COPPA Rule 2025 Amendments
FTC amendments effective 22 April 2026: separate verifiable parental consent for third-party disclosures, written information security programs, data retention limits, expanded definition of personal information (biometrics, government IDs) and new mixed-audience rules.
| Jurisdiction | United States |
|---|---|
| Category | Privacy & Data Protection |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
The COPPA Rule 2025 Amendments are embodied in the FTC’s Final Rule Amendments to 16 CFR Part 312, published in the Federal Register on April 22, 2025, with an effective date of June 23, 2025 and a main compliance deadline of April 22, 2026 for most operators.16 CFR Part 312 Final Rule Amendments – FTC | Federal Register – COPPA Final Rule, Vol. 90, No. 76, April 22, 2025 (PDF) | Public Inspection Copy – COPPA Final Rule 2025-05904 (PDF)
Below is a structured analysis aligned with your requested sections and focused on primary authorities wherever possible.
Key Requirements
The 2025 COPPA amendments introduce several new or expanded obligations for operators of websites and online services directed to children under 13 or that knowingly collect personal information from children.
1. Separate verifiable parental consent for third‑party disclosures
- The Final Rule amends § 312.5(a)(2) to require separate verifiable parental consent before disclosing children’s personal information to third parties, except where the disclosure is integral to the website or online service’s operation.16 CFR Part 312 Final Rule Amendments – FTC | Federal Register – COPPA Final Rule (PDF)
- This change codifies that operators may not bundle consent for collection/use with consent for third‑party disclosures, particularly for targeted advertising or other non‑integral purposes.Federal Register – COPPA Final Rule (PDF) | FTC Business Guidance – Children’s Online Privacy Protection Rule
- Parents must be informed that they can consent to collection and internal use of their child’s data without consenting to disclosures to third parties, except when such disclosure is integral to providing the service.Federal Register – COPPA Final Rule (PDF) | Outside GC – FTC Finalizes Updated COPPA Rules (analysis)
2. Written information security program
- The amendments strengthen § 312.8 (Confidentiality, security, and integrity of information collected from children) to require that operators maintain a written information security program appropriate to the sensitivity of children’s data and the size and complexity of the organization.Federal Register – COPPA Final Rule (PDF) | 16 CFR Part 312 – COPPA Rule Text
- The Rule calls for periodic (at least annual) risk assessments, design and implementation of safeguards, and oversight of service providers handling children’s personal information.Federal Register – COPPA Final Rule (PDF) | Outside GC – FTC Finalizes Updated COPPA Rules
- Operators must obtain written assurances from service providers and third parties that they will implement appropriate confidentiality and security safeguards for children’s data.Federal Register – COPPA Final Rule (PDF) | Finnegan – The FTC’s Updated COPPA Rule
3. Data retention limits and written retention policies
- The amendments to § 312.10 (Data retention and deletion) require operators to retain children’s personal information only as long as reasonably necessary to fulfill the specific purpose for which the information was collected.Federal Register – COPPA Final Rule (PDF) | COPPA Rule – eCFR
- Operators must have a written data retention policy that specifies:
- The purposes for collecting children’s personal information
- The business need for retaining it
- The timeframes and criteria for deletion.Federal Register – COPPA Final Rule (PDF) | Finnegan – The FTC’s Updated COPPA Rule
- The FTC clarifies that a global retention policy covering all personal information can satisfy COPPA if it explicitly addresses children’s data and meets COPPA’s specific requirements.Outside GC – FTC Finalizes Updated COPPA Rules | Federal Register – COPPA Final Rule (PDF)
4. Expanded definition of “personal information” (including biometrics and government IDs)
- The COPPA Rule’s definition of “personal information” in § 312.2 is expanded to include biometric identifiers, such as scans of facial geometry, voiceprints, fingerprints, and other data used to identify or authenticate an individual.Federal Register – COPPA Final Rule (PDF) | COPPA Rule – eCFR
- The Rule also clarifies coverage of government‑issued identifiers (such as Social Security numbers and other official ID numbers) as personal information subject to COPPA protections when collected from children.Federal Register – COPPA Final Rule (PDF) | FTC COPPA FAQs – Q&A on Personal Information
- These expansions reflect FTC’s concern about high‑risk identifiers used for identity verification, payment, and authentication in children’s online services.Federal Register – COPPA Final Rule (PDF) | Fenwick – COPPA’s Coming of Age
