COPPA Compliance Guide: Children's Online Privacy Protection (2026)

COPPA (15 U.S.C. §§ 6501-6506) requires operators of websites and online services directed at children under 13 to obtain verifiable parental consent before collecting personal information. The FTC enforces these obligations through the COPPA Rule (16 C.F.R. Part 312), with civil penalties reaching up to $53,088 per violation.
Children interact with websites, apps, and connected devices at younger ages every year. The Children's Online Privacy Protection Act, known as COPPA, is the primary federal law governing how companies collect and use personal information from children under 13. Enacted in 1998 and enforced by the Federal Trade Commission, COPPA places specific obligations on operators of commercial websites, online services, and mobile applications.
This guide breaks down who COPPA applies to, what it requires, how the FTC enforces it, and what changes are on the horizon. For broader context on family and child-related legal frameworks, see our United States Child Support Laws hub.
What Is COPPA and Why Does It Exist?
Congress passed the Children's Online Privacy Protection Act in 1998 (15 U.S.C. §§ 6501-6506) to give parents control over what personal information companies collect from young children online. The law took effect on April 21, 2000, when the FTC's implementing regulation, the COPPA Rule (16 C.F.R. Part 312), became enforceable.
The statute reflects a straightforward principle: children under 13 lack the maturity to understand privacy risks, so parents should make decisions about their children's data. COPPA does not ban children from using the internet. It places obligations on the companies that operate websites and online services.
The FTC updated the COPPA Rule in 2013 to address smartphones, tablets, social networking, and other technologies that did not exist when the original rule was written. The Commission then finalized a further set of amendments, announced January 16, 2025 and published at 90 FR 16918 on April 22, 2025. The amended Rule took effect June 23, 2025, and regulated entities had until April 22, 2026 to come into full compliance.
Who Must Comply with COPPA?
COPPA applies to two categories of operators:
Operators of websites or online services directed to children under 13. The FTC considers factors like the site's subject matter, visual content, use of animated characters, music, child-oriented activities, the age of models, the presence of advertising directed to children, and whether the site uses language or terms aimed at children. A website does not need to exclusively target children; if a portion of the audience is children and the site is designed in a way that attracts them, COPPA may apply.
Operators of general audience websites or online services that have actual knowledge they are collecting personal information from children under 13. "Actual knowledge" means the operator has been informed or has clear evidence that a specific user is under 13. The FTC has taken the position that deliberately avoiding age-related information does not avoid COPPA obligations.
Third-party plug-ins and advertising networks also face COPPA requirements when they collect data through a child-directed site, even if the third party itself does not operate the site. The FTC's COPPA FAQ addresses this in detail.
Entities Exempt from COPPA
COPPA applies specifically to commercial operators. Nonprofit organizations that are not acting in a commercial capacity are generally exempt under the FTC Act's jurisdictional limits. Schools and school districts are not operators under COPPA, although ed-tech vendors that collect student data on behalf of schools may be covered. Government agencies are also outside COPPA's scope.
What Counts as Personal Information?
COPPA defines "personal information" broadly. Under 16 C.F.R. § 312.2, it includes:
- First and last name
- Home or physical address (including street name and city or town)
- Online contact information (email address, instant messaging ID)
- Screen name or username that functions as online contact information
- Telephone number
- A government-issued identifier, such as a Social Security, state identification card, birth certificate, or passport number
- A photograph, video, or audio file containing a child's image or voice
- Geolocation information sufficient to identify a street name and city or town
- A biometric identifier that can be used for the automated or semi-automated recognition of an individual, such as fingerprints, handprints, retina or iris patterns, genetic data including a DNA sequence, voiceprints, gait patterns, facial templates, or faceprints
- Persistent identifiers (cookies, IP addresses, device serial numbers, processor serial numbers) when used to recognize a user over time and across websites, except when used solely for internal operations
The 2013 Rule update expanded this definition significantly. Adding persistent identifiers, photos, audio recordings, and geolocation brought the definition in line with how children actually use modern devices and apps. The 2025 amendments went further, adding biometric identifiers and government-issued identifiers to the list.
Verifiable Parental Consent Requirements
Before collecting, using, or disclosing personal information from a child under 13, an operator must obtain verifiable parental consent (VPC). The FTC requires that the consent method be "reasonably calculated, in light of available technology, to ensure that the person providing consent is the child's parent."
