Summary. Children's privacy is governed by a 1998 statute reaching only children under thirteen, only operators with actual knowledge or a child-directed service, and only a defined list of personal information — and by a newer generation of state design codes attempting to regulate the experience itself rather than the data. The two regimes ask different questions, and a company can satisfy one while violating the other. This article covers the COPPA Rule as amended, including who is an operator, what makes a service child-directed, the consent methods that actually exist, the internal operations exception, and the retention and deletion obligations recently strengthened. It then addresses the design codes, the constitutional litigation reshaping them, teen privacy under state comprehensive laws, and what age assurance looks like in practice.


Three questions decide almost every children's privacy problem, and companies usually get to the third one only after a regulator asks.

Is the service directed to children under thirteen? If yes, COPPA applies to every user, and the entire consent apparatus is required.

If not, does the company have actual knowledge that a particular user is under thirteen? If yes, COPPA applies to that user.

And separately from both: is the service likely to be accessed by minors at all? If yes, a growing body of state and foreign law imposes design obligations that have nothing to do with COPPA's consent model.

A company can answer "no" to the first two and still face substantial obligations under the third. That is the structural feature that makes this area confusing, and it is why a compliance analysis that begins and ends with COPPA is incomplete.

COPPA: scope

The Children's Online Privacy Protection Act, enacted in 1998, is implemented by the FTC's COPPA Rule at 16 C.F.R. Part 312.

Who is covered. An operator of a website or online service directed to children under 13, or any operator of a general-audience service that has actual knowledge it is collecting personal information from a child under 13. "Online service" is broad: apps, connected toys, voice assistants, gaming platforms, and advertising networks and plug-ins that collect information through a child-directed service.

Third parties are operators too. An ad network, analytics provider, or SDK that collects personal information through a child-directed service is itself an operator, and the 2013 amendments made this explicit. That is what produced the $170 million YouTube settlement in 2019: Google was found to have collected persistent identifiers from viewers of child-directed channels for behavioral advertising, and the channel owners were treated as operators of child-directed content.

What makes a service "directed to children." The Rule lists factors:

  • subject matter;
  • visual and audio content;
  • use of animated characters or child-oriented activities and incentives;
  • music and other audio content;
  • age of models;
  • presence of child celebrities or celebrities who appeal to children;
  • language or other characteristics of the site;
  • whether advertising on the service is directed to children; and
  • competent and reliable empirical evidence of audience composition and intended audience.

Mixed-audience services. A service that is child-directed but does not target children as its primary audience may age-screen in a neutral manner and apply COPPA only to users who identify as under 13. The screen must not encourage falsification — no "you must be 13 to enter" prompt that teaches the user what to say — and should use a neutral date-of-birth field with a session mechanism preventing re-entry after a rejection. The 2025 amendments codified "mixed audience" as a formal subcategory with defined requirements.

Actual knowledge. For general-audience services, liability requires actual knowledge, not constructive knowledge. In practice, actual knowledge arises from: a user stating their age, a parent's complaint, an internal analysis identifying child users, or content and account signals a company chose to collect. Companies sometimes conclude that the safest course is not to ask — which reduces COPPA exposure and increases exposure under design codes and under Section 5 unfairness theories. There is no configuration that avoids every risk.

What counts as personal information

The Rule's definition is broader than most people assume:

  • first and last name;
  • a home or physical address including street name and city or town;
  • online contact information, including email;
  • a screen or user name functioning as online contact information;
  • telephone number;
  • Social Security number;
  • a persistent identifier that can be used to recognize a user over time and across services — cookies, IP address, device serial number, advertising identifier;
  • a photograph, video, or audio file containing a child's image or voice;
  • geolocation sufficient to identify a street name and city;
  • biometric identifiers, added by the 2025 amendments — fingerprints, voiceprints, facial templates, retina and iris patterns, gait; and
  • information concerning the child or the parents that the operator collects online and combines with any of the above.

The persistent identifier inclusion is the one that matters commercially, because it means behavioral advertising on a child-directed service requires parental consent, which is impractical at scale — so child-directed services generally cannot run targeted advertising at all. Contextual advertising, which does not use persistent identifiers to build a profile, remains available.

