Showing posts with label Children's Online Privacy Protection Act. Show all posts
Showing posts with label Children's Online Privacy Protection Act. Show all posts

Sunday, January 4, 2026

Looking Back at Privacy and Cybersecurity Law Changes in 2025 and Looking Ahead to 2026: Children’s Privacy

Looking Back at Privacy and Cybersecurity Law Changes in 2025 and Looking Ahead to 2026: Children’s Privacy

The privacy of children's data was in the spotlight in 2025 and will be in 2026 as well.  What for years was treated as a narrow compliance issue—often handled with a single sentence in a privacy policy—has evolved into a complex and fast-moving legal landscape that now spans federal requirements and an expanding patchwork of state laws.

As we look back at developments in 2025 and ahead to 2026, one thing is clear: organizations that collect data about anyone under 18 need to revisit their policies and practices.

Federal COPPA Changes 

The federal Children’s Online Privacy Protection Act (COPPA) has been in effect since 2000. For a quarter of a century, it has shaped how websites and apps think about children’s data, particularly information about kids under the age of 13. That history explains why so many privacy policies still include a familiar statement along the lines of: “Our website is not directed to children under 13, and we do not knowingly collect personal information from children under 13.”

In 2025, however, COPPA entered a new phase. The Federal Trade Commission amended the COPPA regulations, effective in June 2025. These amendments raise compliance expectations in several important ways. The most significant changes include:

  • New information security program requirements
    Organizations must implement and maintain a written information security program appropriate to the sensitivity of children’s personal information. Organizations must designate personnel to manage the program, assess internal and external risks to children's data, implement and maintain safeguards, regularly test the effectiveness of these safeguards, and review and revise the program at least annually. This could be either a separate children-only program or (preferably) a comprehensive program. This brings COPPA closer to modern data security regimes and raises the bar well beyond basic safeguards.

  • Expanded definitions of “personal information”
    The definition now includes (i) biometric identifiers that can be used for the automated or semi-automated recognition of an individual, such as fingerprints, handprints, retina patterns, iris patterns, genetic data, including DNA sequences, voiceprints, gait patterns, facial templates, or faceprints, and (ii) government-issued identifiers, such as social security numbers, state identification card numbers, birth certificate numbers, or passport numbers.

  • Notice and parental consent
    The Amendments require notice to parents that identifies the categories of third parties who will receive the child's personal information and the purposes for such sharing. The parental notice must explain that parents can consent to the collection and use of kid's data without agreeing to the disclosure to third parties (unless integral to the operation of the website or online service).
    It must also describe how they use persistent identifiers, and (iii) disclosures about the use of audio files.

  • Perhaps the most impactful change: operators must obtain separate, verifiable parental consent before sharing children’s personal information with third parties, even if parental consent was already obtained for collection and internal use. The amendments also expand the acceptable methods for obtaining verifiable parental consent. Operators are now allowed to use the following methods (among others to be approved by the FTC): (i) knowledge-based authentication through multiple-choice questions, (ii) government-issued photo ID, or (iii) text messaging coupled with additional steps, such as a follow-up text, letter, or phone call.

Data Retention

The new regulations only allow organizations to retain children’s information for as long as reasonably necessary to fulfill the specific purposes for which it was collected.

Taken together, these changes mean that COPPA compliance is no longer just about age gates and privacy policy disclosures. It now directly implicates vendor management, advertising technologies, analytics tools, and security governance.

Why Just Claiming “We Don’t Collect Data from Children Under 13” May No Longer Be Enough

Historically, many organizations may have assumed that a disclaimer was all it took to avoid COPPA. That approach is increasingly risky.

First, the FTC has long taken the position that “actual knowledge” of children’s use—not just intent to target them—can trigger COPPA obligations. The new amendments add that the FTC may consider marketing or promotional materials, statements to consumers or third parties, reviews by users or third parties, and the age of users on similar websites or services.

Second, state laws are now expanding protections well beyond age 13, often up to age 18. As a result, organizations must think more carefully about who is actually using their products, not just who they are intended to serve.

State Laws: Expanding Protection for Minors

In parallel with the updated COPPA Rule, states have been actively passing laws that address minors’ privacy. Unlike COPPA, these laws do not all use the same age threshold, which significantly complicates compliance.

Some states focus on children under 13, while others extend protections to all minors under 18, and still others draw a line somewhere between. 

A Closer Look at Maryland

Maryland’s law, described earlier in this series as the most important new privacy law of the year, is a good example of how nuanced these statutes can be. Effective in late 2025, Maryland’s Online Data Privacy Act goes further than other states by prohibiting organizations from selling personal data or engaging in targeted advertising if they know or should have known a consumer is under 18. Maryland defines targeted advertising as advertising directed to a person or a device using a unique identifier. This might create a practical challenge if an organization knows or should know that a minor is using the device.

