RegImpact
ftcproposed· Published 1/11/2024

Children's Online Privacy Protection Rule

The Commission proposes to amend the Children's Online Privacy Protection Rule, consistent with the requirements of the Children's Online Privacy Protection Act. The proposed modifications are intended to respond to changes in technology and online practices, and where appropriate, to clarify and streamline the Rule. The proposed modifications, which are based on the FTC's review of public comments and its enforcement experience, are intended to clarify the scope of the Rule and/or strengthen its protection of personal information collected from children.

What this rule actually says

COPPA (the Children's Online Privacy Protection Rule) requires websites and apps to get parental consent before collecting personal data from kids under 13. The FTC just proposed updates to modernize the rule for today's tech—things like restricting how companies can use kids' data for behavioral ads, tightening rules around "persistent identifiers" (tracking cookies, device IDs), and clarifying obligations for AI and algorithm-driven services.

Who it applies to

  • If your product is directed at children under 13 (or knowingly collects data from them), COPPA applies. This includes educational AI tutors, kids' gaming assistants, or parental-monitoring tools.
  • If your product is general-audience (like a support chatbot or hiring tool) but some users are under 13, you need age-gating or parental consent mechanisms.
  • U.S. only: COPPA is a U.S. federal rule. If founders operate outside the U.S., this doesn't directly apply, though GDPR and similar laws may.
  • Data scope: The rule covers names, contact info, persistent identifiers (device IDs, cookies), location data, photos/videos, and increasingly, behavioral/usage data used for profiling or targeted advertising.
  • Does NOT apply if: Your product explicitly prohibits users under 13 and you have no actual knowledge of child users.

What founders need to do

  1. Assess your user base (1 day): Does anyone under 13 actually use your product? Check analytics, user signup data, or survey users. If zero under-13s and your terms explicitly block them, you may be clear—but document this.
  1. Implement age verification or blocking (3-5 days): Add a simple age gate at signup. If you target kids, use parental consent (email verification is the minimum; options like ID verification exist but are expensive).
  1. Audit data collection (2-3 days): List what data you collect, store, and share. Cut anything unnecessary. If you use third-party analytics (Google Analytics, Mixpanel), check their child-friendly policies or disable them for under-13 users.
  1. Review your ads and targeting (1 day): The updated rule is tighter on behavioral advertising. If you show ads to under-13 users, avoid targeting based on their browsing behavior—stick to contextual ads only.
  1. Update your privacy policy (ongoing): Make it explicitly clear how you handle under-13 data, how parents can access/delete it, and who your contact person is for COPPA questions.

Bottom line

If your audience is primarily adults (hiring tools, medical scribes, business software), monitor but don't panic; if you knowingly serve kids, start implementing parental consent and audit your data practices now—these rules are tightening.