Skip to content

COPPA Rule 2026: what the amended rule requires of apps

Filip LuchianencoUpdated 6 min read

Last updated: 2026-10-02

From April 22, 2026, operators must comply with the Federal Trade Commission's amended Children's Online Privacy Protection Rule (COPPA Rule, 16 CFR Part 312). The FTC published the amendments in the Federal Register on April 22, 2025 (90 FR 16918, document 2025-05904). The rule covers operators of services directed to children under 13 and any operator with actual knowledge that it collects personal information from a child. The COPPA Rule 2026 changes that bear on mobile apps are separate parental consent for disclosures to third parties, new categories of personal information, a stand-alone mixed audience definition, and written security and retention programs.

When did the COPPA Rule amendments take effect?

The amended rule took effect on June 23, 2025. The notice states: "Except with respect to § 312.11(d)(1), (d)(4), and (g), regulated entities have until April 22, 2026 to comply" (90 FR 16918, PDF page 1). For the year between, the FTC wrote that "regulated entities may comply with the Rule provisions that do not specify earlier compliance dates either by complying with the pre-2025 Rule or with the revised Rule" (PDF page 54). Since April 22, 2026, only the amended text applies.

The three excluded provisions bind FTC-approved safe harbor programs (industry groups that certify operators) and have earlier dates. Under § 312.11, member lists were due "No later than July 21, 2025" (paragraph (d)(4)), and the first annual report (paragraph (d)(1)) and proposed guideline modifications (paragraph (g)) by October 22, 2025.

What does the amended COPPA Rule require before disclosure to third parties?

Section 312.5(a)(2) now provides: "An operator must give the parent the option to consent to the collection and use of the child's personal information without consenting to disclosure of his or her personal information to third parties, unless such disclosure is integral to the website or online service. An operator required to give the parent this option must obtain separate verifiable parental consent to such disclosure." The pre-2025 text ended after "to third parties."

"Integral" is explained only in the preamble, where the Commission agreed that disclosures "necessary to provide the product or service the consumer is asking for" are integral, and stated: "Disclosures of a child's personal information to third parties for monetary or other consideration, for advertising purposes, or to train or otherwise develop artificial intelligence technologies, are not integral to the website or online service and would require consent" (PDF page 33). In footnote 400 the Commission declined to list integral disclosures, calling the question "a fact-specific inquiry that depends on the type of services offered".

Two related provisions bear on third-party SDKs. The direct notice to the parent must name "the identities or specific categories of such third parties" and the purposes of disclosure (§ 312.4(c)(1)(iv)). An operator that collects only a persistent identifier for "support for the internal operations" may proceed without prior consent under § 312.5(c)(7). That term includes serving contextual advertising and capping ad frequency, and bars use for behavioral advertising. Since the amendments, that operator must state in its online notice "the specific internal operations for which the operator has collected a persistent identifier" (§ 312.4(d)(3)).

What counts as personal information under the 2026 COPPA Rule?

Section 312.2 lists 11 categories. The amendments replaced "A Social Security number" with "A government-issued identifier, such as a Social Security, State identification card, birth certificate, or passport number" and added "A biometric identifier that can be used for the automated or semi-automated recognition of an individual, such as fingerprints; handprints; retina patterns; iris patterns; genetic data, including a DNA sequence; voiceprints; gait patterns; facial templates; or faceprints."

The persistent identifier and geolocation categories are unchanged: "A persistent identifier that can be used to recognize a user over time and across different websites or online services," which includes "an Internet Protocol (IP) address, a processor or device serial number, or unique device identifier", and "Geolocation information sufficient to identify street name and name of a city or town." The post on EFF's study of four Android ad SDKs covers how location coordinates are sent in ad requests.

What is a mixed audience app under COPPA?

A mixed audience service is one that meets the child-directed factors of § 312.2 "but that does not target children as its primary audience", and that does not collect personal information from any visitor, other than under the § 312.5(c) exceptions, "prior to collecting age information or using another means that is reasonably calculated, in light of available technology, to determine whether the visitor is a child" (§ 312.2). The age check "must be done in a neutral manner that does not default to a set age or encourage visitors to falsify age information." The preamble states the order: such an operator "may not collect personal information from any visitor until it collects age information from the visitor or uses another means that is reasonably calculated" to determine whether the visitor is under 13 (PDF page 3).

