COPPA is the United States federal statute that makes it unlawful for a commercial website or online service to collect personal information from a child under 13 without first notifying a parent and obtaining that parent's verifiable consent. Its full name is the Children's Online Privacy Protection Act of 1998, codified at 15 U.S.C. 6501 to 6506. Congress delegated the detail to the Federal Trade Commission, which writes and enforces the implementing COPPA Rule at 16 CFR Part 312. For advertising, the consequential provision is not the headline consent requirement but the definition of personal information, which since 2013 has included persistent identifiers such as cookies, IP addresses and unique device identifiers. That inclusion placed behavioural targeting of under-13 audiences on the wrong side of federal law.
Who is covered
Two categories of operator fall inside the Rule. The first is any commercial service directed to children. The FTC assesses that against a multi-factor test covering subject matter, visual content, animated characters, child-oriented activities, music, the age of models, the presence of child celebrities, and whether the advertising on the service is itself directed to children. Audience-composition evidence counts too, as do marketing plans and representations made to third parties.
The second category is any general-audience operator with actual knowledge that it is collecting personal information from a child under 13. A service also becomes child-directed when it knows it is collecting data from users of another child-directed service, which is how ad networks and analytics vendors are drawn in.
Between them sits the mixed audience category, formally defined for the first time in 2025. Such a service meets the child-directed criteria without targeting children as its primary audience, and collects nothing beyond narrow permitted purposes until it establishes age in a neutral manner that neither defaults to a set age nor encourages falsification. Non-profits outside FTC Act jurisdiction are excluded.
What the rule requires
Operators must post an online notice describing what is collected, how it is used, the identities or categories of third parties receiving the data, and a written retention policy. A separate direct notice goes to the parent, and consent must precede any collection, use or disclosure.
The Rule enumerates acceptable consent methods rather than leaving them open: a signed form returned by post, fax or scan; a payment card transaction notifying the account holder; a call or video conference with trained personnel; a government identifier checked against a database and then deleted; dynamic knowledge-based authentication difficult enough that a 12-year-old in the household could not answer; and government photographic identification matched by facial recognition against a camera image. Operators that do not disclose data to third parties may use email or text plus a confirmatory step.
Nine exceptions permit collection without prior consent. The commercially decisive one is 312.5(c)(7), allowing an operator to collect a persistent identifier and nothing else where it serves only support for internal operations: maintaining the service, network communications, authentication and content personalisation, security, legal compliance, and serving contextual advertising or capping frequency. Information gathered under it cannot be used to contact an individual, build a profile, or serve behavioural advertising.
Where it sits in the advertising stack
The practical effect is that an ad request from child-directed inventory carries no user-level identifier available for targeting, measurement joins or retargeting. Contextual signals and frequency capping survive. Audience segments, lookalike modelling and cross-site attribution do not.
Publishers and app developers transmit that condition through ad request parameters. Google's tagForChildDirectedTreatment and tagForUnderAgeOfConsent flags carried the signal for over a decade before the company replaced both with a single tag for age treatment, TFAT, on 18 May 2026, adding a TEEN value alongside CHILD and UNSPECIFIED. On YouTube the equivalent declaration is the made for kids audience setting, applied by the uploader rather than the platform.
Platforms have also begun inferring the condition rather than waiting to be told. Google started deploying machine learning age estimation in the United States on 30 July 2025, disabling personalisation for accounts the model judges to belong to minors, six months after it consolidated five minor-protection advertising policies into a single hub.
Origin and evolution
Congress passed COPPA in 1998. The FTC issued the first implementing rule on 3 November 1999, effective 21 April 2000.
The January 2013 amendment, effective 1 July 2013, reshaped ad tech. It added persistent identifiers, photographs, videos, audio files and precise geolocation to the personal information definition, and extended liability to third parties collecting data through a child-directed service.
The current round began in July 2019, when the Commission opened a review covering education technology, voice-enabled devices and general-audience platforms hosting third-party child-directed content. More than 175,000 comments arrived. The FTC set out its proposals in December 2023, publishing the notice of proposed rulemaking on 11 January 2024 and drawing 279 unique responses.
The 2025 amendments
The Commission voted 5-0 on 16 January 2025 to finalise the first substantive revision since 2013, published it in the Federal Register on 22 April 2025, and set it in force on 23 June 2025 with a full compliance deadline of 22 April 2026.
