Governance, risk & compliance
Children's Online Privacy Protection Rule (COPPA) 16 CFR 312, amended 2025
Children's Online Privacy Protection Rule (COPPA Rule), 16 CFR Part 312, enforced by the US Federal Trade Commission.
It applies to operators of websites, apps and online services directed to children under 13, mixed audience services, and any operator with actual knowledge that it collects personal information from a child under 13, including operators outside the United States whose services are directed to children in the United States. The rule as amended on 22 April 2025 (90 FR 16918) took effect 23 June 2025, and compliance with the amendments was required by 22 April 2026.
The amendments added biometric identifiers to personal information, a definition of mixed audience services, separate parental consent for disclosures to third parties, a written information security program, a written data retention policy published in the privacy notice, new consent methods, and safe harbor reporting. Civil penalties are up to $53,088 per violation (the FTC kept its 2025 levels for 2026).
On 25 February 2026 the FTC said it will not bring COPPA cases over data collected only to verify age, if that data is used for nothing else and deleted promptly. Requirements map to the shared control library, so security work already credited to other frameworks counts here where the control is the same.
How Lavawall® helps you get to Children's Online Privacy Protection Rule (COPPA) compliance
Most of Children's Online Privacy Protection Rule (COPPA) comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to Children's Online Privacy Protection Rule (COPPA), and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against Children's Online Privacy Protection Rule (COPPA) in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports Children's Online Privacy Protection Rule (COPPA) as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- Children's Online Privacy Protection Rule (COPPA) 16 CFR 312, amended 2025
- Category
- Privacy
- Region
- USA
Map this framework freeTalk to our team