Children’s Online Privacy Protection Act (COPPA)
The Children’s Online Privacy Protection Act (COPPA) is the U.S. federal law governing the collection of personal information from children under 13 online. It requires operators of covered services to obtain verifiable parental consent before collecting that information, and it is enforced by the Federal Trade Commission through the COPPA Rule. Amendments published in 2025 took full effect in April 2026 and materially expanded what counts as personal information.
| Enacted | 1998; effective April 2000 |
| Statute | 15 U.S.C. §§ 6501–6506 |
| Implementing rule | The COPPA Rule, 16 CFR Part 312 |
| Enforced by | The Federal Trade Commission, and state attorneys general |
| Age threshold | Under 13 |
| Who is covered | Operators of online services directed to children under 13, and operators with actual knowledge they collect personal information from children under 13 |
| Core requirement | Verifiable parental consent before collection, use or disclosure |
| 2025 amendments | Published 22 April 2025, effective 23 June 2025, full compliance required from 22 April 2026 |
How it works
COPPA turns on two triggers. A service is covered if it is directed to children under 13 — assessed on subject matter, visual content, language, advertising, and similar factors — or if the operator has actual knowledge that it is collecting personal information from a child under 13. The second trigger catches general-audience services the moment a user identifies as under 13, which is why age screening and COPPA obligations are entangled in practice.
Where COPPA applies, the operator must post a clear privacy notice, provide direct notice to parents, and obtain verifiable parental consent before collecting personal information. Parents must be able to review what has been collected and require its deletion, and the operator must not condition a child’s participation in an activity on collecting more information than is reasonably necessary.
The FTC has approved several methods of obtaining verifiable parental consent, and the list is deliberately graduated by risk. A signed consent form returned by mail, fax or scan. A payment card transaction that provides notification of each transaction. A call to a toll-free number staffed by trained personnel, or a video conference with them. Checking a government-issued identification against a database, provided the identification is promptly deleted afterwards. Knowledge-based authentication. And matching a photograph of the parent against the photograph on a government-issued identity document.
What the 2025 amendments changed
The amended Rule is now in full force, and three changes matter most:
| Change | Effect |
|---|---|
| Biometric identifiers are personal information | Fingerprints, voiceprints, iris and retina patterns, facial templates, gait patterns and genetic data now fall squarely within the definition |
| Separate consent for third-party disclosure | Disclosure for purposes not integral to the service — targeted advertising in particular — requires its own verifiable parental consent, not a bundled one |
| Written security and retention programs | Operators must maintain a written information security program and a written data retention policy, and may not keep children’s data indefinitely |
The biometric change is the one with the sharpest operational edge. A facial template derived from a child’s image is now unambiguously personal information under COPPA. Any service performing face-based age estimation or face matching on users who may be under 13 has to reason about that carefully, and the fact that a template is generated in order to protect a child does not remove it from the definition.
Why COPPA matters for identity verification
COPPA creates a genuine circularity, and naming it plainly is more useful than working around it. To know whether COPPA applies to a user, an operator needs to know the user’s age. Determining age reliably means collecting information about a person who may be a child — which is the activity COPPA governs. Age assurance is therefore both a compliance control and a compliance exposure.
The resolution is proportionality and data minimization. A check that establishes only whether someone is above a threshold, without retaining the underlying evidence, sits very differently from one that stores an identity document. The FTC’s own approved consent methods point this way: verifying a parent’s identification is permitted precisely on the condition that it is deleted promptly once verification is complete.
This is the same design problem that age verification faces across every regulated category, and COPPA is the sharpest version of it because the subject is a child. For services that must both establish age and hold as little as possible, age verification built on identity document verification can confirm a threshold and a parental relationship without accumulating a store of children’s identity data.
What COPPA can’t do
It does not cover teenagers. The threshold is 13. Users aged 13 to 17 fall outside COPPA entirely, and are addressed by state laws and other frameworks rather than by this one.
It is not a general children’s online safety law. COPPA governs the collection of personal information. Content, contact risk and design harms are outside its scope.
It does not apply outside the United States. Services with international users face the UK Age Appropriate Design Code, the GDPR’s own consent age — which varies by member state — and a growing set of national rules that do not align with COPPA.
It does not tell you how to determine age. The Rule specifies consent methods, not age assurance methods, and the gap between the two is where most implementation difficulty lives.
Frequently asked questions
What age does COPPA cover?
Children under 13. Users aged 13 and above are outside COPPA’s scope, which is why the law is often described as covering children rather than minors generally. Other frameworks address teenagers.
What counts as verifiable parental consent?
The FTC has approved several methods, including a signed consent form returned by mail, fax or scan; a payment card transaction providing notification; a call to trained personnel on a toll-free number; a video conference with trained personnel; checking a government-issued identification against a database and promptly deleting it; knowledge-based authentication; and matching a photograph of the parent to the photograph on a government-issued identity document.
Did the 2025 COPPA amendments change what counts as personal information?
Yes. The amended Rule expressly includes biometric identifiers — fingerprints, voiceprints, iris and retina patterns, facial templates, gait patterns and genetic data. It also requires separate parental consent for disclosures not integral to the service, and mandates written security and data retention programs. Full compliance has been required since 22 April 2026.
Does COPPA apply to a general-audience site?
It can. A general-audience service becomes subject to COPPA in respect of a given user the moment it has actual knowledge that the user is under 13, which commonly happens through a self-declared age or a report. This is why age screening design and COPPA compliance cannot be treated separately.
Related reading
- Age verification — the control COPPA depends on, and the data-minimization problem it creates
- Personally identifiable information — the broader category, and how COPPA’s definition now differs from it
- Knowledge-based authentication — one of the FTC-approved consent methods, and why its reliability has fallen
- US online gambling laws — how age assurance obligations work in a different regulated category