Understanding New FTC Rules on Children’s Online Privacy
A practical guide to the updated COPPA requirements and what they mean for websites, apps, and parents in the digital age.
The Federal Trade Commission (FTC) has strengthened rules under the Children’s Online Privacy Protection Act (COPPA), reshaping how websites, mobile apps, and online services may collect and use data from children under 13. These changes expand what counts as personal information, tighten consent and retention requirements, and emphasize age verification and security obligations.
This article explains the updated legal landscape, how the rules apply, and what practical steps operators and parents can take to better protect children’s privacy online.
1. Why Children’s Online Privacy Rules Are Being Tightened
Children increasingly engage with games, social platforms, educational tools, and connected devices, often without fully understanding how their data is collected and used. Lawmakers and regulators have responded to concerns about targeted advertising, tracking technologies, and exposure to harmful content.
The FTC’s updated COPPA rules and enforcement policies aim to:
- Give parents more meaningful control over their children’s data.
- Account for modern technologies such as persistent identifiers, geolocation, and multimedia content.
- Reduce the risk of profiling and behavioral advertising directed at children.
- Encourage responsible age verification while limiting data collection to what is strictly necessary.
2. Who Must Comply: Scope of the COPPA Rule
COPPA applies to certain operators of websites and online services that interact with children under 13. The rule covers:
- Online services directed to children under 13, such as child-focused games, educational platforms, and entertainment sites.
- Other operators that have actual knowledge that they are collecting personal information from a child under 13, even if the site is not primarily child-focused.
Within this framework, the FTC distinguishes between:
| Type of Operator | Main Audience | Key Obligations |
|---|---|---|
| Child-directed operator | Primarily children under 13 | Full COPPA duties, including verifiable parental consent before collecting personal information, and strict data limits. |
| Mixed-audience operator | Both children and adults | Must determine whether a user is a child in a neutral manner and apply COPPA obligations for child users. |
| General-audience operator with actual knowledge | Primarily adults | Once the operator knows it is collecting data from a child, COPPA obligations apply to that child’s data. |
Even operators that are not clearly child-focused are increasingly expected to think carefully about age estimation and appropriate privacy safeguards.
3. What Counts as “Personal Information” Under Updated Rules
Initially, COPPA focused on traditional identifiers such as names and email addresses. The updated rule now reflects modern tracking and content-sharing practices by broadening the definition of personal information.
Under the revised framework, personal information includes, among other things:
- Full name, home address, phone number, and email address.
- Usernames and screen names that can identify a child or be used to contact them.
- Persistent identifiers like cookies, device identifiers, IP addresses, or similar technology used to recognize users over time and across services.
- Geolocation data sufficient to identify street-level location.
- Photos, videos, and audio recordings that contain a child’s image or voice.
Because persistent identifiers and multimedia content now clearly fall under COPPA, many services that rely on analytics, personalization, or user-generated content must reassess their practices.
4. Core Duties for Operators Under the FTC’s COPPA Rule
The FTC outlines several baseline obligations for covered operators in its COPPA FAQs and official guidance. Key requirements include:
4.1 Clear Privacy Notices
- Post a clear and comprehensive online privacy policy that explains what information is collected from children, how it is used, with whom it is shared, and how parents can exercise their rights.
- Provide direct notice to parents before collecting personal information, describing the specific practices and consent options.
4.2 Verifiable Parental Consent
- Obtain verifiable parental consent before collecting, using, or disclosing personal information from a child, with limited statutory exceptions.
- Offer parents the option to allow internal use of a child’s information while prohibiting sharing with third parties, unless disclosure is integral to the service and clearly explained.
4.3 Parent Access and Control
- Provide parents with access to their child’s personal information to review or request deletion.
- Offer parents the ability to prevent further collection and use of their child’s data.
4.4 Data Security and Limited Retention
- Maintain the confidentiality, security, and integrity of children’s data and share it only with parties capable of protecting it.
