TechKnowSurge
NIST 800-53 PT-2 NIST 800-53 PT-5 ISC2 CISSP 1.4 CompTIA Security+ 5.4
VideoSecurityFree

Children’s Online Privacy Protection Act (COPPA)

The Children's Online Privacy Protection Act (COPPA) is a U.S. law that governs how websites and online services must handle personal data collected from children under 13. Understanding COPPA compliance requirements is essential for any organization operating digital platforms that may reach younger audiences.

Complete this video to capture a CTF flag worth 1 point.

About this video

The Children's Online Privacy Protection Act (COPPA) is a federal U.S. law passed in 1998 and effective since 2000, designed to protect the personal data of children under the age of 13 in online environments. Any website, app, or digital platform that is directed toward children or that knowingly collects data from users under 13 must comply with its requirements. Even organizations whose services are not specifically targeted at children may benefit from including a clear statement in their privacy policy indicating that children under 13 are not their intended audience, as a precautionary measure. COPPA compliance involves several concrete obligations. Organizations must obtain verifiable parental consent before collecting personal information from a child, and they must provide a clear, transparent disclosure of exactly what data is being gathered and the purpose for which it will be used. Parents retain the right to review their child's information and request its deletion at any time. Covered entities are also required to implement appropriate security controls to safeguard collected data and must observe limits on the types of data that can be collected and the methods used to collect it. Failure to comply with COPPA carries serious financial consequences. Regulatory enforcement actions can result in civil penalties of up to $43,280 per violation, making COPPA compliance a critical legal and operational priority for any organization with digital products or services that could reach a younger audience.

What you'll learn

What's covered

COPPA Overview

Aligned to

NIST 800-53
PT-2 Authority to Process Personally Identifiable Information
PT-5 Privacy Notice
ISC2 CISSP
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
CompTIA Security+
5.4 Summarize elements of effective security compliance.

Key terms

Children's Online Privacy Act
COPPA
A U.S. federal law that imposes requirements on operators of websites and online services directed at children under 13, restricting the collection and use of personal information from minors. It requires verifiable parental consent before collecting children's data.
Parental Consent
A COPPA requirement mandating that operators obtain verifiable permission from a parent or guardian before collecting personal information from children under age 13.
Data Transparency
The obligation under COPPA to clearly disclose what data is being collected from children and how it will be used.
Security Safeguards
The COPPA requirement that operators implement reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children.
Confidentiality
The principle that information is accessible only to those authorized to access it.

Topics

Coppa Data Privacy Regulatory Compliance Parental Consent Children Data Protection Privacy Law

Transcript

What COPPA Is

The Children Online Privacy Protection Act, COPPA, is designed to protect children under 13 years old. COPPA was voted in in 1998 and became effective as a law in the year 2000. It's really designed to help protect the data and the information from children under the age of 13.

If you have a website or other online content that's designed or targeted towards children under 13 years old, then you have to comply with COPPA. However, even if you are not targeting that demographic, you may want to consider at least something in your privacy policy stating that that's not your target audience.

Highlights of COPPA

Here's some of the highlights of COPPA:

  • Number one is that you have to get parental consent before you collect data from children under the age of 13.
  • You have to be really clear on what data you're collecting and what you're using it for.
  • You have to give the parents the right to review and delete that information, if they ask you for that information.
  • You also have to meet certain security requirements to make sure that you're safeguarding that information.
  • There's also limitations on what can be collected and how it's collected.

There's some stiff enforcement and penalties if you're breaking COPPA rules. Penalties can include fines of up to $43,200.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →