AI Policy Wiki
Dashboard

Children's Online Privacy Protection Act (COPPA)

medium confidence · updated 2026-08-20

US federal children's privacy statute (1998, 15 U.S.C. §§ 6501–6505) implemented by the FTC's COPPA Rule at 16 CFR Part 312. Requires verifiable parental consent before collecting personal information online from children under 13. Amended by an FTC final rule published April 22, 2025 (effective June 23, 2025; full compliance April 22, 2026) adding biometric identifiers to the definition of personal information, separate consent for third-party disclosure, written retention and security program requirements, and a 'mixed audience' category.

The Children's Online Privacy Protection Act is the principal United States federal statute governing the online collection of personal information from children. Enacted in 1998 and codified at 15 U.S.C. §§ 6501–6505, it directs the Federal Trade Commission to issue implementing regulations, which appear at 16 CFR Part 312 and are known as the COPPA Rule. The Rule imposes requirements on operators of websites and online services directed to children under 13, and on operators of other services that have actual knowledge they are collecting personal information from a child under 13 (Source: ftc.gov).

The statute occupies a distinctive position in United States privacy law: it is sectoral and age-bounded rather than general, it is enforced by an agency with civil penalty authority, and it contains no private right of action. Because it attaches to a category of user rather than to a category of technology, it applies to conversational AI products and recommendation systems on the same terms as to any other online service, and it is the federal baseline against which state minor-protection statutes and the pending federal proposals at Kids Online Safety Act (KOSA, S. 1748) and Kids Internet and Digital Safety Act (KIDS Act, H.R. 7757) are drafted.

Statutory structure

COPPA applies to an "operator" of a website or online service. Coverage attaches in two ways: the service is directed to children under 13, or the operator has actual knowledge that it is collecting personal information online from a child under 13. The actual-knowledge standard means that a general-audience service does not become subject to COPPA merely because children in fact use it, a design point that recurs in debates about age assurance.

Enforcement rests with the FTC and with state attorneys general. There is no private right of action, which distinguishes COPPA from several state privacy statutes and from the Illinois biometric regime discussed in the state-law material at State-Level AI Regulation.

Rulemaking history

The FTC issued the original COPPA Rule in 1999 and has amended it three times. The 2013 amendments clarified the Rule's scope and expanded the definition of personal information to include persistent identifiers, photographs, videos, and audio files. The Commission opened a further review in 2019, held a workshop in October 2019, and extended the comment period twice into December 2019 (Source: ftc.gov).

That review culminated in a final rule published in the Federal Register on April 22, 2025 (RIN 3084-AB20, docket FTC-2024-0003), effective June 23, 2025, with a full-compliance date of April 22, 2026 subject to exceptions (Source: federalregister.gov).

The 2025 amendments

The 2025 final rule made several substantive changes to 16 CFR Part 312.

Definitions. "Personal information" was amended to include "[a] biometric identifier that can be used for the automated or semi-automated recognition of an individual, such as fingerprints; handprints; retina patterns; iris patterns; genetic data, including a DNA sequence; voiceprints; gait patterns; facial templates; or faceprints," and to include government-issued identifiers such as Social Security, state identification card, birth certificate, or passport numbers. "Online contact information" was extended to cover a mobile telephone number where the operator uses it only to send text messages to a parent in connection with obtaining parental consent (Source: federalregister.gov).

The rule added a definition of "mixed audience website or online service" — a service directed to children under the Rule's criteria "but that does not target children as its primary audience, and does not collect personal information from any visitor, other than for the limited purposes set forth in § 312.5(c), prior to collecting age information or using another means that is reasonably calculated, in light of available technology, to determine whether the visitor is a child." Any such age collection "must be done in a neutral manner that does not default to a set age or encourage visitors to falsify age information." A mixed audience service is not deemed directed to children with respect to any visitor not identified as under 13. The definition of a service "directed to children" was amended to list evidence relevant to audience composition, including marketing and promotional materials, representations to consumers or third parties, user and third-party reviews, and the age of users on similar services.

Separate consent for disclosure. Section 312.5(a)(2) now requires separate verifiable parental consent for disclosures of a child's personal information to third parties, unless the disclosure is integral to the nature of the service, and prohibits operators from conditioning access to the service on that consent.

Retention. Section 312.10 now prohibits indefinite retention of children's personal information and requires operators to "establish, implement, and maintain a written data retention policy" stating the purposes of collection, the business need for retention, and a deletion timeframe, and to publish that policy in the online notice required by § 312.4(d).

Security program. Section 312.8 now requires a written information security program with safeguards appropriate to the sensitivity of the information and to the operator's size, complexity, and scope of activities, including designated coordinating employees, risk assessments, safeguard design and implementation, regular testing and monitoring, and evaluation and modification at least annually. A general information security program covering all data can satisfy the requirement if it meets those criteria.

Safe harbor reporting. Section 312.11(d)(1) now requires an approved safe harbor program's annual report to identify each subject operator and all approved services, and to identify operators that have left the program; to include a narrative description of the program's business model, copies of each consumer complaint related to a subject operator's violation of program guidelines, and a description of the discipline determination process. Approved programs must publicly post the list of current subject operators and their certified services and update it every six months.

Consent methods. The rule codified three additional methods of verifiable parental consent: knowledge-based authentication at § 312.5(b)(2)(vi), requiring "dynamic, multiple-choice questions" of sufficient difficulty that a child aged 12 or younger in the household could not reasonably ascertain the answers; face match to verified photo identification at § 312.5(b)(2)(vii), with the parent's identification and images to be "promptly deleted by the operator from its records after the match is confirmed"; and a "text plus" method at § 312.5(b)(2)(ix) for operators that do not disclose children's personal information, pairing a text message with a confirmatory message, letter, or telephone call.

Age assurance

On February 25, 2026 the Commission issued a COPPA policy statement described as intended to incentivize the use of age verification technologies (Source: ftc.gov). The statement sits alongside the 2025 rule's mixed-audience definition, which conditions favourable treatment on a neutral age-determination step. Age assurance is also the operative mechanism in state chatbot statutes such as Colorado HB 26-1263 (Chatbot Safety Act) and in the design-code litigation at NetChoice v. Bonta (CAADCA litigation), where the Ninth Circuit allowed California's age-estimation requirement to proceed while blocking other provisions.

Relation to AI products

COPPA's obligations bind AI developers and deployers through the same operator definition that reaches any online service. Three features of generative products interact with the Rule directly. Voice interfaces implicate the amended definition of personal information, which now names voiceprints. Model training on user interactions implicates the retention prohibition, since indefinite retention of children's personal information is no longer permitted and a written deletion timeframe is required. Third-party model providers implicate § 312.5(a)(2), because routing a child's inputs to an external inference provider is a disclosure requiring separate consent unless integral to the service.

The statute is discussed as a template in the federal minor-protection proposals at Kids Online Safety Act (KOSA, S. 1748) and Kids Internet and Digital Safety Act (KIDS Act, H.R. 7757), and its actual-knowledge standard is a recurring reference point in the harm-theory literature summarized at Content vs Architecture Theory of Social Media Harm and Three Theories of Consent Failure (Information / Capacity / Design).

Relationships

Open questions

  • Whether the 2025 rule's mixed-audience definition changes the practical coverage of general-audience conversational AI products has not been tested in an enforcement action as of August 2026.
  • How the retention prohibition at § 312.10 applies to model weights derived from children's personal information, as distinct from the underlying records, is not addressed in the rule text.