PRIV-03 Privacy, Cyber & AI Data Under Duty Federal + state overlay
Children's Online Privacy: COPPA Coverage, Parental Consent, and Age-Assurance Questions
Most children's privacy disputes begin with whether the rule applies at all. This brief works the coverage test first, then consent mechanics, the recently amended FTC Rule, and the unsettled state layer.
Briefing in 60 seconds
- COPPA reaches operators of services directed to children under 13 and operators with actual knowledge they collect a child's personal information.
- Verifiable parental consent must precede collection, and the FTC recognizes specific methods rather than any reasonable-looking age gate.
- The FTC finalized amendments to the COPPA Rule in 2025, effective that year with certain compliance obligations extending into 2026.
- State teen-privacy and age-assurance statutes add duties beyond COPPA, and several remain under active First Amendment challenge.
Controlling variables
- Facts
- Whether the service's subject matter, visuals, characters, music, and audience evidence make it directed to children under 13 under the FTC's multi-factor test.
- Status
- Whether the operator has actual knowledge of a child user, which converts a general-audience service into a covered one for that user.
- Jurisdiction
- Which state minor-protection statutes apply to the user base, since several impose duties beyond COPPA and several are enjoined in part.
- Documents
- Whether direct notice to parents, the online privacy notice, and the consent record together prove consent preceded the first collection.
- Contract terms
- Whether third parties receiving child data are limited by contract, since disclosure to advertisers and analytics vendors is treated separately from collection.
General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.
Children's privacy work almost never starts with a consent flow. It starts with a coverage question: does the federal rule reach this service at all? The Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506, and the FTC's implementing Rule apply to two groups — operators of websites and online services directed to children under 13, and operators of general-audience services that have actual knowledge they are collecting personal information from a child under 13.
Get that classification wrong and everything downstream is wrong. A service that is covered but believes it is not has collected data without consent. A service that treats itself as covered when it is not may build an age gate that creates the very knowledge it was trying to avoid.
The coverage test comes first
"Directed to children" is not a self-declaration. The FTC applies a multi-factor assessment that looks at subject matter, visual content, use of animated characters or child-oriented activities, music and audio, the age of models, the presence of child celebrities or celebrities who appeal to children, advertising placed on the service, and competent, reliable evidence about actual audience composition or intended audience.
No single factor decides it. A gaming app with cartoon art and a nineteen-year-old median user is not automatically covered; a homework tool with plain design and a nine-year-old user base very likely is. The analysis is evidentiary, and the evidence a regulator will use — your own analytics, marketing decks, app-store category, and influencer partnerships — is already in your files.
| Classification | How it arises | Core obligation |
|---|---|---|
| Directed to children | The multi-factor test points to an under-13 audience as a primary target | Treat every user as a child: direct notice to parents and verifiable consent before any collection |
| Mixed audience | Child-appealing content, but children are not the primary audience | Neutral age screen permitted; apply full protections only to users who identify as under 13 |
| General audience with actual knowledge | A user states an age under 13, a parent reports it, or internal signals make it plain | Obligations attach to that user immediately; delete or obtain consent, and stop further collection |
| Outside COPPA | No child-directed indicators and no actual knowledge | State minor-protection statutes and general privacy law may still apply |
Two traps recur. The first is willful blindness: teams avoid asking ages so they can avoid knowledge, but the directed-to-children test does not depend on knowledge at all. The second is the non-neutral age gate. A screen that says "you must be 13 to continue" invites a false answer; a neutral screen asks for a birth date without signaling the right answer and does not let a user retry after rejection.
What verifiable parental consent requires
Verifiable parental consent means reasonable efforts, given available technology, to ensure that the person giving permission is actually the child's parent. The Rule works from a list of recognized methods rather than a general reasonableness standard, and the FTC also operates a process for approving new methods on application.
Recognized approaches include a signed consent form returned by mail, fax, or scan; a payment-card transaction that provides notice of the charge; a phone or video call with trained personnel; verification of a government-issued identification checked against a database and then deleted; and knowledge-based authentication. A narrow "email plus" option — an email to the parent with a delayed confirmation step — is available only when the child's information is used internally and never disclosed.
Three details decide most compliance reviews. Consent must precede collection, not follow it. Direct notice to the parent is a separate document from the online privacy notice and must state what is collected, how it is used, and that the parent may refuse or later revoke. And the parent must be able to review the child's information and demand deletion without losing the ability to say no to further collection.
- Online privacy notice describing operators, data categories, uses, disclosure recipients, and parental rights.
- Direct notice to the parent sent before collection, matched to the consent method used.
- Consent record retained with a timestamp preceding the first collection event for that user.
- A working parental request channel for review, deletion, and revocation, staffed and time-bounded.
- A written retention schedule showing that child data is kept only as long as needed for the stated purpose.
- Contracts with every downstream recipient limiting use of child data and requiring deletion.
- A no-conditioning check confirming participation in an activity is not tied to collecting more data than necessary.
The Rule as recently amended
The FTC finalized amendments to the COPPA Rule in 2025. The amended Rule took effect that year, with certain compliance obligations phased in during the following months and into 2026. The direction of the changes is consistent: tighter limits on downstream sharing, more explicit security and retention duties, and an expanded view of what counts as personal information.
Practically, operators should expect to obtain consent for disclosure to third parties separately from consent to collect — meaning a parent who allows a child to use a service has not thereby allowed targeted advertising or data sales. Operators should also expect an express written children's data security program, a written retention policy that forecloses indefinite retention, and treatment of a biometric identifier as personal information when it can identify a child.
