Children's Online Privacy Protection Act of 1998 and COPPA Rule
COPPA
Children
COPPA requires notice to parents and verifiable parental consent before collecting personal information from children under 13 online. The FTC's COPPA Rule was substantially amended in 2025 (effective June 23, 2025, with most compliance required by April 22, 2026), adding separate consent for third-party disclosures, a written security program, a written retention policy, and biometric and government identifiers to the definition of personal information.
- Where
- Federal
- Citation
- 15 U.S.C. 6501-6506; 16 CFR Part 312
- Status
- In force
- In force since
- 2000-04-21
- Last amended
- 2025-06-23
- Enforced by
- Federal Trade Commission; state attorneys general (parens patriae, 15 U.S.C. 6504)
- People can sue
- No
- Penalties
- Violations are treated as violations of an FTC rule: civil penalties up to $53,088 per violation (16 CFR 1.98, inflation-adjusted amount in force since Jan. 17, 2025). State AGs may sue for injunctions and damages on behalf of residents.
- Applies to
- Operators of commercial websites or online services directed to children under 13
- Operators of general-audience sites or services with actual knowledge they collect personal information from a child under 13
What a privacy notice must say
- Post a clear online notice of children's information practices and give parents direct notice before collection; the notice must now name third-party recipients (or categories) and include the data retention policy.16 CFR 312.4; 15 U.S.C. 6502(b)(1)(A)(i)
Rights it gives people
- Let parents review the personal information collected from their child, refuse further use or maintenance, and direct deletion.16 CFR 312.6; 15 U.S.C. 6502(b)(1)(B)
Practices it requires
- Obtain separate verifiable parental consent before disclosing a child's personal information to third parties unless the disclosure is integral to the service.16 CFR 312.5(a)(2) · From 2026-04-22
- Do not condition a child's participation in a game, prize offer, or activity on disclosing more personal information than reasonably necessary.16 CFR 312.7; 15 U.S.C. 6502(b)(1)(C)
- Keep children's personal information only as long as reasonably necessary for the purpose collected, under a written data retention policy; no indefinite retention.16 CFR 312.10 · From 2026-04-22
- Obtain verifiable parental consent before collecting, using, or disclosing a child's personal information, subject to limited exceptions.16 CFR 312.5(a)(1), (c); 15 U.S.C. 6502(b)(1)(A)(ii)
Security duties
- Maintain reasonable security and a written information security program with a designated coordinator, annual risk assessments, and safeguards scaled to the sensitivity of children's data.16 CFR 312.8(a)-(b) · From 2026-04-22
Other duties
- FTC-approved safe harbor programs may certify compliance; safe harbors have new reporting duties.16 CFR 312.11; 15 U.S.C. 6503
Sources
- Official text
- 15 U.S.C. 6501 et seq. (OLRC)
- 16 CFR Part 312 (eCFR)
- FTC, Children's Online Privacy Protection Rule, 90 FR 16918 (Apr. 22, 2025)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.