For years, many organizations treated COPPA compliance primarily as a parental consent requirement.
That is no longer enough.
The Federal Trade Commission updated the Children’s Online Privacy Protection Rule in 2025, strengthening requirements around children’s personal information, third-party disclosures, targeted advertising, retention, security, and parental control.
Those changes now matter operationally.
For most amended provisions, the FTC provided 365 days from publication of the final rule in April 2025 for organizations to come into full compliance.
But the larger compliance challenge is not simply updating a privacy notice or adding another consent screen.
Organizations need to answer a harder question:
Can you identify children’s personal information wherever it exists, understand why you have it, know who can access it, determine where it goes, and prove that you delete it when you no longer need it?
That question exposes one of the biggest gaps in children’s privacy programs.
Consent happens at collection. Risk follows the data.
Children’s information can move from an app into analytics platforms, cloud environments, data lakes, advertising technology, customer platforms, logs, AI systems, third-party services, backups, and other repositories.
Modern COPPA compliance therefore requires organizations to govern the lifecycle of children’s data, not simply the point where they collect it.
COPPA Compliance: Key Takeaways
• COPPA changed significantly. The FTC’s amended Rule strengthens requirements around third-party disclosures, targeted advertising, security, retention, parental control, and covered personal information.
• Consent alone does not create compliance. Organizations need visibility into where children’s data resides, why teams process it, who can access it, where it flows, and how long they retain it.
• Biometric and government-issued identifiers now receive explicit treatment as personal information under the amended Rule. Children’s data inventories need to reflect the expanded definition.
• Third parties create material exposure. SDKs, advertising technology, analytics, plug-ins, cloud services, AI tools, and other providers can collect or receive children’s personal information.
• Retention requires operational control. Organizations need to connect each purpose for collecting children’s information with a defensible retention period and deletion process.
• BigID connects compliance requirements to the data itself. BigID helps organizations discover and classify personal data, understand its context and movement, manage consent and data rights, apply retention policies, assess risk, and coordinate remediation.
What Is COPPA?
The Children’s Online Privacy Protection Act, or COPPA, is a U.S. federal law governing the online collection of personal information from children under 13.
The Federal Trade Commission implements COPPA through the Children’s Online Privacy Protection Rule, found at 16 CFR Part 312.
COPPA applies to operators of commercial websites and online services directed to children under 13 that collect personal information. It can also apply to operators of general-audience services when they have actual knowledge that they collect personal information from children under 13.
Covered operators must address requirements involving:
- Privacy notices
- Direct notice to parents
- Verifiable parental consent
- Parental review and deletion rights
- Limits on data collection
- Third-party disclosures
- Data security
- Data retention and deletion
COPPA does not simply regulate names and email addresses.
Its definition of personal information reaches several types of information that digital services routinely collect behind the scenes.
What Changed Under the Updated COPPA Rule?
The FTC finalized major amendments to the COPPA Rule in January 2025, and the final amendments appeared in the Federal Register on April 22, 2025.
The changes reflect how dramatically children’s digital environments have evolved since the FTC last substantially revised the Rule.
What Counts as Personal Information Under COPPA?
One of the easiest ways to underestimate COPPA exposure is to search only for conventional personally identifiable information.
COPPA’s scope extends beyond a child’s name.
Depending on the circumstances, covered personal information can include:
- First and last name
- Home or physical address
- Email and other online contact information
- Telephone numbers
- Usernames or screen names when they function as online contact information
- Persistent identifiers such as cookies, IP addresses, device identifiers, and similar identifiers
- Photos, videos, or audio containing a child’s image or voice
- Precise geolocation information
- Government-issued identifiers
- Biometric identifiers used for automated or semi-automated recognition
- Other information about a child or parent when combined with an identifier covered by the Rule
This matters because some of the highest-risk COPPA data may never appear in a customer profile.
It may sit inside logs, images, audio, device telemetry, analytics platforms, SDK output, authentication systems, advertising infrastructure, or machine-learning pipelines.