Verifiable parental consent

Before collecting personal information from a child, an operator must provide direct notice to the parent and obtain verifiable parental consent — reasonable effort, taking available technology into account, to ensure the person giving consent is the child's parent.

Approved methods in the Rule:

  • a signed consent form returned by mail, fax, or electronic scan;
  • a credit, debit, or online payment transaction that provides notification of each transaction;
  • a toll-free telephone call or video conference with trained personnel;
  • checking a government-issued identification against a database, with prompt deletion;
  • knowledge-based authentication with sufficient difficulty;
  • facial recognition matching a photo ID to a submitted image;
  • a text message to a parent coupled with additional steps, approved through the Rule's application process; and
  • electronic signature with sufficient verification.

The "email plus" method is a limited alternative available only where the operator uses the information for internal purposes and does not disclose it: an email to the parent, plus a confirming step such as a delayed second email, a phone call, or a mailed letter.

New consent for new uses. Material changes to collection, use, or disclosure require new consent. And the 2025 amendments require separate, distinct consent for disclosure to third parties, including for targeted advertising — a parent consenting to a child's use of a service does not thereby consent to sharing.

The parental rights that follow. Parents must be able to review the information collected, to refuse further collection, and to require deletion — and an operator may not condition a child's participation in an activity on disclosing more information than is reasonably necessary to participate.

The support for internal operations exception

This exception is what allows child-directed services to function at all, and it is narrower than commonly assumed.

An operator may collect a persistent identifier without parental consent where it is used solely to provide support for the internal operations of the service — defined as:

  • maintaining or analyzing the functioning of the service;
  • performing network communications;
  • authenticating users and personalizing content;
  • serving contextual advertising and capping frequency;
  • protecting security or integrity;
  • ensuring legal or regulatory compliance; and
  • fulfilling a request of a child as permitted by other exceptions.

"Solely" is doing the work. The moment the identifier is used to build a profile, to target advertising based on behavior, or to be shared with a third party for its own purposes, the exception is gone. The 2025 amendments also require that the operator not use or disclose the identifier for any other purpose and, if it relies on this exception, disclose in its notice the specific internal operations for which the identifier is used.

Other narrow exceptions permit one-time collection of online contact information to respond to a specific request and then delete it; collection to obtain parental consent; multiple contacts with the child where the parent is notified and can opt out; protecting the child's safety; and responding to judicial process or protecting security.

Retention, deletion, and security

The 2025 amendments strengthened obligations that were previously stated at a high level.

  • A written data retention policy is now required, specifying the purposes for which children's personal information is collected, the business need for retention, and the timeframe for deletion. The policy must be published in the operator's online notice.
  • Indefinite retention is prohibited. Information may be retained only as long as reasonably necessary for the specific purpose for which it was collected, and may not be retained indefinitely.
  • Reasonable security procedures appropriate to the sensitivity of the information, and the amendments require a written children's personal information security program with designated responsibility, risk assessment, safeguards, and vendor oversight.
  • Vendor diligence. An operator must take reasonable steps to release children's information only to service providers and third parties capable of maintaining its confidentiality, security, and integrity, and must obtain written assurances.

Enforcement and penalties

Who enforces. The FTC, and state attorneys general, who may bring actions in federal court on behalf of residents. There is no private right of action under COPPA — a point that has been litigated repeatedly, with plaintiffs attempting to plead state law claims premised on COPPA violations and courts frequently finding them preempted or dismissing for failure to state an independent claim, though state privacy statutes increasingly supply an independent hook.

Penalties. Civil penalties are assessed per violation under Section 5(m) of the FTC Act, with the maximum adjusted annually for inflation and currently above $50,000 per violation. Because each child and each collection can be counted, the theoretical exposure is unbounded.

The enforcement record tells the story better than the statute:

  • Google/YouTube (2019) — $170 million, the largest COPPA penalty, for collecting persistent identifiers from viewers of child-directed channels for advertising.
  • Musical.ly/TikTok (2019) — $5.7 million, for operating a child-directed service without consent and failing to honor deletion requests.
  • Epic Games (2022) — $275 million in COPPA penalties, plus $245 million in Section 5 relief for dark patterns and billing practices. The order also required default privacy settings for children and teens, including disabling voice and text chat by default — an early example of a design remedy in a data case.
  • Amazon Alexa (2023) — $25 million, focused on retention: keeping children's voice recordings and geolocation indefinitely and failing to honor deletion requests, including keeping transcripts after audio was deleted.
  • Microsoft Xbox (2023) — $20 million, for retaining information collected during account creation before parental consent was obtained.

