Children’s Online Privacy (COPPA): What Parents and Sites Must Know

Photo of author
Author: Alex
Published:
Updated:
Shield icon blocking personal data collection from a child — children online privacy COPPA explained

Direct Answer: COPPA the Children’s Online Privacy Protection Act is a U.S. federal law that requires websites, apps, and online services to get verifiable parental consent before collecting personal data from children under 13. The law is enforced by the Federal Trade Commission (FTC), and violations can result in fines of up to $53,088 per violation. The FTC finalized major updates to the COPPA Rule in 2025, with a compliance deadline of April 22, 2026.

Children online privacy COPPA explained in plain terms: if your kid downloads a game, signs up for a social platform, or uses any app that collects their name, photo, or location, that company has legal obligations under U.S. federal law and many don’t follow them. The FTC has issued tens of millions of dollars in fines against companies like Epic Games, Disney, and TikTok for failing to protect children’s data. Whether you’re a parent trying to understand what apps can and can’t do with your child’s information, or a business building a product kids might use, here’s what the law actually says and what changed in 2025. Learn how biometric data laws apply to fingerprints and face scans collected from minors.

The Short Version

  • COPPA applies to any commercial website, app, or online service that collects personal data from children under 13 in the United States. Nonprofit entities are generally exempt.
  • Operators must post a clear privacy policy, send direct notice to parents, and get verifiable parental consent before collecting a child’s data.
  • The 2025 amendments expanded what counts as “personal information” to include biometric identifiers and government-issued IDs, and now require separate consent before sharing a child’s data with third parties like advertisers.
  • Fines are serious courts can impose penalties of up to $53,088 per violation, and recent enforcement actions have resulted in settlements of $10 million (Disney, 2025) and $20 million (Cognosphere/HoYoverse, 2025).

What Children Online Privacy COPPA Explained Actually Means Under the Law

COPPA was signed into law in 1998 and took effect in April 2000. The law is codified at 15 U.S.C. §§ 6501–6505, and the FTC issues the COPPA Rule (16 CFR Part 312) that spells out exactly how companies must comply.

The law’s core principle is simple: parents not companies get to decide what personal information is collected from their children online.

Who Must Comply

Under U.S. federal law, COPPA covers:

  • Commercial websites and online services directed to children under 13
  • General audience websites or apps that have actual knowledge they are collecting personal information from a child under 13
  • Third parties like ad networks or analytics plug-ins that collect data through child-directed services

The “actual knowledge” standard is important. If a general audience app asks users to enter their age during sign-up, and a user enters an age under 13, the operator now has actual knowledge and must comply with COPPA. The 2025 Rule update expanded the factors the FTC considers when determining whether a site is “directed to children,” including marketing materials and the ages of users on similar platforms.

What Counts as “Personal Information”

Under the updated COPPA Rule (effective June 23, 2025), personal information includes:

  • A child’s first and last name, or a parent’s name
  • A home address or other physical location, including street name and city
  • An email address or other online contact information
  • A phone number
  • A Social Security number
  • A persistent identifier such as a cookie, IP address, or device serial number — that can track a user over time
  • A photo, video, or audio file containing a child’s image or voice
  • Geolocation data precise enough to identify a street and city
  • Biometric identifiers such as fingerprints, voiceprints, facial templates, or iris patterns (added in 2025)
  • Government-issued identifiers (added in 2025)

What Companies Must Do

The COPPA Rule requires covered operators to:

  1. Post a clear privacy policy on their website or app describing exactly what data they collect from children, how they use it, and who they share it with
  2. Send direct notice to parents before collecting any personal information
  3. Obtain verifiable parental consent before collecting, using, or disclosing a child’s data methods include signed consent forms, credit card verification, video calls, and knowledge-based questions
  4. Allow parents to review their child’s data and request deletion
  5. Limit data collection to only what is needed for the child to participate in the activity
  6. Maintain a written data retention policy (new in 2025) and delete children’s data when it is no longer needed indefinite retention is now prohibited
  7. Get separate parental consent before disclosing a child’s data to third parties for targeted advertising (new in 2025)
Parent granting consent while child accesses an app — COPPA parental consent and compliance process

Real-World Examples

Epic Games (2023): The FTC charged the maker of Fortnite with violating COPPA by collecting personal data from children under 13 without parental consent and using design features that harmed children’s privacy. The settlement included significant financial penalties and required the company to overhaul its privacy practices.