5. New “mixed‑audience” rules
- The amendments codify and refine the concept of “mixed audience website or online service” in § 312.2, which covers services that are directed to children but do not target children as their primary audience and also serve adults or older teens.Federal Register – COPPA Final Rule (PDF) | COPPA Rule – eCFR
- Mixed‑audience sites must determine visitor age (or use another technology reasonably calculated to determine child status) before collecting personal information from any visitor, except for narrow purposes allowed in § 312.5(c).Federal Register – COPPA Final Rule (PDF) | Davis Wright Tremaine – FTC Amends COPPA Rule
- A general‑audience service does not become mixed‑audience merely because some children use it; it must have a portion directed to children, and then comply with COPPA for child users.Davis Wright Tremaine – FTC Amends COPPA Rule | Federal Register – COPPA Final Rule (PDF)
6. Enhanced direct notice and parental rights
- The amendments strengthen direct notice requirements to parents in § 312.4, requiring clear disclosure of:
- How the operator will use children’s personal information
- The categories of third parties receiving that information
- The fact that parents can consent to collection/use while withholding consent for third‑party disclosures (unless integral to the service).Federal Register – COPPA Final Rule (PDF) | Outside GC – FTC Finalizes Updated COPPA Rules
- Parents retain the right to review, delete, and revoke consent for their child’s data, and operators must provide mechanisms to exercise these rights.16 CFR Part 312 – COPPA Rule Text | FTC COPPA Compliance Plan
Compliance Challenges
Organizations face several recurring operational and governance challenges when implementing the COPPA 2025 amendments.
1. Managing separate parental consent flows
- Untangling bundled consent is difficult for platforms that historically used a single checkbox or flow for all data uses and disclosures, requiring redesign of UX flows for collection, internal use, and third‑party sharing.Finnegan – The FTC’s Updated COPPA Rule | Ampcus Cyber – COPPA Explained for Businesses
- Operators must ensure that third‑party SDKs, ad networks, analytics tags, and cloud services do not process children’s data without the specific, separate consent, which often requires contract updates and technical changes.Hunton – COPPA Rule Amendment Compliance Deadline Approaches | FTC Business Guidance – Children’s Privacy
2. Data mapping and retention governance
- Many organizations lack granular data maps identifying where children’s data resides, making it difficult to set purpose‑based retention limits and implement systematic deletion.Finnegan – The FTC’s Updated COPPA Rule | Outside GC – FTC Finalizes Updated COPPA Rules
- EdTech and gaming platforms often have legacy backups and logs where children’s personal information is stored indefinitely, conflicting with the new retention requirements.Promise Legal – COPPA 2025 Amendments EdTech Compliance Audit Guide | Ampcus Cyber – COPPA Explained for Businesses
3. Mixed‑audience classification and age estimation
- Determining whether a service is child‑directed, mixed‑audience, or general‑audience can be complex, especially for social, gaming, and entertainment platforms used heavily by minors.Davis Wright Tremaine – FTC Amends COPPA Rule | Fenwick – COPPA’s Coming of Age
- Implementing age gates or age estimation technologies must be “reasonably calculated” to distinguish children from adults, without encouraging children to misrepresent their age.Federal Register – COPPA Final Rule (PDF) | FTC COPPA FAQs
4. Building and maintaining a written information security program
- Smaller operators and app developers may lack formal security programs and must now develop documented policies, risk assessments, and safeguard implementations tailored to children’s data.Federal Register – COPPA Final Rule (PDF) | Outside GC – FTC Finalizes Updated COPPA Rules
- Aligning COPPA’s security expectations with existing frameworks (e.g., SOC 2, ISO 27001, NIST CSF) requires interpretation and integration, particularly for biometric and government ID data considered highly sensitive.Ampcus Cyber – COPPA Explained for Businesses | NIST Cybersecurity Framework
5. Real‑world enforcement examples
- The FTC’s historical COPPA actions against platforms like YouTube and various game/app providers illustrate typical pitfalls: improper data collection from children, defective consent mechanisms, and sharing data with ad networks without valid parental consent.FTC – COPPA Enforcement Cases Overview | FTC – Google/YouTube COPPA Case Press Release
- These cases are widely referenced in industry compliance guides as case studies of non‑compliance and highlight financial and reputational risks.FTC – COPPA Enforcement Actions | Promise Legal – EdTech Compliance Audit Guide
Implementation Best Practices
Below are actionable implementation steps aligned with the 2025 amendments and supported by recognized frameworks and guides.
