COPPA

The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound

Compliance date April 22, 2026 Compliance date for the amended COPPA Rule, except 16 CFR 312.11(d)(1), (d)(4) and (g), which carried earlier dates Applies to: Operators covered by 16 CFR Part 312

Key Takeaways

  • The amended Rule was effective June 23, 2025; the compliance date was April 22, 2026, except for 16 CFR 312.11(d)(1), (d)(4) and (g), which fell due earlier
  • Section 312.5(a)(2) requires a separate verifiable parental consent for disclosure to third parties, unless that disclosure is integral to the service
  • Section 312.10 bars indefinite retention of children's personal information and requires a written data retention policy published in the online notice
  • The definition of personal information now names biometric identifiers and government-issued identifiers as distinct categories
  • The Commission did not finalize the proposed ed tech and school authorization amendments, citing possible conflict with anticipated FERPA rulemaking

What the FTC Changed

The Commission published final amendments to the Children's Online Privacy Protection Rule, 16 CFR Part 312, at 90 FR 16918 on April 22, 2025 (RIN 3084-AB20). The action followed a January 2024 notice of proposed rulemaking and, the notice states, nearly 300 comments. The Commission's own characterization of the package is modest in form and specific in substance: "one new definition and modifications to several others, as well as updates to key provisions to respond to changes in technology and online practices." The vote to publish was 5-0, with separate concurring statements from Chair Khan, Commissioner Ferguson, and Commissioners Bedoya and Slaughter jointly.

The amendments left the architecture of the Rule alone. An operator of a website or online service directed to children, or with actual knowledge that it collects personal information from a child under 13, still needs verifiable parental consent before collection, use or disclosure. What changed is the granularity of that consent, what happens to the data afterward, and what counts as personal information in the first place.

Separate Consent for Third-Party Disclosure

The most consequential addition sits at 16 CFR 312.5(a)(2). An operator "must give the parent the option to consent to the collection and use of the child's personal information without consenting to disclosure of his or her personal information to third parties, unless such disclosure is integral to the website or online service." Where that option is required, the operator "must obtain separate verifiable parental consent to such disclosure."

Two features of that text carry weight. The exception turns on whether the disclosure is integral to the service, not on whether it is convenient or commercially useful. And the requirement is for a second consent event, not a second checkbox inside the first — the rule says separate verifiable parental consent, which routes back through the methods enumerated at 312.5(b)(2). The Commission's announcement framed the same provision in plainer terms, describing the Rule as requiring "parents to opt in to third-party advertising."

The Retention Limit and Written Policy

Section 312.10 was rewritten. Personal information collected online from a child may be retained "for only as long as is reasonably necessary to fulfill the specific purpose(s) for which the information was collected," and when it is no longer reasonably necessary the operator must delete it using reasonable measures to protect against unauthorized access or use during deletion. The provision then states flatly that such information "may not be retained indefinitely."

It also creates a documentation obligation. At a minimum the operator must establish, implement and maintain a written data retention policy setting out three things:

  • The purposes for which children's personal information is collected
  • The business need for retaining it
  • A timeframe for deletion

That policy is not an internal artifact. Section 312.10 requires the operator to provide it in the online notice under 312.4(d), and the amended 312.4(d)(2) correspondingly requires the online notice to state the operator's data retention policy along with the identities and specific categories of third parties to which personal information is disclosed and the purposes of those disclosures.

The Expanded Personal Information Definition

The definition at 312.2 gained two enumerated categories. Paragraph (6) now covers "[a] government-issued identifier, such as a Social Security, State identification card, birth certificate, or passport number." Paragraph (10) covers "[a] biometric identifier that can be used for the automated or semi-automated recognition of an individual," and gives a list: fingerprints, handprints, retina patterns, iris patterns, genetic data including a DNA sequence, voiceprints, gait patterns, facial templates and faceprints.

The same section added a standalone definition of a mixed audience website or online service: one directed to children under the general criteria, but that does not target children as its primary audience and does not collect personal information from any visitor, beyond the limited purposes at 312.5(c), before collecting age information or otherwise determining whether the visitor is a child. The definition adds a condition on how that determination is made — it "must be done in a neutral manner that does not default to a set age or encourage visitors to falsify age information."

