Summary. Three separate regimes govern data about young people, and they ask different questions. COPPA regulates collection from children under thirteen and answers with parental consent. FERPA and the state student privacy statutes regulate education records and answer with school control and use restrictions. The design codes and the minor provisions of state privacy statutes regulate the product experience for all minors and answer with defaults, regardless of consent. This toolkit runs all three in sequence — audience analysis and data inventory, consent, retention and deletion, school-context obligations, design defaults, age assurance, and the international rules.
What this toolkit is for, and who should use it
A company builds a product that young people use — a game, a learning tool, a video platform, a connected device, a social feature — and discovers that the compliance question is not one question but three, that they apply at different ages, and that satisfying one does not satisfy the others.
This toolkit is for the general counsel or privacy lead at such a company, for an edtech vendor selling into schools, and for counsel conducting diligence on a consumer acquisition where the user base skews young.
Roadmap at a glance
- Classify the service — the audience analysis.
- Inventory the data and every SDK.
- Map to a lawful basis under COPPA.
- Verifiable parental consent.
- Retention, deletion, and security.
- Notices.
- The school context — FERPA, the PPRA, and state student privacy law.
- Design defaults for all minors.
- Teen privacy under state comprehensive statutes.
- Age assurance.
- International regimes.
- Governance, diligence, and regulator readiness.
Stage 1 — Classify the service
- Apply the COPPA Rule's factors and write the analysis down with the date: subject matter; visual and audio content; animated characters and child-oriented activities; music; age of models; child celebrities; language; whether advertising on the service is child-directed; and competent and reliable empirical evidence of audience composition and intended audience.
- Reach one of four conclusions: child-directed, mixed audience, general audience with known child users, or general audience likely to be accessed by minors — the last of which triggers the design-code analysis even where COPPA does not apply.
- For a mixed audience service, implement a neutral age screen with a date-of-birth field and a session mechanism preventing re-entry after rejection.
- Re-run the analysis annually and after any material change in content, marketing, or audience.
Resources
- Children's Privacy Under COPPA and the Age-Appropriate Design Codes
- COPPA Children's Privacy Compliance Checklist
Stage 2 — Inventory the data and the SDKs
- List every element collected and check each against the Rule's definition of personal information, which includes persistent identifiers, photographs, video and audio containing a child's image or voice, precise geolocation, and biometric identifiers.
- Inventory every SDK and third-party library, with what it collects and where it transmits. Ad networks, analytics providers, and attribution tools embedded in a child-directed service are operators in their own right.
- Identify every third party receiving data and the purpose.
- Map each element to a purpose and to a lawful basis, and stop anything that has none.
- Re-verify after every SDK update and after any new integration.
Stage 3 — Lawful bases under COPPA
- Verifiable parental consent, discussed below.
- Support for internal operations — the exception that lets child-directed services function. A persistent identifier may be collected without consent only where used solely for maintaining or analyzing functioning, network communications, authentication and personalization, contextual advertising and frequency capping, security and integrity, legal compliance, or fulfilling a child's request under another exception. Any profiling, behavioral targeting, or disclosure for a third party's purposes destroys it.
- Narrow exceptions for a one-time response to a specific request, for obtaining consent, for multiple contacts with parental notice and opt-out, for child safety, and for legal process.
- Configure every ad SDK for child-directed treatment, and verify the configuration rather than trusting it.
Stage 4 — Verifiable parental consent
- Provide direct notice to the parent before collection.
- Obtain consent by an approved method: a signed form returned by mail, fax, or scan; a payment transaction providing notification; a toll-free call or video conference with trained personnel; government identification checked against a database with prompt deletion; knowledge-based authentication; facial recognition matching a photo identification; or an approved text-plus method.
- "Email plus" only where information is used internally and not disclosed, with the required confirming step.
- Obtain separate, distinct consent for disclosure to third parties, including for targeted advertising.
- Obtain new consent on any material change.
- Do not condition participation on disclosing more than is reasonably necessary.
- Retain the consent record, the method, and the notice version.
Stage 5 — Retention, deletion, and security
Recent enforcement has concentrated here rather than on collection.
- Adopt a written retention policy stating the purposes for collection, the business need for retention, and the deletion timeframe — and publish it in the online notice.
- No indefinite retention of any category.
- Implement automated deletion and verify that it runs.
- Ensure deletion reaches derived data — transcripts, embeddings, profiles, training sets, backups, and analytics systems — not merely the raw record.
- Provide a parent-facing mechanism to review, refuse further collection, and require deletion.
- Adopt a written security program for children's information, with designated responsibility, risk assessment, safeguards, and vendor oversight, plus written assurances from every recipient.
Stage 6 — Notices
- An online privacy notice with the Rule's required content: categories collected, uses, disclosure practices, the retention policy, and parents' rights.
