Guide

COPPA vs. GDPR-K and the UK Children's Code: Comparing Global Kids' Privacy Rules

If your site has visitors in the US, EU, and UK, you're dealing with three different children's privacy frameworks at once, and they don't require the same things. Here's how they actually differ.

Published August 19, 2026·Last updated August 19, 2026

COPPA is a US-specific law, but it’s not the only children’s privacy framework a global site needs to think about. The EU has its own children’s-data provisions under GDPR, informally called “GDPR-K,” and the UK runs a separate, notably more prescriptive regime: the Age Appropriate Design Code, better known as the Children’s Code. Complying with one doesn’t automatically satisfy the others.

COPPA draws its line at under-13, requires verifiable parental consent before collecting personal information from a child, and is enforced by the FTC with specific, pre-approved consent mechanisms. It’s a compliance-checklist-style law: meet the specific requirements, and you’re covered.

GDPR doesn’t use a single EU-wide age threshold, it sets 16 as the default age at which a minor can consent to information society services on their own, but explicitly allows member states to lower that threshold, down to as young as 13, in their own national law. This means the applicable age varies by which EU country your visitor is in, a complication COPPA’s single national standard doesn’t have. GDPR also treats consent as only one of several possible lawful bases, meaning the compliance conversation for a child’s data under GDPR is broader than “did we get verified parental consent.”

The UK Children’s Code: the strictest of the three

The UK’s Age Appropriate Design Code doesn’t just regulate consent, it sets 15 specific standards for how any online service likely to be accessed by children (not just services directed to them) should be designed by default: privacy settings high by default, no nudge techniques that push children toward weaker privacy choices, minimal data collection by default, and specific limits on profiling and geolocation for under-18s. Critically, “likely to be accessed by children” is a broader trigger than COPPA’s “directed to children” or GDPR’s more consent-focused approach, a general-audience UK-facing site with a realistic teen user base can fall under the Children’s Code even without being designed for kids.

Where the three frameworks genuinely conflict

  • Age thresholds don’t align: under-13 (COPPA) vs. up to 16 depending on EU member state (GDPR-K) vs. under-18 protections for some Children’s Code provisions.
  • Trigger tests differ: “directed to children” (COPPA) vs. consent-and-lawful-basis analysis (GDPR-K) vs. “likely to be accessed by children” (UK Children’s Code), a meaningfully broader net.
  • Default behavior requirements differ: COPPA is primarily about consent before collection; the UK Children’s Code additionally mandates specific default settings and design choices regardless of consent status.
Our recommendation

Usercentrics

A global audience means your consent platform needs to apply different age thresholds and default states by region, not one blanket rule. Usercentrics' geolocation-based banner logic can serve different consent defaults and age-relevant flows by region, useful groundwork for reconciling COPPA, GDPR-K, and the UK Children's Code on the same site.

Try Usercentrics

A practical approach for multi-region sites

  1. Identify your actual regional traffic with any meaningful under-18 presence, US, EU, and UK specifically, given how differently each framework treats age.
  2. Build to the strictest applicable standard for each region rather than trying to find one global policy that technically satisfies all three, the requirements are different enough that a single approach usually under-serves at least one framework.
  3. Treat the UK Children’s Code as a design standard, not just a consent question, its default- settings requirements apply even to visitors who never explicitly identify as under 18.

The bottom line

COPPA, GDPR-K, and the UK Children’s Code share a general goal, protecting children’s data, but differ enough in age thresholds, trigger conditions, and required behavior that “COPPA-compliant” does not mean “globally compliant” for children’s privacy. A site with meaningful international traffic needs to treat these as three separate compliance questions.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.