COPPA is the oldest federal privacy statute still gaining teeth. The 2013 amendments quietly made ad tech its main subject by defining cookies and device IDs as personal information; the enforcement wave that followed, YouTube, TikTok, Epic, priced that decision in nine figures; and the 2025 amendments finished the job by making third-party ad disclosure a separately consented choice, banning indefinite retention, and adding biometrics to the definition. The compliance question for any service children actually use is no longer ‘do we ask for names?’ but ‘what does our SDK stack do the moment a child opens the app?’, and the FTC has demonstrated it knows how to read a network log.
| Covers | Under-13 directed services + actual-knowledge operators |
|---|---|
| Rule | 16 CFR Part 312, amended eff. June 23, 2025 |
| Personal info | Includes persistent identifiers, biometrics (2025) |
| New in 2025 | Separate opt-in for targeted-ad disclosure; retention limits; written security program |
| Record penalty | Epic Games, $275M |
| Also enforcing | State AGs; safe harbor programs |
Building under-13 compliance
Audit the identifier layer first. Persistent-identifier flows to ad tech are the modern violation; the age-gating guide covers screening design that holds up.
Unbundle consent for 2025. Collection consent and targeted-ad disclosure consent are now separate switches; wire both into the parental flow.
Write the retention and security artifacts. A dated retention policy and a written security program are now rule text, not best practice; align them with your broader children’s data obligations across states.
Consider a safe harbor. FTC-approved programs offer audited cover; the safe harbor guide weighs the tradeoffs, and FERPA rules stack where schools are involved.
Child-directed pages carrying ad pixels are the canonical COPPA violation: check yours with a free scan.