Four changes bear directly on media buying. Operators must obtain separate consent for disclosure to third parties, including advertisers, unless that disclosure is integral to the service. Biometric identifiers, including voiceprints, gait patterns, facial templates and faceprints, joined the personal information definition. Indefinite retention became unlawful, with a written retention policy now mandatory and publishable. Operators relying on the internal operations exception must disclose the specific operations involved and the measures preventing behavioural use of the identifier.
Enforcement and its record
A Rule violation counts as a violation of a trade regulation rule under Section 18(a)(1)(B) of the FTC Act. Civil penalties reach 53,088 dollars per violation, the figure set by 16 CFR 1.98 for penalties assessed after 17 January 2025 and left unchanged after the Office of Management and Budget cancelled the 2026 inflation adjustment. State attorneys general may sue too.
The record is uneven in scale. The FTC and the New York Attorney General settled with Google and YouTube for 170 million dollars in September 2019, producing the audience designation system the platform still runs. Disney agreed to pay 10 million dollars in September 2025 after failing to designate child-directed videos individually, and days later the FTC sued robot toy maker Apitor over geolocation data collected through a third-party software development kit.
The largest figure came from the case filed against TikTok and ByteDance in August 2024, which alleged that human reviewers spent five to seven seconds deciding whether an account belonged to a child. The Department of Justice announced a 400 million dollar settlement on 21 August 2026, split between 300 million immediately and 100 million on vacatur of the 2019 Musical.ly consent decree.
Limitations and disputes
The actual knowledge standard is the structural weakness. An operator that declines to determine age cannot acquire knowledge, and so avoids the obligation, a perverse incentive against age assurance that the FTC's February 2026 policy statement tries to unwind.
Industry has argued the opposite risk. The IAB warned in March 2024 that the proposals could push services to stop serving children altogether, that verification would require collecting more sensitive data than it protected, and that data limits would impair fraud detection.
Measurement bodies dispute the law's reach. A CIMM report published on 15 July 2026 argued that COPPA restricts profiling of children but does not bar household-level measurement or the identification of adult co-viewers, estimating that inaccurate presence-of-children data wastes 590,000 dollars of every million spent. That report cites a penalty ceiling of 43,280 dollars per violation, and other coverage has used 43,792 dollars, both superseded figures from earlier inflation adjustments.
Not the same as
COPPA 2.0, formally the Children and Teens' Online Privacy Protection Act, is proposed legislation rather than law. It would raise the protected age to under 17, ban targeted advertising to that cohort, and replace actual knowledge with knowledge fairly implied on the basis of objective circumstances. The Senate passed it by unanimous consent on 5 March 2026; the House has not.
Made for kids is a YouTube setting, not a legal category: one platform's compliance mechanism, applied to content rather than users.
Age assurance describes the technical methods used to establish how old a user is. COPPA sets a threshold without prescribing how operators should find it, which is why age assurance developed separately.
GDPR Article 8 sets a digital age of consent between 13 and 16 depending on member state and applies to information society services offered directly to children, on a different legal architecture entirely.
Recent developments
On 25 February 2026 the FTC issued an enforcement policy statement shielding age-verification technology, announcing by a 2-0 vote that it would not pursue general-audience and mixed-audience operators collecting personal information solely to determine age without prior consent, provided they restrict use to that purpose, delete promptly, obtain written vendor assurances and disclose the practice. Bureau of Consumer Protection director Christopher Mufarrige called age verification tools among the most child-protective technologies to emerge in decades. The statement holds until rule amendments are published.
The compliance deadline arrived on 22 April 2026, the date YouTube published a formal FAQ on creator classification duties. Weeks earlier the FTC's 2026 to 2030 strategic plan named children's privacy an institutional priority.
Commercial models are adapting around the constraint rather than through it. SuperAwesome became Roblox's sole third-party under-13 advertising partner worldwide on 4 June 2026, using contextual classification instead of behavioural tracking. In Congress, the SECURE Data Act preserves COPPA rather than replacing it, adding a 13-to-15 teen tier above it.
