Personal Reputation

COPPA Explained: What the Children’s Privacy Law Means for Families

A plain-English guide to COPPA: who the law covers, what verifiable parental consent means, the rights parents have over a child's data, and what COPPA doesn't do.

By Editorial Team 10 min read
A tablet on a wooden desk beside colored pencils and a notebook in soft daylight

COPPA, the Children’s Online Privacy Protection Act, is a US federal law that limits how websites, apps and online services collect personal information from children under 13. Services directed to children, or that know they are collecting data from a child under 13, must give parents clear notice and get verifiable parental consent first, and parents can review the data, ask for it to be deleted and stop further collection. The Federal Trade Commission (FTC) enforces it through the COPPA Rule, which it updated in 2025.

COPPA is the reason so many apps ask for a birthdate and set a minimum age of 13. It’s an important protection, but it’s narrower than many parents assume. This guide explains what it covers, what rights it gives you, and where your own choices still matter most.

What COPPA is and why it exists

Congress passed COPPA in 1998, and the FTC’s rule putting it into practice took effect in 2000. The idea was simple: young children can’t meaningfully understand or agree to data collection, so their parents should decide.

The law doesn’t ban children from the internet or require any particular content standard. It’s a privacy law. It controls what personal information an operator can collect from a young child, what the operator must tell parents, and what it must do to protect and eventually delete that information.

The FTC has revised the rule over time to keep up with technology. A 2013 update expanded the definition of personal information to include things like persistent identifiers used for tracking, photos, videos and voice recordings. The 2025 update, covered below, tightened the rules again.

Who COPPA applies to

COPPA applies to operators of commercial websites, apps, games, connected toys and other online services in two situations:

  • The service is directed to children under 13. The FTC looks at factors such as subject matter, visual content, animated characters, child-oriented activities, music, the age of models, advertising and evidence about the actual audience.
  • The operator has actual knowledge that it is collecting personal information from a child under 13, even if the service is aimed at a general audience. If a user tells a general-audience app they are 9, the app can’t simply ignore it.

Some services are “mixed audience”: aimed at children but not only at them. Those can ask users their age in a neutral way and apply COPPA protections to the users who say they are under 13.

COPPA also reaches third parties, such as ad networks or plugins, that know they are collecting personal information through a child-directed service. It is mainly enforced by the FTC, but state attorneys general can also bring cases under it.

What counts as personal information

The definition is broad. It includes a child’s name, home address, email or other online contact details, phone number, screen name when it works as contact information, geolocation precise enough to identify a street, photos, videos or audio containing the child’s image or voice, and persistent identifiers such as device IDs or cookies used to recognize a user over time. The 2025 update added biometric identifiers, such as fingerprints and facial templates, to the list.

Before a covered service collects, uses or discloses a child’s personal information, it must post a clear privacy policy, send parents a direct notice, and get consent using a method reasonably designed to confirm the person agreeing is actually the parent.

The FTC has recognized several methods, including:

  • A signed consent form returned by mail, fax or scan.
  • A credit card, debit card or other payment transaction that notifies the account holder.
  • A call or video conference with trained staff.
  • Checking a government-issued ID against a database, then deleting the ID.
  • Other methods the FTC has approved, such as certain knowledge-based questions or face-matching against an ID.

There are limited exceptions. A service can collect a parent’s contact details just to ask for consent, respond once to a child’s request without keeping the data, or collect what’s needed for the site’s security. Schools can also consent on a parent’s behalf for educational tools used only for school purposes, not for commercial ones.

Your rights as a parent under COPPA

If a service is covered and has collected your child’s information, COPPA gives you real options. You can:

  1. Review the information. Ask the operator what personal information it holds about your child. It must verify you are the parent first.
  2. Have it deleted. Ask the operator to delete your child’s personal information.
  3. Revoke consent. Tell the operator to stop collecting or using your child’s information going forward.
  4. Consent to collection but not to sharing. You can agree to let a service collect data it needs to work while refusing permission to share it with third parties.
  5. Expect limits on what’s demanded. A service can’t make a child’s participation in a game or activity depend on handing over more information than is reasonably necessary.

To use these rights, start with the service’s privacy policy, which must say how parents can contact the operator. Put your request in writing, keep a copy, and give the account name or username so they can find the data.

What changed in the 2025 COPPA Rule update

The FTC finalized amendments to the COPPA Rule in early 2025, with most obligations taking effect over the following year. In general terms, the update:

  • Requires separate parental consent before a covered service discloses a child’s information to third parties, for example for targeted advertising, unless that disclosure is integral to the service.
  • Limits data retention. Operators must keep children’s personal information only as long as reasonably necessary for the purpose it was collected, can’t keep it indefinitely, and must have a written retention policy.
  • Requires a written information security program scaled to the sensitivity of the data.
  • Expands personal information to include biometric identifiers.
  • Strengthens oversight of the FTC-approved safe harbor programs that some companies use to show compliance.

For parents, the practical effect is that covered services should be asking you more specific questions, especially about sharing your child’s data for advertising, and holding that data for less time.

What COPPA doesn’t do

Knowing the limits helps you decide where to spend your effort.

