COPPA

COPPA: When a Service Is Child-Directed and What Follows

Key Takeaways

  • COPPA applies to operators of child-directed services and to any operator with actual knowledge it collects personal information from a child under 13
  • Persistent identifiers used for behavioral advertising are personal information under the Rule
  • Verifiable parental consent must be obtained before collection, through a method reasonably calculated to ensure the person consenting is the parent
  • The child-directed analysis is multi-factor, and audience composition evidence can move a general-audience service into scope
  • State age-appropriate design and teen privacy laws now impose obligations above the COPPA floor

What COPPA Covers

The Children's Online Privacy Protection Act and the FTC's implementing Rule at 16 CFR Part 312 apply to an operator of a website or online service in two situations: where the service is directed to children under 13, and where the operator has actual knowledge that it is collecting personal information from a child under 13.

Online service is read broadly. It covers mobile applications that connect to the internet, internet-enabled gaming platforms, connected toys and other internet-of-things devices, voice-over-internet services, and plug-ins and advertising networks that collect information through a child-directed service. A third party integrated into a child-directed property can be an operator in its own right where it collects personal information there.

The statute reaches operators of foreign services where the service is directed to children in the United States or where personal information is knowingly collected from them.

The Child-Directed Test

Whether a service is directed to children is not decided by the operator's stated intent or by a terms-of-service age restriction. The Rule sets a multi-factor test considering the totality of circumstances.

  • Subject matter of the service
  • Visual content
  • Use of animated characters or child-oriented activities and incentives
  • Music or other audio content
  • Age of models
  • Presence of child celebrities or celebrities who appeal to children
  • Language or other characteristics of the service
  • Whether advertising appearing on the service is directed to children
  • Competent and reliable empirical evidence about audience composition, and evidence about the intended audience

A service may be directed to children even where children are not its only or primary audience. The Rule provides a distinct path for services directed to children that do not target children as their primary audience: such an operator may age-screen users and apply COPPA protections only to those who identify as under 13, rather than treating all users as children.

Age screening carries its own constraints. A screen must be neutral, meaning it cannot encourage users to falsify their age, and an operator cannot use a screening result it has reason to believe is inaccurate. An operator that collects age and then ignores an under-13 answer acquires actual knowledge rather than avoiding it.

What Counts as Personal Information

The Rule's definition is broader than a name and email address, and the additions are what bring advertising technology into scope.

CategoryNotes
First and last name
Home or physical address including street name and city or town
Online contact informationEmail address or other identifier permitting direct contact
Screen or user nameWhere it functions as online contact information
Telephone number
Social Security number
Persistent identifierCookie, IP address, device serial, unique device identifier, where used to recognize a user over time and across services
Photograph, video or audio fileWhere it contains a child's image or voice
Geolocation informationSufficient to identify street name and city or town
Information concerning the child or parentsWhere the operator collects it and combines it with any of the above

The persistent identifier entry carries most of the practical weight. Collecting a cookie or device identifier from a child-directed service for behavioral advertising is collection of personal information requiring consent. The Rule provides a support for internal operations exception permitting collection of a persistent identifier without consent where it is used solely for enumerated purposes, including maintaining or analyzing functioning of the service, performing network communications, authenticating users, maintaining user preferences, serving contextual advertising, frequency capping, protecting security or integrity, and legal compliance. Behavioral advertising falls outside that list.

Verifiable Parental Consent

An operator must provide direct notice to the parent and obtain verifiable parental consent before collecting, using or disclosing personal information from a child. The Rule requires a method reasonably calculated, in light of available technology, to ensure that the person providing consent is the child's parent.

Approved methods include providing a consent form to be signed and returned; requiring a credit card, debit card or other online payment system that provides notification of each discrete transaction; connecting to trained personnel via toll-free telephone number or video conference; verifying a government-issued identification against a database, with prompt deletion after verification; knowledge-based authentication; and facial recognition matched against a verified photo identification. Operators may seek FTC approval of new methods through a formal process.

A narrower mechanism, commonly called email plus, is available where the operator collects personal information only for internal use and does not disclose it. It involves consent by return email coupled with an additional confirming step. It is unavailable where information is disclosed to third parties.

Limited exceptions permit collection without prior consent: obtaining a parent's online contact information to provide notice and seek consent; responding once to a specific request from a child; responding more than once where the operator uses the information only for that purpose and notifies the parent; protecting the safety of a child participant; and specified legal or security purposes.

In the school context, the FTC has recognized that a school may provide consent for the collection of personal information from students where the data is used solely for an educational purpose and for no commercial purpose. That position does not displace obligations under FERPA or state student-privacy statutes.

Notice Requirements

Two notices are required and they are distinct. An online privacy policy must be posted with a clear and prominent link on the home page and at each point where personal information is collected, describing the operators collecting information, the types collected, how it is used, disclosure practices, and parental rights.

A direct notice to the parent must be given before collection, stating that the operator has collected the parent's online contact information to obtain consent, what information has been or will be collected, how it will be used and disclosed, how consent can be given, and that consent can be revoked with resulting deletion.

Retention, Deletion and Security

An operator may retain personal information collected from a child only as long as reasonably necessary to fulfill the purpose for which it was collected, and must delete it using reasonable measures to protect against unauthorized access or use during disposal. Indefinite retention of children's data is not compatible with the Rule.

Operators must establish and maintain reasonable procedures to protect the confidentiality, security and integrity of personal information collected from children, and must take reasonable steps to release information only to service providers and third parties capable of maintaining its confidentiality and security.

Parents hold rights to review the personal information collected from their child, to refuse further collection or use, and to direct deletion. An operator may terminate a service where the information at issue is necessary to participation.