Disney (2025): A federal judge approved a $10 million settlement after the FTC alleged that Disney allowed personal data to be collected from children watching kid-directed videos on YouTube without notifying parents or getting consent as COPPA requires.

Cognosphere / HoYoverse (2025): The maker of the video game Genshin Impact paid $20 million to settle FTC charges that it marketed loot boxes to children and shared player data including device identifiers and gameplay activity with third-party advertisers without parental consent.

TikTok / Musical.ly (2019): ByteDance paid $5.7 million after the FTC found TikTok’s predecessor app collected names, emails, and location data from children who identified as under 13 during registration.

What People in This Situation Typically Do

For parents:

  1. Check the privacy policy of any app or website before allowing a child under 13 to create an account look for a dedicated children’s privacy section
  2. Look for age gates or parental consent mechanisms when a child signs up for a new service if there’s no age check at all, that may be a red flag
  3. Request to see what data a company has collected about a child, and ask for deletion if desired COPPA gives parents this right
  4. Report suspected COPPA violations to the FTC at ftc.gov or by calling (877) FTC-HELP

For businesses:

  1. Determine whether the service is “directed to children” or whether it has actual knowledge of collecting data from users under 13
  2. Review the updated COPPA Rule requirements the April 22, 2026 compliance deadline for the 2025 amendments has arrived
  3. Implement verifiable parental consent mechanisms and update privacy policies to reflect new requirements around biometric data and third-party sharing
  4. Maintain a formal information security program and a written data retention policy specifically for children’s data

Beyond COPPA: Children’s Privacy in the UK and EU

COPPA is a U.S. law, but other countries have their own frameworks for protecting children online.

In the United Kingdom, the Age Appropriate Design Code (also called the Children’s Code) took effect in September 2021. Created by the ICO under the Data Protection Act 2018, it sets 15 standards for any online service likely to be accessed by someone under 18 broader than COPPA’s under-13 focus. Key requirements include high-privacy default settings, limits on data sharing, and a ban on manipulative “nudge” techniques. Violations can be enforced under UK GDPR, with fines of up to £17.5 million or 4% of annual worldwide revenue.

In the European Union, the GDPR (2018) requires parental consent for data processing when services are offered directly to children. The default age threshold is 16, though member states can lower it to 13 and many have.

Related Articles

Frequently Asked Questions

What age does COPPA protect? COPPA protects children under the age of 13 in the United States. Any commercial website, app, or online service that collects personal information from children in this age group must comply with the law’s requirements for parental notice and consent. The UK’s Children’s Code takes a broader approach, covering anyone under 18.

What apps are required to comply with COPPA? Under U.S. federal law, any commercial app, website, or online service that is either directed at children under 13 or has actual knowledge that it collects personal data from children under 13 must comply. This includes games, social media platforms, educational apps, streaming services, and even connected toys or smart devices. Nonprofit organizations are generally exempt.

What data can websites legally collect from children? Under COPPA, websites can only collect personal information from children under 13 after getting verifiable parental consent. Even with consent, operators must limit collection to what is reasonably necessary. The 2025 amendments added biometric identifiers and government-issued IDs to the definition of protected personal information. Operators must also delete children’s data once it is no longer needed — indefinite retention is now specifically prohibited.

What are the fines for COPPA violations? Courts can impose civil penalties of up to $53,088 per violation. The actual amount depends on factors like the severity of the violation, how many children were affected, what data was collected, and the size of the company. Recent FTC enforcement actions have resulted in settlements ranging from $5 million (NGL, 2024) to $20 million (Cognosphere, 2025). Epic Games’ 2022 settlement, which included both COPPA and other FTC Act violations, was the largest enforcement action involving children’s privacy to date.

Whether you are a parent reviewing an app’s privacy settings or a business building a product that children might access, understanding children online privacy COPPA explained in practical terms is the first step toward protecting kids in a digital world where data collection starts long before adulthood.

This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.

Sources & Further Reading

Pinterest graphic explaining children online privacy COPPA — shield protecting kids' data online

Written by Alex

Alex is the editorial pen name of Mohammed Ez-Zayady, a law student based in Morocco and the founder of Jovonk. The content is provided for educational purposes and does not constitute legal advice.