Children's Online Privacy Protection Act (COPPA)
US federal law (the Children's Online Privacy Protection Act of 1998, 15 U.S.C. §§6501–6506) regulating online collection of personal information from children under 13, implemented and enforced by the Federal Trade Commission through the COPPA Rule (16 CFR Part 312). Unlike FERPA it binds the operator (the vendor) directly.
The Rule was substantially amended by the FTC's 2025 final rule (published 2025-04-22, Federal Register doc 2025-05904): among other changes, biometric identifiers enter the definition of personal information, a written information security program is required (§312.8(b)), and retention/deletion duties are tightened (§312.10). The text reproduced in this folder is the current amended text.
Applicability to EdTech
Applies to operators of websites/online services directed to children under 13, and to operators with actual knowledge they are collecting personal information from under-13s (§312.3) — which describes most K-12 EdTech. Core duties: notice, verifiable parental consent before collection, parental review/deletion rights, no conditioning participation on excessive collection, reasonable security, limited retention.
School-authorised consent: the Rule text itself contains no school-consent provision. The mechanism by which a school consents in place of parents in the educational context is FTC guidance — the "COPPA and Schools" section (Section N) of the FTC's COPPA FAQs — reinforced by the FTC's 2022 EdTech policy statement (which also states that lacking reasonable security violates COPPA even absent a breach). District RFI language about "allowing the school to provide consent on a parent's behalf" rests on this guidance, not on the Rule text.
Contents
| Document | Covers |
|---|---|
| SCOPE-AND-DEFINITIONS.md | 16 CFR §§312.1–312.3 — scope, definitions (incl. biometric identifiers), general prohibition |
| NOTICE-AND-CONSENT.md | 16 CFR §§312.4–312.7 — notice, verifiable parental consent, review rights, conditioning |
| SECURITY-AND-RETENTION.md | 16 CFR §§312.8, 312.10 — security (written program), retention and deletion |
Related
- FERPA — companion regime binding schools over education records
- CIPA — companion regime for content filtering
Sources
- eCFR — 16 CFR Part 312 (COPPA Rule), current text
- 15 U.S.C. §§6501–6506 (COPPA statute)
- Federal Register — Children's Online Privacy Protection Rule amendments (2025-05904)
- FTC — Children's privacy guidance hub
- FTC — Complying with COPPA: Frequently Asked Questions (Section N, COPPA and Schools)
Meta
Built and re-verified mechanically — see tools/ecfr: build_us_regs.py / build_us_regs.py verify. Do not hand-edit regulation text.