Summary. Children's privacy compliance turns on two documents most companies do not have: a dated audience analysis explaining why the service is or is not directed to children, and a written retention policy showing what is kept, why, and for how long. Recent enforcement has concentrated on retention and deletion rather than collection, and the amended rule now requires both explicitly. This checklist runs the analysis in order — classify the service, inventory every data element and every embedded SDK, map each to a lawful basis, build the consent flow where required, and implement deletion that reaches derived data. It closes with the design defaults that satisfy newer regimes.
What this checklist is for. Assessing and building COPPA compliance for a service that children may use. For the broader framework including design codes and teen privacy, see Children's Privacy Under COPPA and the Age-Appropriate Design Codes.
Phase 1 — Classify the service
- Apply the Rule's factors and write the analysis down, with the date: subject matter; visual and audio content; use of animated characters or child-oriented activities and incentives; music; age of models; child celebrities or celebrities appealing to children; language and other characteristics; whether advertising on the service is child-directed; and competent and reliable empirical evidence of audience composition and intended audience.
- Gather the empirical evidence: analytics on age composition, market research, advertiser materials describing the audience, and app store age ratings.
- Reach one of four conclusions and record it: child-directed, mixed audience, general audience with known child users, or general audience likely to be accessed by minors.
- If mixed audience, implement a neutral age screen — a date-of-birth field, not a "you must be 13" prompt, with a session mechanism preventing re-entry after rejection.
- If general audience, identify what would constitute actual knowledge of a child user and how the company would respond.
- Re-run the analysis annually and after any material change in content, marketing, or audience.
Why this matters. The audience analysis is the first document a regulator requests, and a company that never performed one has no answer to the threshold question.
Phase 2 — Inventory the data
- List every element collected, and check each against the Rule's definition of personal information: name; address; online contact information; a screen name functioning as contact information; telephone number; Social Security number; persistent identifiers including cookies, IP address, device identifiers, and advertising identifiers; photographs, video, or audio containing a child's image or voice; precise geolocation; biometric identifiers; and information combined with any of these.
- Inventory every SDK and third-party library embedded in the app or site, with its purpose, what it collects, and where it transmits.
- Identify every third party receiving data, and the purpose.
- Note that an ad network or analytics provider collecting through a child-directed service is itself an operator under the Rule.
- Map each element to a purpose and to a lawful basis: parental consent obtained, the internal operations exception, another Rule exception, or not permitted.
- Stop anything in the last category.
Phase 3 — The internal operations exception
- Confirm any persistent identifier collected without consent is used solely for support for internal operations: maintaining or analyzing functioning; network communications; authenticating users and personalizing content; contextual advertising and frequency capping; protecting security or integrity; legal compliance; or fulfilling a child's request under another exception.
- Confirm the identifier is not used to build a profile, not used for behavioral advertising, and not disclosed to a third party for its own purposes.
- Disclose in the online notice the specific internal operations for which the identifier is used.
- Configure every ad network SDK for child-directed treatment, which disables personalized advertising, and verify the configuration rather than trusting it.
- Re-verify after every SDK update.
Phase 4 — Consent, where required
- Provide direct notice to the parent before collection, stating what is collected, how it is used, whether it is disclosed, and how to give consent.
- Obtain verifiable parental consent by an approved method: a signed form returned by mail, fax, or scan; a payment transaction providing notification; a toll-free call or video conference with trained personnel; government ID checked against a database with prompt deletion; knowledge-based authentication; facial recognition matching a photo ID; or an approved text-plus method.
- Use "email plus" only where information is used for internal purposes and not disclosed, and include the required confirming step.
- Obtain separate, distinct consent for disclosure to third parties, including for targeted advertising.
- Obtain new consent for any material change in collection, use, or disclosure.
- Do not condition participation in an activity on disclosing more information than is reasonably necessary.
- Retain the consent record, the method used, and the notice version.
Phase 5 — Retention, deletion, and security
- Adopt a written data retention policy stating the purposes for collection, the business need for retention, and the timeframe for deletion — and publish it in the online notice.
- Confirm no category is retained indefinitely.
- Implement automated deletion at the stated interval, and verify that it actually runs.
- Ensure deletion reaches derived data — transcripts, embeddings, profiles, model training sets, backups, and analytics systems — not merely the raw record. This is the failure recent enforcement has punished most severely.
- Provide a parent-facing mechanism to review the information collected, to refuse further collection, and to require deletion, and honor requests promptly.
- Adopt a written children's information security program with designated responsibility, risk assessment, safeguards, and vendor oversight.
- Obtain written assurances from every service provider and third party regarding confidentiality, security, and integrity.
Phase 6 — Notices
- Publish an online privacy notice meeting the Rule's content requirements: the categories collected, how used, disclosure practices, the retention policy, and parents' rights.
