EnglishEspañol

COPPA Compliance Guide: Children's Online Privacy Protection (2026)

By Recording Law Editorial TeamReviewed September 3, 202613 min read
COPPA Compliance Guide: Children's Online Privacy Protection (2026)

Frequently Asked Questions

What age does COPPA protect?

COPPA protects children under 13 years old. The law requires operators of websites and online services to obtain verifiable parental consent before collecting personal information from users they know are younger than 13. COPPA 2.0 would raise this threshold to 17 and passed the Senate in March 2026, but it has not been enacted, so the federal age cutoff remains 13.

Does COPPA apply to nonprofit organizations?

Generally, no. COPPA is enforced under the FTC Act, which applies to entities operating in commerce. Most nonprofit organizations fall outside the FTC's jurisdiction. However, a nonprofit that operates a commercial website or partners with a commercial entity for data collection could be subject to COPPA requirements.

What is verifiable parental consent under COPPA?

Verifiable parental consent (VPC) is a mechanism reasonably calculated to ensure that the person giving permission for data collection is actually the child's parent or guardian. Approved methods include signed consent forms, credit card verification, government ID checks, knowledge-based questions, and video conferencing. The specific method must match the sensitivity of the data being collected.

How much can the FTC fine a company for COPPA violations?

The FTC can impose civil penalties of up to $53,088 per violation, a ceiling adjusted for inflation under 15 U.S.C. § 45(m)(1)(A). Each instance of improperly collecting a child's data counts as a separate violation. The largest COPPA enforcement action to date was the $520 million Epic Games settlement in 2022.

Do schools have to comply with COPPA?

Schools themselves are not 'operators' under COPPA and are not directly subject to its requirements. However, ed-tech vendors and online services that schools use to collect student data may be COPPA-covered operators. The FTC has stated that schools can provide consent on behalf of parents when the data is used solely for an educational purpose, not for commercial purposes.

What is a COPPA safe harbor program?

A safe harbor program is an FTC-approved self-regulatory program that establishes guidelines for COPPA compliance. Companies that join and comply with an approved safe harbor (such as CARU, kidSAFE, iKeepSafe, or PRIVO) are deemed to comply with the COPPA Rule. However, the FTC retains enforcement authority and can still investigate safe harbor participants.

Does COPPA apply to apps and games?

Yes. COPPA applies to any commercial online service, including mobile apps and video games, that is directed to children under 13 or that has actual knowledge of collecting data from children under 13. The 2013 COPPA Rule update specifically addressed mobile apps, in-app data collection, and persistent identifiers used by app-based advertising networks.

What happens if my state has stricter children's privacy laws than COPPA?

COPPA does not preempt state laws that provide greater protections for children's privacy. Companies must comply with both COPPA and any applicable state laws. States like California (AADC), Utah (SB 152), and Texas (HB 18) have enacted children's privacy laws that impose additional requirements beyond the federal baseline.

Updates

Updated for the FTC's finalized COPPA Rule amendments (effective June 23, 2025, compliance deadline April 22, 2026), including biometric and government-issued identifiers in the personal information definition, corrected the maximum civil penalty to $53,088 per violation, removed the Flo Health matter from the COPPA enforcement list, and replaced the expired 118th Congress bill numbers with the current COPPA 2.0 (S. 836) and KOSA (S. 1748) status.

Governing law re-checked for recent changes

Sources and References

  1. Children's Online Privacy Protection Act (15 U.S.C. §§ 6501-6506)(uscode.house.gov).gov
  2. FTC COPPA Rule (16 C.F.R. Part 312)(ecfr.gov).gov
  3. FTC COPPA FAQ: Complying with COPPA(ftc.gov).gov
  4. FTC Six-Step COPPA Compliance Plan(ftc.gov).gov
  5. Epic Games $520M FTC Settlement (2022)(ftc.gov).gov
  6. Google/YouTube $170M COPPA Settlement (2019)(ftc.gov).gov
  7. TikTok/Musical.ly $5.7M COPPA Settlement (2019)(ftc.gov).gov
  8. FTC 2024 Inflation-Adjusted Civil Penalty Amounts(ftc.gov).gov
  9. State AG Enforcement Authority (15 U.S.C. § 6504)(uscode.house.gov).gov
  10. COPPA 2.0 (S. 1628, 118th Congress)(congress.gov).gov
  11. Kids Online Safety Act (S. 1409, 118th Congress)(congress.gov).gov
  12. FTC Proposed COPPA Rule Amendments(ftc.gov).gov
  13. California Age-Appropriate Design Code Act (AB 2273)(leginfo.legislature.ca.gov).gov
  14. COPPA Personal Information Definition (16 C.F.R. § 312.2)(ecfr.gov).gov
  15. Edmodo FTC Enforcement Action (2023)(ftc.gov).gov
  16. COPPA Rule Final Amendments, 90 FR 16918 (April 22, 2025)(federalregister.gov)
  17. FTC Finalizes Changes to Children's Privacy Rule (January 16, 2025)(ftc.gov)
  18. FTC Adjusted Civil Monetary Penalty Amounts (16 C.F.R. § 1.98)(ecfr.gov)
  19. COPPA 2.0: Children and Teens' Online Privacy Protection Act (S. 836, 119th Congress)(congress.gov)
  20. Kids Online Safety Act (S. 1748, 119th Congress)(congress.gov)
Share: