Skip to main content

COPPA

Children's Online Privacy Protection Act (COPPA) + FTC COPPA Rule (16 CFR Part 312)

Baseline US children's data privacy regime. Applies to operators of websites/online services directed to children under 13, and to general-audience services with actual knowledge they collect personal info from under-13 users.

Jurisdiction

United States

Enacted

Oct 21, 1998

Effective

Apr 21, 2000

Enforcement

Federal Trade Commission (FTC) + State Attorneys General

eCFR — 16 CFR Part 312

Why It Matters

Applies to services that can attract under-13 users (games, companions, character chat, social features). Key US regulation requiring parental consent and data minimization. FTC actively enforcing against AI companies.

Recent Developments

FTC issued final COPPA Rule amendments January 2025; effective June 23, 2025; full compliance deadline April 22, 2026. Expands "personal information" definition, strengthens consent requirements, limits data retention.

At a Glance

Applies to

Social PlatformOnline PlatformGaming PlatformGeneral ChatbotAI CompanionCharacter Chatbot Minors-focused

Harms addressed

Who Must Comply

  • Operators of child-directed websites/online services
  • Operators with actual knowledge they collect personal info from children under 13
  • Ad networks / plug-ins collecting from child-directed properties

Applicability thresholds:

Under 13 years old — Parental consent required for data collection

Safety Provisions

  • Provide clear/complete privacy notices for children's data practices
  • Obtain verifiable parental consent before collecting/using/disclosing personal information from children under 13
  • Give parents access/choice rights (review, delete, refuse further collection)
  • Data minimization: cannot condition participation on more data than reasonably necessary
  • Maintain reasonable security procedures for children's personal information
  • Retention limits: keep children's data only as long as reasonably necessary, then delete securely
  • Cannot disclose children's data to third parties without parental consent

Compliance & Enforcement

Key Dates

Apr 21, 2000

Initial COPPA Rule becomes effective

Jul 1, 2013

2013 amendments effective (expanded definitions, new parental consent requirements)

Jun 23, 2025

2025 amendments effective

Oct 22, 2025

Safe Harbor programs compliance deadline

Apr 22, 2026

Full operator compliance deadline for 2025 amendments

Penalties

$53K/violation

View on map

United States

Focus Areas

Mental health & crisis
Child safety
Algorithmic accountability
Active safeguards required

Cite This

APA

United States. (1998). Children's Online Privacy Protection Act (COPPA) + FTC COPPA Rule (16 CFR Part 312).

Related Regulations

Pending US

KOSA

Would establish duty of care for platforms regarding minor safety. Passed full Senate 91-3 in July 2024; passed Senate Commerce Committee multiple times (2022, 2023). Not yet enacted.

Pending US

COPPA 2.0

Would expand COPPA-style protections to teens (13-16) and add stronger constraints including limits on targeted advertising to minors. Often paired politically with KOSA.

Enacted US-IL

IL HB 5511

Requires covered operators of online platforms to apply protective default settings to users they know to be minors, including limits on algorithmic feeds, a 10 p.m. to 7 a.m. notification curfew and no autoplay by default on addictive social media platforms, and establishes a device-level age-bracket signal that Internet-enabled device manufacturers must provide and operators must request. Announced by the Governor as the Children's Social Media Safety Act, the title of the bill as introduced. Enforced by the Attorney General.

Enacted US-IA

IA SF 2417

Establishes requirements and guidelines for conversational AI services including AI disclosure to minors, prohibition on sexually explicit content for minors, prevention of deceptive human-like interactions, and parental controls for children under 13.

Enacted US-CO

CO HB 1263

Imposes obligations on conversational AI service operators including minor-user protections, suicide and self-harm protocols, prohibition on emotional dependence and engagement gamification, and annual safeguard reporting.

In Effect FI

Finland AI Act

Finland's EU AI Act implementation using decentralized supervision model. Traficom serves as single point of contact and coordination authority. Ten market surveillance authorities share enforcement across sectors. New Sanctions Board handles fines over EUR 100,000.

Last updated February 17, 2026. Verify against primary sources before relying on this information.