COPPA (Children’s Online Privacy Protection Act)

A 1998 U.S. federal law (effective 2000) restricting how sites and services collect personal information from children under 13. It applies to any site or app directed at children under 13 — judged by subject matter, visual/audio style, animated characters, and similar cues — or to any operator with actual knowledge that a user under 13 is providing information, regardless of the site’s general audience.

A 1998 U.S. federal law (effective 2000) restricting how sites and services collect personal information from children under 13.

Determine whether the law applies before designing around it

A site doesn’t need to be a “kids’ site” to trigger COPPA — actual knowledge is enough, and actual knowledge can come from the interface’s own design. Asking a birthdate on registration, or an age-identifying question like “what grade are you in?”, creates that knowledge the moment a user answers honestly; a site can’t then require more information than the activity actually needs as a workaround, per the general prohibition on conditioning participation on excessive data collection.

A site doesn’t need to be a “kids’ site” to trigger COPPA — actual knowledge is enough, and actual knowledge can come from the interface’s own design.

A general-audience site that screens for age has to keep that screen genuinely neutral — no framing nudging a user toward one answer over another — and can then rely on whatever age a user enters, even an inaccurate one; the FTC’s own obligation attaches to what the site does with the answer, not to catching every miskeyed age. A “mixed audience” site (not aimed at children, but not excluding them either) can use an age screen too, but only if it asks age before collecting any other personal information and gates further collection for anyone who answers under 13 behind COPPA’s notice-and-consent steps. A site actually directed to children doesn’t get this option at all — unlike a general-audience site, it can’t use an age screen to simply turn child users away; it has to go through parental notice and consent instead.

Before collecting personal information from a known child under 13, an operator needs verifiable parental consent. The FTC applies a sliding scale rather than one fixed method: lower-risk internal uses can accept lighter verification (email confirmation plus a follow-up check, “email plus”), while disclosure to third parties calls for stronger verification — a signed form, a credit-card or payment confirmation, a phone or video call, or matching a submitted photo against a government ID. Choosing which tier applies is itself a design decision, not just a legal one.

Minimize what’s collected and how long it’s kept

Children’s data should be limited to what a given activity actually needs, and retained only as long as that purpose requires before deletion. A 2013 update extended this to persistent identifiers (tracking cookies, device IDs) — these now need the same parental notice and consent as other personal information, unless used solely for internal site operations with no other collection.

Give parents visibility and control

Parents must have a reasonable way to review what’s been collected about their child, and to refuse further collection or request deletion. In practice this needs a clear, discoverable path to a parental-account view or request channel — the same review/delete/refuse triad Fair Information Practices already establishes as a general baseline, applied here with no age-appropriate exceptions.

Parents must have a reasonable way to review what’s been collected about their child, and to refuse further collection or request deletion.

Patterns

Standards

Sources

Children's Online Privacy Protection Act (Wikipedia) is this page’s original source for COPPA’s “directed at children”/actual-knowledge trigger, the FTC’s risk-calibrated verifiable-parental-consent sliding scale, the 2013 persistent-identifier update, and the parental review/refusal/deletion rights.

Complying with COPPA: Frequently Asked Questions (FTC) (public domain) is the FTC’s own compliance FAQ, the source for the neutral-age-screen and mixed-audience-site age-gating guidance above.

Created Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time) Updated Thu Aug 27 2026 00:00:00 GMT+0000 (Coordinated Universal Time)