Skip to main content
Category: Privacy Regulations

Children's Online Privacy Protection Act

Also known as: COPPA, Children's Online Privacy Protection Rule, COPPA Rule
Simply put

COPPA is a United States federal law that gives parents control over the personal information that websites and online services can collect from children under 13 years of age. It requires operators of covered websites or online services to follow specific rules before collecting information from young children. This entry describes the law's general purpose and scope and does not detail specific compliance procedures, penalties, or how children's privacy is regulated outside the United States.

Formal definition

The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law, implemented through the FTC's Children's Online Privacy Protection Rule (the COPPA Rule), that imposes requirements on operators of websites or online services directed to children under 13, and on operators of other online services with actual knowledge that they are collecting personal information from children under 13. It is administered by the Federal Trade Commission and is generally regarded as the primary U.S. federal law governing children's online privacy. COPPA applies within the United States and is jurisdiction-specific; children's data protection is treated differently under other regimes, and requirements for older minors or in other jurisdictions fall outside its scope. This definition does not address specific operator obligations such as parental consent mechanics, notice requirements, data retention, enforcement, or how COPPA interacts with U.S. state privacy laws or non-U.S. regulations.

Why it matters

COPPA matters because it establishes the primary U.S. federal baseline for how operators handle the personal information of children under 13, a population that generally cannot meaningfully consent to data collection on its own. For organizations that operate websites or online services, COPPA shifts a degree of control to parents and creates specific accountability for operators whose services are directed to young children or who have actual knowledge that they are collecting such information. Getting the scope wrong, assuming a service is out of scope when it is in fact directed to children, or overlooking the actual-knowledge trigger, can expose an operator to FTC enforcement.

The law is administered by the Federal Trade Commission through the COPPA Rule, which makes the FTC the central authority for interpretation and enforcement in this area. Because COPPA is jurisdiction-specific to the United States and focused on children under 13, teams should not assume it covers older minors or that it satisfies obligations under other regimes. Children's privacy is treated differently in other jurisdictions and under other frameworks, so COPPA compliance should be understood as one component of a broader children's data strategy rather than a universal solution.

This entry describes COPPA's general purpose and scope and does not detail parental consent mechanics, notice requirements, retention rules, penalties, or how COPPA interacts with U.S. state privacy laws or non-U.S. regulations. Organizations should consult the COPPA Rule text, current FTC guidance, and qualified counsel for operational compliance, as requirements depend on the specific service, audience, and data involved.

Who it's relevant to

Operators of child-directed online services
Businesses running websites or online services directed to children under 13 fall squarely within COPPA's scope and must follow its requirements before collecting personal information from those children. Assessing whether a service is 'directed to children' is a threshold determination that should be made carefully, as misclassification can lead to non-compliance and FTC enforcement exposure.
Operators with actual knowledge of collecting children's data
Even operators whose services are not directed to children can be covered where they have actual knowledge that they are collecting personal information from children under 13. This trigger is easy to overlook, so general-audience services should understand how the actual-knowledge standard may bring them within scope.
Privacy and compliance teams
Data protection officers, privacy counsel, and compliance leads need to determine COPPA applicability and coordinate the operator obligations set out in the COPPA Rule and FTC guidance. They should treat COPPA as jurisdiction-specific to the U.S. and focused on children under 13, and not assume it satisfies children's privacy obligations under other frameworks.
Parents and guardians
COPPA is designed to give parents control over what personal information covered websites and online services can collect from their children under 13. It positions parents as a key decision-maker in the collection of their children's data, within the U.S. context the law governs.

Inside COPPA

Scope and Covered Operators
COPPA is a U.S. federal law that applies to operators of websites and online services directed to children under 13, and to operators with actual knowledge that they are collecting personal information from children under 13. It is enforced by the Federal Trade Commission. Its scope is specific to this age threshold and U.S. context, and it does not govern general adult data protection the way broad regimes such as the EU or UK GDPR do.
Verifiable Parental Consent
COPPA generally requires operators to obtain verifiable parental consent before collecting, using, or disclosing personal information from a child under 13, subject to limited exceptions. The verification standard is intended to provide reasonable assurance that the person consenting is the parent, though the specific acceptable methods depend on FTC guidance and implementation context. Consent under COPPA should not be conflated with lawful-basis consent concepts under other regimes such as the GDPR.
Notice and Privacy Policy Requirements
COPPA generally obligates covered operators to provide clear notice of their information practices, including what personal information is collected from children, how it is used, and whether it is disclosed to third parties. These notice obligations are distinct from, and should not be assumed identical to, transparency requirements found in other privacy laws.
Parental Rights
COPPA typically grants parents the ability to review the personal information collected from their child, to refuse further collection or use, and to request deletion. These rights are held by the parent or guardian on behalf of the child within the U.S. COPPA framework and differ from data subject rights defined under other regimes.
Data Security and Retention Expectations
COPPA generally expects operators to establish and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children, and to retain such information only as long as reasonably necessary. This intersects with information security controls but does not by itself specify a complete security control framework; the governance obligation to demonstrate reasonable measures is distinct from the security controls themselves.

Common questions

Answers to the questions practitioners most commonly ask about COPPA.

