Skip to main content
Federal Law Explainer · Reviewed September 2026

What Is Children's Online Privacy Protection Act?

COPPA is the federal law governing collection of personal information from children under 13 online. It applies to commercial websites, apps, games, connected toys, and other online services that are directed to children or have actual knowledge that they are collecting information from a child under 13. COPPA requires operators to provide a privacy policy and direct notice, obtain verifiable parental consent in covered circumstances, give parents continuing control over the child's information, maintain reasonable security, and limit retention. The FTC published final rule amendments on April 22, 2025; they became effective June 23, 2025, and most operator provisions had a compliance date of April 22, 2026, while some Safe Harbor provisions had earlier dates.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Children's Online Privacy Protection Act
Short code
COPPA
Enacted
1998
Last major update
Rule update 2013; FTC final rule amendments published April 22, 2025 (effective June 23, 2025; most operator provisions due April 22, 2026)
Jurisdiction
United States (federal)
Private right of action
No
Primary enforcer
FTC (primary); state Attorneys General (authorized actions); FTC-approved self-regulatory "safe harbor" programs

Scope, who COPPA covers

Operators of commercial websites and online services (including mobile apps, connected devices, IoT, smart toys, and plugins) that are either (a) directed to children under 13 or (b) have actual knowledge that they are collecting personal information from a child under 13. 'Operator' covers any entity that operates the site or collects/maintains personal information on behalf of the operator.

Protected data

Personal information from children under 13: first and last name, home address, email address, telephone number, SSN, persistent identifiers (cookies, device IDs, IP addresses when used to recognize a user over time), geolocation, photos/video/audio containing the child's image or voice, and, under the 2025 amendments, biometric identifiers and government-issued identifiers.

Consumer rights & protections

Parents have the right to receive direct notice of the operator's information practices

In covered circumstances, operators must obtain verifiable parental consent before collecting, using, or disclosing personal information from a child

Parents have the right to review what information has been collected about their child

Parents have the right to delete their child's information and refuse further collection

Parents have the right to refuse to permit further use or disclosure of collected information

As of 2025 amendments: separate parental consent required for disclosure to third parties, including for targeted advertising

Notable features

COPPA has a detailed verifiable-parental-consent framework, and the FTC describes several acceptable consent methods subject to the rule's conditions. Congress has also considered proposals that would expand protections to older minors, but proposed legislation is not part of the current COPPA rule unless enacted. Keep enacted requirements separate from proposals and check the FTC and Congress for status changes.

Enforcement & penalties

Enforcing agency: FTC (primary); state Attorneys General (authorized actions); FTC-approved self-regulatory "safe harbor" programs

Penalties: COPPA violations can result in civil penalties, with the maximum amount adjusted over time and the assessed amount depending on the facts, number of children, information involved, prior conduct, and other factors. State Attorneys General may also bring authorized actions. Check the FTC's current COPPA guidance for the applicable amount rather than relying on an older figure.

Private right of action: COPPA has no private right of action at the federal level. Enforcement is through the FTC and state AGs (authorized by 15 USC § 6504). Some state consumer-protection laws have been used to bring derivative claims based on COPPA violations.

Landmark enforcement cases

FTC v. Epic Games (Fortnite)

2022

Epic Games paid $275M in a COPPA civil-penalty settlement for collecting personal information from children under 13 without verifiable parental consent, plus a separate $245M refund order for alleged dark-pattern billing practices. The FTC described the COPPA penalty as the largest at the time; later cases and remedies should be checked separately.

Official source →

FTC v. YouTube

2019

YouTube and Google paid $170 million for collecting personal information from viewers of child-directed channels without parental consent, the largest COPPA settlement at the time. The case drove YouTube's creation of the 'made for kids' designation.

Official source →

FTC v. TikTok (Musical.ly)

2019

Musical.ly (now TikTok) paid $5.7M, at the time the largest COPPA penalty, for knowingly collecting personal information from children under 13 without parental consent.

Official source →

Relevance to data brokers

COPPA obligations primarily attach to covered operators and the relationships described in the rule. A broker or downstream recipient may face other legal or contractual consequences when it receives children's information, but COPPA coverage should not be inferred solely from the fact that a dataset may include minors. Check the operator, disclosure, consent, and service-provider facts against the current rule.

Generate requests in under 60 seconds

Generate removal requests for 1,034 US/global profiles, $9

Review the provider route, applicable law, and information you intend to send. You send from your own inbox and remain in control of the request; a draft is not a legal determination or provider outcome.

Frequently Asked Questions

What age does COPPA cover?

+

COPPA covers children under 13. Once a user turns 13, COPPA's specific parental-consent requirements generally no longer apply, although other laws may. Proposals to expand protection to older minors should be treated as proposals unless Congress enacts them.

What is a COPPA Safe Harbor Program?

+

Under Section 504 of COPPA (15 U.S.C. § 6503), industry groups and self-regulatory organizations can submit COPPA compliance guidelines to the FTC for approval as "Safe Harbor" programs. An operator that complies with an approved program's guidelines may be deemed in compliance with the COPPA Rule, while the program conducts required assessments and discipline; the FTC retains oversight and enforcement authority, and other laws may still apply.

What is COPPA 2.0 and the 2025/2026 FTC Rule Update?

+

COPPA 2.0 is a label used for legislative proposals that would expand protections beyond the current under-13 framework. It is separate from the FTC's 2025 COPPA Rule amendments, which became effective June 23, 2025 and had a primary operator compliance date of April 22, 2026. Check the current Federal Register notice and Congress record before describing a proposal as law.

Does COPPA apply to schools?

+

Schools can provide consent on behalf of parents when the operator is collecting the information solely for the use and benefit of the school (for educational purposes). This is NOT a blanket exemption, commercial uses of student data still require parental consent, which is a recurring FTC enforcement focus.

What is COPPA 2.0?

+

COPPA 2.0 is not the name of the current COPPA statute. It is commonly used for proposed legislation that would broaden age coverage or add rights such as deletion and data minimization. Confirm the bill number and current Congress.gov status before relying on any proposal as law.

Official sources & citations

Other federal privacy laws

Federal privacy law is sectoral, each statute covers a specific data type or industry. Here are the other federal regimes to know alongside COPPA:

Related concepts & guides