← Framework library

Children's Online Privacy Protection Rule (COPPA)

The duties of the FTC's COPPA Rule, including the 2025 amendments on separate consent for third-party disclosure, written information security programs and written data retention policies. Each control cites the section it derives from.

US Federal Trade Commission · 16 CFR Part 312, as amended April 2025 (effective 23 June 2025; compliance with the amendments required by 22 April 2026) · United States — operators of websites, apps and online services directed to children under 13, or with actual knowledge that they collect children's personal information · Official source

If the service is not directed to children and has no actual knowledge of collecting from under-13s, most of these controls are not applicable — record that assessment under 312.2-312.3. FTC-approved safe harbor programmes (312.11) offer an alternative route to demonstrate compliance. Requirement text is paraphrased; the regulation is authoritative and this tool is not legal advice.
9 of 9 controls
312.2-312.3 Determine whether COPPA applies high

COPPA applies to operators of websites or online services directed to children under 13, and to general-audience or mixed-audience services with actual knowledge that they collect personal information from a child. The operator should document whether its service is child-directed (considering subject matter, visual content, characters, audience composition and advertising) and how it screens for age where the audience is mixed.

Scope childrendata-classification
312.4(d) Online notice of children's information practices high

The operator posts a prominent, clearly labelled link to an online notice of its information practices with regard to children on its home page and at each area where children's personal information is collected, describing what is collected, how it is used and disclosed (including the identities or categories of third-party recipients and purposes), the data retention policy, and parents' rights.

Notice privacy-noticechildren
312.4(b)-(c) Direct notice to parents high

Before collecting a child's personal information, the operator makes reasonable efforts to give the parent direct notice explaining what information is being collected, that consent is required, the purposes, any disclosure to third parties (with the identities or categories of recipients and purposes), and that the information will be deleted if consent is not given within a reasonable time.

Notice privacy-noticeconsentchildren
312.5 Verifiable parental consent before collection critical

The operator obtains verifiable parental consent before collecting, using or disclosing personal information from a child, using a method reasonably calculated to ensure the person consenting is the parent — such as a signed form, a payment-card transaction with notice, a call or video conference with trained staff, government ID checked against a database and deleted, knowledge-based questions, facial matching to ID, or text-plus (email plus) where information is only used internally — unless a 312.5(c) exception applies.

Parental consent consentchildren
312.5(a)(2) Separate consent before disclosing children's data to third parties critical

Under the amended rule (compliance required from 22 April 2026), an operator must obtain separate verifiable parental consent before disclosing a child's personal information to third parties — including for targeted advertising — unless the disclosure is integral to the nature of the service; parents can consent to collection without consenting to disclosure.

Parental consent consentthird-partychildren
312.6 Parents may review, delete and refuse further collection high

On request, a parent who verifies their identity can obtain a description of the types of personal information collected from their child and the information itself, direct the operator to delete it, and refuse to permit further use or future online collection.

Parental rights data-subject-rightsdata-deletionchildren
312.7 No conditioning participation on excess data medium

An operator may not condition a child's participation in a game, prize offer or other activity on the child disclosing more personal information than is reasonably necessary to participate.

Parental consent data-minimisationchildren
312.8 Written information security program for children's data critical

The operator maintains a written information security program appropriate to its size and the sensitivity of the data, with one or more designated coordinators, an annual risk assessment, safeguards to control identified risks, regular testing and monitoring of safeguards, and at least annual evaluation and modification; it takes reasonable steps to release children's information only to recipients capable of protecting it, with written assurances.

Security and retention policy-governancerisk-assessmentchildren
312.10 Written data retention policy for children's information high

Children's personal information is retained only as long as reasonably necessary for the specific purpose it was collected for, never indefinitely; the operator maintains a written data retention policy stating the purposes, the business need, and the timeframe for deletion, publishes it in its online notice, and deletes the information securely.

Security and retention data-retentiondata-deletionchildren