The pattern across recent actions is retention and deletion, not collection. Companies obtained consent and then kept everything forever, and the FTC has treated that as an independent violation.

Safe harbor programs. COPPA permits FTC-approved self-regulatory programs whose members are deemed in compliance if they adhere to program guidelines. Several exist. The 2025 amendments increased transparency requirements — public disclosure of membership lists and of program standards, and more rigorous reporting to the Commission — after criticism that some programs certified members with obvious deficiencies.

The design codes: a different theory

COPPA regulates data collection from young children with parental consent as the remedy. The age-appropriate design codes regulate the product experience for all minors, with the remedy being design obligations that do not depend on consent at all.

The UK Children's Code, in force since 2021 under the UK data protection regime, sets fifteen standards for services likely to be accessed by children under 18: the best interests of the child as a primary consideration, a data protection impact assessment, age-appropriate application, transparency, detrimental use of data avoided, policies upheld, settings high privacy by default, data minimisation, sharing off by default, geolocation off by default, parental controls disclosed to the child, profiling off by default, no nudge techniques encouraging lower privacy, connected toys covered, and online tools to exercise rights.

The Code produced visible product changes — default-private accounts for teens, restrictions on adults contacting minors, turning off targeted advertising for minors — rolled out globally by major platforms rather than only in the UK.

The California Age-Appropriate Design Code Act, Cal. Civ. Code § 1798.99.28 et seq., adopted a similar model for businesses providing services likely to be accessed by children under 18.

And then the courts intervened. NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024), affirmed a preliminary injunction against the Act's data protection impact assessment requirement, holding that compelling businesses to assess and mitigate the risk that children would be exposed to "harmful" content likely violated the First Amendment as a compelled-speech and content-based restriction. The court vacated the injunction as to the Act's remaining provisions and remanded for the district court to analyze them individually, noting that several — default settings, geolocation, dark patterns, data minimization — may be ordinary privacy regulation rather than speech regulation.

What survived, doctrinally. The decision suggests a workable line: provisions regulating how data is collected and used are likely constitutional; provisions requiring a business to evaluate and suppress content based on its potential harm to minors are likely not. Legislatures drafting new codes have responded by stripping content-related provisions.

Other states have followed with narrower statutes — Maryland enacted a code focused on data practices and default settings, and Vermont and Nebraska have enacted or advanced similar measures. Litigation is ongoing in several.

Separately, age verification mandates for social media and adult content have generated their own constitutional litigation. Moody v. NetChoice, LLC, 603 U.S. 707 (2024), addressed facial challenges to content-moderation statutes and instructed lower courts to conduct a proper facial analysis before enjoining, which has slowed but not stopped these challenges. The upshot for compliance planning is that the legal landscape for minors' online experiences is unsettled and will remain so, while the product expectations set by the UK Code and by platform practice are already established.

Teen privacy: the gap COPPA leaves

COPPA stops at the thirteenth birthday. State comprehensive privacy laws have begun filling the gap.

  • Several states' comprehensive privacy statutes require opt-in consent for processing the personal data of consumers between 13 and 16 for targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects — the default flips from opt-out to opt-in for that age band.
  • Connecticut amended its statute to add minor-specific duties for services minors are likely to access: a duty of care regarding heightened risk of harm, default limits on unsolicited contact, restrictions on precise geolocation, and prohibitions on features designed to increase use time.
  • Colorado, Delaware, Oregon, Texas, and others contain minor-specific provisions of varying scope.
  • Age determination. Most of these statutes apply based on actual knowledge or willful disregard of a consumer's age — a lower threshold than COPPA's actual knowledge, and one that arguably penalizes deliberate ignorance.

The FTC's Section 5 authority also reaches practices affecting teens that COPPA does not cover, on unfairness or deception theories. The Epic Games order is the template: default settings for minors, restrictions on communications, and prohibitions on dark patterns, imposed without reference to COPPA.

