Children's Online Privacy Protection Act
Tier 1 Partially in forceCovers personal information collected online from children under 13. Scope turns on either actual knowledge that a user is under 13, or the service being directed to children — a test applied to the service, not to the individual user, which is why general-audience platforms are frequently caught by their child-appealing sections. The amended Rule is in force but full compliance is still phasing in.
Identity
- Citation
- 15 U.S.C. 6501-6506; 16 CFR Part 312
- Jurisdiction
- United States
- Type
- sectoral
The amended Rule was approved on 16 January 2025, published in the Federal Register on 22 April 2025 and took effect on 23 June 2025. Full compliance is required by 22 April 2026, with safe-harbour programmes on an earlier timetable.
Amended by: The 2025 amendments add a separate verifiable parental consent for disclosure to third parties and for targeted advertising; require a written information-security programme; impose data-retention limits; and expand the definition of personal information to include biometric identifiers.
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap. Checked by Fable on 26 July 2026.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | Asymmetry found | Uniform nationwide application, but COPPA is the inverse of the usual US federal pattern: it expressly PRE-EMPTS inconsistent state law rather than setting a floor above which states may build. That ceiling effect is live and contested, because a wave of state statutes on minors' social media use, age verification and design codes now occupies adjacent ground, and the boundary between permissible state regulation of teenagers and pre-empted state regulation of under-13s is being litigated rather than settled. |
| 2 | Commencement | None found — checked | None found — checked. The statute has been in force since 2000 and the amended COPPA Rule phasing is complete: approved 2025-01-16, published at 90 Fed. Reg. on 2025-04-22, effective 2025-06-23, with the full compliance deadline of 2026-04-22 now passed as at 2026-07-26. No provision remains pending. |
| 3 | Sunset / mandatory review | None found — checked | None found — checked. No expiry or lapse provision. The FTC reviews the Rule periodically under its general regulatory review programme, which produced the 2025 amendments, but that is discretionary agency practice rather than a mandatory statutory review clause. |
| 4 | Criminal liability | None found — checked | None found — checked. COPPA creates no criminal offences and no custodial penalty. The entire enforcement apparatus is civil, resting on FTC Act penalty machinery. This is a genuine point of difference from HIPAA, GLBA and FCRA, all three of which carry a criminal track, and it should not be assumed by analogy. |
| 5 | Civil liability | None found — checked | None found — checked. There is no private right of action. Parents cannot sue an operator under COPPA, and attempts to plead COPPA violations directly have been dismissed on that basis; claimants instead rely on state consumer-protection and privacy statutes, sometimes using COPPA non-compliance as supporting evidence. |
| 6 | Regulatory enforcement toolkit | Asymmetry found | Two classes of enforcer: the FTC, and state attorneys general acting in parallel under the statute's express authorisation. The FTC can obtain civil penalties, injunctive relief, deletion of unlawfully collected data and algorithmic disgorgement through consent orders. The maximum civil penalty is USD 53,088 per violation following the FTC's 2025 inflation adjustment (90 Fed. Reg. 5580, effective 2025-01-17), and because each affected child can constitute a separate violation, exposure scales with the size of the affected population rather than with the gravity of the conduct. |
| 7 | Personal / director liability | None found — checked | None found — checked, with a qualification. COPPA itself creates no distinct director, officer or DPO liability. The FTC has in practice named individual executives as respondents in privacy orders where they participated in or controlled the conduct, but that flows from general FTC Act authority rather than from COPPA, and it is an enforcement pattern rather than a statutory route. NOTE: the individual-respondent practice was not covered in the verified pass — see the sheet. |
| 8 | Public vs private sector split | Asymmetry found | The regime is bounded twice over. It binds operators of commercial websites and online services either directed to children under 13 or with actual knowledge that they are collecting personal information from children under 13 — so the trigger is the audience or the operator's knowledge, not the sensitivity of the data. Non-profit entities outside the FTC's general jurisdiction fall outside, as do services aimed at 13-to-17-year-olds, which is why the teen-protection gap has been filled by state legislation rather than by COPPA. |
| 9 | Legal-person coverage | None found — checked | None found — checked. The Act protects children under 13, who are natural persons. Operators are duty-bearers, not protected subjects. |
| 10 | Exemptions — with conditions | Asymmetry found | The exemption regime consists of narrow, condition-bound exceptions to the verifiable parental consent requirement rather than general carve-outs. They include collection of an online contact detail solely to respond once to a specific request and then delete it; collection solely to obtain parental consent or provide notice; collection of persistent identifiers used only to support the internal operations of the service, which is the most heavily relied upon and the most frequently over-read; and collection necessary to protect a child's safety. The 2025 amendments tightened the surrounding obligations by requiring separate verifiable parental consent for disclosure to third parties and for targeted advertising, mandating a written information security programme, imposing retention limits, and expanding the personal information definition to include biometric identifiers. |
Civil liability
None found — checked. Enforcement is public only, by the FTC and by state attorneys general.
Regulatory enforcement
- Penalty ceiling
- Up to $53,088 per violation, per the FTC's 2025 inflation adjustment (90 Fed. Reg. 5580, effective 17 January 2025).
Legal-person coverage
- Covers legal persons
- No — natural persons only
Interactions and conflicts
Pre-emption here is express and displaces inconsistent state law, unlike the floor model used by HIPAA and GLBA. Comparing the three side by side is the clearest illustration of why "US federal privacy law" cannot be discussed as a single thing.
Live issues
Sources
- Primary Children's Online Privacy Protection Rule, 16 CFR Part 312 Federal Trade Commission no verified URL yet
URL unconfirmed.
- Primary COPPA Rule amendments, Federal Register 22 April 2025 Federal Trade Commission no verified URL yet
URL unconfirmed.
Never independently verified — seeded from the prototype.