Don’t do SECURITY. Do business SECURELY.

Amended COPPA Rule compliance deadline arrives in the US

Online services directed at US children under 13 must now comply with the amended COPPA Rule, including written security programmes and retention policies.

The compliance deadline for the amended Children’s Online Privacy Protection Rule (COPPA Rule) arrives today in the United States, one year after the Federal Trade Commission published the updated rule.

Key points

  • Operators must maintain a written children’s information security programme, with annual risk assessments.
  • A written data retention policy is required, and children’s data may not be kept indefinitely.
  • Separate verifiable parental consent is needed before disclosing children’s data to third parties, for example for targeted advertising.
  • Notices must give more detail on data practices and third-party recipients.

The rule applies to any operator whose online service is directed at US children, or who knowingly collects their data, wherever the operator is based. UK developers of apps, games and edtech with US users should review their consent flows and security documentation.

Source: Children’s Online Privacy Protection Rule, final rule (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights