Insight

What Is COPPA? The Children’s Online Privacy Protection Act Explained

Insight Published 25 min read
Two children using laptops, illustrating the Children’s Online Privacy Protection Act (COPPA) and online privacy for kids.

When researchers watched the network traffic of the 5,855 most popular child-directed Android apps, roughly 57% showed signs of potentially violating the federal children’s privacy law, mostly through third-party SDKs (software development kits) whose own terms of service forbid use in children’s apps.

Key takeaways

  • COPPA is the federal law that gives parents, not platforms, control over what online services collect from children under 13, enforced by the FTC at up to $53,088 per violation, with penalties scaling by the number of children affected.
  • You are covered if your service is directed at children, if you actually know under-13s use your general-audience service, or if you are a third party collecting on someone else’s child-directed service.
  • The 2025 amendments are fully in force (the April 22, 2026 compliance deadline has passed), bringing separate opt-in consent for third-party sharing and targeted ads, an expanded personal-information definition, and written security and retention programs.
  • Exclusion is lawful: a neutral age screen (no defaults, no steering) keeps a general-audience service out of scope, and teenagers are covered by other laws, not COPPA.
  • The operator is responsible for third-party code on its pages; since 2025, every collector on a child-audience page needs a legal route (separate consent, a narrow exception, or removal), and a collector you cannot name has no route.

What is COPPA?

COPPA is the US federal law that gives parents, not online platforms, control over what information websites, apps, and online services can collect from children under 13 and under what conditions. The Federal Trade Commission (FTC) and state attorneys general enforce this law.

COPPA is not just for kids’ sites: general-audience services and third-party code can be covered too, as the next section details. The FTC overhauled its COPPA Rule in 2025. The April 22, 2026 compliance deadline has passed.

Quick history:

  • Enacted: October 21, 1998; the FTC’s original COPPA Rule took effect April 21, 2000, per the FTC’s COPPA compliance FAQ.
  • Statute: 15 U.S.C. §§ 6501–6506, implemented by the COPPA Rule, 16 CFR Part 312.
  • Enforced by: the FTC, with state attorneys general and certain federal sectoral regulators.
  • Civil penalty exposure: up to $53,088 per violation.
  • Major revisions: 2013 (persistent identifiers and geolocation became personal information) and 2025 (mixed audience, separate consent for third-party sharing and targeted advertising, expanded personal information, written retention and security programs).

Who does COPPA apply to?

COPPA applies to three kinds of actors, and two of the three never set out to serve children. The three triggers, as checkable statements:

  1. You operate a website or online service directed to children under 13 and collect personal information from them.
  2. You operate a general-audience website or online service and have actual knowledge that you collect personal information from children under 13.
  3. You are a third party (an ad network, analytics provider, plug-in, or SDK) with actual knowledge that you collect personal information directly from users of another operator’s child-directed service.

The Rule’s definition of “website or online service” reaches far past websites: mobile apps, networked video games, internet-connected toys and other IoT (Internet of Things) devices, voice-enabled services, advertising networks, plug-ins, location-based services, and internet telephony (VoIP), which is why the law lands on game studios, toy makers, and ad tech, not just website owners.

There are two legal ways to avoid being covered by COPPA: use a neutral age screen that follows specific design rules, or, if you find out a user is under 13, stop collecting their data and delete any information you already have. The FTC says you must either comply with the law or delete the data. Just stopping collection is not enough if you still have the child’s information. If done correctly, exclusion is allowed.

My site is general-audience: when am I covered?

Actual knowledge means exactly what it says. The FTC’s FAQ gives concrete examples of how a general-audience operator acquires it: your registration form asks for a date of birth and users enter birthdays that make them under 13, your signup flow asks what grade the user is in, or a parent emails you about their child’s account. Any of these converts you into a covered operator for those users, whatever your intended audience was.

Scale is no defense: the largest COPPA resolutions on record belong to platforms that were never kids’ sites at all. YouTube, a general-audience platform that, as the FTC showed, had promoted itself to advertisers as a top destination for children while claiming it had no under-13 users, held the record from 2019 until Epic’s $275 million Fortnite settlement passed it in 2022. The Justice Department’s 2026 TikTok resolution sits above both.

