Cross-Jurisdictional Global

Children's Data Protection Worldwide: COPPA, Design Codes, and Beyond

How children's privacy law works globally: COPPA's verifiable parental consent and the 2025 amendments, GDPR age thresholds, the UK and California age-appropriate design codes, PIPL's under-14 rules, and age assurance.

Regulation

COPPA (with the FTC's 2025 rule amendments), GDPR Article 8, the UK Children's Code, California AADC (litigated) and state minors' laws, PIPL's under-14 sensitivity rule, LGPD Article 14, the EU DSA's minors provisions

Max Penalty

COPPA penalties run to $53,088 per violation (2025 adjustment); the FTC's Epic Games settlement totaled $520 million; the Irish DPC fined TikTok 345 million EUR and Instagram 405 million EUR over children's processing

Enforcing Authority

The FTC (COPPA), state AGs, the ICO, EU DPAs, the CAC, ANPD, and the eSafety/online-safety regulators converging on the same services

Official Source

www.ftc.gov

Executive Summary

  • The age lines differ: COPPA protects under-13s, GDPR Article 8 lets member states set the consent age between 13 and 16, PIPL treats all under-14 data as sensitive, and the design-code generation extends duties to everyone under 18.
  • COPPA turns on 'directed to children' plus actual knowledge, requires verifiable parental consent before collection, and the FTC's 2025 amendments added separate consent for targeted advertising and third-party disclosure.
  • Enforcement is heavyweight on both sides of the Atlantic: Epic Games ($520M), the YouTube and Musical.ly/TikTok COPPA settlements, and the Irish DPC's 405M EUR Instagram and 345M EUR TikTok decisions.
  • The UK Children's Code shifted the paradigm from consent collection to design duties (high-privacy defaults, no nudging, geolocation off), a model California copied and litigation has narrowed but not killed.
  • Age assurance is the unsolved engineering problem: regimes increasingly demand you know who is a child without demanding you identify everyone, and proportionate, layered approaches are the emerging standard.

Children’s privacy is where data protection law is least willing to compromise and most willing to innovate: the consent machinery that suffices for adults is presumed to fail for children, so regulators keep inventing stronger tools, verifiable parental consent in the American tradition, sensitivity classifications in China’s, and, in the current generation, design codes that regulate defaults, nudges, and profiling directly rather than trusting any consent screen. The enforcement economics match the rhetoric: the largest FTC privacy penalty (Epic), the YouTube settlement, and two of the Irish DPC’s biggest fines (Instagram, TikTok) are all children’s cases, and COPPA’s per-child penalty arithmetic makes under-13 data the most expensive data an American consumer service can mishandle. For builders the practical translation is that children’s compliance is a product-architecture problem, audience classification, age assurance, a child flag that every system respects, and an adtech kill-switch, with the paperwork documenting design decisions rather than substituting for them.

Age lines<13 (COPPA), 13-16 (GDPR Art. 8 by state), <14 (PIPL sensitive, Quebec), <18 (design codes, DSA ad ban)
US mechanismVerifiable parental consent + 2025 separate consent for third-party disclosure/targeted ads
EU/UK mechanismDesign duties: high-privacy defaults, profiling off, no nudging (Instagram 405M, TikTok 345M EUR)
Hard lineNo profiling-based ads to minors (DSA Art. 28; post-Code platform practice)
Primary sourceFTC COPPA rule

Building it

The US statute in depth. COPPA compliance and COPPA versus state laws cover the American layer.

The classroom context. EdTech privacy and FERPA for edtech handle the school-data overlay.

The design doctrine. Privacy by design engineering covers the Article 25 defaults the children’s cases enforced.

The dark-pattern line. Dark patterns compliance covers the nudging findings central to the TikTok decision.

Child-directed pages with adtech trackers are COPPA exposure in production: check what your site fires with a free scan.

Frequently Asked Questions

How does COPPA actually work, and what changed in the 2025 amendments?