- Retain children’s personal information only as long as necessary for the specific purpose for which it was collected and then delete it with safeguards against unauthorized access or use.
4.5 Limits on Data Demands
- Operators may not condition a child’s participation in activities on providing more personal information than is reasonably needed to participate.
5. Special Rules for Photos, Videos, and Audio of Children
As children increasingly upload photos, record videos, and share audio clips, the FTC has clarified how COPPA applies to these materials.
Under the updated guidance, operators covered by COPPA must:
- Either pre-screen and remove children’s photos, videos, or audio recordings before they are posted; or
- Provide parents with prior notice and obtain verifiable consent before allowing children to upload such content.
This requirement applies wherever a child’s image or voice is captured, underscoring the need for robust moderation and consent workflows in user-generated content platforms.
6. Age Verification: New Enforcement Flexibility and State Laws
Determining whether a user is a child has long been challenging, especially for services serving mixed audiences. Recent FTC action and state legislation provide more structure while encouraging responsible use of age verification technologies.
6.1 FTC Policy Statement on Age Verification
In an enforcement policy statement, the FTC signaled a more flexible approach for certain operators that collect personal information solely to verify age, without first obtaining parental consent, if specific conditions are met.
To benefit from this flexibility, operators must:
- Use information collected for age verification only to determine a user’s age.
- Delete age verification data promptly after use, retaining it no longer than necessary.
- Disclose such data only to third parties that can safeguard it and provide appropriate written assurances.
- Give clear notice to both parents and children about what age verification data is collected.
- Employ reasonable security safeguards for age verification data.
- Take reasonable steps to ensure that the chosen age verification method is likely to produce accurate results.
This policy applies to general or mixed-audience operators, not to services that target children as their primary audience.
6.2 Neutral Age Determination for Mixed-Audience Sites
Mixed-audience services must determine whether visitors are children in a way that does not encourage misrepresentation. The FTC and legal commentators have emphasized that age prompts should be neutral, without default ages or incentives to falsify birth dates.
- Age gates should not pre-select “13+” or encourage users to choose an older age.
- Age estimation methods should be designed to minimize bias and error while respecting privacy.
6.3 State-Level Developments
Several U.S. states have enacted “harmful content age verification” laws that interact with COPPA by requiring platforms to verify user ages before granting access to certain adult or harmful content. Many of these laws also require risk assessments and parental involvement for services directed to children.
7. Advertising, Tracking, and Behavioral Profiling of Children
One major policy goal behind COPPA’s updates is limiting the use of children’s data for targeted advertising. Because persistent identifiers now clearly fall within the definition of personal information, using tracking technologies for behavioral advertising can trigger COPPA obligations.
In practice, this means:
- Operators cannot use tracking cookies or similar technologies to build behavioral profiles of users known to be under 13 without parental consent.
- Plug-ins and third-party tools (for example, social media “Like” buttons) must be carefully configured to avoid collecting personal information from child users without appropriate safeguards and consent.
- Analytics and measurement tools should be limited to aggregate or non-identifying use where possible, or deployed in COPPA-compliant ways.
8. Practical Compliance Steps for Operators
Operators that may be subject to COPPA should undertake a structured compliance program. Below are practical steps aligned with FTC guidance and recent rule updates.
8.1 Assess Whether COPPA Applies
- Analyze your audience: Is your service directed to children, mixed audience, or general audience?
- Review branding, content, and features for child appeal (cartoon characters, simple language, games, etc.).
- Determine whether you have actual knowledge that you collect data from children under 13, such as through registration fields or customer support interactions.
8.2 Map Data Collection and Uses
- List all data points collected from users, including names, contact information, persistent identifiers, location data, and user-generated content.
- Identify which data points may be collected from children and for what purposes.
- Review third-party integrations (ad networks, analytics, plug-ins) to understand how they collect and use data.
8.3 Implement Consent and Notice Workflows
- Design parent-oriented notices that are concise, clear, and specific to the actual data practices.
- Select appropriate methods for verifiable parental consent (e.g., signed forms, payment card transactions, government ID checks, or other FTC-recognized mechanisms).
