Security and privacy

Children’s online privacy (COPPA)

US rule that restricts collecting personal information from children under thirteen without verifiable parental consent.

CodeCOPPA
RegionUnited States
TypeMandatory in scope
Issued byFederal Trade Commission
Last verified2026-10-10
Quick answerCertification · last verified 2026-10-10

US rule that restricts collecting personal information from children under thirteen without verifiable parental consent. Status: Mandatory in scope. Issued or recognised by Federal Trade Commission.

CodeCOPPA
RegionUnited States
TypeMandatory in scope
Issued byFederal Trade Commission
GroupSecurity and privacy
Last verified2026-10-10
How to cite this pageIoT Atlas. "Children’s online privacy (COPPA)". https://hi-spark.net/certification/coppa.html Last verified 2026-10-10.

What it means

Smart toys, kids’ watches and children’s cameras are a direct COPPA risk area because they combine cameras, microphones, location and app accounts. The rule also constrains third-party analytics and advertising in child-directed services.

Applies to

  • Smart toys, kids’ watches and children’s trackers
  • Apps and services directed to children
  • Sites with actual knowledge of child users

What it does not cover

  • Radio and safety approvals
  • EU child data rules such as GDPR Article 8
  • School procurement rules

Verification checklist

  • Decide whether the product or app is child-directed
  • Minimise collection and disable behavioural advertising where required
  • Implement verifiable parental consent where needed
  • Provide parental review and deletion routes
  • Review vendor data flows for child data