Privacy policies are long, and it’s hard to know what to look for in one. You don’t need to become a privacy lawyer, though. It helps to know what the main US law on children’s privacy requires, because that tells you what a site for kids should be asking you, and what it should never ask your child.
That law is the Children’s Online Privacy Protection Act, usually called COPPA.
What COPPA is
Congress passed COPPA in 1998 and directed the Federal Trade Commission (FTC) to write and enforce rules under it. The FTC’s original COPPA Rule took effect on April 21, 2000. It was updated in 2013, and the FTC finalized another round of changes in January 2025.
The FTC describes COPPA’s main goal as putting parents in control of what information is collected from their young children online. It protects children under 13. According to the FTC’s COPPA FAQ, Congress chose that age because younger children are particularly vulnerable to overreaching by marketers and may not understand the safety and privacy issues of sharing information online.
Who it covers
COPPA applies to commercial websites and online services that are directed to children under 13 and collect, use or share personal information from them. “Online services” includes mobile apps and internet-connected devices such as smart toys. It also applies to general-audience sites and apps that know they are collecting personal information from a child under 13.
What counts as personal information
The FTC’s definition covers a lot more than a name and address. It includes:
- a first and last name
- a home address
- an email address or other online contact information, and a screen name that works like one
- a phone number
- a Social Security number
- a persistent identifier that can recognize a user over time and across different sites, such as an IP address
- a photo, video or audio file with the child’s image or voice
- geolocation precise enough to identify a street and a city or town
The January 2025 changes added biometric identifiers and government-issued identifiers to the definition.
What COPPA asks of a site for kids
A site or app covered by COPPA must, among other things:
- post a clear privacy policy describing what it collects from children and how it uses and shares that information
- give parents direct notice and get verifiable parental consent before collecting personal information from a child, with limited exceptions
- let parents consent to the site’s own use of the information while refusing to let it be passed to third parties
- let parents review their child’s information, have it deleted, and stop further collection
- keep the information secure
- keep it only as long as needed for the purpose it was collected for
- not require a child to hand over more information than is reasonably necessary to take part in an activity
The 2025 changes added a requirement for separate parental consent before a covered site discloses a child’s personal information to third parties for targeted advertising or other purposes. They also state that sites cannot keep children’s personal information indefinitely.
Consent can take different forms. The FTC’s guide for parents gives examples: some sites ask you to verify your identity with a government-issued ID, and others give you a toll-free number to call.
What COPPA doesn’t do
COPPA only applies when a covered site collects personal information from a child. If a site doesn’t collect it, the FTC says, COPPA is not a factor.
It also has limits worth knowing:
- It isn’t a content filter. The FTC’s FAQ says COPPA was not designed to keep children from seeing particular types of content online. For that, the FAQ points parents to filtering programs and parental-control tools.
- It doesn’t stop kids from lying about their age. A general-audience site isn’t required to ask ages. If it does ask in a neutral way, it may rely on the age a user enters, even if a child enters a false one.
- It stops at 13. COPPA doesn’t cover teenagers.
Your rights as a parent
Once you’ve given a site permission to collect your child’s information, the FTC says you’re still in control. You have the right to review what was collected, to withdraw your consent at any time, and to have your child’s information deleted. A site will need to confirm you are the parent before it shows you anything.
If you think a site has collected your child’s information, or marketed to your child, in a way that breaks the law, you can report it to the FTC at ReportFraud.ftc.gov. The FTC’s COPPA FAQ says courts can impose civil penalties of up to $53,088 per violation.
How Lantern Learn handles it
Our privacy page for parents says we never collect personal information from kids directly: kids never sign in, never enter their email, never share photos and never see ads. We collect a parent’s email for sign-in, a first name or nickname and an avatar (chosen from a fixed set) for each kid profile, and a record of which weeks each child has finished. From the account page, a parent can remove a kid profile, which deletes that child’s progress, or delete the whole account.
Questions to ask before your child signs up
Most of these can be answered from a site’s privacy page and its sign-up screen.
- Who creates the account? A site for young kids should have the parent sign up, not the child.
- What does it ask my child to type? Look for an email address, a full name, a birthday, a school or a location. Each of these is worth a second look.
- Can my child upload photos, record their voice, or chat with other people? Photos and voice recordings count as personal information under COPPA, and chat can put your child in contact with people you don’t know.
- Are there ads? If so, does the policy say anything about targeted advertising to children?
- Who else gets the data? The privacy policy should say whether the site gives or sells children’s information to other companies.
- How long is the information kept, and can I delete it myself?
- Is there a way to contact someone with a privacy question?
If a policy is hard to find or impossible to follow, you can take that into account too. The FTC says the notice and the privacy policy should be in plain language that’s easy to understand.
- #parents
- #privacy
- #COPPA
- #online safety
Sources
- Protecting Your Child's Privacy Online. Federal Trade Commission. Accessed September 27, 2026
Plain-language COPPA overview for parents: notice, consent, parents' rights, reporting.
- Complying with COPPA: Frequently Asked Questions. Federal Trade Commission. Accessed September 27, 2026
History of the Act and Rule, who is covered, the definition of personal information, operators' obligations, penalties, and what COPPA does not do.
- FTC Finalizes Changes to Children's Privacy Rule Limiting Companies' Ability to Monetize Kids' Data. Federal Trade Commission, . Accessed September 27, 2026
2025 amendments: separate consent for third-party disclosure, retention limits, expanded definitions.
- For parents: how we handle your kid's privacy. Lantern Learn. Accessed September 27, 2026
What Lantern Learn collects and the controls parents have.