Duties and compliance

The FTC organizes COPPA compliance into six core operational steps for covered businesses.

Core requirements

  1. Determine coverageAssess audience, actual knowledge, data flows, plug-ins, ad networks, connected devices, and what qualifies as personal information.
  2. Post a compliant privacy policyThe notice must clearly describe operators, information collected, uses, disclosures, and parental rights without unrelated or confusing material.
  3. Notify parents and obtain consentProvide direct notice and use a method reasonably designed to verify that consent comes from a parent.
  4. Secure, minimize, retain, and deleteMaintain a written security program and retention policy, collect only what is necessary, retain data only as long as reasonably necessary, and securely delete it.

Civil penalties for COPPA violations

A court can hold operators that violate the COPPA Rule liable for civil penalties of up to $53,088 per violation. The amount in a particular case depends on the law, the conduct, the number of violations, and enforcement or judicial determinations.

Use the controlling text

Coverage, exceptions, knowledge standards, definitions, remedies, and effective dates must be evaluated from the full statutory or legislative text. Agency guidance can explain requirements but does not replace the text.

FTC — COPPA statute