1. Conduct a COPPA‑focused data inventory and classification
- Map all systems that collect, store, or process children’s personal information, including biometrics, government IDs, identifiers, and usage data.Finnegan – The FTC’s Updated COPPA Rule | FTC COPPA Compliance Plan
- Classify data by purpose, retention requirements, and sensitivity, which supports the written data retention and security programs mandated by COPPA.Federal Register – COPPA Final Rule (PDF) | NIST Privacy Framework
2. Design separate parental consent flows
- Implement a multi‑step consent process where parents:
- First consent to collection and internal use of their child’s information
- Then separately, explicitly opt‑in to third‑party disclosures (e.g., advertising, analytics)
Recent developments
- — Overview article explaining the **2025 COPPA Rule amendments**, noting that the amendments took effect on June 23, 2025 with an April 22, 2026 compliance deadline, and highlighting expanded definitions of personal information and tighter parental consent requirements, especially relevant for adtech and child-directed services.[13] (source)
- — Client alert analyzing the **post‑amendment landscape** for children’s privacy, describing how the updated COPPA Rule now covers biometric and government‑issued identifiers, imposes enhanced notice and data retention obligations, and interacts with broader online safety and children’s privacy regimes globally, impacting platforms, gaming, EdTech, and app ecosystems.[5] (source)
- — Blog post warning that the **April 22, 2026 COPPA compliance deadline** has arrived, summarizing key new requirements such as separate verifiable parental consent for third‑party disclosures (including targeted advertising), stricter data retention limits, and a broader definition of personal information, and advising operators to complete gap analyses and implementation.[12] (source)
- — Client update describing how the FTC is **prioritizing COPPA enforcement** as the new obligations take effect, noting the June 23, 2025 effective date and April 22, 2026 compliance deadline, and outlining enforcement risks, expected focus areas (ad targeting, data minimization, mixed‑audience services), and practical steps for companies.[10] (source)
- — Industry explainer on the **2025 COPPA Final Rule amendments**, detailing the new effective and compliance dates, expanded personal information scope (including biometrics), enhanced requirements for internal operations exemptions, and operational impacts on consent flows, data maps, and privacy engineering for child‑directed services.[9] (source)
- — Legal analysis of “Children’s Online Privacy in 2025” summarizing the amended COPPA Rule, including expanded definitions of “personal information” and “online contact information,” new mixed‑audience standards, more prescriptive security and retention rules, and increased safe harbor transparency, with commentary on how media, gaming, and social platforms must adjust product design and compliance programs.[15] (source)
- — Law firm insight on the **FTC’s published updates** to the COPPA Rule, emphasizing stronger protections for children’s data through separate parental consent for third‑party disclosures, new obligations around “support for internal operations,” and more prescriptive security requirements, and assessing likely operational burdens for online services.[3] (source)
- — Client note on the FTC’s **finalization of COPPA amendments**, highlighting key features such as opt‑in verifiable parental consent for targeted advertising, expanded personal information definitions, and tightened retention rules, while discussing enforcement expectations and strategic compliance steps for platforms and app developers.[8] (source)
- — Blog post explaining that the **final COPPA Rule amendments** will take effect around June 21, 2025 with an April 22, 2026 compliance deadline, summarizing major changes and advising privacy and product teams to prioritize consent management, data minimization, and vendor governance in anticipation of enforcement.[2] (source)
- — FTC press release announcing the Commission has **finalized COPPA Rule changes** that limit companies’ ability to monetize children’s data, including requirements for separate opt‑in parental consent for targeted advertising, stricter data retention limits, expanded personal information definitions (e.g., biometrics), and increased transparency for COPPA safe harbor programs, setting the foundation for the 2025–2026 implementation timeline and sparking significant industry reaction.[1] (source)
Related regulations
- COPPA (Children's Online Privacy Protection Act) — United States, Active
- Cybersecurity Maturity Model Certification — United States, Phased, effective 2025-11-10
- NIST AI Risk Management Framework (AI RMF 1.0) — United States, Active, effective 2023-01-26
- SEC Cybersecurity Disclosure Rules — United States, Active, effective 2023-12-18
- Executive Order 14365 - Ensuring a National Policy Framework for Artificial Intelligence — United States, Active, effective 2025-12-11
- TAKE IT DOWN Act — United States, Active, effective 2026-05-19
- SEC Regulation S-P Amendments (Customer Data Incident Response) — United States, Active, effective 2026-06-03
- CIRCIA Cyber Incident Reporting Rule (CISA) — United States, Proposed
Put it into practice
- Generate the policy: COPPA policy generator (generatepolicy.com)
- Buy the policy pack: Privacy Program Bundle (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates