Micron Document

KIDS childrens online privacy protection act
page 1 / 6

Children's Online Privacy Protection Act
retrieved 2026-06-28

archived for offline mesh reading
------------------------------------------------------------

The Children's Online Privacy Protection Act of 1998 (COPPA) is a United States federal law. The act, effective April 21, 2000, applies to the online collection of personal information by persons or entities under U.S. jurisdiction about children under 13 years of age, including children outside the U.S. if the website or service is U.S.-based. It details what a website operator must include in a privacy policy, when and how to seek verifiable consent from a parent or guardian, and what responsibilities an operator has to protect children's privacy and safety online, including restrictions on the marketing of those under 13.
Although children under 13 can legally give out personal information with their parents' permission, many websites, particularly social media sites, but also other sites that collect most personal info, disallow children under 13 from using their services altogether due to the cost and work involved in complying with the law.


== Background ==
In the 1990s, electronic commerce was on its rise of popularity, but various concerns were expressed about the data collection practices and the impact of Internet commerce on user privacy—especially for children under 13, because very few websites had their own privacy policies. The Center for Media Education petitioned the Federal Trade Commission (FTC) to investigate the data collection and use practices of the KidsCom website, and take legal action since the data practices violated Section 5 of FTC Act concerning "unfair/deceptive practices." With the passing of the Drivers Privacy Protection Act in 1997, new precedents had been set in regard to the ability of congress to regulate information held by state agencies. After the FTC completed its investigation, it issued the "KidsCom Letter". The report stated that the data collection and use practices were indeed subject to legal action. This resulted in the need to inform parents about the risks of children's online privacy, as well as to parental consent necessity. This ultimately resulted in the drafting of COPPA.
COPPA was passed in 1998 and took effect reportedly in April 2000. The rule was issued by the Federal Trade Commission, and it is updated quite frequently to stay up to date with new technological advancements. The Federal Trade Commission (FTC) is an agency that works to protect people from illegal practices, scammers, create protection rules, and ensure they are helping people protect their data and information. COPPA was necessary because it has been reported that 89% of children's websites were taking personal information, and many of those websites were not giving privacy notices. Parents were not very involved with their children's website uses or made aware of the dangers of their children's private information being taken without knowledge.
The new millennium ushered in an era of regulation that many were simply unaware of. The early years of the transition were fraught with confusion and a lot of animosity. One of the main concerns of the time was the eventual accessibility of child-based websites at the fear many were unwilling to change their business practices. Many were left with a series of loose guidelines that determined what was correct. The simplification of COPPA provided by the FTC was met with a follow-up of demands to law enforcement that the: "... Commission should continue law enforcement efforts by targeting significant violations and seeking increasingly larger civil penalties, when appropriate, to deter unlawful conduct". A mandatory review of the COPPA regulations were conducted in 2005 (resulting with no changes to the original guidelines), found that there were no adverse effects to the online landscape.
The Federal Trade Commission (FTC) has the authority to issue regulations and enforce COPPA. Also, under the terms of COPPA, the FTC-designated "safe harbor" provisioning is designed to encourage increased industrial self-regulation. Under this provision, industry groups and others may request Commission approval of self-regulatory guidelines to govern participants' compliance, such that website operators in Commission-approved programs would first be subject to the disciplinary procedures of the safe harbor program in lieu of FTC enforcement. As of June 2016, the FTC has approved seven safe harbor programs operated by TrustArc, ESRB, CARU, PRIVO, Aristotle, Inc., Samet Privacy (kidSAFE), and the Internet Keep Safe Coalition (iKeepSafe). In August 2021, Aristotle, Inc. withdrew from the safe harbor program after FTC staff expressed serious concerns about its enforcement of its safe harbor provisions and communicated their intent to recommend the revocation of Aristotle's approval to run a safe harbor program. The FTC also announced its intention to more closely scrutinize the practices of the other six present safe harbors.


< prev page 1/6 next >