COPPA does COPPA doesn’t
Limit what covered services collect from children under 13 Protect teens aged 13 to 17 in the same way
Give parents rights to review and delete data a service holds Control what parents, relatives or schools post about a child
Require consent before collecting and, since 2025, separately before sharing for ads Stop a child from lying about their age to join an app
Let the FTC and state attorneys general bring enforcement actions Give parents a direct right to sue a company under COPPA itself
Cover persistent identifiers, photos and voice recordings Moderate content, chat or contact from strangers

That second row matters for reputation. Photos and stories you share about your child are outside COPPA entirely. Our guide on protecting your child’s online reputation covers the posting habits that fill that gap.

Why age gates don’t solve everything

Most general-audience social apps comply with COPPA by not allowing under-13s at all. The weak point is obvious: a child who types an older birth year gets in, and the service may not have actual knowledge they are younger.

That’s why many platforms now combine age screens with teen accounts, age estimation, family pairing and supervision tools. Our guide to parental controls for social media explains how to set those up in a way that works with your child rather than against them. For gaming platforms popular with younger children, see our guide on Roblox safety for parents.

A worked example

This is an illustrative scenario, not a real family or client.

Marisol’s 10-year-old daughter, Ana, has been using a drawing app aimed at kids. Marisol never remembers agreeing to anything, but she notices Ana has a public gallery with her first name, a selfie as her avatar and a list of “friends”.

  1. She checks the privacy policy. It says the app is designed for children and describes how parents can contact the company about their child’s data.
  2. She writes to the operator. Her email asks what personal information the app holds on Ana’s account, asks for it to be deleted, and says she does not consent to any further collection or sharing. She includes the username and keeps a copy.
  3. She follows up. The company asks her to verify she’s the parent, then confirms the account and associated data have been deleted.
  4. She searches Ana’s name and username in a private browser window and finds the gallery page still showing in results. Once the page is gone from the app, she uses Google’s tools for outdated content to request a refresh.
  5. She sets up a new, supervised account with a nickname, a drawn avatar and a private gallery.

If the company had ignored her, Marisol could have reported it to the FTC. Response times and outcomes vary, but a clear written request to the operator is almost always the fastest first step.

Not sure where to start?

Get a free audit of your search results and review profiles, with a prioritized fix list.

Get a free audit

How to report a possible COPPA violation

If you believe a child-directed service collected your child’s information without consent, or ignored your request to delete it, you can report it to the FTC through its online complaint portal at ReportFraud.ftc.gov. The FTC doesn’t resolve individual complaints, but reports help it spot patterns and choose cases. It has brought COPPA cases against major companies, including a 2019 settlement with Google and YouTube over data collected from viewers of children’s channels and a 2022 settlement with Epic Games over Fortnite.

You can also contact your state attorney general’s office. If your child’s information has been exposed in a data breach, or you are considering legal action over harm to your child, talk to a lawyer about your options, because COPPA itself doesn’t give families a private right to sue.

Common mistakes parents make about COPPA

  • Assuming it covers teens. A 14-year-old’s data is treated differently, so settings and conversations matter more at that age, not less.
  • Helping a child lie about their age. It’s tempting to type an older birthdate so a child can join an app. It removes COPPA protections and often switches on adult defaults, such as public profiles and messages from strangers.
  • Thinking COPPA controls what others post. Relatives, schools and other parents posting your child’s photos is a separate issue, handled through platform reports and direct conversations.
  • Not using the deletion right. When a child outgrows an app, ask the operator to delete the account and data rather than just deleting the app from the device.

If your child has already been exposed online in ways that are hard to fix on your own, such as images or posts spreading across several sites, our personal reputation management team can help with removals and search results, and we’ll tell you honestly what can and can’t be done.

Frequently asked questions

What does COPPA stand for?

COPPA stands for the Children’s Online Privacy Protection Act, a US federal law passed in 1998. The FTC enforces it through the COPPA Rule, which sets out what covered websites, apps and online services must do before collecting personal information from children under 13.

What age does COPPA apply to?

COPPA applies to children under 13. It doesn’t give teens aged 13 to 17 the same protections, which is why many social platforms set 13 as their minimum age and offer separate teen account settings.

Can I make a company delete my child's data under COPPA?

Yes, if the service is covered by COPPA. You can ask the operator to review and delete your child’s personal information and to stop collecting more. The operator may ask you to verify you are the parent before it acts.

Does COPPA apply to YouTube and other video sites?

COPPA applies to content and services directed to children, including children’s content on general platforms. After the FTC’s 2019 settlement with Google and YouTube, YouTube requires creators to label content made for kids and limits data collection and certain features on it.

Can I sue a company for violating COPPA?

COPPA doesn’t give parents a private right to sue under the law itself. Enforcement comes from the FTC and state attorneys general. Other state laws may offer routes, so talk to a lawyer if your child has been harmed.

Editorial Team

The 123 Reputation Management editorial team writes practical guides on reviews, search results and online reputation.

Start with step 1

See what people see when they search for you.

Get a free, no-obligation reputation audit covering search results, review profiles and social mentions, with clear next steps.