COPPA—the Children's Online Privacy Protection Act—supposedly protects children's privacy online. But most parents don't understand what it actually does, what it doesn't do, and why it's insufficient for protecting your toddler.
This guide explains COPPA in plain language, reveals its limitations, and shows you how to actually protect your child beyond legal minimums.
Little Wheels apps go beyond COPPA compliance—we collect zero data, work completely offline, and never show ads or track behavior.
What Is COPPA?
COPPA is a federal law enacted in 1998 (updated in 2013) that regulates how websites and online services can collect personal information from children under 13.
Core COPPA Requirements
Apps and websites directed at children under 13 must:
- Provide clear privacy policies: Explain what data is collected, how it's used, and who it's shared with
- Obtain verifiable parental consent: Before collecting, using, or disclosing personal information from children
- Allow parents to review information: Parents can see what data has been collected about their child
- Give parents deletion rights: Parents can request deletion of their child's information
- Implement reasonable security: Protect the confidentiality and security of children's information
- Limit data collection: Only collect information reasonably necessary for the activity
What Triggers COPPA?
An app must comply with COPPA if it's:
- Directed at children under 13: Content, design, marketing clearly target kids
- General audience with actual knowledge: Knows it's collecting data from children even if not specifically targeting them
Toddler apps clearly fall under COPPA—they're explicitly directed at young children.
What COPPA Requires for Data Collection
Understanding COPPA's specific requirements helps you evaluate apps.
Verifiable Parental Consent
Before collecting personal information, apps must obtain consent through methods that reasonably ensure the person providing consent is the child's parent:
Acceptable methods include:
- Signed consent form (email, fax, or physical mail)
- Credit card or payment verification
- Video conference with staff
- Photo ID verification
- Knowledge-based authentication (answering questions only parents would know)
What this means: Apps can't just collect data and assume parents consent. They must actively verify parental permission.
Personal Information Covered
COPPA protects a broad range of information:
- Full name
- Email address
- Phone number
- Physical address
- Social Security number
- Persistent identifiers (cookies, IP addresses, device IDs used for tracking)
- Photos, videos, audio files
- Geolocation information
- Any information combined with the above identifiers
Essentially: anything that identifies a specific child or allows tracking across services.
Required Privacy Policy Disclosures
Apps must clearly disclose:
- Contact information for the operator
- Types of personal information collected
- How information is used
- Whether information is disclosed to third parties
- Parental rights (review, deletion, refusing further collection)
- Practices regarding tracking technologies
COPPA's Limitations: What It Doesn't Protect
COPPA provides baseline protections but has significant gaps.
Limitation 1: Enforcement Is Reactive and Slow
The FTC enforces COPPA, but:
- Limited resources: Can't monitor every app constantly
- Complaints drive enforcement: Violations continue until enough complaints trigger investigation
- Years to resolve: Companies violate COPPA for years before facing consequences
- Fines often less than profits: Companies calculate violations are worth the risk
YouTube violated COPPA for years, collecting children's data and serving targeted ads, before the 2019 settlement. By then, they'd profited substantially from the violations.
Limitation 2: Only Covers Children Under 13
COPPA protects children under 13. Your toddler is covered, but:
- Different privacy standards apply to teenagers
- Apps can argue mixed-age audience to avoid strictest COPPA requirements
- General-audience apps have fewer restrictions even when children use them
Limitation 3: "Verifiable" Consent Has Loopholes
Some COPPA-compliant consent mechanisms are weak:
- Email plus confirmation: Email parent, parent clicks link to confirm. But companies can't actually verify that email belongs to the parent.
- Knowledge-based authentication: Questions only parents should know answers to. But information might be discoverable by children or others.
These meet COPPA's letter while potentially failing its spirit.
Limitation 4: Doesn't Prevent Collection—Just Regulates It
COPPA doesn't say "don't collect children's data." It says "follow these rules when collecting it."
Apps can legally collect extensive data from children if they:
- Get parental consent
- Disclose practices clearly
- Implement security measures
- Allow parental control
Compliance doesn't mean minimal data collection—just documented, consented collection.
