The Amended COPPA Rules, 2025: How Children’s Online Privacy Is Changing in the Age of Targeted Advertising

POSTED ON AUGUST 12, 2026 BY DATA SECURE
AUTHOR NAME: Ganesh Nair, Privacy Consultant
breach

Introduction

Whenever children access the internet in the form of an app, service, game, social media, etc. From the child’s perspective it is a very simple and playful experience. Behind the scenes however, these platforms are running a web of technologies like analytical tools, advertising networks, software development kits, and device identification technologies which record the child’s every action.

Federal Trade Commission updated the Children’s Online Privacy Protection Rules (COPPA Rules) in 2025 to introduce stronger controls in place to tackle the issue of invisible data collection ecosystems which most of the apps and websites have in place. The amendment also imposes compliance requirements concerning data retention, biometric information, cybersecurity, age screening, parental consent, and third-party service providers on the organisation which offers services to children. Most covered organisations were required to comply with the amended rule by April 22, 2026.

What is COPPA?

breach

Children's Online Privacy Protection Act (COPPA) is a United States Federal Law which has been framed to protect the privacy of Children under the age of 13. The Act is applicable to

  • All commercial websites and online services that are directed towards children under the age of 13.
  • Any general audience website/ online services that knowingly collect use or disclose personal information from a child under 13.
  • Any Mobile apps, online games, connected toys, streaming services, advertising plug-ins, and other internet-connected products that meet these conditions.

Entities that have to comply with COPPA must provide appropriate privacy notice and obtain verifiable parental consent before they collect, use or disclose any personal information from children.

The amended rules do not replace the existing COPPA, instead it upgrades it to ensure regulation is capable enough to address the requirements of the modern-day technologies and data practices.

Why are the amended COPPA rules necessary?

The internet advertising is more complex than it was in the 2000s. Children’s apps and websites are ridden with various third-party tools for analytics, behavioural advertising, crash reporting, location measurement, content recommendations, authentication, fraud prevention, customer support, and payment processing. These tools have the ability to collect information in the background without obtaining the consent from a child and where applicable from a parent.

A Research titled ‘Targeted and Troublesome:Tracking and Advertising on Children’s Websites’ conducted an empirical study on 2000 child-directed websites. It was found that amongst these websites 90% contained at least one tracking technology, while approximately 27% displayed targeted advertising. Further research also identified that some of these websites ran advertisements which were unsuitable for children.

Another study called Not Seen, Not Heard in the Digital World! by Ruoxi Sun et.al reviewed 20,000 Android apps and found that 81.25% if apps in Google Play’s family category used trackers. The researchers also identified location-permission requests, inconsistent age ratings, and privacy notices that were difficult for children to understand. These concerns were further highlighted in Won’t Somebody Think of the Children?” Examining COPPA Compliance at Scale, where majority of the apps targeted to children had third-party and analytics tool running in the background, with about 19% of the apps using software whose terms prohibited their use in child-directed services. Among apps sharing a resettable advertising ID, 66% also shared permanent device identifiers, making tracking harder to stop.

Similarly, 2024 study called DiffAudit: Auditing Privacy Practices of Online Services for Children and Adolescents found that many services collected data before the user gave consent or even disclosed their age. Majority of the services offered a similar level of age based protection for children, teenagers and adults, because of which many identifiable or linkable information was shared with third-party advertising and tracking services.

Such researches show the need to introduced more demonstrable accountability from services to protect children’s data

Major changes introduced under the amended COPPA rules

breach

1. Separate Parental Consent for Targeted Advertising

Under the new rules, companies are required to obtain a separate verifiable parental consent before disclosing a child’s personal information to third parties for purposes such as targeted advertising. This consent cannot be bundled with other permissions that are needed to provide essential services. The idea is to allow parents to consent to the child’s usage of website without consenting to the disclosure of child’s activity to an advertising network.