Approved Consent Methods
The FTC recognizes several methods for obtaining VPC:
- Signed consent form returned by mail, fax, or electronic scan
- Credit card or other online payment system where the operator provides notification to the cardholder and charges a small transaction
- Toll-free telephone number or video conference staffed by trained personnel
- Government-issued ID checked against a database, with the ID deleted promptly after verification
- Knowledge-based challenge questions that would be difficult for a child to answer
- Facial recognition comparing a parent's photo ID to a real-time selfie, then deleting both after verification
For internal use only (where personal information will not be disclosed to third parties), the FTC allows a streamlined "email plus" method: the operator sends a confirmation email to the parent, who must respond, call a number, or connect via another mechanism to confirm consent.
The Privacy Policy Requirement
Operators must post a clear, complete privacy policy on each page where data is collected from children. The policy must describe:
- What information the operator collects and how it is used
- The operator's disclosure practices
- The parent's right to review, delete, and refuse further collection of the child's data
- Contact information for the operator
- The effective date of the policy
Operators must also provide direct notice to parents before collecting information, describing the specific data to be collected and how it will be used.
FTC Safe Harbor Programs
Section 312.11 of the COPPA Rule establishes the safe harbor provision, which allows industry groups to submit self-regulatory guidelines for FTC approval. Companies that participate in an approved safe harbor program and comply with its guidelines are deemed to comply with the COPPA Rule, subject to review.
Currently Approved Safe Harbor Programs
Children's Advertising Review Unit (CARU), operated by BBB National Programs, is the longest-running COPPA safe harbor. CARU monitors and reviews child-directed advertising and privacy practices across digital media.
kidSAFE Seal Program focuses on children's websites, apps, games, and connected products. kidSAFE provides a certification process that includes privacy assessments, compliance monitoring, and a public seal that parents can look for.
iKeepSafe offers COPPA safe harbor certification along with related certifications for FERPA and state student privacy laws. iKeepSafe works primarily with ed-tech companies.
PRIVO provides a technology-based safe harbor program. PRIVO's platform offers age verification and parental consent tools that operators can integrate directly into their products.
Participation in a safe harbor program does not guarantee immunity from FTC enforcement. The FTC retains authority to investigate and take action against any operator, including safe harbor participants, if it finds COPPA violations.
Major COPPA Enforcement Actions
The FTC has brought dozens of COPPA enforcement cases since 2000. The penalties have escalated significantly in recent years, reflecting both rising violation counts and the increased penalty ceiling.
Epic Games ($520 Million, 2022)
In December 2022, the FTC announced a $520 million settlement with Epic Games, the maker of Fortnite. The case involved two components: $275 million for COPPA violations related to collecting personal information from children under 13 without parental consent, and $245 million for dark patterns that tricked players into making unintended purchases. This remains the largest COPPA enforcement action in history.
Epic Games had defaulted all players into open voice and text chat, connecting children with strangers without parental knowledge. The company also collected personal information and persistent identifiers from players it knew were under 13.
Google/YouTube ($170 Million, 2019)
Google and YouTube paid $170 million ($136 million to the FTC and $34 million to the New York Attorney General) for tracking children on YouTube channels directed at kids. YouTube had marketed itself to content creators as a top destination for children while simultaneously telling advertisers it could track and target those same young viewers. The settlement required YouTube to create a system for channel operators to identify child-directed content.
TikTok/Musical.ly ($5.7 Million, 2019)
Musical.ly (now TikTok) paid $5.7 million for collecting names, email addresses, and other personal information from children under 13 without parental consent. The app had actual knowledge that many users were children based on the birthdates users entered, yet continued collecting data. TikTok subsequently launched a restricted mode for users under 13.
Other Notable Cases
The FTC has also pursued cases against Edmodo ($6 million, 2023, ed-tech company using student data for advertising) and numerous smaller operators. The pattern is clear: the FTC prioritizes cases involving large-scale collection, actual knowledge of child users, and companies that profit from children's data.
Penalties for COPPA Violations
The FTC enforces COPPA under Section 5 of the FTC Act, which authorizes civil penalties for unfair or deceptive practices. The maximum civil penalty per violation is adjusted annually for inflation.
The current maximum penalty is $53,088 per violation, the figure codified at 16 C.F.R. § 1.98 following the adjustment that took effect January 17, 2025. Each instance of collecting personal information from a child without proper consent counts as a separate violation. For an app or website with millions of child users, penalties accumulate rapidly.
