Children's Online Privacy Protection Rule (COPPA)
The duties of the FTC's COPPA Rule, including the 2025 amendments on separate consent for third-party disclosure, written information security programs and written data retention policies. Each control cites the section it derives from.
US Federal Trade Commission · 16 CFR Part 312, as amended April 2025 (effective 23 June 2025; compliance with the amendments required by 22 April 2026) · United States — operators of websites, apps and online services directed to children under 13, or with actual knowledge that they collect children's personal information · Official source
COPPA applies to operators of websites or online services directed to children under 13, and to general-audience or mixed-audience services with actual knowledge that they collect personal information from a child. The operator should document whether its service is child-directed (considering subject matter, visual content, characters, audience composition and advertising) and how it screens for age where the audience is mixed.
The operator posts a prominent, clearly labelled link to an online notice of its information practices with regard to children on its home page and at each area where children's personal information is collected, describing what is collected, how it is used and disclosed (including the identities or categories of third-party recipients and purposes), the data retention policy, and parents' rights.
Before collecting a child's personal information, the operator makes reasonable efforts to give the parent direct notice explaining what information is being collected, that consent is required, the purposes, any disclosure to third parties (with the identities or categories of recipients and purposes), and that the information will be deleted if consent is not given within a reasonable time.
The operator obtains verifiable parental consent before collecting, using or disclosing personal information from a child, using a method reasonably calculated to ensure the person consenting is the parent — such as a signed form, a payment-card transaction with notice, a call or video conference with trained staff, government ID checked against a database and deleted, knowledge-based questions, facial matching to ID, or text-plus (email plus) where information is only used internally — unless a 312.5(c) exception applies.
Under the amended rule (compliance required from 22 April 2026), an operator must obtain separate verifiable parental consent before disclosing a child's personal information to third parties — including for targeted advertising — unless the disclosure is integral to the nature of the service; parents can consent to collection without consenting to disclosure.
On request, a parent who verifies their identity can obtain a description of the types of personal information collected from their child and the information itself, direct the operator to delete it, and refuse to permit further use or future online collection.
An operator may not condition a child's participation in a game, prize offer or other activity on the child disclosing more personal information than is reasonably necessary to participate.
The operator maintains a written information security program appropriate to its size and the sensitivity of the data, with one or more designated coordinators, an annual risk assessment, safeguards to control identified risks, regular testing and monitoring of safeguards, and at least annual evaluation and modification; it takes reasonable steps to release children's information only to recipients capable of protecting it, with written assurances.
Children's personal information is retained only as long as reasonably necessary for the specific purpose it was collected for, never indefinitely; the operator maintains a written data retention policy stating the purposes, the business need, and the timeframe for deletion, publishes it in its online notice, and deletes the information securely.