Skip to content

United States · Applies by law

COPPA compliance

Children's Online Privacy Protection Act

Any service directed at children under 13, or that knowingly collects data from them. Edtech, gaming and social products most often.

The context

What it actually asks of you

COPPA is the regulation companies discover late, usually when an app store review or an enterprise school district contract raises it. It applies to services directed at children under 13, and to any service that acquires actual knowledge that a user is under 13, a standard that catches many products whose founders never considered themselves child-directed.

The FTC assesses whether a service is child-directed on the whole: subject matter, visual content, music, characters, celebrity appeal, advertising, and evidence about actual audience. Intent is not the test. A general-audience product with a popular under-13 segment can be in scope for that portion of its users.

Where it bites hardest is third-party code. Advertising and analytics SDKs that collect persistent identifiers from child users are a COPPA issue even though you did not write them, and the 2025 amendments tightened obligations around retention and data sharing considerably.

The common mistake

What teams get wrong.

"We don't target kids" is not a defence if you have actual knowledge they use it. Verifiable parental consent is a specific legal standard, and a checkbox saying "I am over 13" does not meet it.

Our scope

What we do for COPPA.

  1. 01Age-gating design and actual-knowledge assessment
  2. 02Verifiable parental consent mechanism selection
  3. 03Data minimisation review, collect only what the activity needs
  4. 04Third-party SDK and advertising audit for child-directed traffic
  5. 05Parental access, review and deletion workflows
  6. 06Direct-notice and privacy policy drafting support

innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.

Questions

COPPA FAQ

A neutral age screen is a necessary starting point, not a defence on its own. If you collect an age and a user states they are under 13, you now have actual knowledge and full COPPA obligations attach. The gate has to be paired with a compliant path for those users, not just a rejection.

The FTC lists specific approved methods, signed consent form, payment card verification with a transaction, phone or video call with trained personnel, government ID checks, and knowledge-based authentication among them. An email tick-box does not qualify except in the narrow email-plus scenario.

Often the school can provide consent on parents' behalf for educational use, but that route is narrow: the data must be used only for the educational purpose authorised, never for advertising or profiling. You will usually be dealing with FERPA and state student-privacy laws at the same time.

Find out whether COPPA binds you.

Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.