GDPR, COPPA, and KOSA: Children's Privacy Laws US Families Need to Know
Table of Contents

GDPR, COPPA, and KOSA: Children's Privacy Laws US Families Need to Know

Plain-English guide to COPPA, KOSA, and GDPR as they affect US children. Learn what rights these laws give parents and how to file complaints when companies violate them.

When your child’s favorite app was caught selling their location data to advertisers, what law was supposed to protect them? When the game your ten-year-old plays asked for a birthday date and email address, what rules did the company have to follow? When a UK-based social platform your US teenager uses violated their privacy, which legal framework applied?

The answer is different in each case — and that’s the problem. Children’s privacy online is governed by multiple overlapping laws that each cover different platforms, different ages, different data types, and different geographic contexts. For American parents, three frameworks matter most: COPPA (the federal children’s privacy law), KOSA (the Kids Online Safety Act, signed into law in 2024), and the EU’s GDPR, which applies to apps and services used by US children if those apps have European operations.

This guide translates each framework into plain English, explains what rights each gives parents, and tells you how to act when those rights are violated.

Key Takeaways

  • COPPA covers children under 13 and prohibits collecting their personal data without verifiable parental consent, but enforcement has significant gaps in data broker contexts.
  • KOSA (signed 2024) is the first US law to require platforms to design products with children’s safety in mind, not just notify parents; it covers minors up to age 17.
  • GDPR Article 8 requires parental consent for data processing of children under 16 (or 13 in some EU member states) and applies to services your US child uses if those services have EU operations.
  • Parents have the right to access, correct, and delete data COPPA-covered services collected from their under-13 child.
  • Filing complaints: FTC for COPPA, platform-specific safety centers for KOSA violations, Data Protection Authorities (ICO in UK, CNIL in France) for GDPR violations involving EU-operated services.

COPPA: The Foundation (and Its Gaps)

The Children’s Online Privacy Protection Act (COPPA) was enacted in 1998 and substantially updated by FTC rule in 2013. It is administered and enforced by the Federal Trade Commission.

Who it covers: Operators of websites and online services “directed to children” under 13, and operators of general-audience websites that have “actual knowledge” they are collecting data from a child under 13.

What it requires:

  • Post a clear and comprehensive privacy policy.
  • Provide direct notice to parents before collecting personal information from children under 13.
  • Obtain verifiable parental consent before collecting, using, or disclosing personal information from under-13 users.
  • Give parents the right to review and delete information collected from their child.
  • Maintain confidentiality, security, and integrity of children’s personal information.
  • Retain children’s personal information only as long as necessary.

What counts as “personal information” under COPPA:

  • Name, home address, email address, phone number
  • Social Security number
  • Photos, videos, or audio files containing a child’s image or voice
  • Geolocation information precise enough to identify street name and city
  • Persistent identifiers (cookies, IP addresses, device identifiers) that recognize users across sites or services
  • Any information combined with the above

Major enforcement actions (FTC, recent):

  • YouTube/Google: $170 million (2019) for allowing channels directed at children to collect identifiers for behavioral advertising.
  • Epic Games/Fortnite: $275 million (2023), including $275 million in penalties and a requirement to delete children’s data collected without consent — the largest COPPA penalty in history.
  • Musical.ly/TikTok: $5.7 million (2019) for collecting personal information from children under 13 without parental consent.

Where COPPA falls short: COPPA applies to direct online data collection. It does not clearly cover data brokers who build profiles from third-party sources, app ecosystems where data flows between the app and ad networks, or general-audience platforms that choose not to know the age of their users. The “actual knowledge” standard is easy to avoid — platforms simply don’t verify age and claim no knowledge of underage users.

For more on your specific rights under COPPA and how to exercise them, see our guide on kids’ online privacy and COPPA.

KOSA: The 2024 Update That Changes Platform Design

The Kids Online Safety Act was signed into law in late 2024, marking the most significant expansion of US children’s online protection since COPPA.

Who it covers: “Platforms likely to be used by minors” — a much broader standard than COPPA’s “directed to children” language. A platform that is not specifically designed for children but is commonly used by teens (Instagram, TikTok, YouTube, gaming platforms) is covered under KOSA in ways it was not under COPPA.

