Young child looking at a glowing screen in dim lighting
Photo via Unsplash

TL;DR: Yesterday, April 22, 2026, was the compliance deadline for the FTC’s amended COPPA rule, the first major update to children’s online privacy law since 2013. Starting now, companies that collect data from kids under 13 must treat biometric identifiers (face templates, fingerprints, voiceprints) as personal information. They need separate parental consent before sharing a child’s data with advertisers. They can’t hold onto kids’ data forever. And they must publish written data security programs and retention policies. The FTC voted 5-0 to approve these changes in January 2025. The industry had 10 months to comply. Violations carry penalties up to $51,744 per affected child. Enforcement is now the only question that matters.

What Actually Changed on April 22

The Children’s Online Privacy Protection Act has been federal law since 1998. The FTC last updated its enforcement rule in 2013. That was before TikTok existed. Before Roblox had 70 million daily users. Before EdTech platforms started hoovering up kids’ voice recordings to train AI models [1].

On January 16, 2025, the FTC voted unanimously to approve the most significant COPPA amendments in over a decade. The changes took effect June 23, 2025. Companies had until April 22, 2026 to comply [1] [2].

Here’s what’s different now:

  • Biometric data is personal information. Face templates, fingerprints, retina scans, and voiceprints are now explicitly covered. That voice assistant in your kid’s learning app? COPPA applies. That face filter in their game? COPPA applies [2] [3]
  • Separate consent for advertising. Companies must obtain separate, additional parental consent before sharing a child’s data with third parties for targeted advertising. One blanket consent form no longer cuts it [1] [4]
  • No more indefinite retention. Companies must publish written data retention policies. They can only keep children’s data for as long as reasonably needed for the original collection purpose. Then it must be deleted [2] [3]
  • AI training is never “integral.” The FTC explicitly stated that disclosing children’s data for monetary compensation, advertising, or training artificial intelligence is never “integral” to a service. It always requires separate consent [1]
  • Written data security programs. Companies must implement and maintain a documented security program identifying responsible personnel, risks, safeguards, and evaluation procedures [3]
  • Name your third parties. Privacy notices must now identify the specific categories of third parties that receive children’s data. “Our partners” doesn’t count anymore [3]

The AI Problem Nobody Saw Coming

Here’s where it gets ugly. A generation of EdTech companies built AI products by feeding children’s data into machine learning models, and never asked parents for consent to use the data that way [5].

Learning apps that collected voice recordings to assess reading fluency used those recordings to train speech recognition models. Games that tracked behavioral patterns used that data to train recommendation engines. Adaptive learning platforms fed kids’ performance data into algorithms that now power their core product [5].

None of this was covered by the consent parents originally gave. Under the amended rule, using children’s data for AI training requires separate parental consent, every time. Companies that trained models on historical data without that consent now face a choice: go back and get permission (and lose users who say no), or stop using models trained on children’s data entirely [5].

Roblox has 70 million daily active users. A significant chunk are under 13. Every voice chat, every behavioral pattern, every adaptive game system on the platform generates data that’s now covered by the expanded COPPA definition [5].

Enforcement: The Only Question That Matters

Rules without enforcement are suggestions. That’s the tension right now.

FTC Commissioner Mark Meador told the IAPP Global Summit 2026 that the commission is “willing and eager” to enforce compliance. He described the FTC as “trying to spot harm, address it, prevent it from occurring”, favoring case-by-case enforcement over broad rulemaking. When asked about tech companies claiming age verification is too difficult, Meador called it “kind of silly,” comparing it to society’s acceptance of ID checks for alcohol and R-rated films. He indicated upcoming announcements on age assurance actions are forthcoming [6] [10].

On February 25, 2026, the FTC issued a policy statement on age verification, offering enforcement discretion for operators collecting data solely to determine age. Three leading advocacy organizations (EPIC, the Center for Digital Democracy, and Fairplay) fired back in a March 2026 letter warning it “sets a weak federal floor for age verification data practices.” Their concern: the policy lets operators collect personal information from every user, including children, without parental consent, as long as it’s for age verification. That’s a loophole, and everyone knows it [6].

The enforcement track record shows the FTC isn’t all talk. In January 2025, the FTC hit Cognosphere (maker of Genshin Impact) with a $20 million settlement for collecting children’s data without parental consent. In December 2025, Disney paid $10 million for failing to label kid-directed YouTube videos as “Made for Kids,” enabling unlawful data collection. And the DOJ’s 2024 lawsuit against TikTok and ByteDance for “flagrantly violating” COPPA (alleging they knowingly allowed millions of kids under 13 on the main app) survived TikTok’s motion to dismiss in November 2025 and is heading to trial [7] [10].