- Each operator collecting through the service identified with contact information, or one designated to respond for all.
- A prominent link on the home page and at each point of collection.
- Version the notice with effective dates.
- Where the audience includes children, a child-facing explanation in language a child can understand, which the international regimes require and which is good practice everywhere.
Stage 7 — The school context
- FERPA, 20 U.S.C. § 1232g, governs education records maintained by an educational agency or institution. Consent is generally required for disclosure, with exceptions including the school official exception — under which a vendor performing an institutional service may access records if the school has determined it is a school official with a legitimate educational interest, uses the records only for the authorized purpose, and remains under the school's direct control.
- Directory information may be disclosed after notice and an opportunity to opt out, and the categories must be defined by the school.
- The PPRA restricts surveys funded by the Department of Education that touch protected subject areas, and requires notice and opt-out for certain marketing-related collection.
- COPPA school consent: where a service is used for a school-authorized educational purpose, the school may consent on parents' behalf, provided the operator gives the school the required direct notice, uses information only for the authorized educational purpose, makes no commercial use including advertising or profiling, and deletes when no longer needed.
- State student privacy statutes — more than a hundred of them — commonly prohibit targeted advertising to students, prohibit selling student data, restrict profiling, require deletion on request or at contract termination, and impose security obligations. Several impose obligations directly on vendors.
- Contract terms with districts: purpose limitation, no secondary use, no advertising, deletion on termination, subprocessor controls, security standards, breach notification, and audit rights.
Resources
Stage 8 — Design defaults for all minors
Independent of COPPA, apply these to every user identified or estimated as a minor:
- Privacy settings high by default; profiles private.
- Geolocation off by default.
- Profiling and targeted advertising off.
- Communications restricted, with adult contact limited.
- No nudge techniques encouraging lower privacy or extended use.
- Parental controls disclosed to the child where they exist.
- Data minimization — collect only what the service needs.
- Connected devices with a prominent recording indicator and short default retention.
- Gaming: default-off voice and text chat for minors, and scrutiny of purchase flows, loot boxes, and pressure mechanics.
These defaults satisfy the design codes, the UK Children's Code, the FTC's Section 5 expectations reflected in recent orders, and much of what the state minor provisions require — and they are largely independent of any consent question.
Stage 9 — Teen privacy
COPPA stops at the thirteenth birthday; state law does not.
- Several state comprehensive privacy statutes require opt-in consent for processing the personal data of consumers between 13 and 16 for targeted advertising, sale, or profiling in furtherance of significant decisions.
- Some states impose minor-specific duties for services minors are likely to access: a duty of care regarding heightened risk of harm, default limits on unsolicited contact, restrictions on precise geolocation, and prohibitions on features designed to increase use time.
- Several statutes apply on actual knowledge or willful disregard of age — a lower threshold than COPPA's actual knowledge, which penalizes deliberate ignorance.
- FTC Section 5 reaches practices affecting teens that COPPA does not, on unfairness or deception theories, and recent orders have imposed default settings and communication restrictions for minors without reference to COPPA.
- Design codes face active constitutional litigation. NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024), affirmed an injunction against a data protection impact assessment requirement tied to content harm, while vacating the injunction as to the remaining provisions and remanding for individual analysis — suggesting that data practice provisions survive where content evaluation provisions do not.
Stage 10 — Age assurance
Every regime above depends on knowing or estimating age, and no method is both accurate and privacy-preserving.
- Self-declaration — adequate for a neutral age screen, inadequate where a statute requires assurance.
- Facial age estimation — increasingly accurate for broad bands, processes biometric data triggering biometric privacy statutes, and requires on-device processing and immediate deletion.
- Behavioral inference — low friction, contested accuracy, and it creates the actual knowledge the company may then be obligated to act on.
- Document verification — accurate, high friction, exclusionary, and it creates a sensitive repository.
- Device or app-store signals and third-party providers — the direction of travel, centralizing verification once rather than at every service.
- Design principles in every case: collect the minimum to establish the band; delete verification artifacts immediately, retaining only the result; use age data for nothing else; provide an appeal path; and document the method, its accuracy, and the reasoning.
Stage 11 — International regimes
- GDPR Article 8 sets the age of consent for information society services at 16, with member states permitted to lower it to no less than 13 — and they have, unevenly. Consent below the applicable age requires parental authorization with reasonable efforts to verify. Note that consent is only one of six lawful bases, and that transparency must be in language a child can understand.
- The UK Children's Code sets fifteen standards for services likely to be accessed by children under 18, including best interests, impact assessment, high-privacy defaults, data minimisation, sharing and geolocation off by default, profiling off by default, and no nudge techniques.