On February 25, 2026, the FTC issued an enforcement policy statement on age verification. Per the release, the Commission "will not bring an enforcement action under the COPPA Rule against operators of general audience sites and services and mixed audience sites and services that collect, use, or disclose personal information for the sole purpose of determining a user's age without first obtaining verifiable parental consent", on conditions that include deleting the data promptly and using it for no other purpose. The statement stays in effect until rule amendments on age verification are published or it is withdrawn. The post on app store age-signal laws covers app store age signals.

How does the amended COPPA Rule compare with the pre-2025 rule?

Provision Pre-2025 rule Amended rule (compliance from 2026-04-22)
Disclosure to third parties, § 312.5(a)(2) Parent may consent to collection without consenting to disclosure Separate verifiable parental consent for disclosure, unless "integral"
Personal information, § 312.2 Social Security number; 10 categories Government-issued identifiers and biometric identifiers; 11 categories
Mixed audience Paragraph (3) of the "directed to children" definition Stand-alone definition; age information or another means before collecting personal information
Online notice, § 312.4(d) Disclosure practices Identities and specific categories of third parties, purposes, retention policy, internal-operations uses of persistent identifiers
Security, § 312.8 "Reasonable procedures" Written information security program; annual risk assessment; written assurances from recipients
Retention, § 312.10 "Only as long as is reasonably necessary" Written data retention policy with a deletion timeframe, published in the online notice; no indefinite retention

Sources: pre-2025 text from the eCFR as of June 1, 2025 (before the June 23, 2025 effective date); amended text from the current eCFR, Part 312.

What are the COPPA penalties?

The maximum civil penalty is $53,088 per violation for penalties assessed after January 17, 2025 (16 CFR 1.98(d)). In a Federal Register notice of September 15, 2026 (2026-18853), the FTC stated that its civil penalty amounts "will remain unchanged during 2026", after the Office of Management and Budget canceled the 2026 inflation adjustment. A violation of the COPPA Rule "shall be treated as a violation of a rule defining an unfair or deceptive act or practice" under section 18(a)(1)(B) of the FTC Act (§ 312.9). Section 5(m)(1)(A) of the FTC Act lets the Commission sue for a civil penalty against a person who violates such a rule "with actual knowledge or knowledge fairly implied on the basis of objective circumstances" (15 U.S.C. 45(m)).

The most recent item on the FTC's COPPA topic page, checked on October 2, 2026, is the February 25, 2026 policy statement. Federal court dockets were outside this check, so whether any complaint filed after April 22, 2026 applies the separate-consent provision is open.

What does a CITT scan show for a child-directed or mixed audience app?

The amended rule turns on order and recipient: whether personal information, including a device identifier, was collected or disclosed before the age screen or the parental consent step, and to whom. A network capture records each request the app sent, the receiving host, the identifier fields (advertising ID, app set ID, device and IP fields), and whether the request was sent before or after the age screen and any consent prompt.

When I scan an app, the report lists the ad, attribution and analytics SDKs found in the binary, the permissions the app declares, and the child-directed and age settings present in the code, such as the Google Mobile Ads child-directed setting, set with setTagForChildDirectedTreatment() or its replacement setAgeRestrictedTreatment(). It also lists the requests recorded on the test device, with host, fields and timing. Every static finding cites its file and line; every traffic finding cites its capture. SDK presence in a binary shows the code is there; only a capture shows what was sent. What a scan checks and the limits of a scan are on the methodology page.

Two questions turn on evidence other than a capture: whether an app is directed to children under the multi-factor test in § 312.2, and whether a recipient is a "third party" or a provider of support for internal operations. Those facts are found in audience evidence, contracts, SDK documentation and discovery.

I run these investigations for lawyers and for researchers working with lawyers, on one app or on a list of apps in bulk. Sign up for a CanITrustThat (CITT) account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.