Timeline
- 1998: Congress enacts the Children's Online Privacy Protection Act
- 3 November 1999: FTC issues the first COPPA Rule
- 21 April 2000: Original Rule takes effect
- 17 January 2013: FTC publishes amended Rule adding persistent identifiers to personal information; effective 1 July 2013
- July 2019: Commission opens rule review, drawing more than 175,000 comments
- 4 September 2019: FTC and New York Attorney General settle with Google and YouTube for 170 million dollars
- 11 January 2024: Notice of proposed rulemaking published, drawing 279 unique comments
- 2 August 2024: FTC sues TikTok and ByteDance
- 16 January 2025: Commission votes 5-0 to finalise amendments
- 22 April 2025: Final amendments published in the Federal Register
- 23 June 2025: Amended Rule takes effect
- 2 September 2025: Disney settles for 10 million dollars; DOJ sues Apitor
- 28 January 2026: FTC holds age verification workshop
- 25 February 2026: FTC issues age-verification enforcement policy statement
- 5 March 2026: Senate passes COPPA 2.0 by unanimous consent
- 22 April 2026: Full compliance deadline for the 2025 amendments
- 18 May 2026: Google replaces TFCD and TFUA with TFAT
- 21 August 2026: DOJ announces 400 million dollar TikTok settlement
Related PPC Land coverage
- New COPPA rules take effect June 23, 2025 with major advertising changes - the 2025 amendment package and its advertising consequences.
- The FTC proposes new changes to COPPA Rule - the December 2023 proposals that opened the rulemaking.
- IAB warns against FTC rules that could harm children's online access - the trade body's objections to the proposed amendments.
- FTC gives age verification tech a COPPA enforcement shield - the February 2026 policy statement and its six conditions.
- YouTube's COPPA deadline hits: what the audience-setting rules really mean - the April 2026 compliance date as it landed on creators.
- Disney to pay $10 million for YouTube children's privacy violations - the designation failure that made channel-level labelling insufficient.
- FTC sues TikTok for alleged COPPA violations and privacy infringements - the August 2024 complaint and the 2019 consent order behind it.
- TikTok pays $400 million as DOJ moves to vacate its 2019 COPPA decree - the largest COPPA settlement to date and its payment structure.
- FTC sues robot toy maker Apitor over children's privacy violations - enforcement reaching a connected toy and a third-party SDK.
- CIMM report: bad kids data wastes $590,000 of every $1M ad campaign - the argument that COPPA is over-read as a measurement prohibition.
- Google's new TFAT signal kills TFCD and TFUA - and finally adds a TEEN tier - the consolidated age treatment parameter publishers now send.
- Google begins machine learning age detection for ad protections in US - platform-side age inference and the restrictions it triggers.
- Google tightens advertising rules to protect minors across its platforms - the January 2025 consolidation of child and teen advertising policy.
- FTC's 2026-2030 plan puts Big Tech, kids' data, and ad fraud in the crosshairs - children's privacy codified as a five-year enforcement priority.
- SuperAwesome becomes Roblox's only under-13 ad partner globally - a contextual advertising architecture built for an under-13 audience.
- Explaining made for kids - the YouTube audience setting that operationalises COPPA for creators.
- Explaining age assurance - the methods used to establish age and where they break down.
- House Republicans unveil SECURE Data Act to replace US state privacy laws - a federal privacy bill that preserves COPPA and adds a teen tier.
Summary
Who: The Federal Trade Commission enforces the statute and writes the Rule, joined by state attorneys general. Operators of child-directed and mixed-audience services, general-audience platforms with actual knowledge of under-13 users, and the ad tech vendors collecting data through those services carry the obligations. Parents hold the consent right.
What: A federal statute and implementing regulation requiring notice and verifiable parental consent before personal information is collected from a child under 13. Personal information includes persistent identifiers, geolocation and, since 2025, biometric identifiers. Behavioural advertising to this cohort is effectively prohibited absent consent, leaving contextual targeting and frequency capping. Civil penalties reach 53,088 dollars per violation.
When: Enacted 1998, effective April 2000, substantively amended in 2013 and again in 2025. The current amendments took effect 23 June 2025 with full compliance required by 22 April 2026.
Where: The United States, applying to commercial operators serving US children regardless of where the operator is established.
Why: Congress legislated on the premise that children cannot meaningfully consent to commercial data collection and that parents should hold that decision. The 2013 addition of persistent identifiers extended the premise from names and addresses to the identifiers that make programmatic advertising work.
Discussion