Know Where Children’s Data Lives
Find sensitive data before it becomes a compliance blind spot
Discover and classify personal and sensitive information across structured and unstructured enterprise data and connect it to privacy, governance, security, and lifecycle controls.
Who Needs to Comply With COPPA?
COPPA can apply to operators of websites and online services directed to children under 13 that collect personal information.
It can also apply to general-audience operators that have actual knowledge they collect personal information from children under 13.
Online services can include more than conventional websites.
Depending on the service and circumstances, COPPA can affect:
- Mobile applications
- Online games
- Connected devices and toys
- Video and streaming experiences
- Voice-enabled services
- Educational technology
- Social and community features
- Advertising and analytics technology
- Third-party plug-ins and SDKs
The FTC evaluates multiple factors when determining whether a service is directed to children. Organizations should not assume that describing a product as “general audience” resolves the question.
The COPPA Risk Many Companies Miss: Data Moves After Consent
Organizations often concentrate compliance controls at registration.
They establish an age screen, display a privacy notice, obtain consent, and assume they have controlled the risk.
But collection represents only the beginning of the data lifecycle.
The Children’s Data Compliance Chain
Consent controls collection. Compliance must follow the data.
What information enters the service?
Which information qualifies as children’s personal data?
Does each use match the disclosed and approved purpose?
Which providers, SDKs, platforms, or other parties receive it?
Who can access it and which safeguards apply?
Can the organization find every relevant copy when its purpose expires?
Children’s information may move into:
- Analytics systems
- Data warehouses and lakes
- Advertising platforms
- CRM and customer platforms
- Cloud storage
- Logs
- Data science environments
- AI applications
- Third-party processors
- Backups and archives
The privacy notice may describe what should happen. Data discovery can help establish what actually happened.
Seven COPPA Compliance Gaps Companies Commonly Overlook
1. Third-Party SDKs and Embedded Technology
An organization can control its own application code and still lose visibility when third-party technology collects data.
Advertising SDKs, analytics tools, social plug-ins, authentication services, video tools, and other embedded technologies can create downstream collection or disclosure.
Recent FTC enforcement reinforces this point. In 2025, the FTC alleged that the maker of an internet-connected robot toy allowed a third-party SDK provider to collect children’s precise geolocation without proper parental notice and consent.
Vendor inventory is not enough. Organizations need to understand which data each third party can actually collect or receive.
2. Audience Designation and Content Classification
COPPA risk can begin before anyone completes an age screen.
In a 2025 enforcement action involving Disney and YouTube, the FTC alleged that incorrect “Made for Kids” audience designations resulted in personal information collection and targeted advertising associated with child-directed videos.
This exposes a less obvious compliance dependency:
Operational metadata can determine whether downstream privacy controls activate correctly.
Organizations should therefore govern not only children’s data, but also the classifications, audience settings, tags, and configuration decisions that determine how platforms handle that data.
3. Persistent Identifiers
Cookies, IP addresses, device identifiers, and other persistent identifiers can fall within COPPA’s definition of personal information.
Organizations that search only databases containing names and email addresses can miss large portions of their exposure.
4. Copies of Data Outside the Primary Application
A parent may request deletion from the primary application while the same information remains in a data lake, export, development environment, analytics tool, cloud repository, or downstream system.
That creates a critical difference between deleting an account and deleting the child’s applicable personal information.
5. Retention Without a Specific Purpose
“We might need it later” is a weak retention strategy.
The amended Rule makes the connection between purpose and retention much clearer.
Organizations should know:
- Why they collected each category of children’s personal information
- How long that purpose requires retention
- Which systems contain the information
- Who owns deletion
- How teams verify deletion
6. Age Assurance Data Becomes Another Sensitive Dataset
Age assurance can solve one problem while creating another.
An age-checking process might use an identity document, image, biometric signal, or information from another provider.