Beyond monetary penalties, FTC orders typically require the company to:
- Delete all personal information collected in violation of COPPA
- Implement a comprehensive privacy program
- Obtain biennial independent privacy assessments for 20 years
- Submit compliance reports to the FTC
- Refrain from misrepresenting privacy practices
State attorneys general can also enforce COPPA under 15 U.S.C. § 6504, bringing actions in federal court on behalf of state residents.
COPPA 2.0, KOSA, and Pending Legislation
Federal lawmakers have introduced several bills to update children's online privacy protections beyond the original COPPA framework.
COPPA 2.0 (S. 836)
The Children and Teens' Online Privacy Protection Act, commonly called "COPPA 2.0," would raise the age threshold from 13 to 17, ban targeted advertising to minors, create an "Eraser Button" allowing parents and children to delete personal information, and establish a Youth Privacy and Marketing Division within the FTC. The Senate passed the bill by unanimous consent on March 5, 2026. It was received in the House on March 16, 2026 and held at the desk, so it has not become law.
Kids Online Safety Act (KOSA)
KOSA (S. 1748) would impose a duty of care on covered platforms to prevent and mitigate harms to minors, including promotion of suicide, eating disorders, substance abuse, bullying, and sexual exploitation. Platforms would need to enable the strongest privacy settings by default for users under 17. The current bill was introduced on May 14, 2025, and the Senate Commerce Committee ordered it reported with a substitute amendment on August 5, 2026. An earlier version cleared the Senate in the prior Congress as part of S. 2073 on a 91-3 vote in July 2024 but died without a House vote.
FTC COPPA Rule Updates
Separately from legislation, the FTC finalized amendments to the COPPA Rule that require separate opt-in consent for targeted advertising to children, limit data retention, strengthen data security requirements, and add biometric identifiers and government-issued identifiers to the definition of personal information. These changes took effect without new legislation: the amended Rule became effective June 23, 2025, with a compliance deadline of April 22, 2026.
For a state-by-state view of children's privacy legislation going beyond COPPA, see our Children's Online Privacy by State guide.
Practical COPPA Compliance Steps
Organizations that operate websites, apps, or connected products used by children can follow these steps to build a COPPA-compliant program.
Step 1: Determine Whether COPPA Applies
Evaluate whether your site or service is "directed to children" using the FTC's totality of circumstances test. Review your content, design, advertising, and actual user demographics. If your audience includes children under 13 or if you have actual knowledge of child users, COPPA applies.
Step 2: Audit Your Data Collection
Map every point where personal information (as defined by 16 C.F.R. § 312.2) is collected. This includes registration forms, in-app purchases, chat features, analytics tracking, third-party SDKs, advertising networks, and social login integrations. Document what data is collected, why, and where it goes.
Step 3: Implement Age Screening
Use a neutral age gate (ask for date of birth without suggesting the "right" answer). The FTC has penalized companies that allowed children to simply enter a fake birthdate after being rejected. Block collection of personal information from users who indicate they are under 13, unless you implement the full VPC process.
Step 4: Obtain Verifiable Parental Consent
Choose a VPC method appropriate for your service. For apps and games, credit card verification or facial recognition matching may be practical. For lower-risk internal use, the email-plus method works. Maintain records of consent for auditing purposes.
Step 5: Draft a Compliant Privacy Policy
Your COPPA privacy policy must be clear, prominent, and complete. List every category of personal information collected, each purpose for collection, all third parties that receive data, and parent's rights regarding their child's data. Avoid legal jargon. Use plain language.
Step 6: Establish Data Retention and Deletion Procedures
Retain children's personal information only as long as necessary for the purpose it was collected. Implement processes for parents to request deletion of their child's data. Respond to deletion requests promptly.
Step 7: Secure Children's Data
Apply reasonable security measures proportionate to the sensitivity of the data. The FTC expects encryption, access controls, employee training, and incident response procedures. Data breaches involving children's information carry heightened enforcement risk.
Step 8: Consider Safe Harbor Certification
Joining an FTC-approved safe harbor program provides a structured compliance framework and demonstrates commitment to children's privacy. Programs like CARU, kidSAFE, iKeepSafe, and PRIVO offer assessments and monitoring that help maintain ongoing compliance.