- List each operator collecting through the service, with contact information, or designate one to respond on behalf of all.
- Place a prominent link on the home page and at each point of collection.
- Maintain the notice by version with effective dates.
Phase 7 — Special contexts
- Schools. Where a service is used for a school-authorized educational purpose, confirm the school-consent conditions are met: direct notice to the school, use only for that purpose, no commercial use including advertising or profiling, and deletion when no longer needed. Layer FERPA and the applicable state student privacy statute.
- Connected devices and voice. Local processing where possible, a prominent recording indicator, a parent-accessible deletion mechanism, and short default retention.
- Gaming. Default-off voice and text chat for minors, and scrutiny of any purchase flow, loot box, or pressure mechanic.
- Creator content. Where a platform requires designation of content as made for kids, confirm the designation is accurate at the level the platform uses, because misdesignation carries exposure.
- Safe harbor. Consider joining an FTC-approved self-regulatory program, and evaluate its standards rather than assuming membership is protection.
Phase 8 — Design defaults for all minors
Independent of COPPA, apply these to every user identified or estimated as a minor:
- Privacy settings high by default; profiles private.
- Geolocation off by default.
- Profiling and targeted advertising off.
- Communications restricted, with adult contact limited.
- No nudge techniques encouraging lower privacy or extended use.
- Parental controls disclosed to the child where they exist.
- Age assurance that collects the minimum, deletes verification artifacts immediately, uses age data for nothing else, and provides an appeal path.
Common mistakes
- No dated audience analysis.
- An SDK nobody inventoried transmitting advertising identifiers from a child-directed app.
- Consent obtained and everything retained forever — the most-penalized failure in recent years.
- Deletion that misses derived data: audio deleted, transcripts kept.
- An age gate that teaches the answer, with unlimited retries.
- Internal analytics identifying child users in a general-audience service, with no response.
- School consent assumed from a teacher's click-through, with no district agreement.
- Marketing to parents through the child, collecting a parent's email through a child-facing prompt.
- Sweepstakes on child-directed properties collecting identifying information with no consent mechanism.
- An acquisition that inherited both the practices and the retained data, with no diligence.
Primary authority
- 15 U.S.C. §§ 6501–6506 and the COPPA Rule at 16 C.F.R. Part 312, including § 312.2 (definitions), § 312.4 (notice), § 312.5 (consent), § 312.7 (conditioning participation), § 312.8 (security), § 312.10 (retention and deletion), and § 312.11 (safe harbor).
- FERPA, 20 U.S.C. § 1232g, and state student privacy statutes.
- State comprehensive privacy statutes with minor-specific provisions, and state age-appropriate design codes.
- Statute and rule: 15 U.S.C. § 6502(a) (prohibition), § 6501(2) (website or online service directed to children), § 6501(10) (personal information), § 6502(b) (regulations), § 6503 (safe harbors), § 6505 (enforcement by the FTC and state attorneys general).
- The COPPA Rule: 16 C.F.R. § 312.2 (definitions), § 312.3 (general requirements), § 312.4 (direct notice and online notice), § 312.5 (verifiable parental consent and the approved methods), § 312.6 (parental access and deletion), § 312.7 (no conditioning participation), § 312.8 (confidentiality, security, and integrity), § 312.10 (data retention and deletion), § 312.11 (safe harbor programs), § 312.12 (voluntary approval of new consent mechanisms).
- General consumer protection: 15 U.S.C. § 45(a) (unfair or deceptive acts), § 45(m) (civil penalties for rule violations); 15 U.S.C. § 57b (redress).
- Education records: 20 U.S.C. § 1232g and 34 C.F.R. § 99.31(a)(1) (school official exception); 20 U.S.C. § 1232h (PPRA).
- State design codes: Cal. Civ. Code §§ 1798.99.28–1798.99.40, and NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024); Cal. Civ. Code § 1798.120(c) (opt-in under sixteen); Md. Code, Com. Law §§ 14-4601 to 14-4607.
Related
- Children's Privacy Under COPPA and the Age-Appropriate Design Codes
- Education Law for Schools and Edtech: FERPA, Title IX, and Section 504
- Developing a Privacy Compliance Program
- Legal Issues for Mobile Applications: Privacy
- Biometric Data Privacy Laws and Their Impact on AI Development
- Data Minimization and Avoiding the Over-Retention of Personal Information
- State Consumer Privacy Laws
- Children's and Student Privacy Toolkit: COPPA, FERPA, and Age-Appropriate Design
This checklist is educational and not legal advice. The COPPA Rule was recently amended with staged compliance dates, and state design codes and minor-privacy provisions differ and are subject to pending litigation. Consult qualified privacy counsel before launching a service likely to be used by minors.