Who COPPA does not cover

The genuine exemptions are narrower than they sound:

  • Nonprofits generally sit outside the FTC’s jurisdiction, so COPPA’s operator duties (which run through the FTC Act) do not reach them the same way.
  • Schools themselves, acting as schools, are not “operators” of the online services they buy, though their edtech vendors are, which is why school consent gets its own section below.
  • Purely offline collection is outside a statute about online privacy.

Foreign companies are not exempt. If your service targets children in the United States, it does not matter where your company is based. COPPA applies based on the child’s location, not where the company is registered.


Is your site “directed to children”?

The FTC decides “directed to children” based on what your site looks and sounds like, not from the audience you declare. 16 CFR §312.2 lists the factors. Since the 2025 amendments, it also recognizes a formal middle category, “mixed audience,” for services that attract many children without targeting them as the primary audience.

The factors the FTC weighs include:

  • Subject matter of the site or service
  • Visual and audio content
  • Use of animated characters or child-oriented activities and incentives
  • Age of models appearing on the site
  • Presence of child celebrities or celebrities who appeal to children
  • Language and other characteristics of the site
  • Whether advertising on the site is directed to children
  • Competent and reliable empirical evidence about audience composition
  • Evidence about the intended audience

When the FTC settled with Google and YouTube in 2019, then-FTC Chairman Joe Simons stated the principle bluntly: “YouTube touted its popularity with children to prospective corporate clients… Yet when it came to complying with COPPA, the company refused to acknowledge that portions of its platform were clearly directed to kids. There’s no excuse for YouTube’s violations of the law.” (FTC press release, September 4, 2019)

You cannot opt out of the test by labeling your site “13+” in the terms of service. If the factors point at children, the FTC reads the site, not the disclaimer.

Mixed audience

The 2025 Rule codified a category for services that are child-directed under the factor test but do not target children as their primary audience. A “mixed audience website or online service” may screen for age. It collects no personal information, beyond the Rule’s narrow exceptions, until age information has been collected through a neutral means, and it is not treated as directed to children toward visitors not identified as under 13.

Obligations then attach per visitor, not per site: once the screen identifies a visitor as under 13, the operator has actual knowledge, and the full duty set (notice, verifiable parental consent, and the rest) applies to that child.

Creators

On YouTube, the directed-to-children call arrives as a product setting: the “made for kids” designation. Creators are legally required to mark child-directed videos or channels, a duty the 2019 Google/YouTube settlement pushed down to channel owners, and YouTube’s own machine-learning systems can override a creator’s designation, subject to appeal.

The designation has real consequences, per YouTube’s own audience-setting documentation: comments are disabled, the notification bell is turned off, personalized advertising is removed, and cards, end screens, and save-to-playlist stop working on designated content. The label carries a revenue cost. Mislabeling the other way became a federal case (the Disney settlement in the enforcement table below). YouTube’s guidance to creators is direct: “Do not rely on our systems to set your audience for you.”

The same directed-to-children analysis applies anywhere creators publish kids’ content; YouTube is simply the platform that formalized it.

COPPA applicability flowchart showing when websites, apps, and third parties are covered based on child-directed content, mixed audiences, and knowledge of users under 13.

Is an age gate enough? Exclusion and the under-13 line

Blocking children under 13 is a lawful way out of COPPA, but the age screen itself has design rules. The Rule’s coverage line stays fixed at “under 13,” which leaves teenagers to other laws entirely.

A neutral age screen, as the Rule frames it:

  • Asks in a neutral manner. No defaulting to an adult birth year, no copy or design that steers the visitor toward a particular answer.
  • Collects nothing first. No personal information is gathered from any visitor, beyond the Rule’s narrow exceptions, before the age question is answered.
  • Acts on the answer. Once a visitor is identified as under 13, the operator either obtains verifiable parental consent for that child or stops collecting their personal information. A mixed-audience service can’t use the screen as decoration and keep collecting anyway.

The two exits trade differently. Full exclusion (refusing under-13 registrations) is the cleanest legal position but forfeits the under-13 audience. The mixed-audience route keeps the audience but puts every identified child under the full duty set. The choice is a product decision, not a loophole.

Age falsification is the known hole in any screen that only asks, and 12-year-olds beat lazy ones for sport. The Rule’s answer is twofold: the actual-knowledge standard (what matters is what the operator actually learns, not what a checkbox claimed) and the neutrality requirement itself: a screen whose defaults or wording are engineered to produce “adult” answers is not collecting age in a neutral manner.