New State Laws Protecting Minors

Recent and upcoming state laws with new protections for minors include the following:

  • Arkansas HB 1717 (effective 7/1/2026) – protects children under 18

  • Colorado SB 24-041 (effective 10/1/2025) – under 18

  • Delaware HB 154 (effective 1/1/2025) – under 18

  • Maryland SB 541 (effective 10/1/2025) – under 18 (data sales and targeted advertising)

  • Montana SB 297 (effective 10/1/2025) – under 18

  • New Hampshire RSA 507-H (effective 1/1/2025) – under 13

  • Nebraska LB 504 (Age-Appropriate Design Code Act) (effective 1/1/2026) – under 13

  • Vermont SB 69 (Age-Appropriate Design Code Act) (effective 1/1/2027) – under 18

Notably, the Age-Appropriate Design Code Acts (AADCs) are not traditional privacy laws, but they operate much like them. They impose affirmative design requirements on websites and apps likely to be accessed by children or teens, including data minimization, high-privacy default settings, and restrictions on certain design features.

Practical Pointers: What Organizations Should Be Doing Now

For organizations operating websites or mobile apps, it’s time for a comprehensive review.

Key steps include:

  1. Revisit terms of use and privacy policies
    Many companies still rely on outdated COPPA-only language stating that their services are intended for users 13 and older. If the organization does not intend to target teens, that language may need to be clarified or tightened. If it does intend to target teens, the policy should reflect that reality and address applicable state laws.

  2. Align internal data and privacy processes with public disclosures
    External statements should match internal practices, particularly around data sharing, advertising, analytics, and security safeguards.

  3. Assess age thresholds and compliance strategy
    Decide deliberately which age groups the organization intends to serve, what age thresholds it will use, and how it will comply with the relevant federal and state requirements.

  4. Evaluate security and vendor practices
    The updated COPPA security requirements and state law obligations make information security programs and third-party risk management more important than ever.

Looking Ahead

Children’s privacy law is no longer a narrow niche. Between the amended COPPA Rule, expanding state protections for minors, and the rise of age-appropriate design requirements, 2025 and 2026 mark a turning point. Organizations need to re-evaluate their approach in light of the changing legal landscape in order to best manage legal risk in the future.


image showing the silhouette of two children holding devices with images in the background indicating technology

Saturday, March 15, 2014

How Financial Institutions Can Manage Social Media Risks

image by Matt Cordell using Creative Commons content BY-SA 3.0
Bankers, does your bank use social media? Do employees use social media on behalf of the bank? Do you know what examiners will be looking for in a social media risk assessment and a social media risk management program?

The Federal Financial Institutions Examination Council (FFIEC) has published guidance recently that will be used by the Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System (Board), the National Credit Union Administration (NCUA), and the Consumer Financial Protection Bureau (CFPB) to evaluate financial institutions' compliance with various privacy and other laws and regulations.

What kinds of social media are covered?

The guidance defines "social media" as any form of interactive online communication in which users can generate and share content through text, images, audio, and/or video. Examples include micro-blogging sites (e.g., Facebook, Google Plus, MySpace, and Twitter), forums, blogs (e.g., BizLawNC.com or PrivacyLawNC.com), customer review web sites and bulletin boards (e.g., Yelp), photo and video sites (e.g., Flickr and YouTube), sites that enable professional networking (e.g., LinkedIn), virtual worlds (e.g., Second Life), and social games (e.g., Farmville). These platforms have a wide spectrum of uses, and their user profiles vary.

Financial institutions most often use social media for marketing directly to customers, but it can also be used to provide incentives, collect feedback from the public, recruit employees, and to otherwise engage with prospects and customers. Each of these efforts carries with it particular goals and varying types and degrees of risk.

The FFIEC Guidance states that every financial institution must conduct a risk assessment that addresses the risks raised by its use of social media and maintain a risk management program that is tailored to the risk profile. Every institution using social media should identify, measure, monitor,and control the risks related to social media.

How detailed should the policy statement be? How comprehensive should the procedures be?

The size and complexity of the program should be commensurate with the degree of the institution's involvement in social media, both in terms of depth and breadth. For example, a financial institution that relies heavily on one medium (e.g. Facebook) should have a more focused program. An institution using several media (e.g., Facebook, LinkedIn, Twitter, Yelp, Google +, and YouTube) should have procedures that are more comprehensive.

Who should be involved?

