A child sitting at a table using a tablet device with bright screen illuminating their face
Photo via Unsplash

TL;DR: The FTC’s overhauled COPPA rules hit full compliance on April 22, 2026: tomorrow. Every app, game, and platform that collects data from kids under 13 must now treat biometric identifiers (fingerprints, face scans, voiceprints, gait patterns, retina scans, DNA) as protected personal information. Companies must get separate parental consent before sharing kids’ data with third parties. Indefinite data retention is banned. Written security programs are mandatory. Penalties run $53,088 per violation, per day. But the “actual knowledge” loophole (which lets companies avoid COPPA entirely by not asking users’ ages) survived the update. And the FTC’s own age verification policy encourages the exact kind of biometric data collection the new rules are supposed to restrict.

What Actually Takes Effect April 22

The FTC published these amendments on April 22, 2025, and gave companies a full year to comply [1]. That grace period ends tomorrow. Here’s what every operator of a child-directed service or site with “actual knowledge” of underage users must have in place:

  • Expanded data definition: Biometric identifiers (fingerprints, handprints, retina and iris patterns, genetic data, voiceprints, gait patterns, facial templates, and faceprints) are now “personal information” under COPPA. So are government-issued IDs like Social Security numbers, state ID card numbers, birth certificate numbers, and passports [1] [2].
  • Separate consent for sharing: One consent screen no longer covers everything. Parents must give separate, explicit permission before an app discloses their child’s data to third parties for purposes that aren’t “integral” to the service. Advertising, data monetization, and AI model training are explicitly never considered integral [2].
  • Written data retention policy: Companies must publish specific timeframes for how long they keep children’s data and delete it when the stated purpose is fulfilled. Indefinite retention is over [1].
  • Written information security program: Every operator needs a formal WISP with a designated employee coordinator, annual risk assessments, ongoing testing, and annual evaluations when technology changes [3].
  • Safe harbor transparency: The six FTC-approved safe harbor programs (including ESRB and kidSAFE) must publicly disclose their member lists and submit annual disciplinary action reports [2].

$53,088 Per Violation Per Day. The FTC Says It Means It.

Commissioner Mark Meador said the FTC is “willing and eager” to enforce compliance with the updated rules. Associate Director Ben Wiseman went further: “The commission has been loud and clear for a while that protecting kids is going to be a high priority, and we’re going to continue to bring cases on that” [4].

The recent track record backs that up:

  • Cognosphere (Genshin Impact maker), January 2025: $20 million for collecting children’s data without parental consent [4].
  • Disney, September 2025: $10 million for mislabeling child-directed YouTube videos to dodge COPPA requirements [4].
  • Apitor Technology, September 2025: Settlement for letting a third-party SDK embedded in its kids’ app collect data without parental notice or consent [4].
  • Epic Games (Fortnite), 2022: $275 million, still the largest COPPA penalty ever [5].

These aren’t slaps on the wrist. The Apitor case is particularly relevant for tomorrow’s deadline: the company got in trouble because a third-party SDK in its app was collecting kids’ data. Under the new rules, operators are responsible for what their service providers do with children’s data. Updated contracts are mandatory [3].

The Loophole Big Enough to Drive TikTok Through

All of this only applies if a company has “actual knowledge” it’s collecting data from children under 13.

No age-gate on your sign-up page? No actual knowledge. Terms of service that say users must be 13+? Plausible deniability. A platform with millions of obvious child users but no formal age-verification system? Technically, no actual knowledge [6].

Privacy advocates pushed the FTC to adopt a “constructive knowledge” standard, meaning companies would be liable if a reasonable person would know kids were using their product. The FTC declined. The loophole that lets platforms profit from children’s data while claiming ignorance of their existence survived the biggest COPPA update in 12 years [6].

To be fair, the FTC has been willing to infer “actual knowledge” aggressively in recent cases. The Disney settlement hinged on the company knowing certain YouTube channels were child-directed even though kids weren’t the account holders. But the standard still incentivizes looking the other way.

The Age Verification Trap: Using Surveillance to Fight Surveillance

Here’s where it gets uncomfortable.

In February 2026, the FTC issued a policy statement encouraging general-audience sites to use age verification technologies (including biometric systems like facial age estimation) to identify which users are children [7]. The FTC said it won’t bring enforcement actions against operators that collect personal information solely to determine a user’s age.

Think about what that means. The new COPPA rules say fingerprints, face scans, and voiceprints are sensitive data that requires parental consent before collection from children. But to figure out who the children are, the FTC is telling companies to collect biometric data from everyone (adults and children alike) before knowing whether COPPA applies [8].