As for teenagers: COPPA stops at 13. Protection for 13- to 17-year-olds lives in the state kids’ codes covered in the what’s-next section below and, in Europe, in GDPR Article 8‘s parental-consent rules for under-16s (member states may lower the threshold to 13). 

GDPR explainer →


What counts as personal information under COPPA?

COPPA’s definition of personal information runs well beyond names and email addresses. The full definition lives in 16 CFR §312.2; the table below is the working version, with the 2025 additions flagged.

CategoryExamplesNotes
Name and contact basicsFirst and last name; home or physical address; telephone numberThe obvious rows
Online contact informationEmail address; any identifier that permits direct contact with a specific person (instant-message, voice-chat, or video-call identifiers)Mobile phone numbers were made explicit here in 2025
Screen and user namesA handle that functions as online contact informationCovered only when it permits direct contact
Government-issued identifiersSocial Security, state identification card, birth certificate, or passport numbersAdded in 2025
Biometric identifiersFingerprints; handprints; retina and iris patterns; genetic data including a DNA sequence; voiceprints; gait patterns; facial templates and faceprintsAdded in 2025: identifiers usable for automated or semi-automated recognition
Photos, video, and audioFiles containing the child’s image or voiceIn scope since 2013
GeolocationLocation data precise enough to identify a street name and city or townIn scope since 2013. The scope test is the precision threshold, not the category
Persistent identifiersCookies, IP addresses, device serial numbers, advertising IDs: identifiers that can recognize a user over time and across sitesThe row that pulls trackers and SDKs into COPPA scope; usable without consent only under narrow exceptions
CombinationsOther information about the child or the child’s parents collected online and combined with an identifier aboveThe catch-all row

The identifier row that doesn’t look like personal information

A cookie that can follow a child across sites is legally that child’s personal information. This single row pulls trackers, analytics packages, and advertising SDKs into COPPA’s scope even when no child ever fills out a form. That is why the third-party questions later in this article are not edge cases.

The one lawful lane for identifiers without consent is the support-for-internal-operations exception, with hard edges, covered in the consent section’s exceptions table. For the mechanics of how these identifiers move across sites, see how web tracking works →


What does COPPA require?

A covered operator’s obligations come down to nine working duties: two notices (a public policy and direct notice to parents), consent, parental rights, minimization, security, retention, third-party care, and the records that prove each one. The checklist below is the complete set, with the rows the 2025 Rule changed flagged.

DutyWhat it meansChanged in 2025?
Post a compliant privacy policyClear online notice of what you collect from children, how you use it, and who receives it.Online notice must now include your data-retention policy and internal-operations disclosure
Give parents direct noticeBefore collecting from a child, tell the parent what you want to collect and how to consent or refuseDirect notice must now identify the third parties (or categories) receiving the data, and the purposes
Obtain verifiable parental consent before collectionA method reasonably calculated to ensure the consenter is the parent. Methods and exceptions in the next sectionThird-party disclosure and targeted advertising now require a separate opt-in consent
Honor parental rightsLet parents review their child’s data, have it deleted, and refuse further collection or useUnchanged
Collect no more than reasonably necessaryData minimization: never condition a child’s participation in an activity on disclosing more than the activity requiresUnchanged
Maintain a written information security program16 CFR §312.8: a designated security coordinator, annual risk assessments, safeguards against identified risks, regular testing, and at-least-annual evaluationNew written-program mandate
Retain only as long as necessary, then delete securely16 CFR §312.10: a written data-retention policy stating purposes, business need, and a deletion timeframeNew: written policy required; indefinite retention explicitly banned
Exercise care over third partiesTake reasonable steps to release children’s data only to recipients capable of protecting it, with written assurances (§312.8(c))Strengthened
Keep the records that prove each decisionYour applicability determination, the notices you sent, the consents you captured, your retention schedule: the evidence row that makes the other eight defensibleReinforced by the new written-policy mandates

Verifiable parental consent is a method, not a checkbox: a mechanism reasonably calculated to ensure the person giving it is the child’s parent, with the rigor scaled to what the operator does with the data, obtained before any collection begins. Consent here never comes from the user: a parent decides for the child.