How COPPA Intersects with State Laws
COPPA sets a federal baseline, but states increasingly add their own children's privacy requirements. California's Age-Appropriate Design Code Act imposes data protection impact assessments for services likely to be accessed by children. Utah, Texas, Louisiana, Arkansas, and Florida have enacted social media restrictions for minors that go beyond COPPA's scope.
These state laws do not preempt COPPA; they layer additional obligations on top of the federal framework. Companies operating nationally need to comply with both COPPA and the most restrictive applicable state laws. For a detailed breakdown, see our Children's Online Privacy by State guide and individual state data privacy pages like California and Texas.
Cross-Links to Related Topics
Families navigating children's online privacy issues often face related legal questions around child support, custody, and parental rights. State child support agencies increasingly use digital tools that collect family data, raising privacy questions of their own.
- United States Child Support Laws (hub page)
- California Child Support Laws
- Texas Child Support Laws
- Student Data Privacy and FERPA
This article provides general legal information about COPPA compliance. It does not constitute legal advice. Consult an attorney for advice specific to your situation.
Related Privacy Guides
- U.S. Data Privacy Laws: the state and federal consumer-privacy framework.
- Children's Online Privacy Laws by State: how states go beyond the COPPA baseline.
- Biometric Privacy Laws by State: another category of sensitive personal data.
Frequently Asked Questions
What age does COPPA protect?
COPPA protects children under 13 years old. The law requires operators of websites and online services to obtain verifiable parental consent before collecting personal information from users they know are younger than 13. COPPA 2.0 would raise this threshold to 17 and passed the Senate in March 2026, but it has not been enacted, so the federal age cutoff remains 13.
Does COPPA apply to nonprofit organizations?
Generally, no. COPPA is enforced under the FTC Act, which applies to entities operating in commerce. Most nonprofit organizations fall outside the FTC's jurisdiction. However, a nonprofit that operates a commercial website or partners with a commercial entity for data collection could be subject to COPPA requirements.
What is verifiable parental consent under COPPA?
Verifiable parental consent (VPC) is a mechanism reasonably calculated to ensure that the person giving permission for data collection is actually the child's parent or guardian. Approved methods include signed consent forms, credit card verification, government ID checks, knowledge-based questions, and video conferencing. The specific method must match the sensitivity of the data being collected.
How much can the FTC fine a company for COPPA violations?
The FTC can impose civil penalties of up to $53,088 per violation, a ceiling adjusted for inflation under 15 U.S.C. § 45(m)(1)(A). Each instance of improperly collecting a child's data counts as a separate violation. The largest COPPA enforcement action to date was the $520 million Epic Games settlement in 2022.
Do schools have to comply with COPPA?
Schools themselves are not 'operators' under COPPA and are not directly subject to its requirements. However, ed-tech vendors and online services that schools use to collect student data may be COPPA-covered operators. The FTC has stated that schools can provide consent on behalf of parents when the data is used solely for an educational purpose, not for commercial purposes.
What is a COPPA safe harbor program?
A safe harbor program is an FTC-approved self-regulatory program that establishes guidelines for COPPA compliance. Companies that join and comply with an approved safe harbor (such as CARU, kidSAFE, iKeepSafe, or PRIVO) are deemed to comply with the COPPA Rule. However, the FTC retains enforcement authority and can still investigate safe harbor participants.
Does COPPA apply to apps and games?
Yes. COPPA applies to any commercial online service, including mobile apps and video games, that is directed to children under 13 or that has actual knowledge of collecting data from children under 13. The 2013 COPPA Rule update specifically addressed mobile apps, in-app data collection, and persistent identifiers used by app-based advertising networks.
What happens if my state has stricter children's privacy laws than COPPA?
COPPA does not preempt state laws that provide greater protections for children's privacy. Companies must comply with both COPPA and any applicable state laws. States like California (AADC), Utah (SB 152), and Texas (HB 18) have enacted children's privacy laws that impose additional requirements beyond the federal baseline.
Updates
Updated for the FTC's finalized COPPA Rule amendments (effective June 23, 2025, compliance deadline April 22, 2026), including biometric and government-issued identifiers in the personal information definition, corrected the maximum civil penalty to $53,088 per violation, removed the Flo Health matter from the COPPA enforcement list, and replaced the expired 118th Congress bill numbers with the current COPPA 2.0 (S. 836) and KOSA (S. 1748) status.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
United States Code Title 15
§ 6502Regulation of unfair and deceptive acts and practices in connection with collection and use of personal information from and about children on the InternetIn forcecited in 2 of our articles
It is unlawful for an operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting personal information from a child, to collect personal information from a child in a manner that violates the regulations prescribed under subsection (b). Notwithstanding paragraph (1), neither an operator of such a website or online service nor the operator’s agent shall be held to be liable under any Federal or State law for any disclosure made in good faith and following reasonable procedures in responding to a request for disclosure of personal information under subsection (b)(1)(B)(iii) to the parent of a child.
Official text (excerpt) · last checked 2026-09-03 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 19 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts reading 15 U.S.C. 6502 have focused on its preemption clause. Cara Jones v. Google LLC (2023) held COPPA does not bar state-law claims parallel to, or forbidding the same conduct as, COPPA. In Re Nickelodeon Consumer Privacy Litigation (2016) held a state intrusion claim rested on duties compatible with COPPA and was not preempted.
Opinions citing this section in our collection:
- Cara Jones v. Google LLC (Court of Appeals for the Ninth Circuit 2023)“…eatment of those activities or actions under this section.” 15 U.S.C. § 6502(d). The panel held that state laws that…”
- In Re Nickelodeon Consumer Privacy Litigation (Court of Appeals for the Third Circuit 2016, 827 F.3d 262)✓Children alleged Viacom promised parents it collected no personal information on its kids' sites while letting Google track them; the Third Circuit held the statute's preemption clause did not bar their state intrusion upon seclusion claim, because it says nothing about deceit.
- Federal Trade Commission v. Wyndham Worldwide Corp. (Court of Appeals for the Third Circuit 2015, 799 F.3d 236)“…112 Stat. 2681, 2681-730–732 (1998) (codified as amended at 15 U.S.C. § 6502).6 Wyndham contends these “tailored gra…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Children's Online Privacy Laws by State (2026)
§ 6504Actions by StatesIn force
In any case in which the attorney general of a State has reason to believe that an interest of the residents of that State has been or is threatened or adversely affected by the engagement of any person in a practice that violates any regulation of the Commission prescribed under section 6502(b) of this title, the State, as parens patriae, may bring a civil action on behalf of the residents of the State in a district court of the United States of appropriate jurisdiction to— enjoin that practice; enforce compliance with the regulation; obtain damage, restitution, or other compensation on behalf of residents of the State; or obtain such other relief as the court may consider to be appropriate. Before filing an action under paragraph (1), the attorney general of the State involved shall provide to the Commission— written notice of that action; and a copy of the complaint for that action. Subparagraph (A) shall not apply with respect to the filing of an action by an attorney general of a State under this subsection, if the attorney general determines that it is not feasible to provide the notice described in that subparagraph before the filing of the action.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- Center for Digital Democracy v. Federal Trade Commission (District Court, District of Columbia 2016, 189 F. Supp. 3d 151)“…o bring civil actions to enforce the FTC’s regulations. See 15 U.S.C. §§ 6504(a), (d).…”
- C.T. v. Red Roof Inns, Inc. (District Court, M.D. Florida 2022)“…r may be found”); Children’s Online Privacy Protection Act, 15 U.S.C. § 6504(e)(2) (in civil actions, process may be…”
- Hubbard v. Google LLC (District Court, N.D. California 2021)“…parens patriae actions brought by their attorneys general, 15 U.S.C. § 6504(a)(1). Before 12…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 45Unfair methods of competition unlawful; prevention by CommissionIn forcecited in 14 of our articles
Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful. The Commission is hereby empowered and directed to prevent persons, partnerships, or corporations, except banks, savings and loan institutions described in section 57a(f)(3) of this title, Federal credit unions described in section 57a(f)(4) of this title, common carriers subject to the Acts to regulate commerce, air carriers and foreign air carriers subject to part A of subtitle VII of title 49, and persons, partnerships, or corporations insofar as they are subject to the Packers and Stockyards Act, 1921, as amended [7 U.S.C. 181 et seq.], except as provided in section 406(b) of said Act [7 U.S.C. 227(b) ], from using unfair methods of competition in or affecting commerce and unfair or deceptive acts or practices in or affecting commerce.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 3,207 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):United States v. Philadelphia National Bank (1963) applied the bank exclusion in 15 U.S.C. 45(a)(6) when construing Clayton Act section 7, and Copperweld Corp. v. Independence Tube Corp. (1984) noted that a corporation and its wholly owned subsidiaries remain subject to section 5 of the FTC Act.
Opinions citing this section in our collection:
- Morales v. Trans World Airlines, Inc. (Supreme Court of the United States 1992, 504 U.S. 374)“…etition in commerce.” 38 Stat. 719 , codified as amended, 15 U. S. C. § 45 (a)(1). That type of prohibition is ent…”
- Copperweld Corp. v. Independence Tube Corp. (Supreme Court of the United States 1984, 467 U.S. 752)“…d § 5 of the Federal Trade Commission Act, 38 Stat. 719 , 15 U. S. C. §45 . That these statutes are adequate to c…”
- Bowen v. Massachusetts (Supreme Court of the United States 1988, 487 U.S. 879)“…n required to exhaust before coming into court. See 15 U. S. C. §45 (c) (1940 ed.); 29 U. S. C. § 160 (f)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: FTC Fines Travel App Hopper $35 Million Over Hidden "Junk Fees", FTC Finalizes Order Against Illuminate Over Student Data Breach (2026), How the FTC's Nationwide Noncompete Ban Was Struck Down, and What It Means for At-Will Workers
Code of Federal Regulations Title 16
§ 312.2Definitions.In force
Child means an individual under the age of 13. Collects or collection means the gathering of any personal information from a child by any means, including but not limited to: (1) Requesting, prompting, or encouraging a child to submit personal information online; (2) Enabling a child to make personal information publicly available in identifiable form. An operator shall not be considered to have collected personal information under this paragraph if it takes reasonable measures to delete all or virtually all personal information from a child's postings before they are made public and also to delete such information from its records; or (3) Passive tracking of a child online. Commission means the Federal Trade Commission. Delete means to remove personal information such that it is not maintained in retrievable form and cannot be retrieved in the normal course of business.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 13 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Cara Jones v. Google LLC (Court of Appeals for the Ninth Circuit 2023)“…er time and across different Web sites or online services.” 16 C.F.R. § 312.2. In 2013, the FTC adopted regulations un…”
- In Re Nickelodeon Consumer Privacy Litigation (Court of Appeals for the Third Circuit 2016, 827 F.3d 262)“…de Commission authority to expand the types of 160 16 C.F.R. § 312.2 (2000). 161 Children’s Online Priv…”
- NetChoice, LLC v. David Yost (Court of Appeals for the Sixth Circuit 2026)“…advertising[, and] . . . empirical evidence . . . . 16 C.F.R. § 312.2. But Yost does not explain why the resem…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Children's Online Privacy Protection Act (15 U.S.C. §§ 6501-6506)(uscode.house.gov).gov
- FTC COPPA Rule (16 C.F.R. Part 312)(ecfr.gov).gov
- FTC COPPA FAQ: Complying with COPPA(ftc.gov).gov
- FTC Six-Step COPPA Compliance Plan(ftc.gov).gov
- Epic Games $520M FTC Settlement (2022)(ftc.gov).gov
- Google/YouTube $170M COPPA Settlement (2019)(ftc.gov).gov
- TikTok/Musical.ly $5.7M COPPA Settlement (2019)(ftc.gov).gov
- FTC 2024 Inflation-Adjusted Civil Penalty Amounts(ftc.gov).gov
- State AG Enforcement Authority (15 U.S.C. § 6504)(uscode.house.gov).gov
- COPPA 2.0 (S. 1628, 118th Congress)(congress.gov).gov
- Kids Online Safety Act (S. 1409, 118th Congress)(congress.gov).gov
- FTC Proposed COPPA Rule Amendments(ftc.gov).gov
- California Age-Appropriate Design Code Act (AB 2273)(leginfo.legislature.ca.gov).gov
- COPPA Personal Information Definition (16 C.F.R. § 312.2)(ecfr.gov).gov
- Edmodo FTC Enforcement Action (2023)(ftc.gov).gov
- COPPA Rule Final Amendments, 90 FR 16918 (April 22, 2025)(federalregister.gov)
- FTC Finalizes Changes to Children's Privacy Rule (January 16, 2025)(ftc.gov)
- FTC Adjusted Civil Monetary Penalty Amounts (16 C.F.R. § 1.98)(ecfr.gov)
- COPPA 2.0: Children and Teens' Online Privacy Protection Act (S. 836, 119th Congress)(congress.gov)
- Kids Online Safety Act (S. 1748, 119th Congress)(congress.gov)