Children’s Online Privacy Protection Act (COPPA)

The Children’s Online Privacy Protection Act (COPPA) is the U.S. federal law governing the collection of personal information from children under 13 online. It requires operators of covered services to obtain verifiable parental consent before collecting that information, and it is enforced by the Federal Trade Commission through the COPPA Rule. Amendments published in 2025 took full effect in April 2026 and materially expanded what counts as personal information.

Enacted 1998; effective April 2000
Statute 15 U.S.C. §§ 6501–6506
Implementing rule The COPPA Rule, 16 CFR Part 312
Enforced by The Federal Trade Commission, and state attorneys general
Age threshold Under 13
Who is covered Operators of online services directed to children under 13, and operators with actual knowledge they collect personal information from children under 13
Core requirement Verifiable parental consent before collection, use or disclosure
2025 amendments Published 22 April 2025, effective 23 June 2025, full compliance required from 22 April 2026

How it works

COPPA turns on two triggers. A service is covered if it is directed to children under 13 — assessed on subject matter, visual content, language, advertising, and similar factors — or if the operator has actual knowledge that it is collecting personal information from a child under 13. The second trigger catches general-audience services the moment a user identifies as under 13, which is why age screening and COPPA obligations are entangled in practice.

Where COPPA applies, the operator must post a clear privacy notice, provide direct notice to parents, and obtain verifiable parental consent before collecting personal information. Parents must be able to review what has been collected and require its deletion, and the operator must not condition a child’s participation in an activity on collecting more information than is reasonably necessary.

The FTC has approved several methods of obtaining verifiable parental consent, and the list is deliberately graduated by risk. A signed consent form returned by mail, fax or scan. A payment card transaction that provides notification of each transaction. A call to a toll-free number staffed by trained personnel, or a video conference with them. Checking a government-issued identification against a database, provided the identification is promptly deleted afterwards. Knowledge-based authentication. And matching a photograph of the parent against the photograph on a government-issued identity document.

What the 2025 amendments changed

The amended Rule is now in full force, and three changes matter most:

Change Effect
Biometric identifiers are personal information Fingerprints, voiceprints, iris and retina patterns, facial templates, gait patterns and genetic data now fall squarely within the definition
Separate consent for third-party disclosure Disclosure for purposes not integral to the service — targeted advertising in particular — requires its own verifiable parental consent, not a bundled one
Written security and retention programs Operators must maintain a written information security program and a written data retention policy, and may not keep children’s data indefinitely

The biometric change is the one with the sharpest operational edge. A facial template derived from a child’s image is now unambiguously personal information under COPPA. Any service performing face-based age estimation or face matching on users who may be under 13 has to reason about that carefully, and the fact that a template is generated in order to protect a child does not remove it from the definition.

Why COPPA matters for identity verification

COPPA creates a genuine circularity, and naming it plainly is more useful than working around it. To know whether COPPA applies to a user, an operator needs to know the user’s age. Determining age reliably means collecting information about a person who may be a child — which is the activity COPPA governs. Age assurance is therefore both a compliance control and a compliance exposure.

The resolution is proportionality and data minimization. A check that establishes only whether someone is above a threshold, without retaining the underlying evidence, sits very differently from one that stores an identity document. The FTC’s own approved consent methods point this way: verifying a parent’s identification is permitted precisely on the condition that it is deleted promptly once verification is complete.

This is the same design problem that age verification faces across every regulated category, and COPPA is the sharpest version of it because the subject is a child. For services that must both establish age and hold as little as possible, age verification built on identity document verification can confirm a threshold and a parental relationship without accumulating a store of children’s identity data.

What COPPA can’t do

It does not cover teenagers. The threshold is 13. Users aged 13 to 17 fall outside COPPA entirely, and are addressed by state laws and other frameworks rather than by this one.

It is not a general children’s online safety law. COPPA governs the collection of personal information. Content, contact risk and design harms are outside its scope.

It does not apply outside the United States. Services with international users face the UK Age Appropriate Design Code, the GDPR’s own consent age — which varies by member state — and a growing set of national rules that do not align with COPPA.

It does not tell you how to determine age. The Rule specifies consent methods, not age assurance methods, and the gap between the two is where most implementation difficulty lives.

Frequently asked questions

What age does COPPA cover?

Children under 13. Users aged 13 and above are outside COPPA’s scope, which is why the law is often described as covering children rather than minors generally. Other frameworks address teenagers.

What counts as verifiable parental consent?

The FTC has approved several methods, including a signed consent form returned by mail, fax or scan; a payment card transaction providing notification; a call to trained personnel on a toll-free number; a video conference with trained personnel; checking a government-issued identification against a database and promptly deleting it; knowledge-based authentication; and matching a photograph of the parent to the photograph on a government-issued identity document.

Did the 2025 COPPA amendments change what counts as personal information?

Yes. The amended Rule expressly includes biometric identifiers — fingerprints, voiceprints, iris and retina patterns, facial templates, gait patterns and genetic data. It also requires separate parental consent for disclosures not integral to the service, and mandates written security and data retention programs. Full compliance has been required since 22 April 2026.

Does COPPA apply to a general-audience site?

It can. A general-audience service becomes subject to COPPA in respect of a given user the moment it has actual knowledge that the user is under 13, which commonly happens through a self-declared age or a report. This is why age screening design and COPPA compliance cannot be treated separately.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data