What is Children's Privacy (COPPA)?
Children's privacy (COPPA) refers to the U.S. Children's Online Privacy Protection Act, which restricts how websites and online services collect, use and disclose personal information from children under 13. It requires parental notice, verifiable consent, and limits on data retention and sharing.
COPPA is a U.S. federal law designed to protect the privacy of children under 13 who use online services. If a website, app or online survey is directed to children or the operator has actual knowledge that it is collecting information from children under 13, COPPA requires the operator to: provide a clear privacy notice to parents, obtain verifiable parental consent before collecting personal information, allow parents to review and delete their child’s data, and keep collected data secure and limited to what is necessary. Personal information
is broadly defined and can include identifiable details like names, contact information, photos, persistent identifiers, and sometimes IP addresses. COPPA applies to operators in the U.S. and to services outside the U.S. that collect data from U.S. children. Similar rules (and different age thresholds) exist elsewhere, such as GDPR requirements for parental consent in the EU.
Usage example
A primary school wants to run an online wellbeing survey for pupils aged 10–11. Because the respondents are under 13, the school must either obtain verifiable parental consent before collecting any personal information or redesign the survey to collect only non‑identifying data and treat responses as anonymous. If the school collects names or contact details, COPPA procedures apply.
Practical application
For people creating surveys or forms, COPPA matters because it affects how you design, share and store any data collected from children under 13. Practical steps: avoid asking for personal identifiers when possible; include an age question and route under‑13 respondents through a parental consent flow; provide a clear, accessible privacy notice in the languages your communities use; use verifiable parental consent methods where required; limit retention and sharing of children’s data; and keep records of consents. For multilingual surveys, accurate translations of consent language are essential so parents understand what they are consenting to. When in doubt, treat responses from young children as protected and consult your organisation’s legal or privacy officer.
FAQ
Does COPPA apply if I only ask non-identifying questions (e.g., multiple-choice about preferences)?
Sometimes. If answers cannot be linked to a specific child (no names, contact details, photos, persistent identifiers) and are truly anonymised, COPPA may not apply. However, if the service could reasonably identify or track the child (for example by storing IP addresses or persistent IDs), COPPA protections may still be required. When unsure, design the survey to avoid collecting identifiers or seek legal guidance.
Can a school run a survey of students under 13 without getting parental consent?
Schools can sometimes act as an agent of the parent and obtain permission under specific legal frameworks, or rely on local education rules, but this varies by jurisdiction and circumstance. Many schools instead use parental notification and consent processes or limit surveys to anonymised data. Always check local policy and legal advice before proceeding.
How does COPPA relate to GDPR and other international laws?
COPPA is a U.S. law focused on children under 13. GDPR has related protections: it requires parental consent for processing the personal data of children below a member‑state’s age of digital consent (commonly 13–16). Organisations running multilingual or international surveys should consider both local and international rules and follow the strictest applicable requirements, including accurate translated privacy notices and consent flows.