Skip to content
PeekWellThe Rulebook
Join now

COPPA compliance: children's data without parental consent

At a glance

US-10High15 U.S.C. §§6501-6506; 16 CFR Part 312 (as amended 2025); civil penalty under 16 CFR 1.98(d)

Peeky looks for signs that a site is made for young children, then checks whether it collects data and shows a clear notice and a way for parents to say yes.

Last checked against the source:

I need to fix thisI need the rule

The rule

The Children’s Online Privacy Protection Act reaches two kinds of operator: one “of a website or online service directed to children”, and “any operator that has actual knowledge that it is collecting personal information from a child”. Section 6502(b)(1)(A) tells the Federal Trade Commission to write rules requiring such operators to “provide notice on the website of what information is collected from children by the operator, how the operator uses such information, and the operator’s disclosure practices”, and to “obtain verifiable parental consent for the collection, use, or disclosure of personal information from children.”

The FTC wrote those rules as 16 CFR Part 312, the COPPA Rule. A child is “an individual under the age of 13”. Under section 6502(c) a failure to follow the Rule is treated as a failure to follow a rule defining an unfair or deceptive practice, so the FTC enforces it under its own Act, and civil penalties follow from that.

Whether a site is “directed to children” is decided on the whole picture. The Rule lists subject matter, visual content, the use of animated characters or child-oriented activities and incentives, music or other audio content, the age of models, child celebrities, language or other characteristics, and whether advertising is directed to children. The Commission also considers competent and reliable empirical evidence of audience composition and evidence of the intended audience. A site that is directed to children in part, without making them its primary audience, and that does not collect personal information from any visitor before it asks age or uses another means reasonably calculated to tell whether the visitor is a child, is a mixed-audience service, and the Rule says it is not treated as directed to children for any visitor not identified as under 13.

The reach of “personal information” is wider than most founders expect. It includes a name, an address, online contact information, a photo, video or audio file with a child’s image or voice, precise location, and “a persistent identifier that can be used to recognize a user over time”. A cookie or a device ID inside an advertising or analytics kit is within that wording. The Rule also defines support for internal operations, a closed list that covers keeping the service working, security, personalisation and contextual advertising, but not building profiles for behavioural advertising.

The Rule was amended on 22 April 2025 (90 FR 16918). The amendments took effect on 23 June 2025 and, apart from a few safe harbor provisions with their own dates, operators had until 22 April 2026 to comply, so the amended text is now in force. The FTC’s summary of the changes lists a separate verifiable parental consent before children’s data is disclosed to third parties, for example for targeted advertising, a limit on keeping personal information to as long as reasonably necessary for the purpose it was collected, written security and retention programmes, a wider definition of personal information that adds biometric and government-issued identifiers, and more transparency from safe harbor programmes. On 25 February 2026 the FTC issued an enforcement policy statement on age-verification technology; the page we read states its purpose and date, and an operator relying on it should read the conditions there.

The enforcement record is mostly settlements. Penalty amounts are set by 16 CFR 1.98. The text of paragraph (d) we read states $53,088 for each instance, and the amounts apply to penalties assessed after 17 January 2025; the figure is adjusted every year and the current text is the one to rely on. The cases below are settlements, so what they describe are the FTC’s allegations.

What PeekWell checks and how

US-10 asks whether the public pages show signs of being made for young children, and if they do, whether the site collects data and shows a clear notice and a route for parents. It does not give a verdict. The answer to “directed to children” is a mixed judgment and the Rule says it depends on the whole picture.

The check only runs where a first step finds child-directed signals. A language model reads the public pages and classifies the signals: the subject matter, characters, the language used, the activities and rewards, the way the pages look, and any age gate. That classification is the only judgment in the check, and it is shown as a signal with its reasons, never as a fact. The rest is code. Where signals are present, the scan looks for an age screen, for a COPPA notice or a link to a privacy notice that speaks to children and parents, and it notes whether data collection is visible on the pages.

