Skip to main content
Can We Even Build a Consent Flow for 12-Year-Olds?Data Governance Frameworks
4 min readFor Chief Privacy Officers

Can We Even Build a Consent Flow for 12-Year-Olds?

Your team's been tasked with designing a privacy experience for younger users. Legal has handed you the COPPA requirements. Your product manager wants a seamless signup process. A board member asks if you're "COPPA compliant." And you're left wondering: what does that actually mean when a seventh-grader clicks "I agree"?

These questions arise in every privacy team meeting when children's features are on the roadmap. Here's what you need to know.

Understanding the Source of These Questions

Children's privacy is at the crossroads of regulatory compliance, product design, and harm prevention. The U.S. enacted COPPA in 1998 to protect children's data. Nearly 25 years later, privacy officers at platforms with youth audiences face a global regulatory landscape, but the practical questions remain complex. You're tasked with translating age-verification requirements into user flows, explaining why "just get parental consent" isn't a checkbox, and building features that protect kids without making the experience unusable.

Does COPPA Apply to Your Service?

COPPA applies if your service is directed to children under 13, or if you know you're collecting personal information from them. "Directed to children" isn't about intent. The FTC examines subject matter, visual content, use of animated characters, music or celebrities appealing to children, language, and whether your advertising targets kids.

If your service has a mixed audience, you still fall under COPPA for the parts directed at children. You can't avoid the rule by stating "13+" in your terms if your design targets younger users. The FTC will look at your actions, not just your words.

Verifiable Parental Consent vs. Checkbox Consent

Verifiable parental consent means taking reasonable steps to ensure the person providing consent is the child's parent or guardian. A checkbox isn't enough.

The FTC recognizes several methods: requiring a signed consent form, accepting payment information, taking a government-issued ID, answering knowledge-based questions, or video-conferencing with trained personnel. Email consent works only for internal school uses or when notifying about practices without collecting more data.

Your method must match your risk profile. If you're collecting sensitive data or making it public, you need a higher level of verification. For minimal internal use, email-plus-confirmation may suffice. Document your risk assessment. If the FTC asks why you chose your method, "it was easier" isn't an answer.

Blocking Users Under 13

You can block users under 13, but you need to actually block them. Simply stating "You must be 13 or older" on a signup page and accepting any birthdate isn't blocking.

If you implement age-gating, use a neutral age-screening mechanism that doesn't encourage lying. Don't ask "Are you 13 or older?" Ask for a birthdate. If the user enters an age under 13, close the path.

Some teams use soft blocks: holding accounts in a pending state and requiring parental consent before activation. That works, but you're still subject to COPPA's parental consent requirements. You've just delayed the compliance point.

Handling Age Misrepresentation

COPPA requires you to delete data once you know the user is under 13. "Actual knowledge" includes a child self-identifying their age, a parent informing you, or your own research revealing the user's age.

You don't have to proactively hunt for underage users if your service isn't directed at children. But if you receive a credible report, you must act. Delete the data within a reasonable timeframe. Don't wait for the parent to formally request deletion.

Document your response process. When you receive an age-related report, who reviews it? What's your standard for "credible"? How quickly do you delete? If the FTC investigates, they'll ask for your procedures and evidence you followed them.

Adding New Features for Kids

Adding features like video uploads changes your COPPA obligations. If your original notice said you collect name and email, and now you're collecting video uploads, that's a material change.

You need to send direct notice to parents describing the new practice and get fresh consent before enabling the feature for existing child users. For new users, update your Notice and Choice flow before launch.

"Material" isn't defined by data type alone. Ask: does this change the risk profile? Video uploads create disclosure risks, persistent identification risks, and location risks that email collection doesn't. If the answer is yes, get new consent.

Marketing and COPPA Compliance

If you start directing content or advertising at children, you may bring yourself under COPPA even if your original service was adult-focused. The FTC evaluates whether your service is directed to children based on the totality of circumstances, including how you promote it.

Running family-oriented ads doesn't automatically trigger COPPA. But if those ads feature child-focused themes, appear on children's networks, or use child influencers, and your service subsequently attracts a significant child audience, you're building an FTC case that your service has become directed at children.

Before your marketing campaign launches, assess: will this attract users under 13? If yes, do you have COPPA-compliant mechanisms in place? If no, pause the campaign until you do.

Further Resources on Children's Privacy

Start with the FTC's COPPA FAQs and the Rule itself (16 CFR Part 312). For international context, review the GDPR's Article 8 on children's consent, the UK's Age Appropriate Design Code, and California's amendments under COPPA-like requirements in the CCPA.

The IAPP published "Children's Privacy and Safety" as a resource for practitioners working through these issues. It covers regulatory requirements and practical implementation across jurisdictions. If your service has a youth audience in multiple markets, you're not just complying with one law; you're building for the most restrictive requirements across all of them.

You Might Also Like