COPPA (15 U.S.C. 6501-6506 and the FTC's rule at 16 CFR Part 312) applies to operators of websites and online services directed to children under 13, and to any operator with actual knowledge it is collecting personal information from under-13 users, with 'directed to children' judged on subject matter, visuals, music, child celebrities, ads, and audience evidence, and the YouTube settlement (2019, $170 million with the NY AG) establishing that a general-audience platform has actual knowledge of child-directed channels when their content and metadata say so. The core mechanics: direct notice to parents and verifiable parental consent (VPC) before collecting personal information (which includes persistent identifiers, so behavioral advertising to children without VPC is a violation on identifiers alone, the theory of the YouTube and Musical.ly cases); approved VPC methods include signed consent forms, payment-card verification, government-ID matching, knowledge-based authentication, face-match-to-ID, and the support-for-internal-operations exception permits contextual functions (frequency capping, security) without consent; parents get review and deletion rights; data minimization and retention limits apply; and safe-harbor programs offer self-regulatory cover. The 2025 amendments, the first major update since 2013 (effective June 2025, compliance phased): separate VPC required for disclosing children's data to third parties, including for targeted advertising, an opt-in gate on the adtech flow itself; written information-security programs mandated; retention limited to purpose-necessary duration with a published policy and no indefinite holding; the personal-information definition extended to biometric identifiers; and safe-harbor programs face stronger transparency duties. The penalty math: civil penalties adjusted to $53,088 per violation, and 'per violation' counts per child, which is how Epic Games' Fortnite matter reached $275 million in COPPA penalties inside its $520 million total (2022) and why the per-violation exposure is functionally uncapped at scale.

What do the GDPR and its family require for children?

Four features distributed through the regulation rather than one chapter. The consent age (Article 8): where information-society services rely on consent, a child below the member-state threshold cannot give it alone, parental authorization is required, and the threshold varies by state within the 13-16 band Article 8 permits (16 in Germany and the Netherlands, 15 in France, 13 in the UK before and after Brexit, Ireland at 16), so a pan-EU consumer service runs a per-country age table, and 'reasonable efforts' to verify parental authority scale with risk. Enhanced protection doctrine: recital 38's premise that children merit specific protection flows into the legitimate-interests balancing (children's interests weigh heavier, making LI harder to sustain for minors' profiling), transparency (child-comprehensible notices where children are the audience), and the DPIA triggers (children's data is a WP248 criterion making assessments quasi-mandatory). The enforcement record, which made children's defaults the most expensive UX decisions in Europe: the Irish DPC's Instagram decision (September 2022, 405 million EUR) over business accounts publishing minors' contact details and public-by-default settings for child users, and its TikTok decision (September 2023, 345 million EUR) over public-by-default child accounts, the family-pairing weakness, and dark patterns steering children toward public settings, both decisions turning on Article 25 defaults rather than consent paperwork, the doctrinal point being that design is where children's compliance lives. The family resemblances: LGPD Article 14 requires processing in the child's best interest with parental consent for under-12s' data (the ANPD's guidance framing best-interest analysis for adolescents); PIPL classifies all personal information of children under 14 as sensitive, importing separate-consent, necessity, and dedicated-rules duties, with the minor-mode conventions Chinese platforms run reflecting CAC pressure; Quebec's Law 25 requires consent from a parental authority holder for under-14s; and the DSA layers on: platforms accessible to minors must ensure a high level of privacy, safety, and security, and Article 28 bans ads targeted at minors based on profiling, an EU-wide adtech line independent of consent.

What did the age-appropriate design codes change, and where does the California version stand?

The UK Children's Code (the ICO's Age Appropriate Design Code, in force with enforcement from September 2021, a statutory code under the Data Protection Act 2018): applies to information-society services likely to be accessed by under-18s, a deliberately broad net catching mainstream platforms, not just children's apps, and sets fifteen standards including the best interests of the child as a primary consideration; high-privacy settings by default; geolocation off by default with visible indicators; profiling off by default; no nudge techniques steering children toward weaker privacy; data minimization; age-appropriate transparency; and detrimental-use prohibitions; its regulatory theory is that consent architecture fails children, so the duty shifts to the service's design, and its practical effect was visible within months, platforms turned off targeted ads for teens, defaulted minors' accounts private, and disabled location features, changes rolled out globally because per-jurisdiction UX forking costs more than compliance. The California AADC (AB 2273, 2022), closely modeled on the UK code with DPIA obligations and enforcement by the AG, has been the test case for whether design codes survive US speech doctrine: NetChoice's First Amendment challenge produced a preliminary injunction (2023), a Ninth Circuit ruling (August 2024) affirming the injunction against the DPIA-and-mitigation provisions as likely compelled speech while vacating and remanding on the remainder, and continued district-court proceedings enjoining enforcement, so the statute stands mostly inoperative while the litigation runs, but its progeny multiplied: Maryland's Kids Code (effective October 2024) enacted a design-duty regime drafted around the litigation, Vermont and Nebraska followed in 2025, and Connecticut's CTDPA amendments added minors' design duties, alongside the separate wave of social-media minor laws (parental-consent-for-accounts statutes in Utah, Texas, Florida, and others, themselves under constitutional challenge with the Supreme Court's 2025 free-speech jurisprudence reshaping the field). The composite planning reality: design-code duties (defaults, no profiling of minors, age assurance) are the direction of travel on both continents, whatever any single statute's litigation fate, and the engineering investments they demand overlap heavily with the GDPR-enforcement lessons above.

