EXPLOREINDUSTRIESGUIDESLEARNGLOSSARYBOOKSWHITEPAPERTOOLSRESOURCESPIONEERMARKETSCOUNTRIESFEESMISSION FUNDPASSPORT
SUPPORTLOGINJOIN THE PROTOCOL →
GETREADYANDJUMP.COM · BUILT IN DETROIT

COPPA
ON PROTOCOL.

Coppa on the GRAJ protocol. One fee. 195 countries. Join the protocol.

JOIN THE PROTOCOL →
Compliance

SELLING TO,
AND AROUND, CHILDREN.

Reference

COPPA governs the collection of personal information from children under thirteen online, and it is enforced against operators who did not think of themselves as child-directed. Whether it applies is decided by the audience your service actually attracts as much as by the one you intended.

Child-directed is judged on the whole picture

Subject matter, visual content, characters, music, the age of models and advertising placement are all weighed. A site that never asks an age can still be child-directed, and a general-audience service becomes covered for the users it knows are children.

Verifiable parental consent

Where it applies, consent must be obtained from a parent before collection and it must be verifiable — a checkbox is not. The specific acceptable methods are enumerated and are deliberately more effortful than a click.

Collect nothing you do not need

The most reliable compliance position is having no covered data. Persistent identifiers, photographs, voice recordings and location all count as personal information under the rule.

It reaches the supply chain

A brand selling children's products is subject to product safety rules as well: age grading, small-parts testing, tracking labels and third-party testing by accredited laboratories. Those are enforced at import.

Where to go next
/guides/data-privacy/compliance/certifications/privacy
JOIN THE PROTOCOL