Does COPPA apply to all users who are minors under 18?
No. COPPA specifically addresses the online collection of personal information from children under 13, not all minors. Teens aged 13 through 17 are outside COPPA's core scope, though other frameworks may address them differently. Do not conflate COPPA's under-13 threshold with the broader definitions of a child or minor used in other regimes; for example, some provisions under the CCPA and CPRA in California, and the concept of a child's consent age under the EU GDPR, apply to different age brackets and operate under separate legal instruments. COPPA is a U.S. federal statute enforced primarily by the Federal Trade Commission, and its treatment does not automatically carry over to other jurisdictions.
Is obtaining a child's own consent sufficient to satisfy COPPA?
Generally no. COPPA is built around verifiable parental consent rather than the child's own consent, which distinguishes it from consent models where the data subject acts on their own behalf. The operator typically bears the obligation to obtain and document verifiable consent from a parent or guardian before collecting, using, or disclosing personal information from a child under 13, subject to certain limited exceptions recognized under the statute. Do not treat consent here as interchangeable with lawful bases or consent mechanisms used under other regimes such as the EU GDPR; the underlying instruments, actors, and requirements differ. This answer does not detail the specific permitted verification methods, which depend on context and current FTC guidance.
How do we determine whether COPPA applies to our service?
Applicability generally turns on whether an online service is directed to children under 13, or whether an operator has actual knowledge that it is collecting personal information from children under 13. Assessing whether a service is directed to children typically involves reviewing factors such as subject matter, visual and audio content, and intended audience. Because the analysis is fact-specific, operators should document their reasoning as evidence of their determination rather than relying on stated intent alone. This entry does not cover the full set of factors used to evaluate whether a service is child-directed, and that assessment should be made with reference to current FTC guidance and, where appropriate, legal counsel.
What documentation should an operator maintain to demonstrate COPPA accountability?
Accountability under governance and compliance frameworks generally requires demonstrable evidence rather than a stated commitment. For COPPA, operators typically maintain records supporting their applicability determination, their notice practices, their method and records of verifiable parental consent, and their data handling and retention decisions. Governance activities such as documenting who owns the relevant data, how it is cataloged, and how policies are enforced complement, but are distinct from, the security controls protecting that data. This entry does not prescribe a specific document set or retention period, both of which depend on the operator's practices and applicable guidance.
Where do COPPA obligations intersect with information security controls?
COPPA generally addresses both governance-oriented obligations, such as notice, consent, and limits on collection and disclosure, and expectations that operators maintain reasonable security to protect information collected from children. The two areas overlap but are not the same: governance covers ownership, policy, and data handling decisions, while information security covers confidentiality, integrity, and availability controls. Applying encryption, tokenization, or similar measures can support a security posture but does not by itself remove information from COPPA's scope or render it non-personal. This entry does not specify particular technical safeguards, which depend on context and implementation.
How should COPPA obligations be allocated when a service uses third-party providers?
Roles and accountability should be defined clearly where multiple parties handle a child's personal information. The operator generally retains primary responsibility for compliance, including for the practices of parties that collect information on its behalf, and this should be reflected in contractual arrangements and oversight. Documenting how information flows between parties, and who is responsible for each obligation, supports demonstrable accountability. This entry does not address how COPPA's role allocation maps onto controller and processor concepts under other regimes such as the EU GDPR, which are governed by separate instruments and defined differently.

Common misconceptions

COPPA is a general children's privacy law that applies wherever children use online services.
COPPA is a U.S. federal law focused on operators directed to, or with actual knowledge of collecting from, children under 13. Other jurisdictions address children's data differently, and this entry does not cover those non-U.S. regimes or cross-border transfer mechanics.
Any form of parental agreement satisfies COPPA's consent requirement.
COPPA generally requires verifiable parental consent, meaning the method must provide reasonable assurance that the consenting person is the parent. A simple checkbox or unverified assertion typically does not meet that standard, and acceptable methods depend on FTC guidance. COPPA consent should also not be equated with lawful-basis consent under regimes such as the GDPR.
Obtaining consent once means COPPA obligations are fully satisfied.
Consent is one component. Operators generally also carry ongoing obligations around notice, parental review and deletion rights, reasonable security, and limited retention. Demonstrable evidence of these practices, not merely stated intent, supports accountability; a single consent event does not guarantee overall compliance, which depends on context and implementation.

Best practices

Determine early whether your service is directed to children under 13 or whether you have actual knowledge of collecting their personal information, and document that determination, since scope drives whether COPPA obligations apply at all.
Implement a verifiable parental consent process appropriate to the sensitivity of collection, and retain evidence of how and when consent was obtained rather than relying on unverified assertions.
Publish clear notice of your information practices for children, describing what is collected, how it is used, and whether it is disclosed, and keep that notice aligned with actual processing.
Establish operational workflows enabling parents to review collected information, refuse further collection, and request deletion, and record how these requests are handled.
Apply reasonable security measures and limited retention to children's personal information, and treat these as distinct from your general governance obligations while noting where they overlap.
Maintain demonstrable documentation of your COPPA-related practices to support accountability, and consult U.S. legal counsel and current FTC guidance for jurisdiction-specific requirements, as this entry does not cover enforcement penalties, retention specifics, or non-U.S. treatment.