The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law that protects the privacy and personal information of children under 13. The FTC enforces it through the COPPA Rule, which was substantially amended effective June 23, 2025, with compliance for most new provisions required by April 22, 2026.
COPPA regulates how businesses collect, use, store, and disclose children's personal information - and it applies far more broadly than many organizations realize. It reaches not only children's websites and apps, but platforms, services, and tools that knowingly collect data from children or are directed toward a child audience.
For businesses, COPPA is not just a legal requirement. It is a trust and risk issue that runs directly through IT systems, data security, consent mechanisms, and vendor oversight.
COPPA is a consent-first law: before collecting personal information from a child under 13, an operator owes parents clear notice and must obtain verifiable parental consent.
The 2025 amendments sharpened the Rule in ways that matter operationally (Federal Register, April 22, 2025):
The FTC also approves safe harbor programs (16 CFR 312.11): an operator participating in an approved program is deemed in compliance with the Rule - a practical route worth knowing exists.
COPPA applies to:
In practice that includes educational platforms and edtech providers, gaming and entertainment apps, children's streaming and content platforms, healthcare-adjacent platforms serving minors, toy and media companies with child-focused digital experiences, and SaaS platforms used in schools or by children.
COPPA defines personal information broadly when it relates to children:
From an IT perspective, even metadata and tracking technologies can trigger COPPA obligations. A single embedded analytics script can put a service in scope.
COPPA is often treated as a niche regulation, but its required controls align closely with broader frameworks:
Investments made for COPPA strengthen your overall security posture, not just child-focused services.
COPPA requires reasonable procedures to protect children's data - and, under the 2025 amendments, a written information security program and a written data retention policy. Key expectations:
Parental notice and verifiable consent. Clear notice of data collection practices, verifiable parental consent before collection, separate consent before disclosing to third parties (including targeted advertising), and secure storage of consent records.
Data minimization. Collect only what is necessary. Avoid persistent identifiers where possible, and disable unnecessary tracking and analytics - especially third-party scripts.
Strong security safeguards. The written security program in practice: access controls and least-privilege permissions, encryption at rest and in transit, secure cloud and application configurations, and logging and monitoring of access.
Data retention and deletion. A written retention policy, retention limited to as long as reasonably necessary, and secure deletion when data is no longer needed. Indefinite retention is not permitted.
Vendor and third-party oversight. Ensure embedded third-party services comply, restrict vendor data use, and maintain contracts and documentation. COPPA failures often start in a plugin nobody audited.
COPPA compliance often fails not because of intent, but because of how systems are configured. Common risk areas: analytics or ad tools collecting persistent identifiers, inadequate age-gating, weak parental consent workflows, over-collection, poor access control or retention practices, and third-party plugins collecting data outside your visibility. FTC enforcement actions have cited technical misconfigurations, not just policy failures.
The penalties are per violation, and they add up. COPPA violations carry FTC civil penalties currently up to $53,088 per violation (16 CFR 1.98, figure effective January 17, 2025; adjusted annually for inflation). Each child's data, mishandled, is its own violation - multiply across a user base and the number gets serious fast.
The 2026 compliance deadline is real. The amended Rule took effect June 23, 2025; compliance with most new provisions is required by April 22, 2026. Operators still running pre-amendment practices - no written security program, no retention policy, no separate disclosure consent - are now out of date.
Children's data raises the stakes on everything. Regulators, parents, school districts, and press treat children's privacy failures differently. The reputational cost of an enforcement action routinely exceeds the fine.
Safe harbor exists. Participation in an FTC-approved safe harbor program is deemed compliance - one structured path to reducing enforcement risk.
COPPA's written security program requirement is a program requirement - exactly what a structured approach delivers.
Governance, Risk & Compliance maintains the written policies, consent records, and documentation the amended Rule demands. Cyber Risk Management hardens the systems handling children's data and keeps tracking technologies visible and intentional. Third-Party Assessments audit the analytics, advertising, and plugin vendors where COPPA violations most often originate.
COPPA does not invent new security - it raises the stakes when children's data is involved.
Here is the truth most businesses overlook: the overwhelming majority of compliance requirements are the basic protections every business should run anyway.
Strong access controls, minimal data collection, secure systems, and documented processes protect children, parents, your business, and your reputation.
What the 2025 Rule changed is the paper trail: the security program and retention policy now have to exist in writing. If you are already running the controls, writing them down is the easy part.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment traces every point where children's data enters your systems - including third-party scripts - and tests your consent workflows, security program, and retention practices against the amended COPPA Rule.
Document where children's data is collected, which systems store it, who has access, and which vendors receive it. Include the third-party tools embedded in your services - they are part of your data flow whether you chose them deliberately or not.
Confirm age screening is effective (including for mixed-audience services), parental consent is verifiable, separate consent exists for third-party disclosures, and consent records are stored securely.
MFA for administrative access, encryption, secure APIs and integrations, and logging and monitoring. This is the substance behind the written information security program the Rule now requires.
The 2025 amendments require a written information security program and a written data retention policy with defined limits. Draft them to match what your systems actually do - then fix whichever side of that comparison is wrong.
Audit analytics platforms, advertising tools, embedded plugins, and cloud providers. Many COPPA violations stem from third-party data collection the operator never saw.
Employees should understand COPPA basics, data handling restrictions, incident reporting procedures, and why children's data requires extra care.
Yes, if your website or online service is directed to children under 13, or if you have actual knowledge you collect personal data from children - including through embedded third-party tools. Mixed-audience services need age screening under the 2025 Rule. Foreign operators collecting U.S. children's data are covered too.
FTC civil penalties currently run up to $53,088 per violation, adjusted annually for inflation - and each affected child can represent a separate violation. Enforcement actions also bring consent decrees, mandated audits, and reputational damage that outlasts the fine.
The assessment runs two to four weeks; most operators then need a few months to fix consent workflows, write the required security program and retention policy, and clean up third-party trackers. Compliance with most 2025 Rule provisions is required by April 22, 2026 - build the timeline backward from that date.
It depends on how many services touch children's data and how much third-party cleanup is needed. We publish no pricing - you get a firm quote after the assessment, and the conversation costs nothing.
Usually. COPPA lives in consent workflows, tracker audits, and written policies - work that sits between legal and IT, and that neither typically owns. Our co-managed approach adds that layer alongside your provider without replacing anyone.
COPPA is an FTC privacy law about collecting data from children under 13 online, resting on parental consent. FERPA is a Department of Education law protecting student education records at funded institutions. Edtech companies often answer to both: COPPA for the child users, FERPA for the school records.
Operators with simple data flows sometimes can. The hard parts are the ones you cannot see from inside: third-party scripts collecting persistent identifiers, and consent flows that fail the "verifiable" test. Our DIY-with-support tier pairs your team's execution with our gap analysis - scoped and quoted after your assessment.
Start with an honest inventory of what your services actually collect - including every embedded tool. Our Cyber Risk & Compliance Gap Assessment maps those flows against the amended Rule and gives you a prioritized path to the April 2026 compliance deadline and beyond.
Official source: Federal Trade Commission - COPPA Rule
Secondary source: eCFR - 16 CFR Part 312
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25