PRIVACY · USA · CHILDREN

Children's Online Privacy Protection Act (COPPA)
Compliance & Assessment

COPPA is the US law protecting the personal information of children under 13 online, enforced by the FTC. Its 2025 amendments have applied since April 2026 and reach operators outside the US. ThreeShield assesses your services and builds the program, and Lavawall® reuses the safeguards you already run.

Who This Applies To

Apps, games, and websites directed to children under 13Mixed audience servicesEdtech and youth platformsCanadian and other non-US operators with US child usersMSPs serving those clients

What the Children's Online Privacy Protection Act (COPPA) Requires

COPPA, the Children's Online Privacy Protection Act of 1998, is the US law that protects the personal information of children under 13 online. The Federal Trade Commission enforces it through the Children's Online Privacy Protection Rule, 16 CFR Part 312.

It applies to operators of commercial websites, apps, and online services directed to children under 13, to mixed audience services, and to any operator that knows it collects personal information from a child under 13, wherever the operator is based.

The rule was substantially amended in 2025. The amendments took effect on 23 June 2025, and compliance has been required since 22 April 2026. Civil penalties reach $53,088 per violation for 2026, and state attorneys general can enforce COPPA too.

Notice and Direct Notice to Parents

A clear children's privacy notice wherever information is collected, and a direct notice to parents before collection.

Verifiable Parental Consent

Consent from a parent, by a method reasonably calculated to confirm it is the parent, before collecting, using, or disclosing a child's information.

Separate Consent for Third Parties (2025)

Disclosing a child's information to third parties, including advertisers, needs its own consent unless it is integral to the service.

Written Security Program (2025)

A written information security program with a named coordinator, annual risk assessment, testing, and written assurances from service providers.

Written Retention Policy (2025)

A published policy stating why children's information is kept and when it is deleted. No indefinite retention.

Parental Review and Deletion

Parents can review what was collected, refuse further collection, and have it deleted.

What COPPA Shares with Your Privacy Program

Most of COPPA is controls you already run for PIPEDA and will run for the proposed PPCDA. In Lavawall®, COPPA sits on the same shared control set, so a safeguard implemented and evidenced once counts toward each law. The COPPA-specific work (deciding which services are directed to children, age screening, parental notice and consent, limits on persistent identifiers) sits on top.

What you do onceCOPPA RulePIPEDAPPCDA (Bill C-36)
Written information security program with a named coordinator312.8(b)Principles 4.1 and 4.7ss. 8 and 56
Encryption, multi-factor authentication, and access control312.8(a)Principle 4.7s. 56
Service provider assessment and written assurances312.8(c)Principle 4.1.3s. 11
Retention periods and secure deletion312.10Principle 4.5ss. 52 and 54
Collect only what is needed312.7Principle 4.4s. 13
Accurate, published privacy policy312.4(d)Principle 4.8s. 62

COPPA and Canadian Law

Canada has no COPPA today. PIPEDA has no age threshold, though the Privacy Commissioner treats children's information as sensitive, and Quebec Law 25 requires consent from the person with parental authority for children under 14. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, would define a child as anyone under 18. One children's privacy program can meet COPPA for US users and prepare for the PPCDA at home.

Where the Work Splits

COPPA requirementLavawall® collectsThreeShield delivers
Encryption, MFA, and patching evidence✓ Continuously—
Breach detection across Microsoft 365 and Google Workspace✓ Continuously—
Child-directed and mixed audience determination—Documented assessment of each service
Notices, consent procedure, security program, retention policy⚑ TemplatesWritten and reviewed by ThreeShield
Third-party SDK and advertising review—Traffic and configuration review

Related: CCPA/CPRA · PPCDA (Bill C-36) · PIPEDA · FTC Safeguards Rule

Official source: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-312

Frequently Asked Questions

It can. COPPA applies to any operator whose website, app, or online service is directed to children under 13 in the United States, or that knows it collects their personal information, wherever the operator is based.

Biometric identifiers became personal information, mixed audience services were defined, disclosures to third parties now need separate parental consent, and operators need a written information security program and a published retention policy. Compliance has been required since 22 April 2026.

Up to $53,088 per violation for 2026, and each affected child can count as a separate violation. The FTC and state attorneys general can both enforce it.

Yes. The security program, encryption, access control, vendor assurances, and retention controls are the same controls. Lavawall® credits them to every framework that maps them, and ThreeShield adds the COPPA-specific pieces.

Three Ways to Engage, from DIY to Done-for-You

ThreeShield meets you at your current privacy maturity. Every level includes Lavawall®.

Self-Serve

DIY via Lavawall®

For lean IT teams and cost-conscious organizations with internal capacity

  • Lavawall® GRC with COPPA control mapping
  • Continuous safeguards evidence
  • Notice, consent, security program, and retention templates
  • Staff training course on the amended rule
Start with Lavawall®
Recommended for MSPs & Lean IT

Supported

Expert guidance alongside your team, ideal for MSPs and organizations with some internal IT capacity

  • Everything in the DIY tier
  • CISSP/CISA-led gap assessment
  • Prioritized remediation roadmap
  • Policy and procedure development
  • Quarterly compliance review calls
  • MSP white-label available
Get Supported Engagement
Fully Managed

Done-for-You

The privacy program delivered and kept current by ThreeShield

  • Everything in the Supported tier
  • Full privacy program management
  • CISSP/CISA-executed formal assessment
  • Detailed findings methodology
  • Complete documentation package
  • Annual reassessment included
Book Done-for-You

Get Your Children's Privacy Program in Order

ThreeShield assesses your services against the amended COPPA Rule and writes what is missing. Lavawall® keeps the safeguards evidence current between reviews.

Book a Scoping Call

DIY · Supported · Done-for-You