What It Is

COPPA is a consent-first law: before collecting personal information from a child under 13, an operator owes parents clear notice and must obtain verifiable parental consent.

The 2025 amendments sharpened the Rule in ways that matter operationally (Federal Register, April 22, 2025):

  • A written information security program is now explicitly required.
  • A written data retention policy is required, with retention limited to as long as reasonably necessary - indefinite retention is off the table.
  • Separate verifiable parental consent is required before disclosing children's personal information to third parties, including for targeted advertising.
  • A mixed-audience category was defined, with age-screening requirements for services that appeal to children and adults alike.

The FTC also approves safe harbor programs (16 CFR 312.11): an operator participating in an approved program is deemed in compliance with the Rule - a practical route worth knowing exists.

What Information Is Regulated

COPPA defines personal information broadly when it relates to children:

  • Full name
  • Home or email address
  • Phone number
  • Username or online identifier
  • IP address or device identifiers
  • Geolocation data
  • Photos, videos, or audio recordings of a child
  • Persistent identifiers used for tracking (cookies, advertising IDs)
  • Biometric identifiers - added by the 2025 amendments: fingerprints, handprints, retina and iris patterns, voiceprints, facial templates, gait patterns, and DNA (16 CFR Part 312)
  • Any information that can identify or contact a child

From an IT perspective, even metadata and tracking technologies can trigger COPPA obligations. A single embedded analytics script can put a service in scope.

IT Requirements

COPPA requires reasonable procedures to protect children's data - and, under the 2025 amendments, a written information security program and a written data retention policy. Key expectations:

Parental notice and verifiable consent. Clear notice of data collection practices, verifiable parental consent before collection, separate consent before disclosing to third parties (including targeted advertising), and secure storage of consent records.

Data minimization. Collect only what is necessary. Avoid persistent identifiers where possible, and disable unnecessary tracking and analytics - especially third-party scripts.

Strong security safeguards. The written security program in practice: access controls and least-privilege permissions, encryption at rest and in transit, secure cloud and application configurations, and logging and monitoring of access.

Data retention and deletion. A written retention policy, retention limited to as long as reasonably necessary, and secure deletion when data is no longer needed. Indefinite retention is not permitted.

Vendor and third-party oversight. Ensure embedded third-party services comply, restrict vendor data use, and maintain contracts and documentation. COPPA failures often start in a plugin nobody audited.

Why this lands on IT and security teams

COPPA compliance often fails not because of intent, but because of how systems are configured. Common risk areas: analytics or ad tools collecting persistent identifiers, inadequate age-gating, weak parental consent workflows, over-collection, poor access control or retention practices, and third-party plugins collecting data outside your visibility. FTC enforcement actions have cited technical misconfigurations, not just policy failures.

How It Fits Into Cyber Risk Management

COPPA's written security program requirement is a program requirement - exactly what a structured approach delivers.

Governance, Risk & Compliance maintains the written policies, consent records, and documentation the amended Rule demands. Cyber Risk Management hardens the systems handling children's data and keeps tracking technologies visible and intentional. Third-Party Assessments audit the analytics, advertising, and plugin vendors where COPPA violations most often originate.

COPPA does not invent new security - it raises the stakes when children's data is involved.

How We Help With COPPA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment traces every point where children's data enters your systems - including third-party scripts - and tests your consent workflows, security program, and retention practices against the amended COPPA Rule.

How to Prepare

  1. Identify child-related data flows

    Document where children's data is collected, which systems store it, who has access, and which vendors receive it. Include the third-party tools embedded in your services - they are part of your data flow whether you chose them deliberately or not.

  2. Review age-gating and consent mechanisms

    Confirm age screening is effective (including for mixed-audience services), parental consent is verifiable, separate consent exists for third-party disclosures, and consent records are stored securely.

  3. Harden systems handling children's data

    MFA for administrative access, encryption, secure APIs and integrations, and logging and monitoring. This is the substance behind the written information security program the Rule now requires.

  4. Write the required documents

    The 2025 amendments require a written information security program and a written data retention policy with defined limits. Draft them to match what your systems actually do - then fix whichever side of that comparison is wrong.

  5. Review third-party tools

    Audit analytics platforms, advertising tools, embedded plugins, and cloud providers. Many COPPA violations stem from third-party data collection the operator never saw.

  6. Train staff

    Employees should understand COPPA basics, data handling restrictions, incident reporting procedures, and why children's data requires extra care.

Official source

Official source: Federal Trade Commission - COPPA Rule

Secondary source: eCFR - 16 CFR Part 312

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25