In December 2025, a federal court approved a $10 million penalty against Disney to settle FTC allegations that children’s data was collected from kid-directed YouTube videos without parental consent. COPPA enforcement is active and expensive.
COPPA is the US law that controls how online services collect personal information from children under 13. For K-12 schools and the edtech platforms they use, it sets clear obligations around notice, parental consent, data security, and deletion. This guide explains the meaning of COPPA in plain terms, clears up confusion with similar laws, and provides a practical COPPA Compliance Checklist for both schools and platforms.
COPPA Meaning and Who It Applies To
The meaning of COPPA is straightforward: COPPA stands for the Children’s Online Privacy Protection Act, a federal law enforced by the Federal Trade Commission. The COPPA law requires operators of websites and online services to notify parents and obtain verifiable parental consent before collecting personal information from children under 13.
The COPPA law applies to two kinds of operators: those whose services are directed to children under 13, and those with actual knowledge that they are collecting personal information from children under 13.
“Personal information” is broad. It covers names, contact details, photos, location, persistent identifiers, and, under the 2025 amendments, biometric and government-issued identifiers.
For education, the key point is that most edtech platforms used in K-12 fall under COPPA, because they collect data from students under 13. Schools are pulled in too, through the way consent works in a classroom setting.
COPPA vs CCPA vs FERPA
A common source of confusion is mixing COPPA up with other privacy laws. People often search for the full form of CCPA in educational contexts, expecting it to be a children’s law. It is not. The CCPA stands for the California Consumer Privacy Act, a state law about consumer data, not a federal children’s privacy rule. Here is how the three compare.
| Law | Full form | Protects | Applies to |
| COPPA | Children’s Online Privacy Protection Act | Children under 13 online | Operators of child-directed online services |
| CCPA | California Consumer Privacy Act | California residents’ personal data | Qualifying businesses handling that data |
| FERPA | Family Educational Rights and Privacy Act | Students’ education records | Schools that receive federal funds |
COPPA and FERPA overlap most in schools. FERPA, administered by the US Department of Education, governs the education record itself, while COPPA governs the online collection of a child’s data. So when the CCPA full form in education comes up in a search, it points to a California consumer law, not the federal children’s rule that schools actually need. A compliant institution must satisfy both COPPA and FERPA, which is why FERPA and COPPA compliance are handled together rather than as separate projects.
The COPPA Compliance Checklist
Obligations differ depending on whether you build the software or use it. The checklists below are split into the COPPA Compliance Checklist. Several items reflect the 2025 amendments to the COPPA Rule, which carry a compliance deadline of April 22, 2026.
For EdTech Platforms (Operators)

- Determine whether your service is directed to children under 13 or has actual knowledge it collects their data.
- Post a clear, complete privacy policy describing what you collect and why.
- Provide direct notice to parents before collecting a child’s personal information.
- Obtain verifiable parental consent, or valid school consent, before collection.
- Get separate consent before disclosing children’s data to third parties (2025 requirement).
- Collect only the data you need, and nothing more.
- Maintain a written information security program (2025 requirement).
- Keep a written data retention policy and delete data you no longer need (2025 requirement).
- Give parents a way to review and delete their child’s data.
- Sign a data processing agreement with each school client.
For K-12 Schools

- Inventory every edtech tool that collects student data.
- Confirm each vendor is COPPA-compliant and will sign a data processing agreement.
- Understand when the school may consent on parents’ behalf (the school-consent exception).
- Limit the use of vendor data to educational purposes only.
- Give parents notice of the tools in use and their data practices.
- Vet new tools before teachers adopt them in class.
- Keep records of consents and signed agreements.
- Re-check each vendor against the 2025 amendments before the compliance deadline.
How Schools and Platforms Share Responsibility