How should services handle age assurance without over-collecting?

The regulatory ask has sharpened into a paradox: know which users are children (to apply protections) without identifying everyone (which minimization forbids), and the emerging doctrine resolves it through proportionality and layering. The method spectrum: self-declaration (age gates), trivially circumvented and adequate only for low-risk contexts, though even regulators accept it as a first layer where stakes are low; age estimation, facial-age analysis (with the FTC approving a facial-estimation VPC mechanism in 2024-2025 rulemaking contexts), behavioral and account-signal inference, and email/phone-based heuristics, offering privacy-preserving approximation with error bands that must be honestly engineered around (buffer ages, step-up on doubt); age verification, document checks, payment-card methods, credit-bureau matching, mobile-operator confirmation, reserved for high-risk contexts (the UK Online Safety Act's duties for pornography, the social-media minor statutes) because the privacy cost of verifying everyone is itself a harm regulators weigh; and parent-mediated models (family accounts, platform parental controls, the app stores' emerging age-signal APIs) that shift assurance to a device or account layer. The doctrinal anchors: the ICO's Children's Code standard requires age assurance proportionate to the risks of the processing, with its accompanying opinion endorsing layered approaches; the EDPB's 2025 age-assurance statement sets principles (proportionality, minimization, no new tracking built from assurance data, accuracy appropriate to risk); the euCONSENT project and the EU's age-verification blueprint push interoperable, token-based proof-of-age that discloses only the age attribute; and COPPA's actual-knowledge standard means platforms cannot design themselves into ignorance, willful blindness to child-signaling data is the YouTube theory. Engineering disciplines that survive audits: assurance data minimized and purpose-bound (estimate, decide, discard the biometric); the child-flag propagated to every downstream system that varies behavior (ads off, defaults locked, DSAR handling adjusted); error handling that fails protective (uncertain age gets the child experience); and the assurance method itself documented in the DPIA, because 'how do you know who is a child' is now a standard regulator question in every jurisdiction above.

What does a coherent global children's program look like for a mixed-audience service?

Six decisions, made once and enforced in design. Audience determination, honestly: apply the COPPA directed-to-children factors, the Children's Code's likely-to-be-accessed test, and your own analytics to classify each product surface (child-directed, mixed, adult), documenting the analysis, because the classification drives everything and regulators (the FTC on YouTube, the ICO in code audits) treat implausible adult-only claims as the first violation. The age architecture: a jurisdiction table of thresholds (under-13 COPPA, the member-state Article 8 band, under-14 PIPL/Quebec, under-16 and under-18 duties from the design codes and DSA), an assurance method per surface proportionate to its risk, and the child/teen flag as a first-class attribute propagated through ads, defaults, messaging, recommendations, and data retention. Consent plumbing where consent is the mechanism: VPC flows meeting the FTC's approved methods (with the 2025 separate-consent gate for third-party disclosure built in), parental-authorization capture for the GDPR band, and PIPL's separate consent for under-14 data, each producing records. Design duties where design is the mechanism: high-privacy defaults for minors, geolocation and profiling off, no dark patterns in children's flows (the TikTok decision's nudging findings), no profiling-based ads to minors (DSA Article 28 as the bright line, matching the platforms' post-Code practice), and age-appropriate notice surfaces. The adtech kill-switch: child-directed contexts send no behavioral-advertising identifiers at all (contextual only), mixed surfaces gate on the age flag, and the SDK inventory is audited for what child surfaces actually transmit, the recurring FTC and state-AG finding being an SDK the app team forgot. And governance with teeth: children's DPIAs for every relevant launch (quasi-mandatory under GDPR, explicit in the codes and the 2025 COPPA amendments' spirit), retention schedules honoring the new COPPA limits, incident playbooks that treat children's data as high-severity by default, and a standing watch on the moving statutes, the COPPA amendment compliance dates, the state design codes and social-media laws in litigation, the Online Safety Act's phased duties, and the EU's age-verification workstream, because no privacy domain is moving faster.

Regulatory Crosswalk

COPPAGDPR Article 8UK Children's CodePIPLLGPD Article 14

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.