2. ‘Personal Information’ scope extended

The amended rules modernise and extend the scope of what is considered as protected personal information these now include social security, state identification card, birth-certificate, passport numbers and biometric identifiers. These are mentioned in 16 C.F.R. § 312.2, definition of “Personal information,” paragraphs (6) and (10). The newer scope is essential as many children’s products use voice recognition, face filters, identity checks, motion analysis, and camera-based features. So, companies cannot assume biometrics are not relevant for COPPA compliance because it is not name, email address or cookie. If the information can be used for automated or semi-automated recognition of an individual, the rule treats it as personal information.

3. New Rules formally recognizes “Mixed audience” Services

A new category has been defined by the amended rules, these websites, apps or games that appeal to children but do not treat them as the primary audience these are called ‘Mixed-Audience” defined under 16 C.F.R. § 312.2. These services are allowed to keep a neutral age screening, but they should not encourage a user to lie about their age or default to a particular age. If the service provider finds that the individual is under the age 13, then COPPA’s notice, consent, security, parental-access, and deletion requirements apply.

4. Stronger Data-Retention and Deletion Requirements

The amended COPPA rules will prohibit business from storing children’s personal information indefinitely. As per 16 C.F.R. § 312.10, the rules mandate that covered operators must establish a written data-retention policy explaining why the information was collected, what are the reasons for retaining it, how long it will be stored in the company’s systems and what are the circumstances or deadlines that will trigger its deletion.

5. A written information-security program is mandatory

As per 16 C.F.R. § 312.8(b) a covered operator must create and implement an information security program. This program should be designed as per the sensitivity of the children’s information being collected by the organisation and must be tailored to match the operator’s size, complexity, and activities. Rule 16 C.F.R. § 312.8(b)(1) -(5) states that at the minimum the covered operator must:

  • Designate one or more responsible employees;
  • Assess internal and external risks at least annually;
  • Design and implement safeguards addressing identified risks;
  • Regularly test and monitor those safeguards; and
  • Evaluate and modify the program at least annually.

6. Greater Responsibility for Third-Party Vendors

Various children’s digital services are built with a lot of technology which are supplied by third party vendors. A single service may rely on different vendors for advertising, analytics, authentication, cloud hosting, content delivery, payments, customer support, and fraud prevention. Rule 16 C.F.R. § 312.8(c) states that an operator must take reasonable steps to determine whether service providers and third parties can protect children’s personal information. All the companies that are involved in providing the services must confirm that their child-directed settings are activated and they are effective through out their chain of analytics and advertising providers.

7. Additional parental-consent methods are codified

Amended rules also have introduced additional methods to obtain verifiable parental consent. These include:

  • Payment-card verification, 16 C.F.R. § 312.5(b)(2)(ii), a parent can use a credit/ debit card or any other qualifying online payment that notifies the account holder. It is to be solely used for verification purposes i.e. there is no requirement, that an actual monetary charge should be made.
  • Knowledge-based authentication, 16 C.F.R. § 312.5(b)(2)(vi) authentication can be completed by using a sufficiently difficult & dynamic questionnaire with adequately large set of possible answers. The idea here is to design Questions to which the answers cannot be reasonably ascertained by a 12 year old.
  • Verification of the government-issued photographic ID of the parent: The official ID of the parent can be used to compare against a live image of a parent’s face rule 16 C.F.R. § 312.5(b)(2)(vii). However, companies are required to immediately delete the ID and images once the verification is completed.

8. Greater Transparency for COPPA Safe Harbor Programs

COPPA Safe harbour is a Federal Trade Commission (FTC) approved privacy oversight program operated by a private organisation, such as an industry association or certification body. Companies participating in an approved program may follow its guidelines if those guidelines provide protections that are consistent with COPPA.

The introduction of amended rules, reporting and transparency requirements for these programs have been made stronger.

  • 16 C.F.R. § 312.11(d) made sure that that safe-harbour programs must submit annual reports identifying member, operators and certified services.
  • 16 C.F.R. § 312.11(d)(4) Safe harbours association/ certification body must publicly post lists of their current members and the websites or online services certified for each member. Those lists must be updated every six months.

