US Privacy Law United States (Federal)

COPPA Compliance: Children's Online Privacy Rules

COPPA after the 2025 rule amendments: who is covered, verifiable parental consent, the new opt-in for targeted ads, data retention limits, and FTC enforcement.

Regulation

Children's Online Privacy Protection Act (15 U.S.C. 6501-6506) and the COPPA Rule (16 CFR Part 312, amended 2025)

Max Penalty

Civil penalties up to $53,088 per violation (2025 adjusted figure); FTC settlements have reached $275M (Epic Games) and $170M (Google/YouTube)

Enforcing Authority

Federal Trade Commission (and state attorneys general)

Official Source

www.ftc.gov

Executive Summary

  • COPPA applies to operators of websites and online services directed to children under 13, and to general-audience services with actual knowledge they collect personal information from under-13 users.
  • The core mechanic is verifiable parental consent before collecting, using, or disclosing children's personal information, which the Rule defines to include persistent identifiers, geolocation, photos, voice, and (since 2025) biometric identifiers.
  • The 2025 Rule amendments (effective June 23, 2025) added a separate opt-in for disclosing children's data to third parties for targeted advertising, written data-retention limits (no indefinite retention), stronger security-program requirements, and expanded direct-notice content.
  • Enforcement is the FTC's most active privacy program: Epic Games ($275M penalty, 2022), Google/YouTube ($170M, 2019), Amazon Alexa ($25M, 2023), Microsoft Xbox ($20M, 2023), plus 2024-2025 actions against ed-tech and app developers; state AGs can also sue.
  • Per-violation penalties adjust annually for inflation ($53,088 in 2025), calculated per child, which is how nine-figure exposure arises.

COPPA is the oldest federal privacy statute still setting the pace. Twenty-five years in, it produces the FTC’s largest privacy penalties, and the 2025 Rule amendments modernized it around exactly the practices the big cases exposed: ad-tech disclosure of children’s identifiers, indefinite retention of voice and biometric data, and consent collected after the data. For anything children touch, COPPA is an engineering specification with a $53,088-per-child price for skipping it.

LawCOPPA, 15 U.S.C. 6501-6506; COPPA Rule, 16 CFR 312
CoversUnder-13 data; child-directed or actual-knowledge services
2025 amendmentsEffective June 23, 2025
Max penalty$53,088 per violation (per child)
Landmark casesEpic $275M; YouTube $170M; Alexa $25M; Xbox $20M

Engineering the compliance sequence

Classify honestly, then screen neutrally. Document the child-directed analysis with the FTC’s factors; if mixed-audience, implement a neutral age gate before any collection, including persistent identifiers set by analytics and ad SDKs that load on page one.

Consent before collection, unbundled. No personal information (identifiers included) until verifiable parental consent, with the 2025 rule’s separate toggle for third-party advertising disclosure. Audit SDK initialization order; Microsoft’s case was a sequencing failure.

Retention and security in writing. A published retention policy with deletion at purpose-completion, no indefinite storage of voice, photo, or biometric data, and a written security program covering vendors receiving children’s data.

Contract the data path. Third parties receiving children’s data need COPPA-aware terms mirroring your service-provider agreement discipline; the operator remains liable for downstream use.

Layer the state rules on top. Teen consent rules and design codes extend past 13; see the state children’s privacy guide and age-gating approaches for the 13-17 band.

Third-party trackers firing before any consent are the most common COPPA finding, and visible from outside: check your site with a free scan.

Frequently Asked Questions

How do we know if our service is 'directed to children'?

The FTC weighs subject matter, visual and audio content, use of animated characters or child celebrities, ads on the service, and empirical evidence about audience composition. A service need not be exclusively for children; a 'mixed audience' service may age-screen and apply COPPA only to identified under-13 users, but the screen must be neutral (no encouraging false ages). General-audience services acquire obligations the moment they have actual knowledge of an under-13 user, including via third-party notice, the YouTube theory.

What counts as verifiable parental consent?

Methods reasonably calculated to ensure the person consenting is the parent: signed consent forms, credit-card or other payment transactions with notice, toll-free calls or video conference with trained staff, government-ID checks, knowledge-based authentication, and (added over time) facial-comparison matching. Email-plus (email consent with follow-up confirmation) remains available only where data is used internally and not disclosed. The 2025 amendments require separate, distinct consent for third-party disclosure for advertising.

What did the 2025 amendments change in practice?

Four operational shifts: (1) targeted advertising to children now requires its own opt-in consent, unbundled from general consent, ending the default flow of children's persistent identifiers to ad tech under the 'support for internal operations' rationale; (2) operators must maintain and publish a written data-retention policy and may not retain children's data indefinitely; (3) a written children's-data security program with safeguards proportional to sensitivity is mandatory; (4) direct notices must name third-party recipients or categories. Biometric identifiers joined the personal-information definition.

What do the big enforcement cases teach?

Epic ($275M): default-on voice and text chat for children plus dark-pattern purchase flows; design choices are COPPA facts. Google/YouTube ($170M): serving behavioral ads on child-directed channels while claiming general-audience status; content-level knowledge counts. Amazon Alexa ($25M): retaining children's voice recordings indefinitely against deletion promises; retention is now codified. Microsoft ($20M): collecting data during account creation before parental consent; sequence matters. The common thread is architecture, not paperwork.

How does COPPA interact with the state children's laws?

COPPA preempts inconsistent state law for under-13 online data collection, but states legislate around it: teen protections (13-17) in the comprehensive state laws, age-appropriate design codes (California's, currently enjoined; Maryland's in litigation), and social-media access laws. The practical stack for a youth-facing service is COPPA for under-13, state teen ad-targeting consent rules for 13-17, and design-code duty-of-care requirements where they survive review. Our state children's privacy guide maps the layer above COPPA.

Regulatory Crosswalk

State children's privacy lawsCAADCAGDPR Article 8

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.