COPPA Compliance Software: COPPA Requirements, Parental Access Requests, and the Retention Rule
Since April 22, 2026 the amended COPPA Rule has been fully in force, and the change with the longest tail is the one nobody can satisfy with a policy document. Indefinite retention of children's personal information is now prohibited outright, and you have to publish a written retention policy saying how long you keep it and why. Obtainer answers the question both that policy and a parent's review request depend on: what do you still hold about this child, in which system, and how did it get there.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
COPPA compliance means meeting the Children's Online Privacy Protection Act, 15 U.S.C. 6501 to 6506, and the FTC's implementing Rule at 16 CFR Part 312. It applies to an operator of a website or online service directed to children under 13, and to any operator with actual knowledge that it collects personal information from a child under 13. The FTC finalized its amendments on January 16, 2025. They took effect June 23, 2025, and full compliance has been required since April 22, 2026, so the amended Rule is the operative text today rather than a deadline still ahead of you. Four obligations carry most of the operational weight. Under 16 CFR 312.5 you must obtain verifiable parental consent before collecting, using, or disclosing a child's personal information, and the amended Rule adds a separate verifiable parental consent before disclosing that information to third parties for targeted advertising, which means one blanket consent at signup no longer covers a downstream ad or analytics partner. Under 312.4 you must post a clear online notice of what you collect and how you use it. Under 312.6 a parent has the right to review the personal information you collected from their child, to refuse to permit its further use or future collection, and to direct you to delete it, and you have to provide a means of reviewing that is not unduly burdensome to the parent. Under 312.10 you may retain a child's personal information only as long as is reasonably necessary to fulfill the specific purpose for which it was collected, you must establish, implement, and maintain a written data retention policy setting out those purposes, the business need for retaining the data, and a timeframe for deleting it, you must publish that policy in your online notice, and the Rule states plainly that personal information collected online from a child may not be retained indefinitely. The amended Rule also added biometric identifiers to the definition of personal information and requires a written information security program with a named person responsible for it. Two of these are discovery problems before they are policy problems. A parent's review-and-delete request under 312.6 is a data subject request with a stricter standard than most state privacy laws use, since the Rule sets no fee allowance and holds you to a process that is not unduly burdensome on the parent. And a retention schedule you cannot query is a document rather than a control: deleting on time requires knowing what you still hold about a specific child, in which system, and how it arrived there. Obtainer covers that operational half. It intakes the parental request, finds where the child's data actually sits across your product database, analytics, support desk, email platform, backups, and vendor systems, compiles one reviewable source-system manifest, drafts a response, and keeps a timestamped record of what was searched and when, which is the same evidence an FTC inquiry or a retention audit asks for. Nothing is disclosed or erased automatically. A human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so consent mechanics, age determinations, and any refusal stay with your counsel and privacy team. Self-serve from $49/mo.
Why it fits
Kids app and game studios, edtech vendors, and consumer products with users under 13.
A retention policy you cannot query is a document, not a control
Section 312.10 is the amended Rule's sharpest operational change, and it is short. You may keep a child's personal information only as long as is reasonably necessary for the specific purpose you collected it for. You must write a retention policy stating those purposes, the business need, and a deletion timeframe. You must publish it in your online notice, which makes it a public commitment a regulator can read on Tuesday and test on Wednesday. And personal information collected from a child may not be retained indefinitely, full stop. Writing the policy takes an afternoon. Executing it means being able to answer, for one child, what you still hold and where, across every system that ever received a copy. That second part is the work, and it is the part a policy template does not do for you.
The parent review right is a data subject request with a stricter standard
Section 312.6 gives a parent three things: a description of the specific types or categories of personal information collected from children, a means of reviewing the personal information actually collected from their child, and the opportunity to refuse further use or future collection and to direct deletion. The Rule requires that means of review not be unduly burdensome to the parent, and unlike the GDPR it contains no provision letting you charge for it or refuse a repetitive request. What it does give you is protection on the other side: an operator is not liable under any federal or state law for a good-faith disclosure to a parent made following reasonable procedures to verify that the requester is the parent. That immunity is conditioned on your procedures, which is a direct argument for running these requests through a documented process rather than an inbox.
