US Federal Law United States

COPPA Compliance Guide: The 2025 Amended Rule

COPPA after the 2025 amendments: who is covered, verifiable parental consent methods, the new opt-in for targeted advertising, data retention limits, and FTC penalty exposure.

Regulation

Children's Online Privacy Protection Act, 15 USC 6501-6506; COPPA Rule, 16 CFR Part 312, amended final rule effective June 23, 2025 (compliance dates into April 2026)

Max Penalty

Civil penalties per violation, inflation-adjusted above $50,000, each child countable; Epic Games paid a $275 million COPPA penalty, the largest to date

Enforcing Authority

Federal Trade Commission (FTC); state attorneys general

Official Source

www.ftc.gov

Executive Summary

  • COPPA requires operators of websites and online services directed to children under 13, or with actual knowledge they collect children's data, to give notice and obtain verifiable parental consent before collecting personal information.
  • The FTC's 2025 amendments (effective June 23, 2025) added a separate opt-in consent requirement for disclosing children's data to third parties for targeted advertising, strengthened data security and retention rules, and expanded the personal-information definition to include biometric identifiers.
  • Personal information includes persistent identifiers (cookies, device IDs, IP addresses), meaning behavioral advertising to children without consent has been a violation since 2013.
  • Penalties are per violation per child and have scaled accordingly: Epic Games $275 million, Google/YouTube $170 million, Musical.ly/TikTok $5.7 million, with state AGs enforcing in parallel.
  • Mixed-audience services may age-screen and apply COPPA only to under-13 users, but 'directed to children' is judged on factors like subject matter, visuals, music, and child celebrities, not the operator's stated intent.

COPPA is the oldest federal privacy statute still gaining teeth. The 2013 amendments quietly made ad tech its main subject by defining cookies and device IDs as personal information; the enforcement wave that followed, YouTube, TikTok, Epic, priced that decision in nine figures; and the 2025 amendments finished the job by making third-party ad disclosure a separately consented choice, banning indefinite retention, and adding biometrics to the definition. The compliance question for any service children actually use is no longer ‘do we ask for names?’ but ‘what does our SDK stack do the moment a child opens the app?’, and the FTC has demonstrated it knows how to read a network log.

CoversUnder-13 directed services + actual-knowledge operators
Rule16 CFR Part 312, amended eff. June 23, 2025
Personal infoIncludes persistent identifiers, biometrics (2025)
New in 2025Separate opt-in for targeted-ad disclosure; retention limits; written security program
Record penaltyEpic Games, $275M
Also enforcingState AGs; safe harbor programs

Building under-13 compliance

Audit the identifier layer first. Persistent-identifier flows to ad tech are the modern violation; the age-gating guide covers screening design that holds up.

Unbundle consent for 2025. Collection consent and targeted-ad disclosure consent are now separate switches; wire both into the parental flow.

Write the retention and security artifacts. A dated retention policy and a written security program are now rule text, not best practice; align them with your broader children’s data obligations across states.

Consider a safe harbor. FTC-approved programs offer audited cover; the safe harbor guide weighs the tradeoffs, and FERPA rules stack where schools are involved.

Child-directed pages carrying ad pixels are the canonical COPPA violation: check yours with a free scan.

Frequently Asked Questions

Who is covered, and what does 'directed to children' mean?

Two coverage paths: services directed to children under 13, and general-audience services with actual knowledge they collect personal information from under-13 users. 'Directed to children' is a totality test the rule enumerates: subject matter, visual and audio content, use of animated characters or child-oriented activities, music, child celebrities or celebrities appealing to children, advertising on or promoting to children, and empirical evidence of audience composition. YouTube's $170 million settlement turned on channel content and the platform's own audience statements to advertisers. A 'mixed audience' subcategory lets services that are child-appealing but not primarily child-targeted use a neutral age screen and apply COPPA only to users identifying as under 13, but the screen must not encourage misstatement (no pre-filled adult birthdates, no 'you must be 13' hints).

What counts as verifiable parental consent, and what changed in 2025?

Approved methods include: signed consent forms (mail, fax, scan), credit or debit card transactions with notice, toll-free calls or video conferences with trained staff, government-ID verification against databases, knowledge-based authentication with adequately difficult questions, and facial-recognition matching against verified ID. The 2025 amendments added text-message-plus-confirmation ('text plus') for internal-use consent and blessed knowledge-based authentication and facial matching formally. The 'email plus' method survives for internal uses. Critically, the amendments also unbundled consent: operators must now obtain separate, opt-in consent before disclosing children's personal information to third parties for targeted advertising or other non-integral purposes, a parent can consent to collection while refusing ad-tech disclosure, and the service (unless disclosure is integral) must offer that split.

What are the notice, retention, and security requirements now?

Notice: a clear, prominent direct notice to parents before collection describing what is collected, how used, and disclosure practices, plus an online privacy policy listing all operators collecting through the service, updated for the 2025 disclosure details (including identities or categories of third parties and, under the amendments, more specific retention information). Retention: the amendments hardened the rule, children's data may be kept only as long as reasonably necessary for the specific purpose collected, indefinite retention is expressly prohibited, and operators must maintain a written data retention policy. Security: a written children's data security program with safeguards appropriate to sensitivity, plus diligence obligations before releasing data to third parties capable of maintaining it. These convert what were general reasonableness duties into auditable artifacts the FTC can demand.

Do persistent identifiers really trigger COPPA without a name or email?

Yes, since the 2013 amendments, and it is the single most consequential fact in the rule. Personal information includes persistent identifiers that can recognize a user over time and across services: cookies, device identifiers, advertising IDs, and IP addresses. The 'support for internal operations' exception permits their use without consent for contextual advertising, frequency capping, analytics, security, and legal compliance, but NOT for behavioral/targeted advertising or cross-service profiling. That is the theory behind YouTube (serving behavioral ads on child-directed channels), Musical.ly, and Epic: no registration data needed, the ad stack itself was the violation. The 2025 amendments added biometric identifiers (fingerprints, voiceprints, facial templates) and government IDs to the definition, extending the same logic to the newest identifier classes.

What does COPPA enforcement look like, and who else enforces?

FTC actions are penalty-eligible from the first violation, per child, per day, which is how numbers scale: Epic Games $275 million (2022, default-on voice chat and collection without consent), Google/YouTube $170 million (2019, split with New York), Microsoft/Xbox $20 million (2023, registration flow), Amazon/Alexa $25 million (2023, voice recordings and retention), Musical.ly $5.7 million (2019). Orders impose deletion (including of models trained on children's data in some matters), consent re-engineering, and long-term compliance monitoring. State attorneys general have parallel COPPA authority and use it, and the states are layering their own regimes on top, age-appropriate design codes and minors' social-media laws, so under-13 compliance is now the floor, not the ceiling. Safe harbor programs (FTC-approved self-regulatory bodies) offer a compliance pathway with their own audit requirements.

Regulatory Crosswalk

State minors' privacy lawsUK Age Appropriate Design CodeGDPR Article 8

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.