COPPA governs online collection of data from children under 13, and it has become one of the FTC's most active enforcement tools against platforms and games. This hub covers those actions alongside the newer wave of state teen-privacy and age-appropriate design laws.

COPPA

The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound

September 1, 2026

The FTC published amendments to the Children's Online Privacy Protection Rule on April 22, 2025. They added a separate-consent requirement for third-party disclosure, a written retention policy and a prohibition on indefinite retention, two new categories of personal information, a written security program, and staggered obligations for safe harbor programs.

Read more →
FERPA

How an EdTech Vendor Becomes a School Official Under FERPA

September 1, 2026

FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.

Read more →
COPPA

COPPA: When a Service Is Child-Directed and What Follows

August 12, 2026

COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.

Read more →

Related pages