Limitation 5: Self-Certification
Apps essentially certify their own compliance. There's no pre-approval process. Apps implement COPPA requirements, claim compliance, and operate until enforcement action occurs—if it ever does.
How Apps Violate COPPA
Despite legal requirements, violations are common.
Common Violation Patterns
Collecting data without consent: Apps collect identifiers or behavior data without obtaining parental permission first.
Inadequate age screening: Apps don't properly verify users' ages, allowing children to use services meant for older users without COPPA protections.
Sharing data with third parties: Passing children's information to advertisers or analytics companies without proper disclosure and consent.
Using persistent identifiers for tracking: Collecting device IDs, cookies, or other identifiers that track children across apps and websites.
Misleading privacy policies: Claiming not to collect data while actually doing so, or burying critical information in lengthy policies.
Why Violations Happen
Companies violate COPPA because:
- Data is valuable: Children's behavior patterns inform product development and advertising
- Detection is unlikely: Most violations never get caught
- Fines are manageable: Even large settlements (YouTube's $170 million) are often less than profits from years of violations
- Competitive pressure: Competitors collecting data have advantages; compliant companies face pressure to do the same
The economic incentive favors violation when enforcement is weak.
Documented COPPA Violations in Kids' Apps
Major cases show COPPA's limitations in protecting children.
YouTube ($170 million, 2019)
The FTC found YouTube:
- Collected persistent identifiers from viewers of children's content
- Used that data for targeted advertising
- Did this for years despite clear COPPA requirements
- Made hundreds of millions in advertising revenue from the violations
Settlement required changes but came only after years of violations and massive profit.
TikTok/Musical.ly ($5.7 million, 2019)
Musical.ly (acquired by TikTok):
- Collected names, email addresses, and other information from users under 13
- Did so without parental consent
- Continued after receiving complaints about children on the platform
Violations occurred for years before enforcement action.
Pattern Across Cases
Notice the pattern:
- Company violates COPPA
- Violations continue for years
- Company profits substantially
- Eventually faces FTC action
- Pays fine less than profits gained
- Makes required changes going forward
COPPA enforcement is reactive—protecting children only after harm has occurred.
How to Actually Protect Your Child
Don't rely on COPPA alone. Take active protection steps.
Choose Apps That Don't Collect Data
The best protection: apps that architecturally cannot violate COPPA because they collect nothing.
- No internet connection = no data transmission
- Can't track across apps or websites
- Can't share data with third parties
- Can't violate COPPA because they collect nothing to violate with
Little Wheels apps work completely offline. Not "mostly offline with some data collection"—entirely offline. No data leaves your device.
Read Privacy Policies—Actually Read Them
Yes, they're long. But for apps your toddler uses, read them. Look for:
Red flags:
- "We collect device identifiers for analytics"
- "We share data with partners"
- "We use cookies for advertising"
- Vague language about "improving the experience"
- Long lists of collected information types
Green flags:
- "We do not collect any personal information"
- "This app works offline"
- "No data is transmitted or stored"
- Very short policies (nothing to collect = little to disclose)
Classroom App Privacy Checklist
If you're a preschool teacher or daycare director choosing apps for shared tablets, you can use a simple checklist to spot safer options in a few minutes—even without a legal background.
- No child logins: The app does not require each child to create an account, enter their name, or sign in with email or student IDs. One adult account (or no account at all) is usually enough for classroom devices.
- Minimal permissions: The app only requests camera, microphone, or location access when it clearly needs them for a feature you plan to use. For most toddler learning apps, microphone and location are rarely necessary.
- No ads or ad trackers: The privacy policy and store listing explicitly state there are no ads and no advertising networks. If you see "ad partners," "ad SDKs," or "interest-based advertising," skip it for classroom use.
- Short, specific data section: The privacy policy has a brief, concrete statement like "We do not collect personal information" rather than long, vague language about "improving the experience" and "sharing with trusted partners."
- Works in airplane mode: When you turn Wi‑Fi off, the app still works normally. This usually means it is not constantly phoning home or dependent on servers that collect usage data.
- Clear contact information: The developer lists a real email address or website where you can ask privacy questions or request more details for your school.
- Easy to explain to families: You can summarize the app's privacy approach to parents in one or two sentences (for example, "This app works offline and does not collect personal data").