In February 2026, the FTC issued an enforcement policy statement addressing age-verification technologies. Under specified conditions, the FTC said it would not bring a COPPA enforcement action against general-audience and mixed-audience operators that collect, use, or disclose personal information solely to determine age without first obtaining parental consent.
The conditions matter. Among them, organizations should restrict the information to age determination, avoid unnecessary retention, and take appropriate steps regarding third parties that receive it.
Age assurance should minimize children’s data exposure, not create a new permanent identity repository.
7. AI Creates New Uses That Old Consent May Not Cover
Children’s information can now enter AI workflows that did not exist when organizations originally designed their privacy programs.
Potential paths include:
- Model training or tuning datasets
- Enterprise AI assistants
- Generative AI applications
- Automated moderation
- Recommendation systems
- Voice and image analysis
- AI agents
- Third-party AI services
The compliance question should not stop at “Do we have consent?”
Organizations should also ask:
Was this data collected for this purpose, should this AI system have access to it, and can we find and remove it when the approved purpose ends?
COPPA and Targeted Advertising
The amended COPPA Rule places additional emphasis on disclosures of children’s personal information to third parties.
Covered operators may need separate verifiable parental consent before disclosing children’s personal information to third parties for targeted advertising or certain other purposes.
This separates two decisions that organizations should not automatically bundle:
Consent Question 1
Can the operator collect and use this information to provide the service?
Consent Question 2
Can the operator disclose the information to third parties for targeted advertising or another applicable purpose?
Consent architecture should reflect those distinct choices.
COPPA Data Retention and Deletion Requirements
Data retention has moved to the center of COPPA compliance.
Covered operators need a written retention and deletion policy for children’s personal information and should retain the information only as long as reasonably necessary for the specific purpose for which they collected it.
That requirement creates a practical data-management challenge.
A policy that says “delete after 12 months” has little value if the organization cannot identify every relevant repository containing the data.
A defensible retention process should connect:
Data Category → Collection Purpose → System → Owner → Retention Rule → Deletion Action → Evidence
That last element matters.
Compliance teams need more than a retention schedule. They need evidence that teams executed it.
COPPA Security Requirements Are Now More Explicit
The FTC’s updated business guidance states that covered operators need to establish and maintain reasonable procedures protecting the confidentiality, security, and integrity of children’s personal information.
The amended Rule also requires a written information security program with safeguards appropriate to factors including the sensitivity of the information and the organization’s size, complexity, and activities.
Organizations should connect children’s data with:
- Data sensitivity
- Storage location
- User and service-account access
- Third-party access
- Security controls
- Exposure
- Retention
- Remediation
You cannot apply stronger security to children’s data if you cannot reliably identify where that data resides.
Move From Privacy Policy to Data Control
Connect privacy obligations to the data they govern
Use data discovery, classification, consent, rights automation, retention, risk, and remediation to operationalize privacy across the data lifecycle.
COPPA Compliance Checklist for 2026
1. Determine Whether COPPA Applies
Evaluate whether the service is directed to children under 13 or whether the organization has actual knowledge that it collects personal information from children under 13.
Do not evaluate the homepage alone. Consider apps, individual content, features, connected devices, advertising, third-party components, and other online services.
2. Discover and Inventory Children’s Personal Information
Identify relevant personal information across structured and unstructured systems.
Include less obvious categories such as persistent identifiers, precise geolocation, images, voice recordings, biometric identifiers, and government-issued identifiers where applicable.
3. Map Collection, Use, and Disclosure
Document:
- Where information originates
- Why the organization collects it
- Which systems receive it
- Which teams use it
- Which third parties receive it
- Which policies apply
4. Review Privacy Notices
Make sure notices accurately reflect current collection, use, disclosure, retention, and other applicable practices.
The privacy notice should describe reality, not the system architecture the company had when someone last updated the policy.
5. Operationalize Verifiable Parental Consent
Use an appropriate method of verifiable parental consent when COPPA requires it and retain the context needed to understand what the parent approved.