Age assurance in practice

Every regime above depends on knowing, or reasonably estimating, a user's age, and no method is both accurate and privacy-preserving.

The available approaches, with tradeoffs:

  • Self-declaration. Cheap, universally used, trivially defeated. Adequate for a neutral age screen; inadequate where a statute requires assurance.
  • Age estimation from facial imagery. Increasingly accurate for distinguishing broad age bands, processes biometric data (triggering biometric privacy statutes and, now, COPPA's biometric definition), and requires on-device processing and immediate deletion to be defensible.
  • Behavioral and inferential estimation from usage signals. Low friction, contested accuracy, and it creates the actual knowledge that a company may then be obligated to act on.
  • Identity document verification. Accurate, high friction, excludes users without documents, and creates a sensitive data repository.
  • Credit card or payment verification. A COPPA-approved consent method; a poor age signal in isolation.
  • Third-party age assurance providers and device-level or app-store signals. The direction of travel, with several legislative proposals shifting the obligation to operating systems and app stores. Attractive because it centralizes verification once rather than at every service.

Design principles that hold across regimes:

  • Collect the minimum needed to establish the age band, not the exact age or identity.
  • Delete verification artifacts immediately after the determination, retaining only the result.
  • Do not use age data for anything else — not personalization, not advertising, not analytics.
  • Provide an appeal path for users incorrectly classified.
  • Document the method, its accuracy, and the reasoning, because a regulator will ask why the chosen method was reasonable.

Special contexts

Edtech and school consent. Where a service is used in a school setting for an educational purpose, the FTC has taken the position that a school may provide consent on the parents' behalf for the collection of students' personal information used solely for that educational purpose. The 2025 amendments codified a school-authorization mechanism with conditions: the operator must provide the school with the required direct notice, must use the information only for the educational purpose authorized, must not use it for any commercial purpose including advertising or building a profile, and must delete it when no longer needed. FERPA and the state student privacy statutes — of which there are now more than a hundred — impose parallel and sometimes stricter obligations, including restrictions on targeted advertising, on selling student data, and on retention after contract termination.

Connected toys and voice devices. A toy that records a child's voice collects personal information under the Rule, and the Amazon and VTech actions establish that both consent and deletion are enforced. Design implications: local processing where possible, explicit and prominent recording indicators, a deletion mechanism accessible to parents, and short default retention.

Gaming. The intersection of children's privacy and monetization is the FTC's most active area. Beyond COPPA, expect scrutiny of in-game purchase flows, loot boxes, default communication settings, and any design element that pressures spending. The Epic order's requirement of default-off voice and text chat for minors has become a de facto standard.

Advertising and analytics SDKs. Any SDK embedded in a child-directed app is an operator. App developers should maintain an SDK inventory, obtain contractual assurances that each SDK is configured for child-directed use (most major networks offer a "child-directed treatment" flag that disables personalized advertising), verify the configuration rather than trusting it, and re-verify after every SDK update.

Influencer and content creator channels. The YouTube action established that creators of child-directed content are themselves operators. Platforms now require creators to designate content as made for kids, and that designation disables comments, notifications, and personalized advertising. Creators who misdesignate bear exposure.

A compliance program

Step 1 — Classify the service. Is it child-directed, mixed audience, general audience with known child users, or general audience likely to be accessed by minors? Write the analysis down with the Rule's factors, the empirical audience data, and the date. This document is the first thing a regulator will ask for.

Step 2 — Inventory the data. Every field collected, every identifier, every SDK, every third party, and the purpose for each. Persistent identifiers and any audio, video, or biometric capture deserve specific attention.

Step 3 — Map to a lawful basis. For each element: parental consent obtained, internal operations exception, another Rule exception, or not permitted. Anything in the last category stops.

Step 4 — Build the consent flow if consent is required. Direct notice to the parent, an approved verification method, separate consent for third-party disclosure, a record of what was consented to and when, and a mechanism for re-consent on material changes.

Step 5 — Write the notices. An online privacy notice meeting the Rule's content requirements, including the categories collected, how used, disclosure practices, the retention policy, and parents' rights with contact information for each operator collecting through the service.