Prefer Indie Developers
Indie developers typically have better privacy practices:
- No investor pressure to monetize data
- Often don't have infrastructure to collect data even if they wanted to
- Personal reputation matters—can't afford violations
- Many are parents themselves, building apps they'd want
Corporate apps have teams dedicated to data collection and monetization. Indie apps often collect nothing because it's simpler and aligns with their values.
Check Developer Reputation
Research developers before trusting them with your child's app usage:
- Have they had COPPA violations?
- Do they have clear privacy values stated?
- Are they responsive to privacy concerns in reviews?
- Do other parents trust them?
Use Device-Level Protections
Enable privacy settings on devices:
iPhone/iPad:
- Settings > Privacy & Security > Tracking > Turn off "Allow Apps to Request to Track"
- Settings > Privacy & Security > Location Services > Disable for unnecessary apps
Android:
- Settings > Google > Ads > Opt out of Ads Personalization
- Settings > Location > App permissions > Review and restrict
These reduce tracking but don't eliminate data collection within apps.
What COPPA-Compliant Actually Means
Understanding compliance helps you evaluate app claims.
Compliance ≠ No Data Collection
Apps can be COPPA-compliant while extensively collecting data. Compliance means they:
- Disclose collection practices
- Obtain parental consent
- Provide parental controls
But they still collect and use the data. Compliance is about process, not minimization.
Compliance ≠ Safety
COPPA addresses privacy and data collection. It doesn't address:
- Content appropriateness
- Advertising manipulation
- Screen time concerns
- Educational value
- Addictive design
An app can be COPPA-compliant while using manipulative design, showing inappropriate ads (to parents, with child present), or providing no educational value.
What to Look for Beyond Compliance
The best apps go beyond legal minimums:
- Privacy by design: Built from the start not to collect data
- Offline functionality: No data transmission capability
- No ads ever: Funded through fair pricing, not advertising
- Transparent values: Developers clearly state privacy commitments
- Simple, honest policies: "We don't collect data" beats pages of compliance language
The Future of Children's Privacy
COPPA is over 20 years old. The digital landscape has changed dramatically.
Proposed Reforms
Advocates push for stronger protections:
- Raising age of protection from 13 to 16
- Prohibiting targeted advertising to children entirely
- Requiring default privacy-protective settings
- Stronger enforcement with larger penalties
- Mandatory privacy-by-design requirements
These reforms face industry opposition. Don't count on legal protections improving soon.
What Parents Can Do Now
While waiting for better laws:
- Choose apps with strong privacy practices today
- Support developers building ethical products
- Spread awareness about privacy issues
- Report COPPA violations to FTC
- Advocate for stronger protections
The Bottom Line on COPPA
COPPA provides baseline legal protections for children's privacy online. But it has significant limitations:
- Enforcement is reactive and slow
- Violations are common and often unpunished
- Compliance doesn't mean minimal data collection
- Fines are often less than profits from violations
Real protection comes from choosing apps that don't collect data in the first place:
- Offline apps that can't transmit information
- Indie developers without data monetization infrastructure
- Privacy-by-design architecture, not compliance checklists
- Developers whose values align with protecting children
COPPA is better than nothing. But it's insufficient. Don't rely on legal minimums to protect your toddler's privacy.
Choose apps built to collect nothing. Apps like Little Wheels that work offline and never transmit data. Apps from developers who view privacy protection as core values, not legal obligations.
Your child's privacy deserves better than legal minimums. Choose apps that deliver it.
You Might Also Like
Indie Toddler Apps: Why Small Developers Win
Discover why indie developers build better toddler apps than corporations—fair pricing, privacy respect, and apps built by parents for toddlers ages 2–6.
Why Choose Indie Apps: 7 Reasons Parents Love Them
Indie apps beat corporate subscription apps on what matters to families—fair pricing, real privacy, and respect over manipulation for toddlers ages 2–6.
Designing Apps for Kids in 2026: Ethics, Accessibility & Wellbeing
Evidence-based principles for designing children's apps in 2026: why 180pt tap targets matter, testing breathing exercises, and prioritizing wellbeing over metrics.