Account for the amended Rule’s separate-consent requirements for applicable third-party disclosures.
6. Minimize Collection
Do not condition a child’s participation on providing more information than reasonably necessary for the activity.
Review telemetry, analytics, optional profile fields, SDK collection, and AI inputs in addition to information the child actively enters.
7. Establish Purpose-Based Retention
Connect children’s data categories to specific collection purposes and retention periods.
Identify redundant, stale, and unnecessary copies and establish workflows for secure deletion.
8. Support Parental Rights
Maintain processes that allow parents to review applicable information collected from their children, revoke consent where applicable, and request deletion.
Rights workflows should reach relevant downstream systems, not simply the front-end account.
9. Assess Third Parties
Identify service providers, SDKs, plug-ins, advertising technologies, analytics tools, cloud providers, and other recipients that may interact with children’s information.
Understand what data they receive and apply the Rule’s applicable diligence and assurance requirements.
10. Maintain a Written Security Program
Document appropriate safeguards and connect those safeguards to the actual systems and repositories containing children’s information.
11. Review Age Assurance Practices
If the organization uses age-verification or age-assurance technology, minimize the information collected for that purpose, restrict secondary use, control third-party disclosure, and delete it when it is no longer necessary.
12. Evaluate AI Use
Determine whether children’s personal information reaches AI models, applications, copilots, training datasets, prompts, vector stores, or agents.
Validate the purpose, access, policy, retention, and deletion implications before introducing new AI uses.
13. Keep Evidence
Document consent, policies, assessments, retention decisions, vendor controls, deletion, and remediation.
Compliance requires both control and the ability to demonstrate that control.
How Is COPPA Enforced?
The FTC enforces the COPPA Rule, and state attorneys general can also play an enforcement role.
As of the FTC’s current COPPA business guidance, courts can hold operators liable for civil penalties of up to $53,088 per violation. The actual amount depends on the circumstances of a case.
Enforcement history also shows that liability can extend well beyond monetary penalties.
The FTC’s 2022 Epic Games matter included a $275 million civil penalty related to COPPA allegations.
In 2025, the FTC announced a $10 million settlement with Disney involving allegations tied to improperly designated child-directed YouTube content.
Recent cases make another point clear:
COPPA failures can originate in operational decisions such as third-party SDK configuration or content classification, not just the absence of a consent form.
COPPA Is Only One Part of the Children’s Privacy Landscape
Organizations should not assume COPPA represents the full scope of children’s privacy obligations.
State laws increasingly address children’s and minors’ data through broader privacy, age-assurance, design, and online-safety requirements.
For example, Maryland’s Online Data Privacy Act took effect October 1, 2025 and treats personal data of a child as sensitive data. Maryland has also enacted a separate Kids Code addressing online products reasonably likely to be accessed by children.
California continues to develop and litigate children’s online privacy and safety requirements, while its Protecting Our Kids from Social Media Addiction Act creates requirements around certain addictive feeds, parental consent, and age assurance.
Organizations operating internationally may also need to account for requirements such as the GDPR and other jurisdiction-specific protections for children’s data.
The operational answer should not be a separate data inventory for every law.
A stronger approach creates a common understanding of children’s and minors’ data and then applies the appropriate jurisdiction, age, purpose, consent, retention, access, and policy requirements.
How BigID Supports COPPA Compliance
BigID helps organizations connect children’s privacy requirements to the enterprise data those requirements govern.
Organizations can use BigID capabilities to:
- Discover and classify personal data: Find sensitive and personal information across supported structured and unstructured enterprise data environments and classify relevant categories of children’s information.
- Build a data-centric inventory: Understand where relevant information resides rather than relying only on application inventories, questionnaires, or policy documentation.
- Understand data context and movement: Connect information with systems, business context, lineage, ownership, and other metadata to improve visibility into how data moves and where privacy risk can emerge.
- Manage consent and preferences: Capture, manage, correlate, and synchronize consent and preference records across supported channels, systems, and applications.