Age coverage: Minors under 17, not just under 13.

Core requirements:

Duty of Care: Platforms must act in the best interests of child users, which the law defines as avoiding designs that lead to excessive use, anxiety, or depression. This is a fundamental shift: prior law focused on data collection. KOSA focuses on design choices.

Default Privacy Settings: The “most protective” privacy and safety settings must be the default for minors, not something parents have to hunt for and enable manually.

Required Features: Platforms must provide minors with tools to:

  • See and limit time spent on the platform
  • Disable addictive design features (autoplay, infinite scroll)
  • Opt out of algorithmic recommendations
  • Restrict who can see their information and interact with them

Prohibited Actions for Minors:

  • Platforms cannot use features designed to increase compulsive use by minors
  • Cannot use targeting advertising based on personal information of minors
  • Cannot collect precise geolocation of minors
  • Cannot promote self-harm, suicide, eating disorders, or substance abuse content to minors

Parental Rights:

  • Parents can request removal of a minor’s account data
  • Platforms must provide an accessible, clearly labeled mechanism for these requests

Enforcement: The FTC enforces KOSA. State attorneys general also have enforcement authority. KOSA creates a private right of action — meaning affected families can potentially sue platforms directly for KOSA violations, not only wait for federal enforcement.

KOSA is new enough that its enforcement history is still being written. Watch the FTC’s rules and guidance page for implementation guidance as the law’s provisions take effect over 2025–2026.

GDPR Article 8: How EU Law Affects Your US Child

The EU’s General Data Protection Regulation (GDPR) is the world’s most comprehensive data privacy law. It went into effect in May 2018. Even though your family lives in the US, GDPR affects your child through a simple mechanism: if a platform or app operates in the EU (has EU users, offers services in the EU), GDPR applies to how that platform handles all users, including US users, on many of its policies.

Article 8 specifically covers children’s data. It requires parental consent for processing personal data of children under 16 (EU member states can lower this to 13 — the UK, Germany, and most northern European states use 13). This is why TikTok, Instagram, YouTube, and most global platforms have 13+ age limits that have real teeth in Europe — they’re required by GDPR.

How this affects US families:

  • Global platforms that comply with GDPR often apply similar protections globally, because it’s operationally easier than maintaining separate privacy architectures by geography.
  • UK’s Age Appropriate Design Code (AADC, also called the Children’s Code) goes further than GDPR and has shaped design standards across platforms. The UK’s Information Commissioner’s Office (ICO) has levied significant fines, including a £12.7 million fine against TikTok in 2023 for processing children’s data unlawfully.
  • EU enforcement of GDPR against major tech platforms has driven significant privacy design changes — most of which US families also benefit from.

Your rights under GDPR (if the service operates in the EU):

  • Right to access: Request what data the platform holds on your child.
  • Right to erasure (“right to be forgotten”): Request deletion of your child’s personal data.
  • Right to restriction: Request that the platform stop using your child’s data while a request is being processed.
  • Right to data portability: Receive your child’s data in a machine-readable format.

How to file a GDPR complaint from the US: File with the Data Protection Authority (DPA) in the country where the company’s EU headquarters is located. Most major platforms have EU headquarters in Ireland, making the Irish Data Protection Commission (DPC) the relevant authority. UK-based operations go to the ICO. This process can be slow — the Irish DPC in particular has faced criticism for processing times — but the fines resulting from sustained complaints have been substantial: Meta received a €1.2 billion fine in 2023 for GDPR violations related to data transfers.

Comparison: What Each Law Covers

FrameworkJurisdictionAge CoveredKey FocusWho EnforcesPrivate Lawsuit?
COPPAUS (federal)Under 13Data collection consentFTCNo
KOSAUS (federal)Under 17Platform design + dataFTC + state AGsYes
GDPR Art. 8EU (global reach)Under 16 (or 13)All personal data useEU/UK DPAsVia DPA complaint
California AADCCaliforniaUnder 18Design harm + default settingsCA AGLimited
COPPA state equivalentsVariesVariesData collectionState AGsVaries

How to File a Complaint

For COPPA violations (US, under-13 data collection without consent):

  1. Document the violation: screenshot the privacy policy, the data collection interface, and any consent flow that did not properly verify parental consent.
  2. File at ftc.gov/complaint — select “Privacy, Identity Theft, and Online Security” → “Children’s Privacy (COPPA).”
  3. The FTC does not resolve individual complaints but uses them to identify investigation targets.

