On April 22, 2026, the FTC’s revised Children’s Online Privacy Protection Rule took effect. The amendments — years in the making — represent the most significant update to children’s digital privacy law since the original COPPA rule was enacted in 1998.
For parents, educators, and anyone running an app used by children under 13, the changes matter in ways that aren’t yet widely understood. The gap between what the new rules require and what many popular children’s apps actually do is wider than the headlines suggest.
What COPPA Covers — and What It Doesn’t
COPPA applies to commercial websites, mobile apps, and internet-connected devices that either are directed at children under 13, or knowingly collect personal information from children under 13. If an app knows its audience includes children — or reasonably should know — it falls under COPPA’s requirements.
The original 1998 rule and subsequent 2013 amendments established a framework: get verifiable parental consent before collecting data from children, post a clear privacy policy, give parents access to their children’s data, and let parents delete it.
The 2026 amendments didn’t discard that framework. They significantly expanded what it covers and tightened the rules around how data can be used once collected.
What Changed in April 2026
Biometric Data Is Now Personal Information
The previous COPPA definition of “personal information” included obvious identifiers — name, address, phone number, email address, photos, and certain online identifiers. The 2026 amendments added biometric identifiers to that list.
This means a children’s app that uses facial recognition for personalization, emotion detection for adaptive learning, or voice biometrics for identification now needs explicit verifiable parental consent before collecting that data. Many apps had been collecting biometric data under the argument that it wasn’t covered by the original definition. That argument no longer holds.
Separate Consent for Third-Party Data Sharing
Under the old framework, a single consent for data collection was treated as covering most downstream uses. The 2026 amendments require separate, specific verifiable parental consent before disclosing a child’s data to third parties for targeted advertising.
This is a significant change. Many children’s apps — particularly free educational apps — have business models that depend on behavioral advertising. The new rule doesn’t ban that model, but it requires explicit, specific consent for the advertising data sharing, separate from the general consent to use the app.
In practice, most apps that relied on implied consent for advertising data sharing have been forced to either obtain specific consent, change their business model, or stop serving users under 13.
Stricter Data Retention and Deletion Requirements
The amendments added explicit requirements around how long child data can be retained. Apps must now retain children’s personal information only as long as is reasonably necessary to fulfill the purpose for which it was collected.
Vague retention policies — “we keep data as long as your account is active” — are no longer compliant for children’s data. Apps must define the purpose of retention, set a retention period based on that purpose, and delete the data when the purpose has been fulfilled.
Parents must also be able to delete their child’s data on request, with confirmation that deletion occurred. The confirmation requirement was absent from the previous rule.
Age Verification Tightened
The amendments increased expectations for how operators must verify parental consent — the “verifiable” standard. Methods that were arguably compliant under the old rules (a simple checkbox confirming parental status, for example) have been explicitly identified as insufficient.
Acceptable verification methods now include: providing a credit or debit card (with a charge to verify), a government-issued ID check, a signed consent form, calling a toll-free number staffed by trained personnel, or a knowledge-based authentication quiz. Operators must use one of these methods, not a self-assertion.
Which Categories of Apps Are Most Affected
The rule applies across all digital products reaching children under 13, but the practical impact is sharpest in certain categories.
Educational and Learning Apps
Free educational apps — the kind downloaded by millions of families because they cost nothing — typically fund themselves through behavioral advertising. Khan Academy Kids, ABCmouse, Duolingo for schools, and similar platforms all have to navigate the tension between their business models and the new consent requirements.
The nonprofit apps in this space (Khan Academy, Starfall) face less conflict, since they don’t depend on advertising revenue. The commercial apps face genuine business model questions under the new requirements.
Gaming Apps for Children
Children’s games that offer in-app purchases, show ads, or collect behavioral data for recommendation systems are affected. The gaming category has historically been one of the most aggressive in behavioral data collection from children, and enforcement actions in the space have produced some of the largest COPPA settlements on record.
Apps with Photo and Voice Features
Any children’s app that includes a camera or voice feature — whether for education, play, or communication — now faces the expanded definition of personal information covering biometric data. An app that takes a photo of a child’s artwork and uses computer vision to provide feedback is now potentially collecting biometric data that requires specific consent.
School-Deployed Apps
Apps deployed by schools occupy a legally complex space. The school can act as an agent of parental consent under certain conditions — but those conditions are more strictly defined under the new rules. Schools that have deployed educational apps without updated COPPA compliance agreements may be in a problematic position.
