COPPA is the US law protecting the personal information of children under 13 online, enforced by the FTC. Its 2025 amendments have applied since April 2026 and reach operators outside the US. ThreeShield assesses your services and builds the program, and Lavawall® reuses the safeguards you already run.
COPPA, the Children's Online Privacy Protection Act of 1998, is the US law that protects the personal information of children under 13 online. The Federal Trade Commission enforces it through the Children's Online Privacy Protection Rule, 16 CFR Part 312.
It applies to operators of commercial websites, apps, and online services directed to children under 13, to mixed audience services, and to any operator that knows it collects personal information from a child under 13, wherever the operator is based.
The rule was substantially amended in 2025. The amendments took effect on 23 June 2025, and compliance has been required since 22 April 2026. Civil penalties reach $53,088 per violation for 2026, and state attorneys general can enforce COPPA too.
A clear children's privacy notice wherever information is collected, and a direct notice to parents before collection.
Consent from a parent, by a method reasonably calculated to confirm it is the parent, before collecting, using, or disclosing a child's information.
Disclosing a child's information to third parties, including advertisers, needs its own consent unless it is integral to the service.
A written information security program with a named coordinator, annual risk assessment, testing, and written assurances from service providers.
A published policy stating why children's information is kept and when it is deleted. No indefinite retention.
Parents can review what was collected, refuse further collection, and have it deleted.
Most of COPPA is controls you already run for PIPEDA and will run for the proposed PPCDA. In Lavawall®, COPPA sits on the same shared control set, so a safeguard implemented and evidenced once counts toward each law. The COPPA-specific work (deciding which services are directed to children, age screening, parental notice and consent, limits on persistent identifiers) sits on top.
| What you do once | COPPA Rule | PIPEDA | PPCDA (Bill C-36) |
|---|---|---|---|
| Written information security program with a named coordinator | 312.8(b) | Principles 4.1 and 4.7 | ss. 8 and 56 |
| Encryption, multi-factor authentication, and access control | 312.8(a) | Principle 4.7 | s. 56 |
| Service provider assessment and written assurances | 312.8(c) | Principle 4.1.3 | s. 11 |
| Retention periods and secure deletion | 312.10 | Principle 4.5 | ss. 52 and 54 |
| Collect only what is needed | 312.7 | Principle 4.4 | s. 13 |
| Accurate, published privacy policy | 312.4(d) | Principle 4.8 | s. 62 |
Canada has no COPPA today. PIPEDA has no age threshold, though the Privacy Commissioner treats children's information as sensitive, and Quebec Law 25 requires consent from the person with parental authority for children under 14. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, would define a child as anyone under 18. One children's privacy program can meet COPPA for US users and prepare for the PPCDA at home.
| COPPA requirement | Lavawall® collects | ThreeShield delivers |
|---|---|---|
| Encryption, MFA, and patching evidence | ✓ Continuously | — |
| Breach detection across Microsoft 365 and Google Workspace | ✓ Continuously | — |
| Child-directed and mixed audience determination | — | Documented assessment of each service |
| Notices, consent procedure, security program, retention policy | ⚑ Templates | Written and reviewed by ThreeShield |
| Third-party SDK and advertising review | — | Traffic and configuration review |
Related: CCPA/CPRA · PPCDA (Bill C-36) · PIPEDA · FTC Safeguards Rule
Official source: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-312
It can. COPPA applies to any operator whose website, app, or online service is directed to children under 13 in the United States, or that knows it collects their personal information, wherever the operator is based.
Biometric identifiers became personal information, mixed audience services were defined, disclosures to third parties now need separate parental consent, and operators need a written information security program and a published retention policy. Compliance has been required since 22 April 2026.
Up to $53,088 per violation for 2026, and each affected child can count as a separate violation. The FTC and state attorneys general can both enforce it.
Yes. The security program, encryption, access control, vendor assurances, and retention controls are the same controls. Lavawall® credits them to every framework that maps them, and ThreeShield adds the COPPA-specific pieces.
ThreeShield meets you at your current privacy maturity. Every level includes Lavawall®.
For lean IT teams and cost-conscious organizations with internal capacity
Expert guidance alongside your team, ideal for MSPs and organizations with some internal IT capacity
The privacy program delivered and kept current by ThreeShield
ThreeShield assesses your services against the amended COPPA Rule and writes what is missing. Lavawall® keeps the safeguards evidence current between reviews.
Book a Scoping CallDIY · Supported · Done-for-You