The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound
Key Takeaways
- The amended Rule was effective June 23, 2025; the compliance date was April 22, 2026, except for 16 CFR 312.11(d)(1), (d)(4) and (g), which fell due earlier
- Section 312.5(a)(2) requires a separate verifiable parental consent for disclosure to third parties, unless that disclosure is integral to the service
- Section 312.10 bars indefinite retention of children's personal information and requires a written data retention policy published in the online notice
- The definition of personal information now names biometric identifiers and government-issued identifiers as distinct categories
- The Commission did not finalize the proposed ed tech and school authorization amendments, citing possible conflict with anticipated FERPA rulemaking
What the FTC Changed
The Commission published final amendments to the Children's Online Privacy Protection Rule, 16 CFR Part 312, at 90 FR 16918 on April 22, 2025 (RIN 3084-AB20). The action followed a January 2024 notice of proposed rulemaking and, the notice states, nearly 300 comments. The Commission's own characterization of the package is modest in form and specific in substance: "one new definition and modifications to several others, as well as updates to key provisions to respond to changes in technology and online practices." The vote to publish was 5-0, with separate concurring statements from Chair Khan, Commissioner Ferguson, and Commissioners Bedoya and Slaughter jointly.
The amendments left the architecture of the Rule alone. An operator of a website or online service directed to children, or with actual knowledge that it collects personal information from a child under 13, still needs verifiable parental consent before collection, use or disclosure. What changed is the granularity of that consent, what happens to the data afterward, and what counts as personal information in the first place.
Separate Consent for Third-Party Disclosure
The most consequential addition sits at 16 CFR 312.5(a)(2). An operator "must give the parent the option to consent to the collection and use of the child's personal information without consenting to disclosure of his or her personal information to third parties, unless such disclosure is integral to the website or online service." Where that option is required, the operator "must obtain separate verifiable parental consent to such disclosure."
Two features of that text carry weight. The exception turns on whether the disclosure is integral to the service, not on whether it is convenient or commercially useful. And the requirement is for a second consent event, not a second checkbox inside the first — the rule says separate verifiable parental consent, which routes back through the methods enumerated at 312.5(b)(2). The Commission's announcement framed the same provision in plainer terms, describing the Rule as requiring "parents to opt in to third-party advertising."
The Retention Limit and Written Policy
Section 312.10 was rewritten. Personal information collected online from a child may be retained "for only as long as is reasonably necessary to fulfill the specific purpose(s) for which the information was collected," and when it is no longer reasonably necessary the operator must delete it using reasonable measures to protect against unauthorized access or use during deletion. The provision then states flatly that such information "may not be retained indefinitely."
It also creates a documentation obligation. At a minimum the operator must establish, implement and maintain a written data retention policy setting out three things:
- The purposes for which children's personal information is collected
- The business need for retaining it
- A timeframe for deletion
That policy is not an internal artifact. Section 312.10 requires the operator to provide it in the online notice under 312.4(d), and the amended 312.4(d)(2) correspondingly requires the online notice to state the operator's data retention policy along with the identities and specific categories of third parties to which personal information is disclosed and the purposes of those disclosures.
The Expanded Personal Information Definition
The definition at 312.2 gained two enumerated categories. Paragraph (6) now covers "[a] government-issued identifier, such as a Social Security, State identification card, birth certificate, or passport number." Paragraph (10) covers "[a] biometric identifier that can be used for the automated or semi-automated recognition of an individual," and gives a list: fingerprints, handprints, retina patterns, iris patterns, genetic data including a DNA sequence, voiceprints, gait patterns, facial templates and faceprints.
The same section added a standalone definition of a mixed audience website or online service: one directed to children under the general criteria, but that does not target children as its primary audience and does not collect personal information from any visitor, beyond the limited purposes at 312.5(c), before collecting age information or otherwise determining whether the visitor is a child. The definition adds a condition on how that determination is made — it "must be done in a neutral manner that does not default to a set age or encourage visitors to falsify age information."
Security Program Requirements
Section 312.8 previously required reasonable procedures to protect confidentiality, security and integrity. It now requires, at a minimum, a written information security program with safeguards appropriate to the sensitivity of the information and the operator's size, complexity, and nature and scope of activities. The rule enumerates what satisfying that requires: designating one or more employees to coordinate the program; identifying internal and external risks and performing additional assessments at least annually; designing and maintaining safeguards calibrated to the volume and sensitivity of the data at risk and the likelihood of compromise; regularly testing and monitoring those safeguards; and at least annually evaluating and modifying the program. Section 312.8(c) adds a diligence step before third parties are allowed to collect or maintain children's personal information on the operator's behalf.
Safe Harbor Program Transparency
The Commission-approved safe harbor programs took on reporting duties with their own dates, which is why the compliance date at 90 FR 16918 is expressed as an exception. Under 312.11(d)(1), approved programs were required to submit an annual report to the Commission by October 22, 2025 identifying each subject operator and approved service, and containing a narrative description of the program's business model, copies of consumer complaints related to member violations, an aggregated summary of independent assessment results, a description of disciplinary actions and the process for determining them, and a description of any approvals of member consent mechanisms.
Section 312.11(d)(4) required each approved program to publicly post, no later than July 21, 2025, a list of all current subject operators with each certified website or online service, updated every six months. Section 312.11(g) required programs to submit proposed modifications to their guidelines by October 22, 2025. A separate provision, 312.11(f), sets the next technological-capability report for no later than April 22, 2028 and every three years thereafter.
Compliance Dates
The Federal Register notice states the dates in two lines: "Effective date: The amended Rule is effective June 23, 2025. Compliance date: Except with respect to Sec. 312.11(d)(1), (d)(4), and (g), regulated entities have until April 22, 2026 to comply." Both dates have passed. No extension of the April 22, 2026 compliance date appears in the Federal Register.
One proposed piece did not survive to a compliance date at all. The 2024 notice had proposed definitions of School and School-authorized education purpose, provisions on collection in schools, and a codified school authorization exception to verifiable parental consent. The Commission dropped them, explaining that the Department of Education had affirmed an intention to propose amendments to the FERPA regulations at 34 CFR Part 99, that those changes "may be relevant" to the proposed ed tech provisions, and that "[t]o avoid making amendments to the COPPA Rule that may conflict with potential amendments to DOE's FERPA regulations, the Commission is not finalizing the proposed amendments to the Rule related to ed tech and the role of schools at this time." It added that it "will continue to enforce COPPA in the ed tech context consistent with its existing guidance."
Background
For the underlying law rather than this development: Technology & SaaS privacy law.
Frequently Asked Questions
When did the amended COPPA Rule become binding?
What does separate consent for third-party disclosure actually require?
Are biometric identifiers personal information under COPPA?
What is a mixed audience service under the amended Rule?
Did the FTC adopt the proposed rules for ed tech and schools?
Does the Rule set a fixed retention period for children's data?
Sources
Everything above is reported from these documents. Follow them to verify.
- Children's Online Privacy Protection Rule, Final Rule Amendments, 90 FR 16918 (April 22, 2025) regulation
- 16 CFR Part 312, Children's Online Privacy Protection Rule (current text) regulation
- FTC Finalizes Changes to Children's Privacy Rule Limiting Companies' Ability to Monetize Kids' Data (January 17, 2025) agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.