The compliance deadline for the amended Children’s Online Privacy Protection Rule (COPPA Rule) arrives today in the United States, one year after the Federal Trade Commission published the updated rule.
Key points
- Operators must maintain a written children’s information security programme, with annual risk assessments.
- A written data retention policy is required, and children’s data may not be kept indefinitely.
- Separate verifiable parental consent is needed before disclosing children’s data to third parties, for example for targeted advertising.
- Notices must give more detail on data practices and third-party recipients.
The rule applies to any operator whose online service is directed at US children, or who knowingly collects their data, wherever the operator is based. UK developers of apps, games and edtech with US users should review their consent flows and security documentation.
Source: Children’s Online Privacy Protection Rule, final rule (Federal Register)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.