COPPA does not treat the school and the platform identically, and understanding the split is where most compliance failures are avoided.
Under the FTC’s school-consent exception, a school can provide consent on parents’ behalf for an edtech service, but only when the data is used for an educational purpose and nothing else. The school is acting as the parents’ agent. This is not a loophole that lets a vendor do as it pleases. The platform still has to honor parental rights, limit data use, and secure the data, and the school has to confirm the vendor actually does.
The document that ties the two together is the data processing agreement. A data processing agreement sets out what the vendor may collect, how it will be used, how long it will be retained, and how it will be deleted. Without one, a school has no enforceable record of what a vendor does with student data.
This is where the platform a school chooses matters. When the student information system that holds student data already provides the compliance artifacts, a children’s privacy policy, a direct notice to parents, and a signed DPA, the school’s compliance burden drops sharply.
Classe365 publishes these as standard, alongside its general privacy policy, so that a school does not have to assemble the paperwork from scratch. For institutions serving students across borders, documented international data transfer terms address how that data moves between countries.
What Counts as Verifiable Parental Consent
Verifiable parental consent is the heart of COPPA, and a checkbox claiming “I am over 18” does not meet it. The standard requires a method reasonably designed to confirm the person giving consent is actually the parent. Accepted methods include a signed consent form, a credit-card or payment-linked check, a phone or video call, or, under the 2025 amendments, a text message to the parent.
For schools using the school-consent exception, the practical work involves collecting that consent, recording it, and clearly communicating with families about which tools are in use. Handling this through the communication tools already connected to student records keeps consent, parental notice, and the student’s data in one place, rather than scattered across email threads and paper forms that are hard to produce if a regulator asks.
Common COPPA Mistakes
The same errors come up repeatedly, on both sides:
- Assuming COPPA does not apply because the users are “students” rather than “children.”
- Relying on a click-through checkbox that does not meet the verifiable-consent standard.
- Using an edtech tool with no data processing agreement in place.
- Overlooking the 2025 rule that requires separate consent for third-party disclosures.
- Collecting more student data than the educational purpose actually requires.
Build Compliance Into Your Platform Choice
The simplest way to reduce COPPA risk is to run on a system built for student data from the start. Book a Classe365 walkthrough to see how its privacy documentation, parental notices, and data agreements support your compliance work.
Frequently Asked Questions
What happens to a child’s data when they turn 13?
COPPA no longer applies to new data once a user turns 13, but information gathered while they were under 13 was collected under COPPA’s rules, and the parent’s rights still attach to it. Operators do not automatically delete that older data, so a school should ask vendors how they handle accounts as students age up.
Can a teacher download a free edtech app without creating a compliance problem?
Often not. A free tool still triggers COPPA if it collects data from students under 13, and the school-consent exception applies only when the tool has been vetted and used for an educational purpose. A teacher adopting an app on an ad hoc basis, with no review and no data processing agreement, is one of the most common ways schools end up out of compliance.
What happens if a parent refuses consent for a classroom tool?
If a parent declines, the operator cannot collect that child’s personal information, so the school needs an alternative that does not require it. This is why schools should confirm a non-data-collecting option exists before adopting a tool, rather than discovering the gap after a parent objects.
Does COPPA cover AI tools and chatbots used in classrooms?
Yes, if an AI feature collects personal information from students under 13, including text they type, their voice, or identifiers tied to them. The newer the feature, the more important it is to check, since AI tools often collect and process more data than the classroom activity appears to require.
Is de-identified or aggregated student data still covered by COPPA?
Properly de-identified data generally falls outside COPPA, but the de-identification standard is strict. Persistent identifiers, such as device IDs tied to a single student, still count as personal information, so “anonymized” data that can be linked back to a child remains covered.
How do COPPA and state student-privacy laws interact?
COPPA is the federal baseline. Several states, including California and Colorado, have student-privacy laws that impose stricter requirements, and schools must meet both the federal rule and any applicable state law. Where they differ, the stricter standard usually governs.
What should a school do if it discovers a vendor is not compliant?
Stop using the tool, document the issue, and check the data processing agreement for the vendor’s obligations and your termination rights. If student data may have been exposed or misused, the school should notify affected families and require the vendor to remediate or delete the data.
Does COPPA apply to schoolwork that students post publicly?
Yes. If a platform lets students under 13 publish personal information publicly, such as their full name or photo on shared project work, that disclosure is covered, and COPPA restricts making a child’s personal information public without verifiable parental consent.