The short version
- There are two doorways and only one is a design choice. 16 CFR § 312.3 binds any operator of a service **directed to children**, and separately any operator with **actual knowledge** it is collecting from a child. The first covers every user of the app; the second covers the one child you were told about.
- The amended Rule’s compliance date was 22 April 2026, so all of it is now live: biometric identifiers and government-issued identifiers count as personal information, disclosure to third parties needs its own separate consent, a written retention policy has to be published, and § 312.8(b) requires a written information security programme.
- A persistent identifier is personal information. § 312.5(c)(7) lets you collect one without consent only where it is used solely for support for the internal operations of the service — which reaches crash reporting, frequency capping and contextual ads, and stops dead at behavioural advertising or profile-building.
- The SDK is the usual violation. Penalties run to $53,088 per violation; Epic Games paid $275 million in 2022, Cognosphere $20 million in January 2025, and Apitor drew a $500,000 judgment in September 2025 purely because a third-party SDK inside its toy app collected children’s location.
The rule that implements COPPA, 16 CFR Part 312, runs to thirteen sections and can be read in half an hour. Almost every mistake in it is made before a word of the privacy policy is written, because the mistake is architectural: the app already collects a persistent identifier from every install, and a persistent identifier is personal information.
Two doorways, and only one of them is a choice
Section 312.3 makes it unlawful for "any operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting or maintaining personal information from a child" to collect in breach of the Rule. Two independent routes in. The first is decided by what you built and how you sold it, and once it applies it applies to everyone who opens the app — there is no adult carve-out. The second is decided by an inbox message: a parent writes in saying their nine-year-old uses the account, and from that moment you are covered as to that child.
A "child" is anyone under 13. An "operator" is anyone who collects or maintains personal information from users of the service, or on whose behalf it is collected — and the Rule spells out that information is collected on your behalf where "the operator benefits by allowing another person to collect personal information directly from users". That clause is why an ad network embedded in your app is your problem and not only its own.
What the age screen does and does not buy you
Neutral age screen before any collection
How it reads on the § 312.2 factors
General audience
Child-directed
No screen
Outside the Rule, for now
Until someone tells you a user is under 13. Then the actual-knowledge door opens.
Covered as to every user
No adult exception. The Rule applies to the whole audience, grown-ups included.
Screen in place
The screen bought nothing
Asking does not create a mixed audience. The age data is just more data.
Mixed audience
Bites only for visitors who identify as under 13 — the one cell where a screen works.
What "directed to children" is actually decided on
It is a multi-factor test and no single factor settles it. Section 312.2 has the Commission weighing subject matter, visual content, use of animated characters or child-oriented activities and incentives, music or other audio content, age of models, presence of child celebrities or celebrities who appeal to children, and language or other characteristics — plus, tellingly, "whether advertising promoting or appearing on the website or online service is directed to children". The advertising you accept is evidence about who you built for.
It also weighs "competent and reliable empirical evidence regarding audience composition" and evidence of intended audience, which expressly includes marketing plans, representations to third parties, user reviews and the age of users on similar services. A pitch deck sent to a toy brand and a five-star review reading "my daughter loves this" are both in the record. Developers assume the test is about intent; it is at least as much about reception.
The mixed audience escape hatch was written into § 312.2 by the 2025 amendments. A mixed audience service is one that is child-directed on those factors but does not target children as its primary audience, and collects no personal information from any visitor before asking their age. The screen has to be neutral: it "must be done in a neutral manner that does not default to a set age or encourage visitors to falsify age information". A slider starting at 18, or a line saying multiplayer is unavailable under 13, fails that test — and a failed screen leaves you fully child-directed.