The methods the current Rule (16 CFR §312.5(b)(2)) accepts:

  • A signed consent form returned by postal mail, fax, or electronic scan
  • A credit or debit card, or similar online payment account, used in connection with a transaction, with per-transaction notification to the primary account holder
  • A toll-free phone call to trained personnel
  • A video conference with trained personnel
  • Government-issued ID checked against databases, with the ID deleted promptly after verification
  • Knowledge-based authentication: dynamic multiple-choice questions with low guessability, hard enough that a child 12 or younger in the household could not answer them
  • Photo ID plus facial match: a government-issued photo ID verified as authentic and compared by facial recognition against a live camera image, confirmed by trained personnel, with prompt deletion
  • “Email plus”: an email request plus a delayed confirmatory step, permitted only where the child’s personal information is never disclosed to third parties
  • “Text plus”: the same structure by text message, added in 2025

Consent depends on the direct notice, which tells the parent what the operator wants to collect from the child, how it will be used, who it goes to, and how to consent or refuse before any collection and again whenever the operator’s practices materially change.

See what a compliant disclosure must contain →

The exceptions and their limits

Consent is not required for every collection. The Rule lists nine exceptions (16 CFR §312.5(c)), each with hard edges:

ExceptionWhat it permitsWhat it forbids
Obtaining consentParent’s or child’s name and online contact information, solely to provide notice and seek consentAny other use; the data must be deleted if consent is not given within a reasonable time
Voluntary noticeTelling a parent about a child’s participation on a service that collects nothing elseCollecting anything beyond the notice itself
One-time responseOne response to a child’s specific requestRecontacting the child; the information must be promptly deleted
Multiple responsesRepeated responses to a child’s specific request, with notice to the parentAny use unrelated to the request
Child safetyCollecting information to protect a child’s safetyUse beyond the safety purpose
Security and legal processProtecting security and integrity, taking liability precautions, responding to judicial process, cooperating with law enforcementUnrelated uses
Support for internal operationsA persistent identifier, and nothing else, for maintaining and analyzing the service’s functioning, authenticating users, personalizing content, serving contextual advertising or capping ad frequency, security, and legal complianceContacting a specific individual, behavioral advertising, building a profile on a specific individual, or any other use or disclosure
Prior adult registrationA persistent identifier collected from a previously registered non-child user of a child-directed serviceAny other personal information
Voice audio for a requestAn audio file of a child’s voice used solely to respond to that child’s requestKeeping it: the file must be deleted immediately after the response

The internal-operations row is the one analytics and ad tech reach for. Read its right-hand column: the moment an identifier feeds behavioral advertising, profiling, or any disclosure beyond the listed internal purposes, the exception is gone, and consent was required all along.


What changed in the 2025 Rule amendments?

The FTC’s 2025 amendments rebuilt the Rule around one target: the monetization of children’s data by third parties. Any COPPA program written before 2025 predates the current Rule.

Announcing the final rule, FTC Chair Lina M. Khan said: 

“By requiring parents to opt in to targeted advertising practices, this final rule prohibits platforms and service providers from sharing and monetizing children’s data without active permission.”

(FTC press release, January 16, 2025)

Old rule versus new, side by side:

AreaBefore 2025Now, in force
Mixed audienceNo defined category: a service either was or was not child-directedA codified “mixed audience” category (16 CFR §312.2) with neutral age screening; duties attach per identified child
Third-party disclosure and targeted advertisingSwept into the general parental consentSeparate opt-in verifiable parental consent required for disclosure to third parties, unless the disclosure is integral to the service (§312.5(a)(2))
Personal informationThe 2013 definitionExpanded: government-issued identifiers, biometric identifiers, and mobile numbers as online contact information (§312.2)
Data retentionGeneral limits; no written-policy mandateA written data-retention policy is required; retention only as long as reasonably necessary; indefinite retention explicitly banned (§312.10)
Security“Reasonable procedures” to protect children’s dataA written information security program with five mandated elements, plus written assurances before releasing data to other operators or third parties (§312.8)
Safe Harbor programsSelf-regulation with limited public visibilityAnnual reviews, public membership lists, and reporting obligations: the programs themselves now answer to the FTC in public (§312.11)

The dates, precisely. The Commission approved the final rule 5–0 on January 16, 2025. It was published in the Federal Register on April 22, 2025 (90 FR 16918), became effective June 23, 2025, and its full compliance date, already passed, was April 22, 2026. For balance: the FTC also declined parts of its own proposal: the suggested edtech and school-consent rules and the limits on push notifications to children were not finalized, which is why school consent remains guidance-based, as the school section above explains.