Step 6 — Implement retention and deletion. A written retention policy, automated deletion at the stated interval, a parent-facing deletion mechanism, and — critically — deletion that reaches derived data such as transcripts, embeddings, and profiles, not only the raw record. The Amazon action turned on exactly this.

Step 7 — Apply design defaults for all minors, not only under-13s: privacy settings high by default, geolocation off, profiling off, no targeted advertising, communications restricted, no engagement-maximizing nudges directed at minors. This is the layer that satisfies the design codes and the FTC's Section 5 expectations, and it is largely independent of COPPA.

Step 8 — Govern the vendors. Contractual assurances, configuration verification, periodic audits, and a change-control process for SDK updates.

Step 9 — Train and test. Product managers make the decisions that create liability here. Include children's privacy in the product review gate, and test the actual shipped experience rather than the spec.

Step 10 — Monitor the law. This is the fastest-moving area in American privacy, with new state statutes each session and active constitutional litigation. Assign someone to track it quarterly.

Where this is heading

Two observations, offered as forecast rather than as law.

First, the consent model is losing ground to the design model. COPPA's premise — that a parent, properly informed, will make a good decision — has not worked well at scale, because consent flows are friction that both operators and parents route around. The design codes take a different view: certain defaults should apply to minors regardless of what anyone consented to. The Epic order, the UK Code, and the surviving portions of the state codes all reflect that shift, and it is likely to continue.

Second, the age boundary is moving up. Thirteen was chosen in 1998 for reasons connected to the practicalities of online contracting, not to developmental psychology, and essentially every new statute in this area reaches minors up to sixteen or eighteen. Companies building compliance programs around a thirteenth-birthday cutoff are building for a rule that is already being superseded around them.

The practical implication of both is the same. Design the product for minors the way you would want it designed for your own child, and the compliance obligations across every regime become substantially easier to meet. That is not a legal standard, and it is not a substitute for the analysis above. But it predicts regulatory outcomes in this area better than any close reading of the Rule.

International obligations beyond the UK

A service available globally faces obligations that are not merely stricter than COPPA but structurally different.

The GDPR. Article 8 sets the age of consent for information society services offered directly to a child at 16, with member states permitted to lower it to no less than 13 — and they have, unevenly, so the operative age varies from 13 in Denmark and Sweden to 16 in Germany and the Netherlands. Where the child is below the applicable age, processing based on consent is lawful only if authorized by the holder of parental responsibility, and the controller must make reasonable efforts to verify that authorization, taking available technology into account. Recital 38 adds that children merit specific protection because they may be less aware of risks, and that specific protection should apply in particular to marketing and profiling.

Two consequences that surprise U.S. operators: consent is only one of six lawful bases, so a service relying on legitimate interests must run a balancing test that gives extra weight to a child's interests; and the GDPR's transparency obligation requires that information addressed to a child be provided in clear and plain language that a child can understand, which means a second, child-facing notice rather than a link to the adult privacy policy.

Brazil's LGPD requires parental consent for children under 12 and treats children's data as requiring processing in their best interest. Canada's PIPEDA treats the personal information of children as sensitive, and the Office of the Privacy Commissioner has taken the position that consent from anyone under 13 must come from a parent. China's PIPL requires separate consent from a parent for personal information of minors under 14 and requires a dedicated processing rule for it. India's Digital Personal Data Protection Act requires verifiable parental consent for anyone under 18 and prohibits tracking, behavioral monitoring, and targeted advertising directed at children — a materially broader prohibition than any U.S. rule.

The practical planning point. A global service cannot run a single age gate at 13. The workable architecture is a jurisdictional age matrix driving which consent and default rules apply, with the highest applicable standard used where the jurisdiction is uncertain. Building that matrix once is far cheaper than retrofitting it after a European supervisory authority opens a file.