Why a compliance checklist written in 2024 is now short
The FTC published amendments to the Rule on 22 April 2025. They took effect on 23 June 2025, and regulated entities had until 22 April 2026 to comply — a date that has passed, so the whole of the amended Rule is live and the transitional option of complying with the pre-2025 text is gone.
| What changed | Where | What it means for a small app |
|---|---|---|
| Biometric and government identifiers are personal information | § 312.2 | A voiceprint from a voice-note feature, or a faceprint from a camera filter, is now consent-gated in its own right. So is a passport or state ID number. |
| Disclosure to third parties needs its own consent | § 312.5(a)(2) | One tick box no longer covers everything. Parents must be able to approve the app and refuse the ad network, unless the disclosure is integral to the service. |
| A written data retention policy, published | § 312.10 | Indefinite retention is prohibited outright. The policy — purposes, business need, deletion timeframe — must appear in the children’s privacy notice. |
| A written information security programme | § 312.8(b) | A named coordinator, an annual risk assessment, safeguards sized to the data, testing, and an annual review. There is no headcount threshold below which this is optional. |
Consent is the part that costs you users
Verifiable parental consent means a reasonable effort, given available technology, to ensure the person consenting is actually the parent. Section 312.5(b)(2) lists the methods that satisfy that, and they are not equivalent — they differ by an order of magnitude in both cost and abandonment rate, and the cheap ones come with a condition attached.
The approved consent methods, cheapest first
- Free
Email plus
Open only to operators that never disclose children’s data. Consent email, then a confirming email, letter or call.
- Pennies per parent
Text plus
Added in 2025, same no-disclosure limit, and the notice must say the consent can be revoked.
- Processor fee
Card transaction
Only where the payment system notifies the account holder of each discrete transaction.
- Per-check vendor fee
Knowledge-based authentication
Dynamic multiple-choice questions a 12-year-old in the household could not reasonably answer.
- Highest, plus the drop-off
Photo ID matched to a selfie
Government ID verified as authentic, compared to a live camera image by trained staff, then deleted.
The two free rungs vanish the moment you ship an ad SDK, because sharing data with it is a disclosure.
That last line is worth reading twice. Section 312.2 defines "disclose" as releasing a child’s personal information to anyone other than a provider of support for the internal operations of your service, and an ad network targeting on its own account is not that. So the moment behavioural advertising enters the build you are on a paid rung, and you separately owe the parent the option to say yes to the app and no to the network.
Start from a privacy policy
The children’s notice under § 312.4(d) has fixed contents: every operator collecting through the service, the categories of third parties and why, and the retention policy. Build it from a structured base rather than a competitor’s page.
The exception that lets you keep analytics
You do not need parental consent to run a crash reporter. Section 312.5(c)(7) permits collecting a persistent identifier, and no other personal information, where it is used solely to provide support for the internal operations of the service. That definition covers maintaining or analysing how the service functions, network communications, authenticating users or personalising content, serving contextual advertising or capping ad frequency, protecting security or integrity, and ensuring legal compliance.
The proviso is where it ends. Data collected for those activities "cannot be used or disclosed to contact a specific individual, including through behavioural advertising, to amass a profile on a specific individual, or for any other purpose". Contextual ads, chosen by what is on screen, sit inside the exception; retargeting and lookalike audiences sit outside it, and no version of them fits. Relying on the exception also triggers § 312.4(d)(3): name the internal operations in the notice, and say how you stop the identifier being used for anything else.
The SDK is the violation
In September 2025 the FTC took action against Apitor Technology, a robot-toy maker whose companion app used a third-party SDK called JPush. The SDK collected precise geolocation from children. Apitor was not selling the data and, on the FTC’s account, had not looked closely at what the SDK did. The judgment was $500,000, suspended because the company could not pay. The Bureau of Consumer Protection put the principle in one line: companies serving kids must notify parents and get consent "even if the data is collected by a third party".
Two duties follow, and a vendor’s marketing page satisfies neither. Section 312.8(c) requires you, before letting anyone collect through your service, to take reasonable steps to determine they can keep the data secure and to obtain written assurances that they will. And a generic mediation SDK is built to pass identifiers to whichever demand partner fills the slot, so unless it runs in a documented child-directed mode you cannot list the third parties the § 312.4 notice demands. That is the practical test: no names, no notice — and no notice, no lawful consent.
Before a child-directed build ships
- Enumerate every SDK and what each transmits — analytics, crash, attribution, ads, push, social login.
- Put each one in its documented child-directed mode, and keep the vendor’s written confirmation.
