๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

What is COPPA

What is COPPA (Children's Online Privacy Protection Act)?

COPPA (the Children's Online Privacy Protection Act) is the United States law that protects the personal information of children under 13 online. The Federal Trade Commission enforces it through the Children's Online Privacy Protection Rule (the COPPA Rule, 16 CFR Part 312), which was substantially amended in 2025. Compliance with the amendments has been required since 22 April 2026.

Map your COPPA controls See what overlaps with your privacy program

Children under 13 · verifiable parental consent · written security program · published retention policy

Definition

COPPA (the Children's Online Privacy Protection Act of 1998, 15 U.S.C. 6501 to 6506) is the US federal law that controls how operators of commercial websites, apps, and online services collect, use, and disclose personal information from children under 13. The Children's Online Privacy Protection Rule, 16 CFR Part 312, is the FTC regulation that sets out what operators must actually do.

It applies to an operator whose service is directed to children under 13, to a mixed audience service that children are part of, and to any operator with actual knowledge that it collects personal information from a child under 13. The FTC decides whether a service is directed to children by looking at its subject matter, visuals, animated characters, music, advertising, and the ages of its actual audience.

COPPA reaches operators outside the United States. A Canadian, British, or Australian company whose service is directed to children in the US, or that knows it collects from them, is covered.

"Personal information" under the rule is broad: names, addresses, email and other online contact information, phone numbers, photos, video and audio containing a child's image or voice, geolocation, persistent identifiers such as cookies and device IDs, and, since 2025, biometric identifiers such as fingerprints, voiceprints, and facial templates.

Core components

Notice (312.4)

A clear online privacy notice linked wherever children's information is collected, and a direct notice to parents before collection, saying what is collected, why, and who receives it.

Verifiable parental consent (312.5)

Consent from a parent, by a method reasonably calculated to confirm it is the parent, before collecting, using, or disclosing a child's information, with narrow exceptions.

Separate consent for third parties (312.5(a)(2))

New in 2025: disclosing a child's information to third parties, including for targeted advertising, needs its own parental consent unless the disclosure is integral to the service.

Parental review and deletion (312.6)

Parents can review what was collected, refuse further collection, and have it deleted, after the operator confirms they are the parent.

No conditioning (312.7)

A child's participation in a game, prize, or activity cannot depend on giving more information than the activity reasonably needs.

Written security program (312.8)

New in 2025: a written information security program with a named coordinator, an annual risk assessment, safeguards, testing, and annual evaluation, plus written assurances from service providers.

Written retention policy (312.10)

New in 2025: a written policy stating why children's information is kept and when it is deleted, published in the online notice. Indefinite retention is not allowed.

Persistent identifiers (312.5(c)(7))

Cookies and device IDs can be collected without consent only to support internal operations, never to build a profile or target advertising, and the notice must say which operations.

Safe harbor programs (312.11)

An operator that follows an FTC-approved safe harbor program is treated as complying with most of the rule. Programs now report more to the FTC.

Why it matters

COPPA cases are among the FTC's most active privacy enforcement. Civil penalties reach $53,088 per violation for 2026, and because every affected child can be a separate violation, settlements with app developers, game publishers, and edtech providers often reach millions of dollars. State attorneys general can bring COPPA cases too.

The 2025 amendments moved COPPA from a notice-and-consent rule toward a security and data governance rule. Since 22 April 2026, an operator needs a written information security program, a published retention schedule, and separate consent before sharing a child's data with advertisers. Those are the same disciplines a privacy and security program already runs, applied to children's data.

For MSPs, the exposure usually sits with clients: schools' software vendors, youth sports and recreation platforms, tutoring and edtech companies, and any consumer app that teenagers and younger children both use. The MSP's own safeguards and contracts become part of that client's COPPA evidence.

What COPPA shares with your privacy program

Most of COPPA is controls you already run for other laws. In Lavawall®, COPPA is mapped to the same shared controls as PIPEDA and the proposed Protecting Privacy and Consumer Data Act (PPCDA), so a control you implement and evidence once counts toward each of them.