Safe Harbor after 2025

COPPA’s Safe Harbor mechanism lets industry groups run FTC-approved self-regulatory programs whose guidelines provide the same or greater protections as the Rule. Operators that stay within an approved program’s guidelines are treated as compliant. Exactly six programs are currently approved, per the FTC’s Safe Harbor program page: the Children’s Advertising Review Unit (CARU), the Entertainment Software Rating Board (ESRB), iKeepSafe, kidSAFE, Privacy Vaults Online, Inc. (doing business as PRIVO), and TRUSTe.

Membership signals diligence, but it has never been immunity, and since the 2025 amendments, the programs themselves face annual reviews, public membership reporting, and FTC oversight of their own performance.

The February 2026 age-verification policy

On February 25, 2026, the FTC issued an enforcement policy statement on age-verification technology, adopted by a 2–0 vote. It will not bring COPPA enforcement actions against operators of general-audience and mixed-audience services that collect personal information solely to determine a user’s age without first obtaining verifiable parental consent, provided six conditions are met:

  • no use or disclosure for any other purpose
  • retention no longer than necessary with prompt deletion
  • disclosure only to third parties reasonably determined capable of protecting the data (with written assurances)
  • clear notice to parents and children
  • reasonable security safeguards
  • reasonable steps to ensure the method produces reasonably accurate results.

Child-directed services are not covered: they must treat all users as children. It is enforcement discretion, not a rule change, and it does not bind state attorneys general. The FTC has said it intends to open a review of the COPPA Rule itself to address age-verification mechanisms.


Who enforces COPPA, and what are the penalties?

COPPA is enforced by the FTC, with the Department of Justice filing its federal court cases, by state attorneys general acting under 15 U.S.C. §6504, and by certain federal regulators for their own sectors. Civil penalties run up to $53,088 per violation, and because the number of children affected is an explicit penalty factor, single cases reach eight and nine figures.

The figure comes from the FTC’s inflation-adjusted penalty schedule, 16 CFR §1.98, for penalties assessed after January 17, 2025.

COPPA contains no private right of action: individuals cannot sue under it.

The enforcement examples:

YearCasePenaltyWhat they did wrong
2019Musical.ly (now TikTok) (Feb. 27)$5.7 millionCollected names, email addresses, and other personal information from users under 13 without parental notice or consent; failed to honor deletion requests
2019Google and YouTube (Sept. 4)$170 million for COPPA violations ($136 million to the FTC, $34 million to New York)Collected cookies from viewers of channels YouTube knew were child-directed to serve targeted ads, without parental notice or consent; the order created the “made for kids” labeling system
2022Epic Games (Fortnite) (Dec. 19)$275 million for COPPA. A separate administrative order the same day added $245 million in refunds for billing dark patterns ($520 million total)Collected personal information from under-13 Fortnite players without parental notice or consent; the order imposed first-of-its-kind privacy defaults for children and teens
2023Amazon (Alexa) (May 31)$25 millionKept children’s voice recordings indefinitely, undermined parents’ deletion requests, and used the recordings to train speech-recognition algorithms
2025Disney (Sept. 3; order approved by a federal court in December 2025)$10 millionChannel-level YouTube audience designations left child-directed videos mislabeled. Targeted ads ran on children’s videos without parental consent
2025Apitor (Sept. 3)$500,000, suspended for inability to payThird-party SDK (JPush) in the robot-toy companion app collected children’s precise geolocation while the privacy policy claimed COPPA compliance
2026DOJ–TikTok settlement (Aug. 21)$300 million unconditional, plus $100 million conditionalDOJ’s 2024 suit: TikTok knowingly collected personal information online from children under 13, including through “Kids Mode” accounts and age-gate bypasses, and failed to honor parents’ deletion requests

The TikTok settlement’s second tranche carries an open condition: the final $100 million is payable only if the court vacates TikTok’s 2019 consent decree.

Epic Games’ own statement on the day of its settlement remains the clearest practitioner account of what shifted: “No developer creates a game with the intention of ending up here… The laws have not changed, but their application has evolved, and long-standing industry practices are no longer enough.” (Epic Games, December 19, 2022)

What the recent cases were about

The recent actions are about what operators’ systems and settings did, not about children typing their names into forms.

