TL;DR: The FTC voted 5-0 on January 16, 2025 to overhaul COPPA for the first time since 2013. The new rules add biometric data (fingerprints, face scans, voiceprints, DNA) to the list of protected information. Companies must get separate parental consent before sharing kids' data with advertisers or AI training systems. Indefinite data retention is banned. Compliance deadline: April 22, 2026, 70 days from now. The penalty for violations? Up to $51,744 per incident, per day.

Twelve Years Is a Long Time in Tech

The last time the FTC updated COPPA rules was 2013. Instagram was two years old. TikTok didn't exist. Neither did Fortnite, Roblox's public launch, or any AI chatbot your kid could talk to at 2 a.m.

In the 12 years since, the children's internet became a data extraction machine. Apps collected fingerprints for "fun filters." Games demanded microphone access for voice chat, and kept the recordings. Platforms tracked kids across devices, fed their behavior data to advertisers, and trained AI models on their conversations [1].

The 2013 rules didn't cover any of that. Now they do. Kind of.

What Actually Changed

Seven major updates. Some are significant. Some have loopholes big enough to drive an ad network through.

1. Biometric Data Is Now Protected

The definition of "personal information" now covers:

  • Fingerprints and handprints
  • Facial templates and faceprints
  • Voiceprints
  • Retina and iris patterns
  • DNA and genetic data
  • Gait patterns
  • Government-issued ID numbers (state IDs, birth certificates, passports)

If a gaming app scans your kid's face for an avatar, that's now protected data under COPPA. Collect it without verified parental consent? That's a potential federal violation [2].

2. Separate Consent for Third-Party Sharing

This is the big one. Previously, when a parent consented to an app collecting their child's data, that consent covered everything, including sharing with advertisers, data brokers, and AI companies. One checkbox, blanket permission.

Now, companies must get separate parental consent before disclosing a child's data to third parties. Parents can say yes to the app collecting data and no to sharing it. The FTC was explicit: disclosures for advertising, monetary compensation, or AI training are never considered "integral" to a service. They always require separate consent [3].

Companies also must tell parents exactly which third parties will get the data and why. Not "our partners." Names.

3. No More Hoarding Kids' Data Forever

Companies can no longer keep children's personal information indefinitely. They must:

  • Retain data only as long as "reasonably necessary" for its stated purpose
  • Delete it when that purpose is fulfilled
  • Publish a written data retention policy with specific timeframes

Translation: if your kid stopped using a learning app three years ago, the company can't still be sitting on their data. They have to define how long they'll keep it, publish that timeline, and actually follow through [4].

4. Mandatory Security Programs

Operators must maintain a written information security program with:

  • A designated employee coordinator
  • Annual risk assessments
  • Ongoing testing and monitoring
  • Annual evaluations when technology changes

This isn't groundbreaking, but it's new for COPPA. Before this, there was no explicit requirement for companies handling children's data to maintain formal security programs [4].

5. "Mixed Audience" Sites Get a Definition

Sites that aren't aimed at kids but have some kid users (think YouTube, Reddit, general-audience games) now have codified rules. They can ask users' ages to determine whether COPPA applies, but they can't incentivize users to lie about their age by offering a better experience to those who claim to be 13+ [5].

6. New Ways to Verify Parental Consent

The FTC added several new acceptable verification methods:

  • Knowledge-based authentication: questions a 12-year-old couldn't answer
  • Facial recognition matched to government ID (images must be deleted immediately after)
  • Text-plus method: SMS combined with additional steps

The irony: the government is authorizing facial recognition as a method to protect children's privacy. Using surveillance to fight surveillance [5].

7. Safe Harbor Programs Must Show Their Work

Six FTC-approved Safe Harbor programs (including ESRB, kidSAFE, and TRUSTe) must now publicly disclose their member lists, report disciplinary actions annually, and share complaints with the FTC. The self-regulation clubhouse just got a window [3].

The Fine Print: What Didn't Change

Before you celebrate, here's what the FTC left alone:

Still only protects kids under 13. Your 14-year-old is on their own. COPPA 2.0, which would have extended protections to 17, passed the Senate but never became law. At the federal level, teens have zero privacy protections from data collection [6].

The "actual knowledge" loophole lives on. Companies only have to follow COPPA if they have "actual knowledge" they're collecting data from kids under 13. No age verification field in your sign-up form? No actual knowledge. Critics say this incentivizes willful ignorance, and they're right. The FTC declined to adopt a "constructive knowledge" standard that would have presumed companies know kids are present if basic diligence would reveal it [6].