Legal scholars at Truth on the Market put it bluntly: age verification inverts COPPA’s foundational logic. COPPA was designed to prevent data collection from kids without parental consent. Age verification requires collecting data first and determining age afterward. A child’s biometric data could be processed before a parent even knows their kid visited the site [8].

And those biometric databases? As Geoffrey Manne wrote, they’re “attractive targets for hackers”: centralized repositories of facial scans and government IDs covering millions of users, including the children the system is supposed to protect [8].

Privacy groups haven’t been quiet about this. The criticism is pointed: instead of holding the industry to the stronger biometric data standards COPPA now requires, the FTC’s enforcement statement gives operators a weaker standard for collecting children’s facial scans during the verification process [7].

Who’s Ready and Who’s Scrambling

The Toy Association lobbied for the full one-year compliance window, and it still may not be enough for everyone [9]. ComplianceHub.Wiki noted in April that many operators are still implementing basic requirements “this week,” suggesting significant portions of the industry are running right up against the deadline [3].

The industries most affected:

  • EdTech platforms: Apps like ABCmouse, Khan Academy Kids, and classroom tools that collect login data, usage patterns, and sometimes voice recordings
  • Gaming: Any game with in-app communication, avatar creation (which may use face scanning), or voice chat
  • Smart toys: Connected devices with microphones, cameras, or fingerprint readers
  • Social media: Platforms with age-gating that know kids get through anyway

The biggest compliance challenges aren’t the headline items. It’s the third-party SDK audit. Under the updated rules, operators are responsible for every data collection that happens inside their app, including by third-party analytics, advertising, and engagement tools. If a tracking SDK buried in your kids’ learning app pings an ad network with device identifiers, that’s on you [4].

What Parents Should Do Starting Tomorrow

  • Watch for separate consent prompts. After April 22, apps should ask for separate permission before sharing your child’s data with advertisers or other third parties. If an app still bundles everything into one consent screen? That’s a COPPA violation. Screenshot it.
  • Check data retention policies. Every kids’ app must now publish how long they keep your child’s data. It should be in the privacy policy with specific timeframes. “Indefinitely” or “as long as needed” no longer cuts it.
  • Audit biometric permissions. If a kids’ app wants camera access for face filters, microphone access for voice features, or fingerprint access for login, those are now regulated biometric identifiers. The app needs your verified consent before collecting them.
  • Report violations. File complaints at reportfraud.ftc.gov. The FTC has publicly committed to enforcement. Give them something to enforce.
  • Don’t rely on age verification alone. If an app asks to scan your child’s face to “verify their age,” understand that’s biometric data collection too. Ask whether the scan is deleted immediately after verification. If the privacy policy doesn’t say so, assume it isn’t.

The Bigger Picture

COPPA’s overhaul is the most significant children’s privacy update the FTC has made since the internet was a very different place. The biometric protections are real. The separate consent requirement for third-party sharing is a genuine win. The data retention ban closes an obvious gap.

But the rules only cover kids under 13. Teens have no federal privacy protection. The “actual knowledge” standard still rewards willful blindness. And the FTC is simultaneously telling companies to collect more biometric data (for age verification) while regulating biometric data collection (under COPPA).

That’s the fundamental tension: you can’t protect children from biometric surveillance by building a biometric surveillance system to figure out who the children are.

Tomorrow, the deadline arrives. The enforcement actions that follow will tell us whether these rules have teeth, or whether COPPA remains the law that companies fear in press releases and ignore in code.

References

  1. Federal Register: Children’s Online Privacy Protection Rule (April 22, 2025)
  2. White & Case: Unpacking the FTC’s COPPA Amendments: What You Need to Know
  3. ComplianceHub.Wiki: The COPPA Clock Runs Out April 22: What Every Operator Must Have in Place This Week
  4. Davis Polk: FTC Prioritizes COPPA Enforcement as New Compliance Obligations Take Effect
  5. FTC: Kids’ Privacy (COPPA) Enforcement Page
  6. Finnegan: The FTC’s Updated COPPA Rule: Redefining Children’s Digital Privacy Protection
  7. FTC: Policy Statement on Age Verification Technologies (February 2026)
  8. Truth on the Market: COPPA, Age Verification, and the FTC’s Enforcement End Run (March 4, 2026)
  9. Toy Association: Updated COPPA Rule Requirements Take Effect April 22