For KOSA violations (unsafe platform design, no default protections for minors):

  1. File with the FTC at ftc.gov/complaint.
  2. File with your state attorney general’s consumer protection division — state AGs have independent authority under KOSA.
  3. Consult an attorney if you believe your family has suffered specific harm from KOSA violations — the private right of action created by KOSA may allow a direct lawsuit.

For GDPR violations (EU-operated services):

  1. Submit a complaint to the relevant national DPA — the Irish DPC (forms.dataprotection.ie) for most major US tech platforms, the UK ICO (ico.org.uk/make-a-complaint/) for UK operations.
  2. First attempt to use the platform’s own data deletion and access request mechanisms (most platforms have these under “Privacy Settings” or “Data Download”).

Upcoming Changes to Watch

COPPA 2.0 / FTC Rule Revision: The FTC announced rulemaking to update the COPPA rule in 2024, with expected final rules in 2026. Proposed changes include extending protections to teens under 17, covering data brokers more explicitly, and restricting targeted advertising to minors even when parental consent for general data collection has been obtained.

American Data Privacy and Protection Act (ADPPA): Repeatedly reintroduced in Congress; if passed, would create a federal privacy framework covering all Americans (not just children) with specific enhanced protections for minors. Would preempt some (but not all) state privacy laws.

State Children’s Privacy Laws: Arkansas, Texas, Indiana, and Montana have enacted or proposed children’s social media laws that go beyond COPPA in different ways. Implementation and constitutionality challenges are pending in several states.

For guidance on protecting your family’s digital privacy in the meantime, see our complete family cybersecurity audit guide and our guide on kids’ online privacy under COPPA.

Frequently Asked Questions

Does COPPA require my child’s app to ask my permission for everything?

COPPA requires verifiable parental consent for collecting, using, or sharing “personal information” from children under 13. This covers a specific defined list — name, address, email, photos, precise location, persistent identifiers. It does not require consent for every interaction with the app. Many apps comply with COPPA by avoiding personal information collection entirely, rather than setting up parental consent systems.

No. COPPA covers under-13 only. At 14, your teen is outside COPPA’s age range. They may have protections under KOSA (which covers under-17) and potentially state privacy laws depending on where you live. For California families, the Age-Appropriate Design Code Act (CAADCA) provides design-focused protections for under-18.

How can I request what data a company has on my child?

Under COPPA, you can contact any covered company that has collected data from your under-13 child and request to review and delete it. Email the company’s privacy address (listed in their privacy policy) and identify yourself as the parent of a child user. Under GDPR (for EU-operating companies), submit a Subject Access Request (SAR); most major platforms have a specific form for this in their privacy settings.

What can I do if a platform ignores my data deletion request?

For COPPA-covered situations: report to the FTC at ftc.gov/complaint and to your state AG. Document the request and the non-response. For GDPR-covered situations: escalate to the relevant DPA with documentation of your request and the failure to respond — failure to respond within 30 days is itself a GDPR violation.


About the author Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.


Sources

  1. Federal Trade Commission. “Children’s Online Privacy Protection Rule (COPPA).” ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa
  2. US Congress. “Kids Online Safety Act (S.1409).” congress.gov, signed 2024
  3. European Commission. “General Data Protection Regulation (GDPR) — Article 8.” gdpr.eu
  4. UK Information Commissioner’s Office. “Children’s Code (Age Appropriate Design Code).” ico.org.uk/for-organisations/childrens-code-hub/
  5. Irish Data Protection Commission. “GDPR Enforcement.” dataprotection.ie
  6. Federal Trade Commission. “FTC Takes Action Against Epic Games for Fortnite: $275 Million.” ftc.gov, 2023
  7. Electronic Privacy Information Center. “Children’s Privacy.” epic.org/privacy/kids/
Ricky Flores
Written by Ricky Flores

Founder of HiWave Makers and electrical engineer with 15+ years working on projects with Apple, Samsung, Texas Instruments, and other Fortune 500 companies. He writes about how kids learn to build, think, and create in a tech-driven world.