At $51,744 per affected child, the penalties add up fast. But enforcement requires resources. Whether the FTC has the capacity to police an entire industry that just hit a compliance deadline remains the open question [1].

Who’s Ready and Who Isn’t

No major platform has issued a public compliance announcement tied to the April 22 deadline. That silence is telling.

The BBB National Programs operates a COPPA Safe Harbor program, an industry self-regulation framework where certified companies get some FTC enforcement flexibility. Companies in the program are supposed to meet compliance standards. But Safe Harbor certification doesn’t mean the FTC won’t investigate [3].

The EdTech sector is in the most trouble. Many companies collected children’s language data, behavioral patterns, and learning analytics for years and used it to train AI models without AI-specific consent. Retrofitting consent flows means some parents will say no. That means worse model performance or smaller user bases. Neither option is great for quarterly earnings [5].

Fairplay executive director Josh Golin put it plainly when the rule was finalized: “The new Rule offers critical new protections for children and should serve as a wake-up call to an industry that far too often collects and uses kids’ data in deceptive and exploitative ways” [8].

He also noted the 5-0 vote showed “a growing bipartisan consensus that children need better protections online” and urged Congress to pass an update to COPPA that bans targeted advertising to minors entirely and extends privacy protections to teens [8].

What COPPA Still Doesn’t Cover

For all the improvements, there are gaps you could drive a data broker through:

  • Teens are invisible. COPPA only covers children under 13. A 14-year-old gets the same privacy protections as an adult, which in most states means: none. COPPA 2.0, which passed the Senate unanimously, would raise the age to 17. It hasn’t moved through the House [9]
  • Age verification creates new surveillance. To figure out who’s under 13, companies have to verify ages. The new parental consent methods include government-issued ID verification with facial recognition. Privacy organizations argue this trades one surveillance problem for another [6]
  • “Mixed audience” is slippery. The rule defines “mixed audience” sites differently than “directed to children” sites. General audience platforms like YouTube can claim they’re not specifically targeting kids, even when kids make up a huge share of their users [2]
  • State preemption looms. Multiple states have passed stronger children’s privacy laws. If federal COPPA 2.0 legislation passes with preemption language, those state protections could get wiped out [9]

What Parents Can Do Right Now

  • Check your kid’s apps for biometric features. Voice assistants, face filters, emotion detection: all now covered by COPPA. If an app uses these features and your kid is under 13, the company needed your consent. If they didn’t ask, that’s a violation
  • Look for COPPA Safe Harbor seals. The BBB’s COPPA Safe Harbor program certifies compliant products. It’s not perfect, but it’s a minimum standard [3]
  • Request data deletion. Under the amended rule, companies must honor parental requests to delete their child’s data. Send the request in writing. If they refuse or don’t respond, file a complaint with the FTC
  • File FTC complaints. The FTC’s enforcement depends partly on consumer complaints. If a children’s app or site isn’t following the rules, report it at reportfraud.ftc.gov
  • Push for COPPA 2.0. The Senate passed it unanimously. Contact your House representative. Teens deserve protections too

References

  1. FTC: FTC Finalizes Changes to Children’s Privacy Rule Limiting Companies’ Ability to Monetize Kids’ Data (January 16, 2025)
  2. Toy Association: Updated COPPA Rule Requirements Take Effect April 22 (2026)
  3. BBB National Programs: Amended COPPA Rule Compliance Deadline Approaching (2026)
  4. Gibson Dunn: FTC Updates to the COPPA Rule Impose New Compliance Obligations (2025)
  5. DEV Community: COPPA Compliance Deadline Is April 22, 2026: Here’s What Your EdTech Product Needs to Do Now (2026)
  6. Davis Polk: FTC Prioritizes COPPA Enforcement as New Compliance Obligations Take Effect (2026)
  7. FTC: FTC Investigation Leads to Lawsuit Against TikTok and ByteDance (August 2024)
  8. Fairplay: Fairplay Welcomes New FTC Children’s Online Privacy Protection Act Rule (2025)
  9. UPI: Multiple Bills Highlight Challenge Protecting Children Online (April 13, 2026)
  10. IAPP: FTC Commissioner Meador Stresses Agency Preference for Case-by-Case Enforcement (2026)