  • Designation failure (Disney): the wrong label let targeted ads run on children’s videos.
  • Third-party code (Apitor): an embedded SDK did the collecting. The operator was still liable.
  • Retention and deletion (Amazon): keeping voice recordings “to improve the algorithm” was the violation.
  • Defaults (Epic): default-on chat with strangers and ignored deletion requests.
  • Platform knowledge (YouTube): promoting itself to advertisers as a kids’ destination created the knowledge it denied having.
  • Gate integrity (TikTok): children could allegedly bypass the age gate itself.

Who is liable for third parties and SDKs on your site?

The operator is liable. The FTC’s COPPA holds the operator of a child-directed service responsible for the personal information collected through it: “no matter who is doing the collection.” Ad networks, analytics packages, plug-ins, and SDKs are collection channels. Since the 2025 amendments, each one is a routing decision with its own legal basis.

The channels through which third parties collect on your pages:

  • Ad networks and exchanges serving impressions or bidding on them
  • Analytics and crash-reporting SDKs compiled into apps
  • Social plug-ins and widgets embedded in pages
  • Tag managers that load all of the above
  • Embedded players and content: video, maps, captchas

Disney and Apitor, in the enforcement table above, are the same story: a designation setting and an embedded SDK did the collecting. The operators’ own code never touched the data. It didn’t have to: the operators paid.

The 2025 amendments sharpened the point. Disclosure of a child’s personal information to third parties (targeted advertising included) is now a separately consented event unless it is integral to the service. Every channel on the list above therefore needs to be known, named, and routed.

If you ARE the third party

Trigger three applies to you directly. Ad networks, SDK providers, and analytics vendors that actually know they are collecting personal information from users of a child-directed service have their own COPPA obligations. You can’t ride the operator’s consent flow or hide inside its privacy policy.

The FTC’s guidance to ad networks and similar services treats signals that a property is child-directed as the knowledge trigger, so “the publisher never told us” is a posture, not a defense, once a signal has arrived. Vendor-side accountability runs through contracts, data-processing terms, and monitoring: 

Read Third-Party Privacy Risk Management → 


How do you know what your site actually collects from children?

Since the 2025 Rule, every third-party collector on a child-directed or mixed-audience page must land on one of three legal bases (separate parental consent, a narrow exception, or removal), and the direct notice must name the collectors. A collector you cannot name has no route. That is the observation gap.

We trace what websites’ code actually sends for a living, so we will say the structural part plainly: the gap exists because of how websites work in practice. Your privacy policy states your practices. Your tag manager, SDKs, and third-party scripts perform them. Liability attaches to the performance: what fires and what it carries. Where it goes is a runtime fact too, not a document fact.

Four questions decide compliance on a child-audience page, and none of them can be answered from paperwork:

  1. Which identifiers fire on child-directed pages or child-flagged sessions?
  2. What fires before any consent exists: in the window between page load and the consent mechanism?
  3. Who receives the data: including recipients two and three hops past the vendor you named?
  4. What changed after the last release: what did the last deploy add to the page that nobody reviewed?

The contrast, concretely:

The paperwork saysThe page actually does
The policy lists three partnersNine scripts fire on a child-flagged session, four of them named nowhere
A consent screen gates collectionTwo identifiers transmit at page load, before the screen appears
The vendor list was reviewed last yearAn SDK update last month added a fourth-party destination (a recipient downstream of your vendor’s vendor)
COPPA consent-routing map showing how third-party trackers on child-directed websites require parental consent, qualify for limited exceptions, or must be blocked.

Observation is a precondition, not a compliance result. Routes must still be chosen, consents captured, exceptions honored, and lawful routes (contextual advertising, genuine internal operations) remain lawful whether or not anyone watches them run. A general-audience operator that prefers not to manage any of this still has lawful exits from the age-gate section: a neutral screen or stopping collection and deleting the child’s data on actual knowledge.

What fires on a child-directed page before anyone consents

At page load (before any age screen, consent banner, or parental mechanism has engaged), a modern page can already transmit. Analytics beacons, ad pixels, and session scripts send identifiers in the first network calls the browser makes.

The 2025 Rule’s design acknowledges: a mixed-audience service may collect nothing beyond the narrow exceptions until age screening has run.


What’s next for children’s privacy law?

Nothing has replaced COPPA. But the legislative frontier has moved to the teenagers it never covered. As of September 2026, the Senate has passed COPPA 2.0, the House has passed a separate omnibus children’s bill, and neither has become law.

