# COPPA privacy policy: the online notice for children

> Who COPPA covers, what the online notice for children under 13 must say after the 2025 rule amendments, and how the clauses handle it.

Under the COPPA Rule, an operator of a website or online service directed to children under 13, or one with actual knowledge that it collects personal information from children under 13, must post a clear and prominent online notice of its practices. The notice must identify every operator that collects or maintains children's information and how to contact them, describe what is collected and how it is used and disclosed, and explain that parents can review and delete their child's information and refuse further collection.

Canonical URL: https://legalpolicygenerator.com/laws/coppa-privacy-policy

## Who this law applies to

The Children's Online Privacy Protection Act and the FTC's rule apply to commercial operators of websites and online services, including apps, connected devices, and games, that are directed to children under 13 and collect personal information, and to general-audience operators that have actual knowledge they collect personal information from a child under 13. Whether a service is directed to children depends on factors such as subject matter, visual content, animated characters, child-oriented activities and incentives, music, the age of models, child-directed advertising, and evidence about the actual audience. A service can be mixed-audience when children are part of its audience but not the primary one. Third parties such as advertising networks or plug-ins can also be covered when they have actual knowledge that they collect from users of a child-directed service. The FTC amended the rule in a notice published in the Federal Register on April 22, 2025. The amendments took effect on June 23, 2025, and the general compliance date was April 22, 2026, with later dates only for certain safe-harbor provisions. The amendments require separate verifiable parental consent before disclosing children's information to third parties, for example for targeted advertising, unless the disclosure is integral to the service; add biometric identifiers and government-issued identifiers to the definition of personal information; and require a written data retention policy for children's information.

## What your privacy policy must include

The rule's online notice requirements call for the name, address, telephone number, and email address of every operator collecting or maintaining children's personal information through the service, or of one operator designated to answer parents' questions together with the names of the others; a description of what information the operator collects from children, including whether children can make personal information publicly available; how the operator uses that information; the operator's disclosure practices; and a statement that a parent can review or have deleted the child's personal information and refuse to permit its further collection or use, with the procedures for doing so. The notice must be clearly labelled and linked prominently from the home page and wherever personal information is collected from children. It is separate from the direct notice that must reach a parent before collection, and from the verifiable parental consent method itself. A children's retention policy that explains why information is kept and when it is deleted must also exist in writing under the amended rule; check the rule text for how it must be made available.

## How Legal Policy Generator handles it

Selecting US COPPA adds a regional clause that lists the operators and their contact details, the children's-information practices, the direct notice and verifiable parental consent practice, and how a parent can review or delete information, refuse further collection, or ask a question. It also states that a child's participation is not conditioned on providing more information than is reasonably necessary. The United States framework clause is added with it, and the general children's clause, which is present in every privacy policy, describes the intended audience. The list below is read from the clause library each time this page is rendered.

## Questionnaire answers that switch it on

The COPPA clause activates only when the jurisdiction answer includes US COPPA for children under 13. Validation then requires four free-text answers: the operators and their public contact details, the children's information with its use, disclosure, and public availability, the direct notice and parental consent practice, and the parental review, deletion, and collection-stop procedure. These are written by you from your actual operations, because the generator cannot invent a consent method or an operator list. The audience answer separately drives the general children's clause: a children or teenagers audience adds age-specific wording, and an adults or general audience adds a statement about deleting information collected from a child contrary to the stated audience.

## Common mistakes

Stating that the service does not knowingly collect information from children while the content, characters, or marketing are plainly aimed at them does not remove the rule's application. Listing only the app publisher and not the SDK, analytics, or advertising operators that collect from children leaves out required operators. Relying on a single checkbox from the child instead of a verifiable parental consent method does not meet the rule. Running behavioral advertising on a child-directed service without the separate consent that the amended rule requires is a serious risk. Keeping children's information indefinitely, or without a written retention policy, is inconsistent with the amendments. Finally, the online notice does not replace the direct notice to parents.

## Common questions

### Does COPPA apply to teenagers?

No. COPPA protects children under 13. Some state laws add duties for teenagers, and those are outside the COPPA module.

### Does a general-audience site need a COPPA notice?

It does when the operator has actual knowledge that it collects personal information from a child under 13, or when part of the service is directed to children.

### What changed in the 2025 COPPA amendments?

Separate parental consent for most third-party disclosures, an expanded definition of personal information that includes biometric and government-issued identifiers, and a written retention policy. The compliance date was April 22, 2026.

### Does the generator obtain parental consent?

No. It drafts the online notice from the consent practice you describe. Collecting verifiable parental consent must happen in your own service.

### Is the generated COPPA wording legal advice?

No. Children's privacy is a high-risk area, and the wording reflects supplied facts without guaranteeing compliance. Qualified review is recommended.

Generated wording reflects supplied facts. It is not legal advice or a guarantee of compliance or enforceability.