No restrictions on addictive design. Push notifications at midnight. Infinite scroll. Autoplay. Streak mechanics that punish kids for taking a day off. The FTC proposed limiting these engagement-design features but dropped them from the final rule [6].

The Enforcement Track Record

Rules are only as good as enforcement. Here's what the FTC has done with COPPA so far:

  • Epic Games (Fortnite), 2022: $275 million (the largest COPPA penalty ever) plus $245 million for dark patterns. Total: $520 million [7].
  • Google/YouTube, 2019: $170 million for tracking kids and serving targeted ads [7].
  • HoYoverse (Genshin Impact), January 2025: $20 million for collecting children's data without consent and deceptive loot boxes [7].
  • Disney, December 2025: $10 million for mislabeling child-directed YouTube videos [7].
  • TikTok, 2024–ongoing: DOJ suit on behalf of FTC alleging "massive-scale invasions of children's privacy." Penalties up to $51,744 per violation per day. Still in litigation [7].

FTC Associate Director Ben Wiseman confirmed in January 2026 that enforcing the updated COPPA rule is a "key focus" for the agency this year. New FTC Chair Andrew Ferguson, a Trump appointee, voted for the amendments and called children's privacy a bipartisan priority [8].

The money is real. The question is whether companies with armies of lawyers will find the gaps faster than the FTC can close them.

Why It Matters Right Now

Three out of four teens use AI chatbots. One in three tell researchers they've been uncomfortable with a chatbot's response. AI companions are having extended conversations with minors, collecting, processing, and potentially training on every word [9].

The new COPPA rules explicitly say that collecting children's data for AI training is never considered part of providing a service. That means separate parental consent, every time. For companies that built their products on the assumption that all user data feeds the model, this is a direct hit.

California already went further. SB 243, effective January 2026, requires AI companions to detect and respond to comments about self-harm and prevent sexually explicit content for minors. Multiple states have pre-filed chatbot safety bills. Congress has three bipartisan proposals in the hopper: the GUARD Act, the CHAT Act, and the SAFE Act [9].

The regulatory picture is shifting. COPPA's update is the floor, not the ceiling.

What Parents Should Do

Audit Your Kid's Apps

Check what permissions each app has. Camera, microphone, location, contacts: if a game doesn't need it, revoke it. On iOS: Settings > Privacy & Security. On Android: Settings > Apps > Permissions.

Look for Separate Consent Prompts

After April 22, apps should ask for separate permission before sharing your child's data with third parties. If an app bundles everything into one consent screen, that's a red flag.

Check Data Retention Policies

Under the new rules, every kids' app must publish how long they keep data. Look for it in privacy policies. If it says "indefinitely" or doesn't specify, report it to the FTC.

File FTC Complaints

If an app is collecting biometric data from your child without consent, or sharing data without separate permission after April 22, file a complaint at reportfraud.ftc.gov. The FTC has signaled enforcement is a 2026 priority.

The Bottom Line

COPPA's update is 12 years late. It still doesn't protect teens. The "actual knowledge" loophole still lets companies pretend they don't know kids are using their products. And addictive design features that keep children glued to screens didn't make the cut.

But: biometric data is now protected. Companies can't share your kid's data with advertisers without asking twice. Data hoarding is banned. And the FTC just hit Epic for half a billion dollars, so the enforcement teeth are real.

April 22, 2026. That's the deadline. Every app, platform, and service that touches children under 13 has 70 days to comply. Mark it.

Sources

  1. FTC: FTC Finalizes Changes to Children's Privacy Rule Limiting Companies' Ability to Monetize Kids' Data (January 16, 2025)
  2. Finnegan: The FTC's Updated COPPA Rule: Redefining Children's Digital Privacy Protection (2025)
  3. IAPP: Top 5 Impacts of the New COPPA Rule (2025)
  4. Federal Register: Children's Online Privacy Protection Rule (April 22, 2025)
  5. Davis Wright Tremaine: FTC Amends COPPA Rule with Sweeping New Children's Privacy Protections (May 2025)
  6. ITIF: New FTC COPPA Rule Update Does Little to Protect Children Online (February 28, 2025); EPIC: Children's Privacy
  7. FTC: Kids' Privacy (COPPA) Enforcement Page; FTC v. Epic Games (December 2022)
  8. Womble Bond Dickinson: Overview of FTC's 2026 Children's Privacy Focus (January 2026)
  9. Stanford Report: AI Chatbot Privacy Concerns and Risks (October 2025); EPIC: How Existing Laws Apply to AI Chatbots for Kids and Teens