The current status of each vehicle:

  • COPPA 2.0 (the Children and Teens’ Online Privacy Protection Act), S. 836 (Sens. Markey and Cassidy): passed the Senate with the committee-reported amendments by unanimous consent on March 5, 2026. Received in the House and held at the desk on March 16, 2026, and never referred to a House committee. No House floor action as of September 23, 2026. It is not law. (Backdrop: an earlier version passed the Senate 91–3 on July 30, 2024, as part of the Kids Online Safety and Privacy Act, then stalled in the House and died at adjournment.)
  • KIDS Act (the Kids Internet and Digital Safety Act), H.R. 7757: an omnibus package folding together a House-negotiated kids-online-safety framework, other online-safety titles, and a COPPA 2.0 title. It leaves out KOSA’s duty of care. Passed the House on June 29, 2026 (267–117, under suspension of the rules). Referred to the Senate Commerce Committee on July 13, 2026. Not enacted.
  • KOSA (the Kids Online Safety Act), S. 1748 (Sens. Blackburn and Blumenthal): ordered reported by the Senate Commerce Committee on August 5, 2026. No Senate floor vote this Congress. It is a distinct vehicle from the KIDS Act: the House passed the latter, not a standalone KOSA.
  • State codes: the states are moving without waiting for Congress, though not always successfully. California’s Age-Appropriate Design Code Act (Cal. Civ. Code §§ 1798.99.28–.40) is the flagship of the design-duty approach, but key provisions remain enjoined after the Ninth Circuit’s March 12, 2026 opinion in NetChoice v. Bonta. Utah’s H.B. 55 (effective July 1, 2026) was passed after a BYU and Internet Safety Labs investigation for the Utah State Board of Education found many school apps collecting data their privacy agreements didn’t permit. The law requires schools to terminate vendor contracts when violations aren’t fixed after notice, and it directs the State Board to investigate alleged violations and audit agreements.

How MELURNA helps with COPPA

Since the 2025 Rule, every collector on a child-audience page is a routing decision: separate parental consent, a narrow exception, or removal, with the collectors named in your direct notice. That is the part no policy document can answer, and it is the part MELURNA observes.

MELURNA watches what your pages and apps actually send: which scripts and SDKs fire on child-flagged pages, what transmits before any consent exists, who receives the data including recipients past the vendor you named, and what each release changed. Its stated-versus-observed comparison shows where your notice diverges from your pages, and because the observation repeats, drift surfaces instead of accumulating.

Observation does not create compliance. The consents, exceptions, and deletions remain your decisions; MELURNA makes them possible to make and to prove.

Reserve a review slot | Sensitive data discovery | Risk and compliance monitoring


FAQs

Is COPPA a privacy law?

Yes. COPPA is the US federal children’s online privacy law: a data-collection statute (15 U.S.C. §§ 6501–6506) enforced by the Federal Trade Commission, not a general consumer privacy framework.

Does COPPA apply to 17-year-olds?

No. COPPA covers children under 13 only. Protection for 13- to 17-year-olds lives in state kids’ codes and, in Europe, in GDPR Article 8.

Does COPPA apply to foreign companies?

Is there a COPPA certification?

No. There is no official COPPA certification. The nearest mechanism is membership in an FTC-approved Safe Harbor program, which signals adherence to approved guidelines but is not immunity from enforcement.

What is COPPA on YouTube?

On YouTube, COPPA arrives as the “made for kids” designation: creators must mark child-directed videos or channels, which disables comments, notifications, and personalized advertising, and YouTube can re-designate content itself. The system grew out of the 2019 Google/YouTube settlement.

Does COPPA apply to AI toys and chatbots?

Yes. Internet-connected toys and other connected devices are “online services” under the Rule, and an AI chatbot or voice feature on a child-directed service is covered the same way. The same triggers and the same duties apply: a service directed at children under 13, or one that knowingly collects from them, needs verifiable parental consent before collection.

What can a parent do if a site collected their child’s data?

Ask the operator to let you review the child’s personal information, have it deleted, and refuse any further collection or use (the Rule requires operators to honor all three), and file a complaint with the FTC or your state attorney general.

Can parents delete their child’s data?

Yes. Operators must honor parental requests to review, delete, and refuse further collection or use of a child’s personal information.


DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.


Reference

Cite this page

Dany Mirza. “What Is COPPA? The Children’s Online Privacy Protection Act Explained.” Melurna, September 30, 2026. https://www.melurna.com/blog/what-is-coppa/