Mixed-Audience Websites: COPPA's Hardest Compliance Question
Most sites aren't purely for kids or purely for adults, they're somewhere in between. COPPA has a specific carve-out for this, the mixed-audience approach, but it only works if you implement it correctly.
Pure children’s sites and pure adult sites are the easy cases under COPPA. The harder, far more common case is the site that’s neither: general-audience content with a segment of the user base that includes children, family entertainment, school-adjacent tools, hobby and gaming communities. COPPA has a specific mechanism for this, but it’s frequently implemented incorrectly.
What “mixed audience” actually means under COPPA
A mixed-audience site is one where children are a meaningful part of the audience, but the site isn’t exclusively or primarily directed to them, it serves a general or family audience where kids are one segment among others. This is distinct from being “directed to children” outright, which would trigger COPPA obligations for every visitor by default.
The age-screen mechanism
For a mixed-audience site, the FTC allows an age screen: before collecting any personal information, ask for age (or birth year), and route users who identify as under 13 through COPPA-compliant handling, verifiable parental consent, restricted data collection, no behavioral advertising, while treating everyone else under the site’s standard privacy practices.
Where implementations actually fail
- Asking for age after data is already being collected. If tracking scripts, analytics, or ad pixels fire before the age screen resolves, the screen isn’t actually gating anything, the exposure already happened for every visitor, including children, before the site even knows their age.
- Designing the screen to be easy to lie through. A neutral, unbiased age input is expected. An age gate that’s structured to nudge users toward entering an over-13 birthdate (for example, a design that makes the under-13 path visually or functionally punishing) undermines the good-faith basis of the mechanism.
- Not actually branching behavior after the screen. Collecting the age input but applying the same tracking and data collection regardless of the answer defeats the purpose entirely, the screen has to change what happens next.
- Allowing repeated attempts to “age up.” If a user enters an under-13 birthdate and is then simply allowed to retry with a different answer without any friction, the mechanism isn’t functioning as a good-faith screen.
What correct handling looks like technically
The core requirement is sequencing: the age screen has to sit upstream of any data collection or third-party script execution, not run in parallel with it. Concretely:
- No analytics, ad, or session-recording scripts fire until the age screen resolves.
- Users identifying as under 13 get a COPPA-compliant path: no behavioral advertising, no persistent tracking identifiers, verifiable parental consent before any further collection.
- Users identifying as 13+ proceed under the site’s standard privacy practices.
This is structurally the same problem as pre-consent script blocking for GDPR or CCPA, gating tag execution on an upfront signal rather than disclosing after the fact, just gated on an age answer instead of a cookie-consent choice.
Usercentrics
An age screen only works if it actually blocks tags until it resolves, the same technical requirement as consent-gated banners. Usercentrics' banner logic can hold third-party scripts until a condition is met, worth evaluating as the same mechanism that gates an age-screen branch for a mixed-audience site.
The bottom line
The mixed-audience age-screen approach is a legitimate, FTC-recognized way to serve a general audience without treating every visitor as a child under COPPA, but it only works if the screen is neutral, sits before any data collection, and actually changes what happens next. An age screen that data collection has already run past isn’t a compliance mechanism, it’s a formality.
This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.