- Confirm no advertising identifier leaves the device and no ad served is behavioural.
- Collect nothing participation does not need: § 312.7 forbids conditioning a game or prize on excess collection.
- Publish the retention policy, and give parents a working route to review, refuse and delete under § 312.6.
The app stores are a second gate, not the same gate
Both stores run their own kids regimes, and clearing review is not evidence of COPPA compliance. Apple says it plainly: the Kids Category parental gate "is generally not the same as securing parental consent to collect personal data under these privacy statutes". A gate stops a five-year-old wandering into a purchase flow; it authorises nothing. Nor does either store’s age-signal API amount to consent — those tell you which regime applies, not that you have discharged it.
Two rulebooks that overlap without lining up
COPPA
- Verifiable parental consent
- Direct notice to the parent
- Deletion on parental request
- A published retention policy
Both, differently
- A privacy policy
- No behavioural advertising to children
- An honest audience declaration
Store policy
- Parental gate on links out
- Only certified ads SDKs
- No third-party analytics
- Removal, without a hearing
What the mistake actually costs
A COPPA Rule violation is treated as a breach of a trade regulation rule, carrying civil penalties of up to $53,088 per violation under the FTC Act as currently adjusted for inflation — and per violation, in practice, means per child. Epic Games paid $275 million in December 2022, described at the time as the largest penalty ever obtained for breach of an FTC rule. Cognosphere, publisher of Genshin Impact, paid $20 million in January 2025 over mixed COPPA and loot-box charges, and Disney agreed to $10 million in September 2025 for failing to label kid-directed videos as "Made for Kids" on YouTube.
The useful thing about COPPA is how early it is decided. By the time a parent complains, or a store review flags the listing, the architecture is fixed and the identifiers have already been leaving the device for months. Every enforcement action above turns on a decision someone made in an afternoon — accept this SDK, tick this audience box, skip this vendor question. Run the SDK inventory before the first build goes to review, and the rest of the Rule is paperwork you can actually finish.
Sources
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule (current text)
- FTC, Children’s Online Privacy Protection Rule; Final Rule, 90 FR 16918 (22 April 2025)
- FTC business blog — Using a third party’s software in your app (September 2025)
- FTC action against Apitor Technology (September 2025)
- FTC COPPA policy statement on age-verification technologies (25 February 2026)
- 16 CFR § 1.98 — civil penalty amounts
- Apple App Store Review Guidelines — 1.3 Kids Category and 5.1.4 Kids
- Google Play — Families policy requirements
General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.
Frequently asked
Does COPPA apply to a free app made by one person?
Yes. The Rule reaches any operator of a commercial online service directed to children, with no revenue or headcount threshold. Free apps are commercial where they earn through advertising or in-app purchases. Only genuine non-profits that would fall outside section 5 of the FTC Act are excluded, and running a hobby project through a personal account does not create that exemption.
Is an age gate enough to keep my app out of COPPA?
Only if the service is child-directed on the section 312.2 factors and children are not its primary audience. That combination is the mixed audience category, and it requires collecting no personal information before the age question and asking in a neutral way that does not default to an age or nudge users to lie. On a general-audience app, an age gate changes nothing.
Can I use Google Analytics or a crash reporter in a kids app?
Usually yes. Section 312.5(c)(7) allows collecting a persistent identifier and nothing else where it is used solely for support for the internal operations of the service, which includes analysing how the service functions and protecting its security. The vendor must not reuse the data for its own advertising or profiling, and the internal operations relied on have to be described in the privacy notice.
What does actual knowledge mean if my app is for adults?
It means a specific, concrete indication that a particular user is under 13 — a parent emailing about their child, a support ticket giving an age, a profile stating a birth year. From that point the Rule applies to that user, so you either obtain verifiable parental consent or delete what you hold. General awareness that some minors use the service is not the same thing.
How long can I keep a child user’s data?
Only as long as is reasonably necessary for the specific purpose it was collected for, and never indefinitely. The amended Rule also requires a written retention policy setting out the purposes, the business need for keeping the data and a deletion timeframe, published in the privacy notice on the service. Deletion has to be done with reasonable measures against unauthorised access during the process.