The school-consent exception edtech runs on never made it into the Rule text
This is the detail most COPPA summaries skip, and it matters if you sell into K-12. In its 2024 proposal the FTC put forward definitions of school and school-authorized education purpose and proposed codifying the school authorization exception, the long-standing position that a school can give consent in place of a parent. In the final 2025 amendments the Commission declined to finalize any of the ed tech provisions, saying it would weigh the Department of Education's plans to update the FERPA regulations first. The exception still stands, but it stands in FTC guidance and the 1999 Statement of Basis and Purpose rather than in the Rule itself, and it has always been narrow: the information must be collected for the use and benefit of the school and for no other commercial purpose. Use that data for your own product analytics or marketing and school consent stops covering you.
Biometrics widened what counts, and one consent no longer covers the ad stack
Two amendments changed what you have to be able to find. Biometric identifiers that can be used for automated or semi-automated recognition, including voiceprints, fingerprints, and facial templates, are now personal information, which reaches voice features, photo tools, and any recognition step you shipped without thinking of it as data collection. Separately, disclosing a child's personal information to a third party for targeted advertising now needs its own verifiable parental consent, distinct from the consent you obtained to run the service. Both changes push in the same direction: you need an accurate map of what leaves your product and who receives it, per child, because the consent you can evidence is now the boundary of what you were allowed to send.
More use cases
Related features
Questions
Common questions about this
What is COPPA compliance?
It is meeting the Children's Online Privacy Protection Act and the FTC Rule at 16 CFR Part 312. In practice that means posting a clear online notice, obtaining verifiable parental consent before collecting personal information from a child under 13, giving parents a way to review that information and direct its deletion, keeping the data secure under a written information security program, retaining it only as long as reasonably necessary under a published written retention policy, and never retaining it indefinitely.
Who has to comply with COPPA?
Operators of websites and online services directed to children under 13, and operators of general-audience services that have actual knowledge they are collecting personal information from a child under 13. Whether a service is directed to children turns on factors the FTC weighs together, including subject matter, visual and audio content, animated characters, child-oriented activities and incentives, the age of models, celebrities who appear, advertising placement, and any competent, reliable evidence about the actual audience. Calling your product general audience in the terms of service does not settle it.
What changed in the amended COPPA Rule?
The FTC finalized amendments on January 16, 2025, effective June 23, 2025, with full compliance required since April 22, 2026. The main changes: biometric identifiers became personal information, a separate verifiable parental consent is now required before disclosing a child's information to third parties for targeted advertising, operators must maintain a written data retention policy published in the online notice, indefinite retention is prohibited outright, and a written information security program with a named responsible person is required. The Commission declined to finalize its proposed ed tech and school-consent provisions.
How long can you keep a child's personal information under COPPA?
Only as long as is reasonably necessary to fulfill the specific purpose for which it was collected. Section 312.10 sets no fixed number of days and instead ties the period to your documented purpose, then requires you to write that reasoning down in a retention policy covering the purposes, the business need, and a deletion timeframe, and to publish it in your online notice. The one bright line is absolute: personal information collected online from a child may not be retained indefinitely. When the data is no longer necessary you must delete it using reasonable measures to protect against unauthorized access or use during deletion.
Do parents have a right to delete their child's data under COPPA?
Yes. Section 312.6 lets a parent refuse to permit an operator's further use or future online collection of the child's personal information and direct the operator to delete what it holds. The parent can also review the information collected and get a description of the types or categories collected from children generally. You may terminate the service to the child if the deletion makes it impossible to continue providing it, subject to the limits in section 312.7, which bars you from conditioning participation on collecting more information than is reasonably necessary in the first place.
Can a school give consent instead of a parent under COPPA?
In limited circumstances, and on a narrower footing than most vendors assume. FTC guidance has long allowed a school to authorize collection on parents' behalf where the operator collects the information for the use and benefit of the school and for no other commercial purpose. The FTC proposed writing that exception into the Rule in 2024 but chose not to finalize it in the 2025 amendments, deferring to the Department of Education's expected FERPA rulemaking, so it remains guidance rather than regulation. If you use school-sourced student data for your own product development, advertising, or analytics, school authorization does not cover that use.
What is the difference between COPPA and FERPA?
They regulate different parties and different data. COPPA is an FTC rule that binds commercial operators collecting personal information online from children under 13, and it is built around parental consent, review, deletion, and now retention limits. FERPA binds educational agencies and institutions that receive Department of Education funding, covers education records regardless of the student's age, gives a 45-day inspect-and-review right with no extension, and creates no deletion right at all. An edtech vendor in a K-12 district can sit under both at once: FERPA reaches it contractually as a school official, while COPPA reaches it directly as an operator.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.