The FFIEC advises that a social media risk management program should be designed with participation from specialists in compliance, technology, information security, legal, human resources, and marketing. A better suggestion, in my opinion, is the inclusion of individuals whose expertise spans more than one of these categories. (Can you think of anyone who might know about more than one of these areas?)

What are the elements of a social media risk management program?

  • A governance structure with clear roles and responsibilities;
  • Policies and procedures (either stand-alone or incorporated into other policies and procedures) regarding the use and monitoring of social media and compliance with all applicable consumer protection laws and regulations;
  • A process for selecting and managing third-party relationships;
  • An employee training program;
  • An oversight process;
  • Audits to ensure ongoing compliance; and
  • Reporting to the board of directors or senior management to enable periodic evaluation of the program.

What are the key areas of risk?


What if we don't use social media at our bank?

Even financial institutions that do not use social media should perform a risk assessment, say the regulators: "a financial institution that has chosen not to use social media should still consider the potential for negative comments or complaints that may arise within the many social media platforms described above, and,when appropriate, evaluate what, if any, action it will take to monitor for such comments and/or respond to them." I have already written about online reputation management at length, and rather than repeat my advice here, I will refer you my earlier post on the subject.

Furthermore, just because an institution does not have an official social media account does not mean individual employees (especially those with business development responsibilities) are not posting on LinkedIn, Facebook, Twitter, and other platforms about, and apparently on behalf of, the the institution. It is unusual these days to find anyone in a sales role who is not active on social media.

Conclusion

The FFIEC Guidance is intended to help financial institutions understand and successfully manage (not eliminate) the risks associated with use of social media. The regulators expect institutions to manage potential risks to themselves and and their customers by identifying areas of risk proactively and adopting and implementing programs to mitigate those risks effectively...and more importantly, so do an increasing number of customers.




Wednesday, February 19, 2014

What You Need to Know about the Children's Online Privacy Protection Act (COPPA)

Online privacy and information security are areas of ever-increasing concern for the Federal Trade Commission, state and federal prosecutors, plaintiff's lawyers, and consumer advocates.  There are now a smattering of laws and regulations that operators of websites, applications, and advertisers must comply with relating to these issues.  Anyone who (a) operates a website designed for kids or (b) operates a website geared to a general audience but who is aware that it is collecting information from someone under 13 should understand and comply with the Children's Online Privacy Protection Act, the FTC's rules, and the FTC's guidance.  

The Children's Online Privacy Protection Act (COPPA) became law almost 15 years ago, but in 2013, the Federal Trade Commission's revisions to the COPPA Rule, which were intended to modernize the Rule, became effective. 

image credit: Mike Licht

What Is the Children's Online Privacy Protection Act Rule?
 
The COPPA Rule requires operators of websites or online services directed to children under 13 years of age (and operators of other websites or online services that have actual knowledge that they are collecting personal information online from a child under 13 years of age, even if not by design) to provide notice to parents and obtain verifiable parental consent prior to collecting, using, or disclosing personal information from children under 13 years of age. The Rule also requires operators to keep secure the information they collect from children, and prohibits them from requiring the disclosure of more personal information than is reasonably necessary.
What Revisions Took Effect in 2013?
The lengthy 2013 revisions were designed to achieve the following:
  • Modify the definition of "operator" to make clear that the Rule covers an operator of a child-directed site or service where it integrates outside services, such as plugins or advertising networks, that collect personal information from its visitors;
  • Modify the definition of "Web site or online service directed to children" to clarify that the Rule covers a plug-in or ad network when it has actual knowledge that it is collecting personal information through a child-directed Web site or online service;
  • Modify the definition of "Web site or online service directed to children" to allow a subset of child-directed sites and services to differentiate among users, and requiring notice and parental consent only for users who self-identify as under age 13;
  • Modify the definition of "personal information" to include geolocation information and persistent identifiers that can be used to recognize a user over time and across different Web sites or online services;
  • Modify the definition of "support for internal operations" to expand the list of defined activities;
  • Streamline and clarify the direct parental notice requirements to ensure that key information is presented to parents in a succinct ‘‘just-in-time’’ notice;
  • Expand the non-exhaustive list of acceptable methods for obtaining prior verifiable parental consent;
  • Create three new exceptions to the Rule’s notice and consent requirements;
  • Strengthen data security protections by requiring operators to take reasonable steps to release children’s personal information only to third parties who are capable of maintaining the confidentiality, security, and integrity of the information;
  • Require reasonable data retention and deletion procedures;
  • Strengthen the FTC’s oversight of self-regulatory "safe harbor" programs; and
  • Institute voluntary pre-approval mechanisms for new consent methods and for activities that support the internal operations of a Web site or online service.
You can read more about the 2013 Rule changes here, here, and here.