Children's Online Privacy Protection Act
COPPA is a United States federal law that gives parents control over the personal information that websites and online services can collect from children under 13 years of age. It requires operators of covered websites or online services to follow specific rules before collecting information from young children. This entry describes the law's general purpose and scope and does not detail specific compliance procedures, penalties, or how children's privacy is regulated outside the United States.
The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law, implemented through the FTC's Children's Online Privacy Protection Rule (the COPPA Rule), that imposes requirements on operators of websites or online services directed to children under 13, and on operators of other online services with actual knowledge that they are collecting personal information from children under 13. It is administered by the Federal Trade Commission and is generally regarded as the primary U.S. federal law governing children's online privacy. COPPA applies within the United States and is jurisdiction-specific; children's data protection is treated differently under other regimes, and requirements for older minors or in other jurisdictions fall outside its scope. This definition does not address specific operator obligations such as parental consent mechanics, notice requirements, data retention, enforcement, or how COPPA interacts with U.S. state privacy laws or non-U.S. regulations.
Why it matters
COPPA matters because it establishes the primary U.S. federal baseline for how operators handle the personal information of children under 13, a population that generally cannot meaningfully consent to data collection on its own. For organizations that operate websites or online services, COPPA shifts a degree of control to parents and creates specific accountability for operators whose services are directed to young children or who have actual knowledge that they are collecting such information. Getting the scope wrong, assuming a service is out of scope when it is in fact directed to children, or overlooking the actual-knowledge trigger, can expose an operator to FTC enforcement.
The law is administered by the Federal Trade Commission through the COPPA Rule, which makes the FTC the central authority for interpretation and enforcement in this area. Because COPPA is jurisdiction-specific to the United States and focused on children under 13, teams should not assume it covers older minors or that it satisfies obligations under other regimes. Children's privacy is treated differently in other jurisdictions and under other frameworks, so COPPA compliance should be understood as one component of a broader children's data strategy rather than a universal solution.
This entry describes COPPA's general purpose and scope and does not detail parental consent mechanics, notice requirements, retention rules, penalties, or how COPPA interacts with U.S. state privacy laws or non-U.S. regulations. Organizations should consult the COPPA Rule text, current FTC guidance, and qualified counsel for operational compliance, as requirements depend on the specific service, audience, and data involved.
Who it's relevant to
Inside COPPA
Common questions
Answers to the questions practitioners most commonly ask about COPPA.