Guide

What Is COPPA? The Federal Children's Privacy Law Explained

COPPA has governed how US websites handle children's data since 1998, and its requirements are stricter and more specific than most general privacy law. Here's what it actually covers.

Published August 14, 2026·Last updated August 14, 2026

The Children’s Online Privacy Protection Act, COPPA, is a US federal law that’s been on the books since 1998, well before GDPR or CCPA existed, and it remains one of the more specific, rule-based privacy laws in the US. If your site has any chance of reaching visitors under 13, COPPA applies a different, stricter standard than general privacy law does.

Who COPPA actually regulates

COPPA applies to operators of commercial websites or online services that either:

  1. Are directed to children under 13, or
  2. Have actual knowledge that they’re collecting personal information from children under 13, even if the site is generally aimed at adults.

Both prongs matter independently. A general-audience site can still trigger COPPA obligations the moment it becomes aware a specific user is under 13, for example, through an age field on a signup form.

What counts as “personal information” under COPPA

COPPA’s definition is broader than many businesses expect. It includes the obvious (name, email, address, phone number) but also:

  • Persistent identifiers that can be used to recognize a user over time or across sites, including cookies and device IDs used for behavioral advertising.
  • Photos, videos, or audio files containing a child’s image or voice.
  • Geolocation data precise enough to identify a street name and city.
  • Screen or user names, if they function as online contact information.

This is the detail that catches sites off guard: a persistent advertising cookie set on a page a child is using can itself be regulated “personal information” under COPPA, independent of any name or email collected.

What COPPA actually requires

  1. A clear, COPPA-specific privacy notice describing what’s collected from children, how it’s used, and whether it’s disclosed to third parties.
  2. Verifiable parental consent before collecting personal information from a child, with narrow exceptions (covered in our parental consent guide).
  3. A parent’s right to review, delete, and refuse further collection of their child’s data.
  4. Data minimization, collecting no more than reasonably necessary for the activity.
  5. Reasonable security to protect the data collected.
Our recommendation

Usercentrics

COPPA compliance depends on knowing exactly what's collected and from whom, which is easier when your consent platform's audit trail actually covers the full picture. Usercentrics' Proof of Consent log retains consent records for up to 12 months, useful documentation if a COPPA compliance question ever comes up.

Try Usercentrics

Why COPPA is different from GDPR or CCPA

GDPR and CCPA are broad, principle-based frameworks that apply differently depending on context. COPPA is closer to a checklist: specific required disclosures, specific consent mechanisms the FTC has pre-approved, and a specific enforcement body (the FTC, plus state attorneys general) with a track record of pursuing violations. Treating COPPA as “covered by our GDPR compliance” is a common and risky assumption, the two laws don’t map onto each other cleanly.

The bottom line

COPPA is narrower in scope than GDPR or CCPA, it only cares about children under 13, but it’s more prescriptive about exactly what compliance looks like. If there’s any realistic chance your site reaches that age group, knowingly or not, it’s worth understanding COPPA on its own terms rather than assuming broader privacy compliance covers it.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.