Skip to main content

Children’s Online Privacy Protection Act

The Children’s Online Privacy Protection Act (COPPA) helps give parents control over how personal information from children under 13 is collected and used online. For K–12 schools, understanding COPPA is an important part of evaluating websites, apps, and instructional technology—but it is only one piece of the larger student-privacy landscape.

COPPA at a Glance

COPPA applies to operators of commercial websites and online services directed to children under 13, as well as operators that have actual knowledge they are collecting personal information from a child under 13. The Federal Trade Commission enforces the COPPA Rule.

What COPPA requires

Parental notice and consent

Covered services generally must give parents clear notice and obtain verifiable parental consent before collecting, using, or disclosing a child’s personal information.

Clear privacy practices

Operators must explain what information they collect, how they use it, whether it is disclosed to others, and how parents can exercise their rights.

Parent access and control

Parents must be able to review their child’s personal information, revoke consent, and request that the information be deleted.

Security and limited retention

Covered operators must maintain reasonable safeguards and retain children’s personal information only as long as reasonably necessary for the purpose for which it was collected.

Data minimization

A service cannot require a child to disclose more personal information than is reasonably necessary to participate in an activity.

Additional advertising consent

The updated COPPA Rule requires separate parental consent for certain disclosures to third parties, including disclosures connected with targeted advertising.

What This Means for Schools

COPPA places its legal obligations primarily on covered website and online-service operators. Schools nevertheless play an important practical role when selecting and managing classroom technology. Before approving a service for younger students, districts should understand what information it collects, why it needs that information, which parties receive it, how it is secured, how long it is retained, and how deletion requests are handled.


COPPA is part of a larger privacy framework

No single federal law governs every type of student information. The law that applies depends on the organization, funding source, type of record, technology, and activity involved.

Family Educational Rights and Privacy Act (FERPA)

FERPA protects the privacy of education records maintained by schools and educational agencies that receive applicable U.S. Department of Education funds. It gives parents—and later eligible students—rights to inspect records, seek corrections, and control many disclosures of personally identifiable information, subject to specific exceptions.

Protection of Pupil Rights Amendment (PPRA)

PPRA addresses certain student surveys, analyses, evaluations, marketing activities, instructional materials, and physical examinations. Depending on the activity and funding involved, it may require parental notice, consent, or an opportunity to opt out.

Individuals with Disabilities Education Act (IDEA)

IDEA contains confidentiality protections for personally identifiable information collected, maintained, or used in providing services to children with disabilities. Its requirements operate alongside FERPA and include safeguards related to access, disclosure, retention, and destruction.

Children’s Internet Protection Act (CIPA)

CIPA is primarily an internet-safety law for schools and libraries receiving certain federal connectivity support. It requires internet-safety policies and technology protection measures addressing specified online content. It complements—but does not replace—student-privacy laws such as FERPA and COPPA.

Every Student Succeeds Act (ESSA)

ESSA includes confidentiality requirements for certain education data and reporting activities. Schools and agencies must consider these requirements together with FERPA and other applicable federal, state, and local rules.

Health Insurance Portability and Accountability Act (HIPAA)

HIPAA may apply to health information maintained by a covered healthcare provider, including some school-based health clinics. However, student health records that qualify as education records under FERPA are generally excluded from HIPAA’s Privacy Rule. The responsible entity and the type of record determine which law applies.

Remember state and local requirements

State student-privacy laws, district policies, contracts, records-retention rules, and security standards may impose additional or stronger requirements. Compliance should therefore be evaluated as a coordinated program rather than as a one-law checklist.

A practical review for educational technology

  • Identify every category of student information the service collects.
  • Confirm that each data element is necessary for an educational purpose.
  • Document whether information is disclosed to subprocessors or other third parties.
  • Review parental notice, consent, access, correction, and deletion procedures.
  • Examine security commitments, breach-notification terms, and retention schedules.
  • Prohibit behavioral advertising and unrelated commercial uses of student information.
  • Establish an offboarding process that includes account closure and verified data deletion.

This overview is provided for general educational purposes and is not legal advice. Organizations should consult qualified counsel when evaluating their specific obligations.