COPPA Rule: Children’s Online Privacy Protection Act (16 CFR Part 312) United States silhouette

COPPA Rule: Children’s Online Privacy Protection Act (16 CFR Part 312)

Effective Date: 2000-04-21

The COPPA Rule and the Children’s Online Privacy Protection Act apply to any website or online service directed to children under 13, or any operator that knows it is collecting personal information from children under 13. That reach can include ordinary small business sites that run child-directed content or collect birthdates.

Core COPPA Rule Requirements

Covered operators must post a clear children’s privacy notice, obtain verifiable parental consent before collecting personal information, let parents review and delete their child’s data, and keep data only as long as needed.

The 2025 Amendments and 2026 Deadline

The FTC’s amended rule, published April 22, 2025 and effective June 23, 2025, required full compliance by April 22, 2026. It expands personal information to include biometric identifiers, requires separate parental consent before disclosing children’s data to third parties such as ad networks, and requires a written information security program plus a written data retention policy that bars indefinite retention. Civil penalties can exceed $50,000 per violation, and the FTC has made COPPA an enforcement priority, so any site touching children’s data should treat these duties as non-negotiable.

Source: United States Code: 15 U.S.C. 6501-6506; 16 CFR Part 312

Report a violation: If you believe a business is violating this law, you can file a complaint at FTC Fraud Report.

More Rules & Regulations