The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not create an account, submit a form, enter a birth date or test a consent flow, so it cannot tell whether a parental consent step exists behind sign-up and works. It does not read your contracts or know who your audience is, and a model’s reading of the signals can be wrong. Collection that happens on a server or inside an app is outside what a browser visit can see. The scan’s shared engine records network requests and cookies, but this check does not test how they behave. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.

Why it matters for a company

The FTC’s cases are specific about the facts it relied on. In the Disney matter the FTC alleged that more than 300 videos were labelled at the channel level as not made for kids, despite a 2020 notice from YouTube asking for reclassification, and that the label let data be collected for targeted advertising from children who watched. The order requires Disney to review how it labels videos unless YouTube adopts age assurance. The amount was $10 million, and a court approved the order on 31 December 2025.

In the Cognosphere matter the FTC alleged the company knew children under 13 used its game and shared identifiers and play data with analytics and advertising companies. The $20 million settlement also covers loot box claims.

Two points follow. Responsibility does not stop at your own code: the FTC’s guidance says that if another company collects personal information through your child-directed site, for example through an ad network or plug-in, you are responsible for complying. And since April 2026 the separate consent for third-party disclosure and the retention rules apply to everyone in scope.

Smaller companies and larger companies

The Rule has no size threshold. What decides it is the audience and what the service collects.

In a small company the problem often arrives through a product that happens to attract children: a game, a learning app, a toy with a companion app, a creator channel. A founder adds an analytics or advertising kit, or a location library, to understand users, and nobody asks what it collects from a child. In the Apitor matter the FTC alleged that a third-party kit in the app collected children’s precise location while the app had no notice to parents or consent step. The company said it could not pay, and the $500,000 penalty was suspended.

In a larger company the same pattern is spread across more hands. Content teams publish to platforms, marketing owns the pixels, and a setting made years ago keeps applying. The Disney allegations are of that kind: a channel-level setting covering hundreds of videos.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC

    FTC (United States), 2025$10 million

    The FTC alleged that Disney set some of the videos it uploaded to YouTube as not made for kids, at the channel level, even though they were directed to children. It alleged that this let personal data be collected from children who watched them, and used for targeted advertising, without notice to parents or their consent. The settlement requires a program to review how videos are labelled, unless YouTube adopts age assurance, and a court approved the order on 31 December 2025.

    Read the FTC (United States) publication about Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC
  • Cognosphere Pte. Ltd. and Cognosphere LLC (HoYoverse)

    FTC (United States), 2025$20 million

    The FTC alleged that the maker of Genshin Impact was aware that children under 13 were using the game and collected their user IDs, device identifiers, player progress and purchases without parental consent, and shared some of it with analytics and advertising companies. The same settlement covers loot box claims, so the amount is not for the children's data claims alone.

    Read the FTC (United States) publication about Cognosphere Pte. Ltd. and Cognosphere LLC (HoYoverse)

Smaller companies

  • Apitor Technology

    FTC (United States), 2025$500,000, suspended

    The FTC alleged that the robot toy maker's app let a third-party software kit collect children's precise location data without telling parents or getting their consent. Android users had to turn on location sharing to use the app. A proposed order requires parental notice and consent and deletion of the data, and the $500,000 penalty is suspended because the company said it could not pay.

    Read the FTC (United States) publication about Apitor Technology

How to fix it

These steps follow the FTC’s own six-step plan: decide whether you are in scope, post a notice, tell parents directly, get verifiable consent, honour parents’ rights, and secure and delete the data. They are practical, not legal advice.

