Iubenda logo
Start generating

Documentation

Table of Contents

COPPA Compliance Checklist

The Children’s Online Privacy Protection Act (COPPA) was established to protect children’s online privacy and place certain requirements on website operators and app developers. Failure to comply with COPPA can result in significant legal and financial consequences. That’s where our COPPA Compliance Checklist comes in handy!

COPPA Compliance Checklist

In this article, we will provide a brief but comprehensive COPPA compliance checklist that website operators and app developers can use to ensure they are in compliance with the law. 

What is COPPA compliance?

The Children’s Online Privacy Protection Act (COPPA), which was passed by Congress in 1998 and mandated that the Federal Trade Commission create and implement regulations pertaining to children’s online privacy. On July 1st, 2013, the revised Regulation went into force.

COPPA’s main objective is to safeguard children’s internet privacy (and at the same time on the mobile ecosystem).

👀 See here for a guide to COPPA mobile apps →

Do I need to comply with COPPA?

Operators of websites and online services that gather personal data from children under 13 are subject to COPPA. Here’s a more detailed guide to figuring out whether COPPA applies to you. COPPA must be followed if:

  • Your website or online service is directed to children under 13, and you collect personal information from them; or
  • Your website or online service is directed to children under 13, and you let others collect personal information from them; or
  • Your website or online service is directed to a general audience, but you have actual knowledge that you collect personal information from children under 13; or
  • Your company runs an ad network or plug-in, for example, and you have actual knowledge that you collect personal information from users of a website or service directed to children under 13.
🚀
Targeting Minors in the US?

Here’s 1 Thing you Have to Know. Click here to see the specific guidelines.

What are the requirements for COPPA compliance?

The Children’s Online Privacy Protection Act (COPPA) places several requirements on website operators and app developers to protect the online privacy of children under the age of 13. Here are the key requirements for COPPA compliance:

  1. Obtaining parental consent before collecting personal information from children under 13.
  2. Providing clear and concise privacy policies that explain how personal information is collected, used, and shared.
  3. Displaying a prominent and easy-to-use mechanism for parents to review and delete their child’s personal information.
  4. Implementing reasonable security measures to protect the confidentiality, security, and integrity of personal information collected from children.
  5. Designating a COPPA compliance officer responsible for overseeing the company’s compliance with the law.
  6. Providing ongoing training to employees about COPPA compliance.

Need to comply? Use this COPPA compliance checklist

Step 1: Privacy Policy

Providing a privacy policy is the next step. It must specify in detail how any personal data obtained online from children under the age of 13 will be handled. The notice must outline not only your policies but also those of any third parties who may be using your site or service to gather personal information, such as plug-ins or ad networks.

Add a link to your privacy policy on your homepage and anywhere else you gather children’s personal information. 

Your privacy policy must be understandable and simple to read in order to comply with COPPA. Avoid including any irrelevant or perplexing material.

What your policy must contain is as follows:

  1. A list of all operators collecting personal information;
  2. A description of the personal information collected and how it’s used;
  3. A description of parental rights.

👀 Further information on what to include in your privacy policy can be found here →

Step 2: Notify Parents 

When collecting information from children, COPPA mandates that you “directly notify” parents of your information practices. Also, you must issue an updated direct notice if you materially alter the procedures that parents originally authorized.

Step 3: Get Parents’ Verifiable Consent 

You need the verifiable consent of the child’s parents before you can collect, use, or disclose their personal information.

💡 How can you collect parent’s consent?

COPPA leaves it up to you, but it’s crucial to pick a technique that’s been sensibly created in light of the technology that is currently available to make sure that the person providing the consent is the child’s parent. You may obtain consent directly or through the child-directed site or service if you have real knowledge that you are collecting personal information from a site or service that is targeted toward children.

Step 4: Honor Parents’ Ongoing Rights 

Parents have ongoing rights, and you retain ongoing obligations, even if parents have given you permission to collect information from their children.

If a parent requests it, you must:

  • Provide them with a way to evaluate the personal data gathered about their kid;
  • Provide them with a way to withdraw their consent and object to the use or collection of additional personal data about their child;
  • Erase their child’s data.

Step 5: Protect the Security of Kids’ Personal Information

In accordance with COPPA, you must set up and keep in place appropriate safeguards for the privacy, security, and integrity of any personal data you collect from minors. Reduce the amount you initially acquire. Take reasonable steps to ensure that only service providers and other third parties who can preserve the confidentiality, security, and integrity of the information are given access to personal information. 

Targeting kids? Get started with COPPA compliance now

Generate your COPPA-compliant Privacy Policy