Security Program Requirements

Section 312.8 previously required reasonable procedures to protect confidentiality, security and integrity. It now requires, at a minimum, a written information security program with safeguards appropriate to the sensitivity of the information and the operator's size, complexity, and nature and scope of activities. The rule enumerates what satisfying that requires: designating one or more employees to coordinate the program; identifying internal and external risks and performing additional assessments at least annually; designing and maintaining safeguards calibrated to the volume and sensitivity of the data at risk and the likelihood of compromise; regularly testing and monitoring those safeguards; and at least annually evaluating and modifying the program. Section 312.8(c) adds a diligence step before third parties are allowed to collect or maintain children's personal information on the operator's behalf.

Safe Harbor Program Transparency

The Commission-approved safe harbor programs took on reporting duties with their own dates, which is why the compliance date at 90 FR 16918 is expressed as an exception. Under 312.11(d)(1), approved programs were required to submit an annual report to the Commission by October 22, 2025 identifying each subject operator and approved service, and containing a narrative description of the program's business model, copies of consumer complaints related to member violations, an aggregated summary of independent assessment results, a description of disciplinary actions and the process for determining them, and a description of any approvals of member consent mechanisms.

Section 312.11(d)(4) required each approved program to publicly post, no later than July 21, 2025, a list of all current subject operators with each certified website or online service, updated every six months. Section 312.11(g) required programs to submit proposed modifications to their guidelines by October 22, 2025. A separate provision, 312.11(f), sets the next technological-capability report for no later than April 22, 2028 and every three years thereafter.

Compliance Dates

The Federal Register notice states the dates in two lines: "Effective date: The amended Rule is effective June 23, 2025. Compliance date: Except with respect to Sec. 312.11(d)(1), (d)(4), and (g), regulated entities have until April 22, 2026 to comply." Both dates have passed. No extension of the April 22, 2026 compliance date appears in the Federal Register.

One proposed piece did not survive to a compliance date at all. The 2024 notice had proposed definitions of School and School-authorized education purpose, provisions on collection in schools, and a codified school authorization exception to verifiable parental consent. The Commission dropped them, explaining that the Department of Education had affirmed an intention to propose amendments to the FERPA regulations at 34 CFR Part 99, that those changes "may be relevant" to the proposed ed tech provisions, and that "[t]o avoid making amendments to the COPPA Rule that may conflict with potential amendments to DOE's FERPA regulations, the Commission is not finalizing the proposed amendments to the Rule related to ed tech and the role of schools at this time." It added that it "will continue to enforce COPPA in the ed tech context consistent with its existing guidance."

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

When did the amended COPPA Rule become binding?
The amendments were effective June 23, 2025, sixty days after publication. The general compliance date was April 22, 2026. Three safe harbor provisions — 16 CFR 312.11(d)(1), (d)(4) and (g) — carried their own earlier dates of October 22, 2025, July 21, 2025 and October 22, 2025 respectively.
What does separate consent for third-party disclosure actually require?
Under 16 CFR 312.5(a)(2), an operator must offer the parent the option to consent to collection and use without consenting to third-party disclosure, unless that disclosure is integral to the service, and must obtain a separate verifiable parental consent for the disclosure where the option is required.
Are biometric identifiers personal information under COPPA?
Yes, as of the 2025 amendments. Paragraph (10) of the definition at 16 CFR 312.2 covers a biometric identifier usable for automated or semi-automated recognition of an individual, listing fingerprints, handprints, retina and iris patterns, genetic data including DNA sequences, voiceprints, gait patterns, facial templates and faceprints.
What is a mixed audience service under the amended Rule?
A service directed to children under the general criteria that does not target children as its primary audience and does not collect personal information from any visitor, beyond the limited 312.5(c) purposes, before collecting age information or otherwise determining whether the visitor is a child. That age determination must be neutral, must not default to a set age, and must not encourage visitors to falsify their age.
Did the FTC adopt the proposed rules for ed tech and schools?
No. The Commission declined to finalize the proposed School and School-authorized education purpose definitions and the school authorization exception, citing the Department of Education's stated intention to propose FERPA rule amendments and the risk of conflicting requirements. It said it would keep enforcing COPPA in that sector under its existing guidance.
Does the Rule set a fixed retention period for children's data?
No. Section 312.10 ties retention to the specific purpose of collection and requires deletion when the information is no longer reasonably necessary for that purpose. It prohibits indefinite retention and requires a written retention policy that states the purposes, the business need and a deletion timeframe, published in the online notice.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.