What Business should be able to prove to parents?

breach

For businesses offering services to children aged 12 and under, COPPA compliance means being able to clearly inform parents about:

  • What data you collect? - What type of data will you be collecting location data, photos, voice recordings, device IDs, or online activity
  • Who receives the data? – Provide clear information on the companies or third parties who will subsequently receive the child;s information and also explain the reason for sharing such data.
  • What is the purpose of sharing that data? - make it clear to the parent that whether this data sharing is mandatory to provide the services or if it is being collected to be used or targeted advertising or similar optional purposes
  • How long the data is kept? -The duration for which the children’s information will be kept and when it will be deleted. Companies should never retain the data indefinitely.
  • Advertising consent is optional- inform the parents that basic services can be provided without agreeing to sharing of the data for advertising.
  • Consent choices are clear- Consent requests must be presented in simple, complete, and understandable language without burying the refusal option in layers of texts.
  • Why Compliance should not be delayed?

    Various factors such as the number of children affected, the sensitivity and amount of personal information collected, how children’s information was used. whether it was shared with third parties, the seriousness of the violation, and the size and compliance history of the organisation may influence the penalties that can be imposed on an organisation for the violating COPPA. The FTC’s current guidance states that a court may impose civil penalties of up to $53,088 per violation.

    In 2025, Walt Disney Company had to pay $10 million fine to settle a Federal Trade Commission lawsuit alleging it allowed personal data to be collected of kids under 13, violating federal law. Disney was found to be violating the provisions of COPPA, as it collected personal information from children, through various child-oriented apps and websites without the parent’s consent. Along with this Disney had also failed to tag various YouTube videos “Made for kids” which allowed YouTube to collect data from children under 13 which was further used by Google for targeted advertising.

    Such cases demonstrate that regulators are actively monitoring and enforcing children’s privacy laws. Companies must therefore ensure ongoing compliance with COPPA and other applicable data-protection laws.

    Conclusion

    The amended COPPA Rule strengthens the protection of children by addressing the new tracking tools, targeted advertising, biometric data, data retention and third-party data sharing. The amended rules have increased the accountability of companies by making it mandatory to obtain proper parental consent, secure children’s information and ensure proper auditing of the service providers. The compliance is now not limited to the mere documentation instead companies are now expected to keep a continuous oversight of how children’s data is collected, used, shared, and deleted across the entire digital ecosystem.

    We at Data Secure (Data Privacy Automation Solution) DATA SECURE - Data Privacy Automation Solution  can help you to understand Privacy and Trust while lawfully processing the personal data and provide Privacy Training and Awareness sessions in order to increase the privacy quotient of the organisation.

    We can design and implement RoPA, DPIA and PIA assessments for meeting compliance and mitigating risks as per the requirement of legal and regulatory frameworks on privacy regulations across the globe especially conforming to GDPR, UK DPA 2018, CCPA, India Digital Personal Data Protection Act 2023. For more details, kindly visit DPO India – Your outsourced DPO Partner in 2025 (dpo-india.com).

    For any demo/presentation of solutions on Data Privacy and Privacy Management as per EU GDPR, CCPA, CPRA or India DPDP Act 2023 and Secure Email transmission, kindly write to us at info@datasecure.ind.in or dpo@dpo-india.com.

    For downloading the various Global Privacy Laws kindly visit the Resources page of DPO India - Your Outsourced DPO Partner in 2025

    We serve as a comprehensive resource on the Digital Personal Data Protection Act, 2023 (Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025), India's landmark legislation on digital personal data protection. It provides access to the full text of the Act, the Draft DPDP Rules 2025, and detailed breakdowns of each chapter, covering topics such as data fiduciary obligations, rights of data principals, and the establishment of the Data Protection Board of India. For more details, kindly visit DPDP Act 2023 – Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025

    We provide in-depth solutions and content on AI Risk Assessment and compliance, privacy regulations, and emerging industry trends. Our goal is to establish a credible platform that keeps businesses and professionals informed while also paving the way for future services in AI and privacy assessments. To Know More, Kindly Visit – Your Trusted Partner in AI Risk Assessment and Privacy Compliance | AI-Nexus