Today, children use the internet very frequently and explore websites for gaming, learning, social networking, and entertainment. In the process, they share personal information (PI) that can put them at risk if it ends up in the wrong hands. To protect children and keep them safe, COPPA was introduced in 2000. The law sets clear rules for any website serving children under 13, giving parents or legal guardians greater control over the personal information collected from them. It also prohibits unfair practices in the collection, use, or sharing of this information, ensuring children’s privacy is safeguarded. The law also defines data retention and deletion guidelines to prevent breaches.
To implement the act, the FTC issued the ‘COPPA Rule’, which is codified at 16 C.F.R. Part 312, outlining the obligations that businesses must fulfill to comply with COPPA. The Rule’s key provisions have been updated to respond to changes in online practices and technology. The most recent amendment took effect on 23rd June 2025, known as the ‘Final Rule.’
Who Needs to Comply with COPPA?
COPPA applies to any website or online service that is directed at children, as well as general-audience platforms that collect data from them. It also extends to third-party services, such as ad networks, analytics providers, and plug-ins. These platforms include, but are not limited to:
- Educational and e-learning platforms
- Gaming websites and apps
- Smart toys / IoT devices for children
- Social networks focused on kids
- Streaming services for cartoons & child content
- Video-sharing platforms hosting child-directed material
COPPA applies to all foreign-based websites and services that target children in the United States, as well as to US-based platforms that collect data from children abroad.
For example, a chat room operator based in Finland collecting data from children in California would be subject to COPPA. Similarly, a US-based gaming company collecting data from children in Denmark would also fall under COPPA’s scope.
What is Personal Information as per COPPA?
In 16 C.F.R. Part 312.2, the COPPA Rule defines various terms, including children’s PI, website operators, parents, support services, etc. Under COPPA, personal information refers to any data that can be used to identify or contact a child, including the child’s full name, address, email, phone number, or identifiers like a Social Security Number. It also covers online identifiers like cookies, device IDs, IP addresses, or geolocation data, precise enough to point to a street location. Additionally, other forms of PI like photographs, video or audio recordings, screen names, and user IDs that can reveal a child’s identity, fall under this definition.
With the 2025 update to the COPPA Rule, biometric data like fingerprints, facial templates, and voice prints also fall under the scope of PI.
Regulation of Unfair & Deceptive Acts § 312.3
COPPA prohibits the use of unfair practices for collecting or disclosing children’s data, and requires website operators to:
- Provide a notice on the website that clearly specifies what information will be collected from children, how it will be used and disclosed, including transfer to any third party.
- Take verifiable consent from a parent or legal guardian before collecting or disclosing children’s PI.
- Offer a way for parents to review the information collected about their children and opt out of its further use, and request deletion of the data.
- Not require a child to share more PI than needed to play a game, enter a contest, or take part in any activity.
- Establish and maintain safeguards to protect the security, integrity and confidentiality of children’s PI.
Notice Requirements § 312.4
Under COPPA, websites that collect information from children must provide a clear and transparent notice to parents. The rule defines two types of notices: a direct notice to parents explaining what information will be collected and how it will be used, and an online notice outlining the website’s information practices. It further requires the website operator to:
- Provide options to seek parents’ verifiable consent.
- Disclose the identities of third parties with whom the children’s personal data is shared and the category they belong to.
- Ensure that parental consent for third-party disclosures is obtained separately from consent for collection and use by the website itself, unless such disclosure is integral to the service.
- Delete the information of parents or children that was used for providing notice and obtaining consent if parental consent is not received in a reasonable amount of time.
- Provide a hyperlink to the information practices notice that is available in a clear and easy to comprehend language and does not have any confusing or inconsistent content.
- State the name, address, contact number, and email ID of all the operators that collect children’s information via the website or the online service being provided.
- Ensure that notices are sent directly to parents where required.
Parental Consent Requirements § 312.5
Website operators must implement methods to verify that consent is given by the child’s parent or guardian only. These methods must be developed considering the available technology.
- Verifiable parental consent must be retaken if there is any material change in the collection, use, or disclosure practices after the previous consent.
- Consent verification methods may include signed forms, credit/debit card verification, phone or video verification, government ID checks, knowledge-based authentication using multiple choice questions, or email/text confirmation with follow-up verification.
- Follow safe harbor-approved parental consent methods when applicable, even if not explicitly listed, as long as they reliably verify the parent’s identity.
