish no pricing - you get a firm quote after the assessment, and the conversation costs nothing.

We already have an IT provider. Do we still need help with COPPA?

Usually. COPPA lives in consent workflows, tracker audits, and written policies - work that sits between legal and IT, and that neither typically owns. Our co-managed approach adds that layer alongside your provider without replacing anyone.

What's the difference between COPPA and FERPA?

COPPA is an FTC privacy law about collecting data from children under 13 online, resting on parental consent. FERPA is a Department of Education law protecting student education records at funded institutions. Edtech companies often answer to both: COPPA for the child users, FERPA for the school records.

Can we handle COPPA compliance ourselves?

Operators with simple data flows sometimes can. The hard parts are the ones you cannot see from inside: third-party scripts collecting persistent identifiers, and consent flows that fail the "verifiable" test. Our DIY-with-support tier pairs your team's execution with our gap analysis - scoped and quoted after your assessment.

Where do we start with COPPA?

Start with an honest inventory of what your services actually collect - including every embedded tool. Our Cyber Risk & Compliance Gap Assessment maps those flows against the amended Rule and gives you a prioritized path to the April 2026 compliance deadline and beyond.

Official source

Official source: Federal Trade Commission - COPPA Rule

Secondary source: eCFR - 16 CFR Part 312

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25