- Brazil's LGPD requires parental consent under 12 and processing in the child's best interest. Canada treats children's data as sensitive with parental consent generally required under 13. China's PIPL requires separate parental consent under 14 and a dedicated processing rule. India's DPDP Act requires verifiable parental consent for anyone under 18 and prohibits tracking, behavioral monitoring, and targeted advertising directed at children.
- The planning consequence: a global service needs a jurisdictional age matrix driving which consent and default rules apply, with the highest applicable standard used where jurisdiction is uncertain. Build it once.
Stage 12 — Governance, diligence, and regulator readiness
- Product review gate that includes children's privacy, because product managers make the decisions that create liability.
- Test the shipped experience, not the specification.
- SDK change control with re-verification after updates.
- Annual training for product, engineering, and marketing.
- Vendor management with contractual assurances, configuration verification, and audits.
- Consider a safe harbor program, evaluating its standards rather than assuming membership is protection.
- Diligence in acquisitions: children's privacy belongs on the checklist for any consumer acquisition, and the remediation cost — retained data, non-compliant flows, embedded SDKs — should be priced.
- What a regulator will request: the dated audience analysis; every version of the privacy notice and the direct notice; the consent mechanism with screenshots and aggregate consent-versus-account statistics; a data map; the retention schedule and evidence that deletion executed; parental requests and their resolution; vendor and SDK agreements with evidence of child-directed configuration; and internal product and design documents discussing minors, engagement, or age. That last category is where the damaging material usually is, and it cannot be improved after the request arrives.
Master resource index
Articles
- Children's Privacy Under COPPA and the Age-Appropriate Design Codes
- Education Law for Schools and Edtech: FERPA, Title IX, and Section 504
- State Consumer Privacy Laws: The CCPA, the CPRA, and the Multi-State Patchwork
- Biometric Data Privacy Laws and Their Impact on AI Development
- Legal Issues for Mobile Applications: Privacy
- Data Minimization and Avoiding the Over-Retention of Personal Information
Guides
Checklists
- COPPA Children's Privacy Compliance Checklist
- Privacy Compliance Program Checklist
- Data Subject Rights Request Handling Checklist
- Vendor Cybersecurity Diligence Checklist
- Mobile App Launch Legal Checklist
Related toolkits
- Privacy and Data Protection Toolkit
- Consumer Marketing Compliance Toolkit
- Cybersecurity Program Toolkit
- AI Governance Toolkit
External and primary sources
- COPPA, 15 U.S.C. §§ 6501–6506, and the COPPA Rule at 16 C.F.R. Part 312
- FERPA, 20 U.S.C. § 1232g, and 34 C.F.R. Part 99; the Protection of Pupil Rights Amendment, 20 U.S.C. § 1232h
- FTC Act § 5, 15 U.S.C. § 45; NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024); Moody v. NetChoice, LLC, 603 U.S. 707 (2024)
- California Age-Appropriate Design Code Act, Cal. Civ. Code § 1798.99.28 et seq.; state comprehensive privacy statutes with minor provisions; state student privacy statutes
- GDPR Article 8; the UK Age Appropriate Design Code
- COPPA: 15 U.S.C. §§ 6501–6506; 16 C.F.R. § 312.2 through § 312.12, including verifiable parental consent methods in § 312.5(b), the conditioning prohibition in § 312.7, the security program requirement in § 312.8, and retention limits in § 312.10.
- Education records: 20 U.S.C. § 1232g and 34 C.F.R. §§ 99.3, 99.7, 99.31(a)(1), 99.33, and 99.35; 20 U.S.C. § 1232h and 34 C.F.R. Part 98 (PPRA); 20 U.S.C. § 1400 et seq. and 34 C.F.R. § 300.610 (IDEA confidentiality).
- State student privacy: Cal. Bus. & Prof. Code §§ 22584–22585 (SOPIPA and the Early Learning Personal Information Protection Act); N.Y. Educ. Law § 2-d and 8 N.Y.C.R.R. Part 121; Colo. Rev. Stat. §§ 22-16-101 to 22-16-112.
- Design codes and minors' provisions: Cal. Civ. Code §§ 1798.99.28–1798.99.40; Cal. Civ. Code § 1798.120(c); Md. Code, Com. Law §§ 14-4601 to 14-4607; Conn. Gen. Stat. § 42-515 et seq.
- General consumer protection and security: 15 U.S.C. § 45(a) and § 45(m); 16 C.F.R. Part 314 (Safeguards Rule); 16 C.F.R. Part 318 (Health Breach Notification Rule).
- Litigation and constitutional limits: NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024); Moody v. NetChoice, LLC, 603 U.S. 707 (2024).
This toolkit is educational and not legal advice. The COPPA Rule was recently amended with staged compliance dates, several state design codes are subject to pending constitutional litigation, and international ages of consent and requirements differ materially. Consult qualified privacy counsel before launching or modifying a service likely to be used by minors.