Guide

What COPPA Requires in Your Privacy Policy (and What Most Sites Get Wrong)

COPPA doesn't just require a privacy policy, it requires specific disclosures a general privacy policy usually doesn't include. Here's exactly what has to be there.

Published August 21, 2026·Last updated August 21, 2026

Most businesses already have a privacy policy for GDPR or CCPA purposes and assume it covers COPPA too. It usually doesn’t. COPPA requires specific, additional disclosures that a general-purpose privacy policy frequently omits entirely.

What a COPPA-compliant notice actually has to include

  1. What information is collected from children specifically, not just a general description of data collected from all users. The notice needs to identify categories collected from the under-13 population distinctly.
  2. How that information is used.
  3. Whether the operator discloses children’s information to third parties, and if so, the categories of third parties and the purposes.
  4. A statement that the operator will not require a child to disclose more information than reasonably necessary to participate in an activity, this specific data-minimization statement is a COPPA-specific requirement, not standard boilerplate.
  5. The parent’s rights: to review the child’s personal information, request its deletion, and refuse further collection or use, along with the actual process for exercising those rights.
  6. Contact information for the operator, including a way to reach someone who can act on a parent’s request.

The “direct notice” requirement

Beyond the general privacy policy, COPPA requires a direct notice to parents before collecting personal information from their child, separate from and in addition to the policy posted on the site. This direct notice has its own more specific content requirements depending on what consent exception (if any) applies, and it’s the piece most frequently missing entirely, businesses often have a compliant-looking policy page but no actual direct-notice mechanism reaching parents before collection happens.

Common gaps we see

  • A single, generic privacy policy that mentions “we may collect information from users of all ages” without the specific COPPA disclosures required once children’s data is actually in scope.
  • No distinct link or section for the COPPA notice, burying children’s-data practices inside a much longer general policy where the specific required elements are hard to find or missing outright.
  • Missing the data-minimization statement. This exact commitment, not collecting more than reasonably necessary, is often absent even from policies that otherwise look thorough.
  • No functioning process behind the stated parental rights. A policy that says parents can request deletion, with no actual internal process or contact route to make that happen, is a real compliance gap that surfaces the first time a parent tries to exercise it.
Our recommendation

Usercentrics

If you're already running a consent platform for GDPR or CCPA, check whether its generated policy language actually includes COPPA-specific disclosures, most general privacy policy generators don't by default. Usercentrics' privacy policy tooling supports multiple regulatory frameworks in one generated document rather than a GDPR/CCPA-only template.

Try Usercentrics

A cookie consent banner and a COPPA privacy notice serve different legal purposes and shouldn’t be conflated. A GDPR/CCPA-style “accept cookies” banner does not satisfy COPPA’s direct-notice-to- parents requirement, and a COPPA notice doesn’t substitute for general cookie consent disclosures either. Sites that need both should treat them as two distinct, coexisting obligations, not one combined mechanism.

The bottom line

A general privacy policy, even a good one, almost never satisfies COPPA’s specific disclosure requirements on its own. If your site collects data from children under 13, the practical step is a distinct, findable COPPA notice covering the specific required elements, backed by an actual process for parents to exercise their rights, not just a written promise that they can.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.