- Automate privacy rights workflows: Find relevant personal information and coordinate access and deletion workflows across enterprise systems.
- Operationalize retention: Connect retention requirements to data, identify information that has exceeded its useful or approved lifecycle, and coordinate disposition.
- Assess privacy risk: Add data context to privacy assessments so teams can evaluate processes based on the personal information actually involved.
- Identify access and exposure: Understand where sensitive information has excessive or inappropriate access that can increase security and privacy risk.
- Coordinate remediation: Turn privacy findings into assigned actions and workflows rather than leaving risks in reports.
- Support compliance evidence: Connect policies, data findings, ownership, workflows, and remediation to strengthen reporting and demonstrate operational control.
The goal is not simply to prove that a parent clicked “I agree.”
Organizations need to know what children’s data they have, where it went, who can use it, whether that use remains appropriate, how long they should keep it, and whether they can take action when something needs to change.
That is the difference between managing COPPA as a consent event and managing children’s privacy as a data lifecycle.
Connect the Dots Across Children’s Data
Turn COPPA Requirements Into Data Control
See how BigID helps organizations discover personal data, manage privacy rights and consent, apply retention, assess risk, and coordinate remediation across enterprise data.
COPPA Compliance FAQs
What is COPPA?
COPPA is a U.S. federal children’s privacy law. The FTC’s COPPA Rule regulates how covered operators collect, use, disclose, protect, retain, and delete personal information from children under 13.
Who must comply with COPPA?
COPPA applies to operators of commercial websites and online services directed to children under 13 that collect personal information. It also applies in certain circumstances to general-audience operators that have actual knowledge they collect personal information from children under 13.
What changed in the updated COPPA Rule?
The amended Rule strengthens requirements involving third-party disclosures and targeted advertising, data retention, information security, parental control, and Safe Harbor accountability. It also expressly expands personal information to include government-issued identifiers and certain biometric identifiers.
What is verifiable parental consent under COPPA?
Verifiable parental consent is a process reasonably calculated, in light of available technology, to ensure that the person providing consent is the child’s parent. The appropriate method depends on the circumstances and applicable COPPA requirements.
Does COPPA apply to cookies and device identifiers?
It can. COPPA’s definition of personal information includes persistent identifiers that can recognize a user over time and across websites or online services, subject to specific exceptions such as certain uses supporting internal operations.
Does COPPA cover biometric data?
Yes. The amended COPPA Rule expressly includes biometric identifiers that can support automated or semi-automated recognition of an individual within its definition of personal information.
Does COPPA prohibit targeted advertising to children?
The amended Rule requires separate verifiable parental consent for certain disclosures of children’s personal information to third parties, including disclosures related to targeted advertising. Organizations should evaluate their specific collection and disclosure practices against the Rule.
How long can a company keep children’s data under COPPA?
Covered operators should retain children’s personal information only as long as reasonably necessary to fulfill the specific purpose for which they collected it and should securely delete the information when that purpose no longer supports retention.
Does COPPA require a security program?
The amended Rule requires covered operators to establish, implement, and maintain a written information security program with safeguards appropriate to factors including the sensitivity of children’s personal information and the organization’s size, complexity, and activities.
What are the penalties for violating COPPA?
According to current FTC guidance, courts can impose civil penalties of up to $53,088 per violation. Penalties vary according to factors such as the nature of the violation, the information involved, how the data was used or disclosed, and other circumstances.
How does AI affect COPPA compliance?
AI can create new uses and destinations for children’s information. Organizations should determine whether children’s personal information enters training, tuning, retrieval, inference, recommendation, moderation, generative AI, or agentic workflows and evaluate whether the purpose, access, retention, security, and disclosures remain appropriate.
How does BigID help with COPPA compliance?
BigID helps organizations discover and classify personal information, understand where relevant data resides, manage consent and privacy rights, operationalize retention, assess privacy risk, identify access and exposure, coordinate remediation, and strengthen compliance evidence across enterprise data.

