Coppa on the GRAJ protocol. One fee. 195 countries. Join the protocol.
COPPA governs the collection of personal information from children under thirteen online, and it is enforced against operators who did not think of themselves as child-directed. Whether it applies is decided by the audience your service actually attracts as much as by the one you intended.
Subject matter, visual content, characters, music, the age of models and advertising placement are all weighed. A site that never asks an age can still be child-directed, and a general-audience service becomes covered for the users it knows are children.
Where it applies, consent must be obtained from a parent before collection and it must be verifiable — a checkbox is not. The specific acceptable methods are enumerated and are deliberately more effortful than a click.
The most reliable compliance position is having no covered data. Persistent identifiers, photographs, voice recordings and location all count as personal information under the rule.
A brand selling children's products is subject to product safety rules as well: age grading, small-parts testing, tracking labels and third-party testing by accredited laboratories. Those are enforced at import.