Each row is one control in Lavawall, credited to every framework in the row.
What you do onceCOPPA RulePIPEDA (in force)PPCDA (Bill C-36, proposed)
Run a written information security program with a named coordinator312.8(b)Principles 4.1 and 4.7ss. 8 and 56
Encrypt stored and transmitted data; require multi-factor authentication312.8(a)Principle 4.7s. 56
Assess service providers and get written assurances312.8(c)Principle 4.1.3s. 11
Set retention periods and delete securely312.10Principle 4.5ss. 52 and 54
Collect only what the purpose needs312.7Principle 4.4s. 13
Keep consent records312.5Principle 4.3s. 15
Verify identity before giving access or deleting312.6Principle 4.9s. 56(3)
Publish an accurate privacy policy312.4(d)Principle 4.8s. 62

The work that is specific to COPPA sits on top: deciding whether each service is directed to children, neutral age screening, the direct notice to parents, verifiable consent methods, separate consent for third-party disclosure, limits on persistent identifiers, and parental review. Lavawall® gives each of those its own control, question, and template.

When you compare tools, check whether COPPA is pre-built and already mapped to the controls behind your other frameworks, or whether you would be building it and mapping it yourself. Lavawall® ships COPPA, PIPEDA, and the PPCDA pre-built on the same control set and includes every framework in the Complete tier.

COPPA and Canadian law

Canada has no COPPA today. PIPEDA sets no age threshold, though the Office of the Privacy Commissioner treats children's information as sensitive and expects meaningful consent from a parent when a child cannot give it. Quebec Law 25 requires consent from the person with parental authority for children under 14.

That is likely to change. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, defines a child as anyone under 18, lists a child's information as sensitive, and lets a parent or guardian exercise the child's rights. A Canadian organization with young users can build one children's privacy program that meets COPPA for US children and prepares for the PPCDA at home.

How Lavawall® helps with COPPA

  • Assess against the amended COPPA Rule section by section, with questions on scope, notice, consent, parental rights, security, and retention.
  • Write it down with templates for the children's privacy notice, the direct notice to parents, the parental consent procedure, the written information security program, the retention policy, and service provider assurances.
  • Prove the safeguards with evidence collected from your endpoints, Microsoft 365, and Google Workspace: encryption, multi-factor authentication, patching, access review, and breach detection.
  • Train staff with a short course on the amended rule.

Start your COPPA assessment →

This page summarizes the COPPA Rule for planning. It is not legal advice; confirm the current rule text and FTC guidance before relying on it.

Frequently asked

Does COPPA apply to a Canadian company?
It can. COPPA applies to any operator of a commercial website, app, or online service that is directed to children under 13 in the United States, or that knows it collects personal information from them, wherever the operator is based. A Canadian company with US children among its users should assess it.
What changed in the 2025 COPPA amendments?
The FTC published amendments on 22 April 2025 that took effect on 23 June 2025, with compliance required by 22 April 2026. They added biometric identifiers to personal information, defined mixed audience services, required separate parental consent before disclosing a child's information to third parties, required a written information security program and a written, published data retention policy, added new consent methods, and increased safe harbor reporting.
What are the penalties for violating COPPA?
Civil penalties of up to $53,088 per violation, the inflation-adjusted amount the FTC applies for 2026. The FTC and state attorneys general can both enforce COPPA, and each child affected can count as a separate violation.
Is there a Canadian equivalent of COPPA?
Not today. PIPEDA has no age threshold, but the Privacy Commissioner treats children's information as sensitive, and Quebec Law 25 requires consent from the person with parental authority for children under 14. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, would define a child as anyone under 18 and treat a child's information as sensitive.
Can we collect a birth date to check a user's age?
Yes, if it is done neutrally. The rule requires age screening that does not default to an age or encourage children to lie. In February 2026 the FTC said it will not bring COPPA cases over information collected only to verify age, as long as it is used for nothing else and deleted promptly.