  1. Decide who the site is for. Write down the audience on one page, using the factors the Rule lists: subject matter, characters, music, activities, ads and what your analytics say about age. If young children are a main audience, treat the whole service as child-directed. If they are part of a wider audience, you are mixed-audience.
  2. List everything that collects data. Open the site and the app with the network tab and list every third-party request, kit and embed. For each, find out whether it records an identifier. The FTC says you must inquire into the practices of every third party that can collect information through your service.
  3. Remove or hold what you cannot justify. On a child-directed service, take out advertising and cross-site analytics kits unless you have parental consent for that disclosure. Keep to the Rule’s internal-operations list for anything that stays.
  4. Add a neutral age screen if you are mixed-audience. Ask for month and year of birth with no hint that answers change what is available, collect nothing before the answer, and use a cookie or similar to stop retries. Do not block children altogether. Load third-party tags only after the screen.
  5. Publish the notice and tell parents directly. Put a children’s privacy notice where data is collected, saying what you collect, how it is used and who receives it, and send parents a direct notice before collecting from a child.
  6. Get verifiable parental consent, and a separate one for sharing. Use a consent method the Rule accepts, and ask separately before disclosing a child’s data to third parties for purposes such as advertising.
  7. Set retention and security. Write a retention policy that keeps data only as long as needed for the purpose, delete the rest, and keep a written security programme.
  8. Re-scan. Clear cookies and storage, reload the public pages, and run a scan again. The finding should drop away once no collection starts before the age screen or the parents’ consent.

Whether your service is child-directed, and whether a particular consent method works, are questions for your legal adviser. Peeky reports only what it sees.

Questions

Who has to follow COPPA?

Operators of websites and apps directed to children under 13, and any operator that has actual knowledge it is collecting personal information from a child. Section 6502(a)(1) of the statute sets both tests. A site is not treated as child-directed just because some children visit it.

What are the COPPA compliance requirements?

Post a notice, tell parents directly, get verifiable parental consent before collecting, honour parents' rights to review and delete, and protect and limit the data you keep. The FTC sums this up in six steps. The 2025 amendments added a separate consent for sharing children's data with third parties and a written retention policy.

What are the penalties under COPPA?

The statute treats a failure to follow the Rule as a failure to follow an FTC rule, which carries a civil penalty for each instance. The figure in 16 CFR 1.98(d) as we read it is $53,088, and it is adjusted for inflation each year, so check the current text. The cases above show $10 million, $20 million and a suspended $500,000.

Does an age gate make a site COPPA compliant?

Only in the narrow case of a mixed-audience site, and only if the gate is neutral and collects nothing before the age is known. The FTC says an age screen must not nudge children to lie, for example by saying some features are unavailable under 13. It also says you may not block children from taking part altogether.

How does Peeky check for COPPA signals?

Peeky reads your public pages for signs the site is made for young children, such as characters, language and the way it is designed. Only where those signs appear does it look for data collection, an age screen and a notice for parents. It never signs up, never enters a birth date and never talks to a child's account. How a scan works has the full path.

Filed with

The rule

Children's Online Privacy Protection Act, 15 U.S.C. §§6501-6506

Read the rule (Children's Online Privacy Protection Act, 15 U.S.C. §§6501-6506)

A case

Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC

FTC (United States), 2025

Read the decision (Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. 15 U.S.C. §6502, Regulation of unfair and deceptive acts and practices in connection with the collection and use of personal information from and about children on the Internet (Cornell LII)
  2. FTC, Children's Online Privacy Protection Act statute page
  3. 16 CFR Part 312, Children's Online Privacy Protection Rule (eCFR, text current at 1 October 2026)
  4. Federal Register, Children's Online Privacy Protection Rule, final amendments, 90 FR 16918, 22 April 2025
  5. FTC, FTC Finalizes Changes to Children's Privacy Rule Limiting Companies' Ability to Monetize Kids' Data (16 January 2025)
  6. FTC, Complying with COPPA: Frequently Asked Questions
  7. FTC, Children's Online Privacy Protection Rule: A Six-Step Compliance Plan for Your Business
  8. FTC, Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology (25 February 2026)
  9. 16 CFR 1.98, Adjustment of civil monetary penalty amounts (eCFR)
  10. FTC, Disney to Pay $10 Million to Settle FTC Allegations the Company Enabled the Unlawful Collection of Children's Personal Data (2 September 2025)
  11. FTC, Court Approves Order Requiring Disney to Pay $10 Million (December 2025)
  12. FTC, Genshin Impact developer will be banned from selling loot boxes to teens under 16 without parental consent, pay a $20 million fine (17 January 2025)
  13. FTC, FTC Takes Action Against Robot Toy Maker for Allowing Collection of Children's Data without Parental Consent (3 September 2025)

Last checked against the source:

For information only. Not legal advice.