The federal children's privacy rule, known as COPPA, covers children under 13. It requires a covered app or site to tell you what it collects, get your verifiable consent before collecting it, let you review or delete that information, and stop collecting on request. It governs data, not content, and it does not cover teenagers.
What follows is information about how the rule works, drawn from the rule text and the Federal Trade Commission's own guidance. It is not legal advice, and it is not a verdict on any particular app. A legal conclusion about a specific service is a question for a lawyer, not for a parenting explainer.
Who does the rule actually cover?
It applies to operators of online services directed to children under 13, and to general-audience services that knowingly collect personal information from a child under 13. The FTC's compliance guidance lists websites, mobile apps, gaming platforms, ad networks and connected devices among the services in scope. The trigger is the child's age, not the parent's comfort level.
Two things follow from that. When a service sets its minimum at 13, it is usually placing itself outside COPPA rather than making a developmental claim about what a 13-year-old can handle. And a service plainly built for younger kids cannot escape the rule by adding a birthday box: under the amended rule, mixed-audience services must collect age information before collecting personal information, using a neutral screen that does not default to an age or encourage a child to falsify one.
What counts as "personal information" here?
More than most parents expect. The rule text lists eleven categories, and several of them are invisible to the person holding the tablet. This is the part of COPPA that does the real work, because it reaches the identifiers a child never types in.
According to 16 CFR Part 312, current as of August 19, 2026, the list covers first and last name; physical address; online contact information; a screen name where it functions as contact information; telephone number; government-issued identifiers such as a Social Security, state ID, birth certificate or passport number; persistent identifiers such as cookies and IP addresses; a photo, video or audio file containing the child's image or voice; geolocation; biometric identifiers; and information about the child or parent collected online and combined with any identifier.
Biometric identifiers and government-issued identifiers were added in the 2025 amendments. Biometric here means data usable for automated recognition, including fingerprints, iris patterns, voiceprints, gait patterns, genetic data and faceprints. A voice-controlled toy and a face-unlock feature are both squarely inside that definition.
What does "verifiable parental consent" mean in practice?
It means a method reasonably designed, in light of available technology, to make sure the person consenting is really the parent. The FTC's guidance on verifiable parental consent, last modified April 30, 2026, states plainly that the Rule "does not mandate the method a company must use" — operators choose, and the choice has to hold up.
Section 312.5 of the rule enumerates the recognized approaches: a signed consent form returned by mail, fax or scan; a credit, debit or online payment transaction; a toll-free call staffed by trained personnel; a video conference with trained personnel; checking a government-issued ID against a database; knowledge-based authentication; facial recognition matched against a photo ID; and, for operators that do not disclose the data onward, an email or text message with confirmation steps.
One provision is easy to miss and worth knowing. Section 312.5(a)(2) says an operator "must give the parent the option to consent to the collection and use of the child's personal information without consenting to disclosure of his or her personal information to third parties, unless such disclosure is integral to the website or online service." Consent to the app is not automatically consent to everyone the app does business with. A separate provision, section 312.7, bars an operator from conditioning a child's participation in a game or prize offer on "disclosing more personal information than is reasonably necessary to participate in such activity."
What changed in the 2025 amendments, and when do they bite?
The FTC published amendments to the rule in the Federal Register on April 22, 2025. They expanded the definition of personal information, added the mixed-audience definition, tightened retention duties, and set a compliance date roughly a year out. Here are the dates the rule itself states.
| Milestone | Date | Source |
|---|---|---|
| Amendments published in the Federal Register | April 22, 2025 | SRC-03 |
| Amendments effective | June 23, 2025 | SRC-03 |
| Full compliance date (with narrow exceptions in §312.11) | April 22, 2026 | SRC-03 |
| Rule text as consulted for this article | August 19, 2026 | SRC-01 |
Details of the amended rule as published are technical, and rules change. Treat any specific figure here as accurate as of the dates above and subject to later amendment or enforcement guidance.
What rights do you have once you have said yes?
Three, and they are durable. Under the FTC's six-step compliance plan for businesses, a parent may review the personal information an operator has collected from their child, delete that information, and "refuse to permit further collection or use of that information." Saying yes at signup is not a permanent decision.
The rule also limits how long a company may keep what it collects. Section 312.10 permits retention of a child's personal information "for only as long as is reasonably necessary to fulfill the specific purpose(s)" it was collected for, and requires operators to "establish, implement, and maintain a written data retention policy" covering purposes, business need and deletion timeframes. Indefinite retention is not a lawful default.
Practically, that means the privacy policy is the document to open before the download, not after. The FTC's compliance guidance, updated May 2026, requires that notice to be posted prominently on the home page and at each place where information is collected from children — so if you cannot find it, that itself is information.
Where do age checks fit in?
They are being actively encouraged. On February 25, 2026, the FTC issued a policy statement saying it does not intend to pursue COPPA enforcement against general-audience and mixed-audience operators that collect personal information solely to determine a user's age, provided they limit the use to that determination, delete the data promptly, share it only with trustworthy third parties, give clear notice, secure it and produce accurate results.
Christopher Mufarrige, director of the FTC's Bureau of Consumer Protection, said in the announcement that "age verification technologies are some of the most child-protective technologies to emerge in decades." That is the agency's stated position, not a finding about how well any particular product works, and the statement itself sets conditions rather than granting a blanket pass.
What the rule does not do
COPPA is a data law. It says nothing about whether a game is too violent, whether a feed is too absorbing, or whether a chat function is a good idea for your particular nine-year-old. It sets no screen-time limits and makes no developmental claims. Content judgments sit with ratings boards, with the research literature, and with you.
So the honest division is this. The rule requires notice, consent, access, deletion and limited retention for under-13s. The FTC recommends age-assurance tools under stated conditions and tells operators to make their notices findable. Whether a given app earns a place on your child's device — and how much data you are willing to trade for it — remains your call, and no federal rule is going to make it for you.
For a related business news perspective, read How child-influencer earnings laws actually work.