Common failure modes

Drawn from enforcement actions and from diligence reviews, in rough order of frequency:

  1. An SDK nobody inventoried. An analytics or attribution library added by a contractor three years ago transmits advertising identifiers from a child-directed app. The developer had no idea and cannot say when it started.
  2. "Made for kids" designated at the channel level but not the video level, or the reverse, on platforms that permit both.
  3. Consent obtained, then everything retained forever. The most-penalized failure in recent years, and the easiest to fix.
  4. Deletion that misses derived data. Audio deleted, transcripts kept. Photos deleted, face embeddings kept. Accounts deleted, profiles retained in an advertising system.
  5. An age gate that teaches the answer. "You must be 13 or older to continue" followed by a date-of-birth field, with unlimited retries.
  6. A general-audience service with obvious child users. Internal analytics identify the cohort, a product manager writes a memo about it, and nothing changes. That memo is actual knowledge and it will be produced.
  7. School consent assumed rather than obtained. An edtech vendor relies on a teacher clicking through a signup as the school's authorization, with no district agreement and no written notice.
  8. Marketing to parents through the child. Collecting a parent's email through a child-facing prompt and then adding it to a marketing list.
  9. Sweepstakes and contests on child-directed properties collecting name, address, and age with no consent mechanism at all.
  10. Acquisition without diligence. A company buys an app with a young user base and inherits both the practices and the retained data. Children's privacy belongs on the diligence checklist for any consumer acquisition, and the remediation cost should be priced.

What a regulator asks for

If the FTC or a state attorney general opens an inquiry, the initial request is predictable, and knowing it in advance shapes what a company should be maintaining now:

  • The audience analysis — how the company determined whether the service is child-directed, including any market research, audience measurement data, advertiser materials describing the audience, and internal communications about the user base.
  • Every version of the privacy notice and the direct notice to parents, with effective dates.
  • The consent mechanism as implemented, including screenshots, the verification method, and aggregate statistics on consents obtained versus accounts created — a mismatch is the first thing an investigator looks for.
  • A data map identifying every element collected from users identified or estimated as children, every internal system holding it, and every third party receiving it.
  • The retention schedule and evidence that deletion actually executed, not merely that a policy existed.
  • Parental requests received for access or deletion, and how each was resolved, with timestamps.
  • Vendor and SDK agreements, and evidence of configuration for child-directed treatment.
  • Internal product and design documents discussing minors, engagement, or age — which is where the damaging material usually is, and which cannot be created or improved after the request arrives.

The unglamorous conclusion is that children's privacy compliance is mostly a records exercise. The companies that come through inquiries well are not the ones with the best legal arguments; they are the ones that can produce a dated audience analysis, a versioned notice history, and proof that deletion ran.

Primary authority

Children's privacy is now three overlapping regimes: a federal statute, a wave of state design codes, and general consumer protection law.

  • 15 U.S.C. §§ 6501–6506 (COPPA) — the statute, including the definition of a website or online service directed to children and the actual-knowledge standard.
  • 16 C.F.R. Part 312 — the COPPA Rule: the notice requirements in § 312.4, verifiable parental consent in § 312.5, parental review and deletion rights in § 312.6, the conditioning prohibition in § 312.7, the security and retention duties in § 312.8 and § 312.10, and the safe harbor program in § 312.11. The Commission's 2025 amendments tighten consent for third-party disclosure and add a written information security program requirement.
  • 15 U.S.C. § 45 — Section 5 of the FTC Act, the vehicle for unfairness and deception claims that reach conduct the Rule does not.
  • 20 U.S.C. § 1232g and 34 C.F.R. Part 99 (FERPA) — education records, and the school-official exception that vendors rely on.
  • 20 U.S.C. § 1232h (PPRA) — surveys and marketing in schools.
  • Cal. Civ. Code §§ 1798.99.28–1798.99.40 — the California Age-Appropriate Design Code Act, and NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024), which enjoined its data protection impact assessment provisions on First Amendment grounds while leaving other portions to be considered on remand.
  • Cal. Civ. Code § 1798.120(c) — the CCPA opt-in for consumers under sixteen.
  • UK Age Appropriate Design Code and the EU GDPR Article 8 age-of-consent provision — the sources most global product teams are actually designing against.

Related articles

This article is provided for general informational purposes and does not constitute legal advice. The COPPA Rule was recently amended with staged compliance dates, several state design codes are subject to pending constitutional litigation, and state minor-privacy provisions differ materially. Consult qualified privacy counsel before launching a service likely to be used by minors.