Before granting a parent access to a child's information, an operator must take reasonable steps to confirm the requester is the parent, taking into account available technology. That verification obligation exists because the access right itself creates a route to a child's data, and the Rule treats a wrongly granted request as a harm rather than a formality. An operator that cannot verify a requester is not permitted to disclose the information as a matter of customer service.

Third Parties on Child-Directed Services

The Rule reaches beyond the operator of the property itself. An advertising network, analytics provider, plug-in or software development kit that collects personal information through a child-directed service is an operator with respect to that collection, and carries obligations in its own right.

Liability is allocated by knowledge. A third party is liable where it has actual knowledge that it is collecting personal information directly from users of a child-directed service. The Rule contemplates that a child-directed publisher will notify the integrated third parties of the nature of its audience, and a third party that receives such notice cannot rely on ignorance.

The operator of the child-directed property is separately responsible for the collection that occurs on it, including collection by integrated third parties. That structure means an application that embeds a general-purpose advertising SDK without configuring it for a child audience has a compliance problem regardless of whether the SDK vendor also does.

Two operational consequences follow. First, the mixed-audience path that permits age screening does not extend automatically to third-party code, which continues to run unless the operator gates it. Second, the support-for-internal-operations exception is assessed against how the identifier is actually used downstream, not against how it is labelled at collection.

Recurring Enforcement Themes

The Commission's children's privacy matters have clustered around a recognisable set of facts rather than spreading evenly across the Rule's provisions.

  • Persistent identifiers for advertising. Collection of device identifiers or cookies on child-directed properties for behavioural advertising, without consent and outside the internal-operations exception
  • Actual knowledge disregarded. Services that received age information, or direct notice from a publisher about audience composition, and continued collecting
  • Indefinite retention. Children's data kept long after the purpose for collection was exhausted, contrary to the retention limitation
  • Inadequate consent mechanisms. Methods not reasonably calculated to ensure the person consenting is a parent, including reliance on an unverified checkbox
  • Deficient notice. Direct notice omitting required elements, or a privacy policy that does not identify all operators collecting through the service

Remedies in these matters have extended past civil penalties to include deletion of the data collected in violation, and in some orders deletion of models or algorithms derived from that data. That remedy is significant because it reaches assets built on the information rather than only the information itself.

Safe Harbor Programs

The statute allows industry groups to seek FTC approval of self-regulatory guidelines. An operator that fully complies with an approved program's guidelines is subject to the review and disciplinary procedures of that program in lieu of formal FTC enforcement, which is the principal incentive for participation. Approved programs are required to conduct annual reviews of member compliance and report to the Commission. Safe harbor participation does not immunize an operator that fails to comply with the program's guidelines.

Enforcement and the State Overlay

Violation of the Rule is treated as an unfair or deceptive act or practice under the FTC Act, and civil penalties are available on a per-violation basis, adjusted for inflation. State attorneys general also hold authority to bring actions on behalf of state residents. Remedies in Commission orders have extended beyond penalties to include deletion of data collected in violation and, in some matters, of models or algorithms derived from it.

COPPA now functions as a floor rather than the whole framework. States have enacted age-appropriate design codes imposing duties on services likely to be accessed by minors, and comprehensive state privacy statutes commonly treat data of known minors as sensitive and require opt-in consent for targeted advertising to teenagers above the COPPA age cutoff. Those regimes reach a population COPPA does not, and their obligations are not satisfied by COPPA compliance alone.

The state statutes also differ from COPPA in structure, not only in age range. Age-appropriate design codes tend to impose affirmative design duties, such as defaulting minors to the most protective privacy settings, avoiding profiling by default, and assessing the risks a service poses to young users, rather than conditioning collection on parental consent. A service can satisfy COPPA's consent mechanics and still fall short of a design code that asks a different question about how the product is built.

Preemption operates in one direction only. COPPA expressly preempts inconsistent state law regarding the collection of personal information from children in connection with online activities, but states have legislated in the space above the age cutoff and in the area of design duties, where the preemption argument is weaker. Several of these statutes have faced First Amendment challenges, and their status has varied between jurisdictions, so the applicable obligations in a given state are not stable enough to be assumed from a summary.

Whether a particular service falls within COPPA, a state design code, both or neither turns on the audience, the data collected and the design of the product, and those determinations are fact-specific.

Background

For the underlying law rather than this development: Technology & SaaS privacy law, Education privacy law.

Frequently Asked Questions

Does a terms-of-service age restriction keep a service outside COPPA?
No. Whether a service is directed to children is decided by a multi-factor test looking at subject matter, visual content, characters, music, models, celebrities, language, advertising and empirical evidence about audience composition. A contractual age limit is not among the factors and does not resolve the question.
Is an IP address personal information under COPPA?
A persistent identifier such as an IP address, cookie or device identifier is personal information where it is used to recognize a user over time and across services. Collection without consent is permitted only where the identifier is used solely for support for internal operations, a defined list that excludes behavioral advertising.
What is the email plus method and when is it available?
It is consent obtained by return email coupled with an additional confirming step. It is available only where the operator collects personal information solely for internal use and does not disclose it to third parties. Any disclosure requires one of the more robust verification methods.
Can a school consent on behalf of parents?
The FTC has recognized that a school may provide consent where the personal information is used solely for an educational purpose and no commercial purpose. That position does not displace obligations under FERPA or state student privacy statutes, which apply independently.
Does COPPA cover teenagers?
No. COPPA's protections apply to children under 13. Obligations toward older minors come from state law, including age-appropriate design codes and comprehensive privacy statutes that treat known minors' data as sensitive or require opt-in consent for targeted advertising.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.