- Ensure parents can easily access dashboards or contact channels to review, delete, or restrict use of their child’s data.
8.4 Strengthen Security and Retention Governance
- Apply access controls so only authorized staff and vetted third parties handle children’s data.
- Use encryption and other technical safeguards appropriate to the sensitivity of the data.
- Define retention schedules that specify how long each category of children’s data is kept and the methods used to securely delete it.
8.5 Document Policies and Training
- Create written policies describing COPPA compliance procedures and incident response plans.
- Train employees, especially developers and product managers, on children’s privacy obligations.
- Periodically audit data flows and consent records to ensure ongoing compliance.
9. What Parents Can Do to Protect Children’s Privacy
Although COPPA gives parents legal rights and imposes obligations on operators, parents also play a critical role in protecting children’s privacy online.
Helpful actions include:
- Review the privacy policies of child-focused apps and websites before allowing children to use them.
- Set device-level and account-level privacy controls, including limiting access to cameras and microphones.
- Talk with children about what personal information is and why sharing it widely can be risky.
- Encourage children to avoid posting identifiable photos or videos in public spaces and to seek adult help before sharing sensitive content.
- Use parental controls and age-appropriate profiles where platforms offer them.
Parents can also exercise rights under COPPA by contacting operators to review, delete, or restrict the use of their child’s data when the service is covered by the rule.
10. Frequently Asked Questions (FAQs)
Q1: Does COPPA apply to every website or app used by children?
No. COPPA applies to operators of websites and online services that are directed to children under 13 or that have actual knowledge they are collecting personal information from a child under 13. However, the FTC recommends that all sites and services, especially those likely to attract children, post clear privacy policies.
Q2: Is collecting cookies from child users always a COPPA issue?
Cookies and other persistent identifiers are considered personal information when they are used to recognize a user over time and across services. If an operator uses such identifiers with child users for purposes beyond internal operations, such as behavioral advertising, COPPA obligations—including parental consent—are triggered.
Q3: Can an operator rely on age verification without getting parental consent first?
Under the FTC’s enforcement policy statement, certain operators may collect limited personal information solely to verify age without first obtaining parental consent, if they meet strict conditions on use, retention, security, and accuracy. This flexibility does not apply to services primarily targeting children.
Q4: What happens if a parent revokes consent?
If a parent withdraws consent, the operator must stop collecting and using the child’s personal information and, upon request, delete existing data consistent with COPPA’s retention and security requirements.
Q5: Are educational institutions treated differently?
The FTC has provided specific guidance for schools acting as intermediaries for parental consent in certain educational contexts, but operators must still comply with COPPA’s core requirements and ensure that data collected for educational purposes is not used for unrelated commercial uses.
References
- Complying with COPPA: Frequently Asked Questions — Federal Trade Commission. 2023-07-01. https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions
- Children’s Online Privacy Protection Rule (COPPA) — Federal Trade Commission. 2025-04-22. https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa
- Children’s Online Privacy Protection Rule — Federal Register. 2025-04-22. https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule
- Children’s Privacy — Federal Trade Commission. 2024-06-10. https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy
- Kids’ Revised Online Privacy Act Went Into Effect — Bitdefender Hot for Security. 2013-07-05. https://www.bitdefender.com/en-us/blog/hotforsecurity/kids-revised-online-privacy-act-went-into-effect
- FTC Releases COPPA Policy Statement Promoting Age Verification Technology — Ogletree Deakins. 2026-02-26. https://ogletree.com/insights-resources/blog-posts/ftc-releases-coppa-policy-statement-promoting-age-verification-technology
- Children’s Online Privacy: Recent Actions by the States and the FTC — NYU Program on Corporate Compliance and Enforcement. 2025-03-10. https://wp.nyu.edu/compliance_enforcement/2025/03/10/childrens-online-privacy-recent-actions-by-the-states-and-the-ftc/
Read full bio of medha deb





