Explore Digital Accessibility Regulations
Children’s Online Privacy Protection Act (COPPA)
Implemented in 2000, the Children’s Online Privacy Protection Act (COPPA) applies to websites and online service operators—including apps, games, social networks, VoIP services, IoT devices, and advertising services—that knowingly collect, use, or disclose personal information from children under the age of 13. Nonprofit organizations engaged solely in non-commercial activities are generally exempt from COPPA requirements.
How Is a Child-Directed Website Determined?
Several factors are considered on a case-by-case basis to determine whether a website or online service is directed toward children, including:
-
Subject matter
-
Visual content
-
Use of animated characters or child-oriented activities and incentives
-
Music and audio content
-
Age of models
-
Presence of celebrities who appeal to children
-
Language and other characteristics
-
Advertising displayed on the website or online service
-
Evidence regarding the intended audience and actual audience composition
What Is Required Under COPPA?
Websites and online service operators must:
-
Provide clear notice about the personal information collected from children, how it is used, and how it may be disclosed.
-
Publish a comprehensive online privacy policy describing their practices for collecting, using, and sharing children’s personal information.
-
Obtain verifiable parental consent before collecting personal information from children, except where limited exceptions apply.
-
Allow parents to consent to internal use of a child’s information without requiring unnecessary disclosure to third parties.
-
Give parents access to their child’s personal information and the ability to review or delete it.
-
Allow parents to stop future collection or use of their child’s personal information.
-
Maintain the confidentiality, security, and integrity of children’s personal information, including when shared with authorized third parties.
-
Securely delete children’s personal information when it is no longer needed.
-
Retain personal information only for as long as necessary to fulfill its intended purpose.
-
Ensure participation in online activities is not conditioned on providing more personal information than is reasonably necessary.
What Led to COPPA?
Congress enacted COPPA in 1998, directing the Federal Trade Commission (FTC) to establish and enforce children’s online privacy regulations. The original COPPA Rule became effective in 2000 and was significantly updated in 2013 to address evolving technologies and online services.
How Is COPPA Enforced?
The FTC enforces COPPA and may impose substantial civil penalties for violations. In addition, state attorneys general and certain federal agencies have authority to enforce the law in applicable cases.
Choose Barriano for Your Accessibility & Compliance Needs
Organizations trust Barriano to help build accessible, inclusive, and standards-compliant digital experiences. From AI-powered accessibility solutions and comprehensive accessibility testing to remediation support and ongoing compliance guidance, Barriano provides the expertise and tools needed to help organizations meet global accessibility and regulatory requirements.
FAQ
Frequently asked questions.
Can’t find your answer? Reach out — we’d love to chat.