Rights of Parents § 312.6
As with other data privacy laws like CCPA and EU-GDPR, COPPA provides several rights to parents and legal guardians related to the collection, usage, and dissemination of children’s data. These rights include:
- Request details about the categories and types of PI collected.
- Refuse further usage or collection of PI.
- Review the collected information without having to face any undue burden.
Restriction on Conditioning for Participation § 312.7
Operators cannot require a child to provide more information than is reasonably necessary to participate in a contest, game, or activity.
Maintaining Confidentiality, Security, and Integrity of Children’s PI § 312.8
This section outlines the procedures that businesses must follow to ensure that children’s data remains confidential. These include:
- Establishing, implementing, and maintaining a written Information Security program that is based on the sensitivity of data involved. It must be handled by designated employees.
- Carrying out a yearly audit to check for risks to the confidentiality, security, and integrity of children’s data, while reviewing whether existing safeguards are strong enough. If gaps are found, the program should be updated with better technological or operational measures to keep the data safe.
- Designing and maintaining safeguards to mitigate the risks identified in the annual assessment.
Enforcement of COPPA § 312.9COPPA
Enforcement is done by the Federal Trade Commission under the FTC Act, subject to sections 6503 and 6505. COPPA violations can lead to significant financial penalties (Up to $53,088 per violation). Several businesses have been penalized by the FTC for violating provisions of COPPA. Below are a few prominent examples from recent years.
|
S.No.
|
Business/Company
|
COPPA Violation
|
Penalty
|
Month & Year
|
Link
|
|
1
|
The Walt Disney Company
|
Mislabeled kids’ content on YouTube, enabled data collection & targeted ads
|
$10 Million
|
Sep-25
|
FTC Press Release
|
|
2
|
Cognosphere, LLC (Genshin Impact)
|
Collected minors’ data without consent; unfair business practices & lootbox issues
|
$20 Million
|
Jan-25
|
FTC Press Release
|
|
3
|
Amazon.com, Inc. (Alexa)
|
Retained kids’ voice beyond the retention period, ignored deletion requests
|
$25 Million
|
Jul-23
|
DOJ Press Release
|
|
4
|
Microsoft Corporation (Xbox)
|
Collected/retained kids’ info during Xbox signups without notifying parents
|
$20 Million
|
Jun-23
|
FTC Press Release
|
|
5
|
Epic Games, Inc. (Fortnite)
|
Collected personal info without verifiable parental consent & used unfair default privacy and communication settings
|
$275 Million
|
Dec-22
|
FTC Press Release
|
|
6
|
Google LLC / YouTube
|
Improper handling of child-directed content; collected kids’ data without parental consent
|
$170 Million
|
Sep-19
|
FTC Press Release
|
Data Retention and Deletion Requirements § 312.10
COPPA requires website operators to establish and implement a written Data Retention Policy. This policy should specify the purpose for which children’s information is collected, business requirements for its retention, and the time frame for its deletion. It further states that:
- Information shall only be retained for as long as it is reasonably required to fulfill its purpose of collection.
- Once this collected information has served its purpose, it must be permanently deleted and safeguarded against unauthorized access or use.
- The data retention policy must be available on the website and should be easily accessible.
Data deletion must be done irrevocably using software like BitRaser, that helps erase data permanently from drives and devices, along with proof of data destruction for auditors.
Safe Harbor Programs § 312.11
Industry groups or organizations may apply to the FTC for approval of safe harbor programs that set compliance guidelines equal to or stronger than COPPA itself. The idea is to provide alternative complaint frameworks in order to protect children’s privacy and enforce against misconduct.
Voluntary Commission Approval Processes § 312.12
Businesses may request FTC approval for new parental consent methods not listed in § 312.5(b), provided they demonstrate that the method meets COPPA’s verification standards. The FTC may also authorize additional activities as “support for internal operations” where justified and consistent with protecting children’s privacy.
Conclusion: Role of Data Erasure in COPPA Compliance
Protection of children’s personal data is a top priority for any business that collects information from them. For this purpose, secure data erasure plays an important role in order to stay compliant with COPPA rules, especially 16 C.F.R. § 312.9, that mandates data deletion. By using data erasure standards like NIST 800-88 or IEEE 2883:2022, organizations can permanently erase a child’s personal information so it cannot be recovered, reducing the risk of data breaches or misuse.