The Enforcement Reality
The FTC has been clear that it intends to enforce the new requirements. Since the 2025 amendments were finalized and before the April 2026 compliance deadline, several major cases signaled the direction:
Enforcement actions against companies violating COPPA have averaged $50,000 to $500,000 per violation in recent years, with the largest cases exceeding $5 million in settlements. The FTC can also seek injunctive relief that requires operational changes, not just monetary penalties.
The highest-profile recent action was against YouTube in 2019, when Google paid $170 million to settle COPPA allegations. The scale of that settlement reflected both the severity of the violations and the size of the audience involved. More recent enforcement has continued in this direction.
The FTC has also signaled that it will pursue individuals at companies — not just the companies themselves — when violations are serious and deliberate.
What Parents Should Actually Check
The new rules don’t automate compliance. Apps are self-certifying, and enforcement is complaint-driven and resource-limited. A compliant-sounding privacy policy doesn’t guarantee compliant practices.
Here’s what parents can actually verify:
Read the Privacy Policy — Specifically the COPPA Section
Most apps serving children include a COPPA-specific section in their privacy policy. Read it. Look for:
- Whether the app identifies which data it collects from children (personal information, including biometric data under the new definition)
- Whether it describes how parental consent is obtained and verified
- What it says about data sharing with advertising partners
- How long it retains children’s data
- How parents can request access to or deletion of their child’s data
Vague or generic language in any of these areas is a warning sign.
Check Whether the App Is Ad-Supported
A free app with advertising is, by definition, collecting and sharing behavioral data to fund those ads. Under the new rules, that requires specific parental consent for the advertising component — separate from the general terms of use.
If you agreed to a single set of terms when setting up an account for your child, and the app runs ads, check whether a separate consent for advertising data sharing was collected. If it wasn’t, the app may not be compliant.
Look for Data Access and Deletion Mechanisms
Compliant apps must offer parents a mechanism to access their child’s data and to request its deletion. This mechanism should be clearly described in the privacy policy and actually functional. Test it. If you submit a data deletion request and receive no response or confirmation, that’s a red flag.
Check School-Deployed Apps Separately
If your child’s school uses apps for learning — reading apps, math platforms, communication tools — those apps have their own COPPA compliance obligations. Schools should have data processing agreements with the companies whose apps they deploy. Parents can ask the school to share those agreements and review them.
The Gap Between Law and Practice
COPPA has been law since 1998, and violations have been widespread throughout that time. The 2026 amendments add important protections — particularly around biometric data and advertising consent. But the history of COPPA enforcement suggests that the gap between what the law requires and what apps actually do will remain significant.
The FTC’s enforcement capacity is limited relative to the number of apps serving children. The agency responds to complaints and conducts targeted investigations — it doesn’t continuously audit the entire market. Apps that don’t attract regulatory attention can maintain non-compliant practices for years.
This means the responsibility for verification falls significantly on parents, schools, and institutions that deploy apps for children. The new rules give those stakeholders clearer legal standards to hold companies to. They don’t create automatic enforcement.
For App Developers: What the New Rules Require
If you build or deploy apps used by children, the April 2026 compliance requirements include:
- Updated privacy policy language reflecting the expanded definition of personal information (including biometric data)
- Separate consent mechanisms for advertising data sharing, distinct from general consent
- Defined and documented data retention periods for each category of children’s data
- Functional mechanisms for parents to access, review, and delete their child’s data — with confirmation of deletion
- Verifiable parental consent methods that meet the FTC’s updated standards (no more self-attestation)
Non-compliance is no longer a matter of regulatory ambiguity. The rule is clear, the deadline has passed, and the FTC has signaled active enforcement intention.
Storing Children’s School Records and Learning Files Privately
One category of data that often gets overlooked: the files, reports, screenshots, and assessments parents save about their children’s educational progress. Grade reports, drawings from learning apps, IEP documents, therapy notes — these often end up in general-purpose cloud storage where they sit alongside adult content and are subject to whatever indexing, AI analysis, and advertising the platform runs.
daftei stores personal files without running an advertising business, without training AI on stored content, and without the behavioral tracking that characterizes advertising-funded platforms. Files are encrypted in transit with TLS 1.3 and at rest with AES-256. For parents who want a private place to store their children’s sensitive educational records separate from platforms that depend on behavioral data monetization, that’s a meaningfully different option.
The Bottom Line
The April 2026 COPPA amendments are the most significant children’s privacy update in more than a decade. They close real gaps — particularly around biometric data and advertising consent — that the original rule left open.
They also require active verification from parents and institutions, not passive trust in self-certification. The apps that matter most to your children deserve the same scrutiny you’d apply to any other service holding sensitive personal data. The new rules give you clearer standards to hold those apps to. Using them is the work that remains.