Updated: September 3, 2026 · Docs · Clothoff AI Editorial Team
What is COPPA?
A glossary entry on the US children’s privacy rule, the 2025 amendments, and how an adult review publisher keeps children out of scope.
Educational glossary entry by a review publisher; not legal advice.
What does the COPPA Rule require?
COPPA is the Children’s Online Privacy Protection Act of 1998 and the FTC rule that implements it, 16 CFR Part 312. It requires operators of sites directed to children under 13, or with actual knowledge of child users, to obtain verifiable parental consent before collecting personal information. Amendments published April 22, 2025 required compliance by April 22, 2026.
The statute dates from 1998; the rule was amended in 2013 and 2025. The table shows the duties an operator in scope must meet.
| Law | Effective date | What it covers | Penalty | Source |
|---|---|---|---|---|
| COPPA, 15 U.S.C. §§6501–6506 | April 21, 2000 (rule) | Parental consent before collecting personal data from children under 13 | Civil penalties per violation under the FTC Act | FTC – Children’s Privacy |
| 16 CFR Part 312 – 2013 amendments | July 1, 2013 | Added geolocation, photos, video, audio and persistent identifiers to personal information | Same enforcement | 16 CFR Part 312, eCFR |
| 2025 amendments, 90 FR 16918 | Effective June 23, 2025; compliance April 22, 2026 | Separate consent for third-party disclosures; written retention policy; biometric identifiers; mixed-audience definition | Same enforcement | Federal Register, April 22, 2025 |
| Safe harbor programs, §312.11 | 2000; expanded 2025 reporting | FTC-approved self-regulatory programs may certify operators | Program members deemed compliant if they follow program rules | 16 CFR §312.11, eCFR |
Who is covered by COPPA?
The rule applies to operators of websites or online services directed to children under 13, and to general-audience operators with actual knowledge that they collect personal information from a child. Personal information includes names, contact details, photos, voice, persistent identifiers and, since 2025, biometrics.
A mixed-audience service, child-directed but not primarily aimed at children, may age-screen visitors and apply COPPA only to those who identify as under 13. The 2025 amendments codified that definition.
What changed in the 2025 amendments?
The FTC published the final rule on April 22, 2025 at 90 FR 16918. Operators must obtain separate parental consent before disclosing a child’s data to third parties for advertising, publish a written retention policy, and treat biometric identifiers as personal information. Compliance was due April 22, 2026.
The amendments also expanded approved consent methods and increased reporting duties for safe harbor programs. Civil penalties are assessed per violation under the FTC Act, and the FTC has brought cases against app developers, ad networks and toy makers.
Why does an adult review site care about COPPA?
Clothoff AI is an 18+ publisher: every page shows an age gate, the privacy policy states that no data is knowingly collected from anyone under 18, and the site runs no accounts or uploads. COPPA’s consent duties do not apply, but a report of a child user must still be acted on.
The tools we review accept uploads and run accounts, so their age verification and data practices are scored under privacy. State rules add another layer, tracked on our state age verification page.
“The Federal Trade Commission (‘Commission’ or ‘FTC’) amends the Children’s Online Privacy Protection Rule (‘COPPA Rule’ or ‘Rule’), consistent with the requirements of the Children’s Online Privacy Protection Act”
— Federal Register, 90 FR 16918 (April 22, 2025), accessed September 3, 2026
Consent Note
This site is a publisher: it reviews third-party tools and does not create, edit, accept or store images. Docs entries are general information, not legal advice.
Sources
All sources accessed on September 3, 2026; educational entry, not legal advice.
- Federal Register – Children’s Online Privacy Protection Rule, final rule, 90 FR 16918 (April 22, 2025)
- 16 CFR Part 312 – Children’s Online Privacy Protection Rule (eCFR)
- FTC – Children’s Privacy business guidance
- 15 U.S.C. §6501 – Children’s Online Privacy Protection Act definitions (LII)
- California Office of the Attorney General – CCPA (minors’ opt-in)
FAQ: COPPA
What age does COPPA protect?
Children under 13. Minors between 13 and 17 fall outside COPPA, although the CCPA requires opt-in consent before selling data of consumers under 16 and several state laws add duties for older minors. Our site treats every visitor under 18 as out of scope and collects no account data.
What are the 2026 COPPA compliance dates?
The amended rule was published April 22, 2025 and took effect June 23, 2025. Operators had until April 22, 2026 to comply with most new requirements, including separate consent for third-party disclosures, the written retention policy and updated notices. Those dates have now passed.
Does COPPA apply to adult websites?
Not to their consent duties, unless they are directed to children or have actual knowledge of a child user. An adult site with an age gate and a policy of collecting no data from minors is outside COPPA’s core scope but must act if it learns a child provided information.
What are the penalties for violating COPPA?
The FTC treats a violation as an unfair or deceptive practice under the FTC Act and seeks civil penalties assessed per violation, plus consent orders that mandate data deletion and compliance programs. State attorneys general may also bring COPPA actions.
Does COPPA cover photos and biometrics?
Yes. Photos, videos and audio containing a child’s image or voice have been personal information since the 2013 amendments, and the 2025 amendments added biometric identifiers such as facial templates. An image tool that accepts a child’s photo therefore triggers the rule.
How is COPPA different from the GDPR?
COPPA is a US federal rule for children under 13 that requires verifiable parental consent before collection. The GDPR sets a digital consent age between 13 and 16 depending on the member state and applies to all personal data processing, not only child-directed services.