Verify before relying: the amended Rule's staged compliance dates are the single most fact-sensitive item in this brief. Confirm the operative text and the applicable date on the FTC's COPPA Rule page before building to any specific deadline.
Because biometric identifiers now sit inside the children's framework, services that use face-based age estimation, voice features, or liveness checks are running two regimes at once. The state biometric statutes described in our brief on biometric privacy laws apply on their own terms, and Illinois exposure does not disappear because a parent consented under federal law.
The state layer, and why it is contested
COPPA sets a federal floor for under-13 users. States have built above it, and that construction is unsettled. Broadly, four categories exist as of mid-2026: age-appropriate design codes imposing default-privacy and design duties; social-media statutes requiring parental consent for minor accounts; age-verification statutes for specified categories of content; and teen provisions inside comprehensive privacy laws, several of which prohibit targeted advertising or data sales involving users under sixteen or eighteen without opt-in consent.
The first three categories have drawn sustained First Amendment litigation, and outcomes have been mixed rather than uniform. Design-code provisions compelling content judgments have been enjoined in part. Several social-media parental-consent statutes have been blocked in whole or in part. In 2024 the Supreme Court's decision in the NetChoice cases sent facial challenges back for a more careful analysis of a law's full range of applications, and in 2025 the Court upheld a Texas requirement of age verification for sites hosting material harmful to minors. The practical read: age verification tied to sexual content has survived, while broader speech-adjacent mandates remain genuinely uncertain.
The teen provisions inside comprehensive privacy statutes have attracted far less constitutional attention and are, for most businesses, the more predictable obligation. They are also the ones most likely to catch a general-audience service that never thought of itself as a children's product.
Operational sequence for a mixed service
- Classify honestly
Document the directed-to-children analysis with the evidence a regulator would gather: analytics on age distribution, marketing materials, store category, and the design choices in the product itself. Keep the memo current when the product changes.
- Build the age screen correctly
If you rely on mixed-audience treatment, use a neutral birth-date collection that does not disclose the cutoff, does not allow re-entry after rejection, and is not skippable through a social login.
- Route the under-13 path
Send direct notice and obtain consent by a recognized method before any collection. Suspend feature access rather than collecting first and papering later.
- Close the third-party doors
Disable advertising identifiers, analytics SDKs, and social plug-ins on child sessions by default. Separate consent is required for disclosure, and vendor code is where most unintentional disclosure happens.
- Handle knowledge events
Give support staff a defined script for reports that a user is under 13, with a fixed window to suspend collection, notify the parent, and delete. Knowledge that sits in a ticket queue is still knowledge.
- Re-test annually
Audience composition drifts. Re-run the classification, re-verify the consent method still functions, and confirm retention deletions actually executed.
Vendor management carries unusual weight here, because a children's service rarely leaks data itself — it embeds something that does. Contracts should prohibit use of child data for model training or profile building, require deletion on termination, and provide indemnification for regulatory claims arising from the vendor's own processing. Where analytics or recommendation features are involved, the negotiation register in contracting with AI vendors transfers directly.
Questions the desk gets
Our app is for teenagers. Does COPPA apply?
Not on its face, since the statute covers children under 13. But two things follow. If younger children are in fact using the service and you learn it, actual knowledge attaches for those users. And several state privacy laws impose opt-in requirements for targeted advertising and data sales involving minors well above 13. A teen product is regulated; it is simply regulated by a different set of rules.
Is a checkbox saying "I am a parent" ever sufficient?
No. Self-declaration is the paradigm case of what verifiable consent is designed to exclude. The Rule works from recognized methods that create some friction — a payment transaction, an identification check, a live call, a returned form. If a method costs nothing and proves nothing, assume it fails.
What happens if we discover child data we collected without consent?
Stop collecting from that account, isolate the data, and decide between obtaining consent and deleting. Deletion is usually cleaner. Document the discovery, the scope, and the remediation, and assess whether any downstream recipient must also delete. If the exposure came from a security event rather than a design gap, the sequencing in data-breach response and notification governs the first hours.
Do state age-assurance laws require us to verify every user's age?
It depends entirely on the state and the content. Age verification obligations have been upheld for sites distributing sexual material harmful to minors, while broader mandates covering general social platforms have faced injunctions. There is no single national answer as of mid-2026, and a compliance plan built on one state's statute will not transfer cleanly to another.
Does a safe harbor program eliminate FTC risk?
An FTC-approved safe harbor program can substitute its own approved guidelines for direct Rule compliance and provides structured review, which many operators find valuable. It does not immunize an operator that fails to follow those guidelines, and the amendments increased transparency expectations for the programs themselves.
Sequencing the work
Do the classification memo first and date it. Everything else — consent method, notice text, vendor controls, retention schedule — is derived from that single determination, and a decision made without documentation is difficult to defend later even when it was correct.
Then fix the highest-consequence item, which is almost always third-party disclosure rather than first-party collection. Disabling advertising and analytics on child sessions removes the largest category of unconsented sharing in a single change. Confirm the current requirements against the FTC's children's privacy guidance and the statutory definitions at 15 U.S.C. § 6501, then set a calendar review because this area moves. Adjacent obligations are collected on the Privacy, Cyber & AI desk.
Sources
Atlas Research Desk
ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.