Court Rules
All enforcement actions
GuidanceLow Risk

FTC Proposes COPPA Amendments to Restrict Children's Data Monetization

Website and Online Service Operators Covered by COPPADecember 20, 2023Federal Trade Commission

Summary

The FTC has proposed amendments to the COPPA Rule to enhance children's privacy protections. Key changes include requiring separate parental consent for targeted advertising, prohibiting conditioning access on data collection, limiting push notifications, strengthening data security and retention requirements, and restricting commercial use in educational technology. The proposal shifts responsibility from parents to companies to safeguard children's data.

Remedy

The proposed rule would mandate written data security and retention programs, require public disclosure of retention policies, ban conditioning access on data collection and push notifications to encourage use, and require separate consent for targeted advertising and disclosures to third parties.

Compliance ProgramReporting RequirementsBanCorrective Notice

Contract Impact

In-house legal teams should review vendor agreements (especially those involving data processing or analytics for children's services), customer-facing terms of service and privacy policies, data processing addendums, and educational technology contracts. Key clauses to examine include: consent mechanisms (ensuring separate, verifiable parental consent for any targeted advertising), data sharing and disclosure provisions (limiting sharing for monetization), data retention and deletion schedules (complying with stricter limits), security requirements (aligning with enhanced standards), push notification and in-app communication terms (requiring parental consent and limiting use), and any clauses that condition access to services on data collection or consent to advertising. Updates may be needed to remove conditioning language, implement granular consent flows for advertising, add explicit restrictions on commercial use in educational contexts, and strengthen data security and retention obligations.

Contract Search Terms

verifiable parental consenttargeted advertising consentdata collection conditioning prohibitionpush notification restrictionsdata security standardsdata retention limitseducational technology data restrictionscommercial use limitations

Laws Cited

Children's Online Privacy Protection Act
312.5

Violation Types

Entity Details

Entity

Website and Online Service Operators Covered by COPPA

Also known as: COPPA-Covered Operators

Industry

Technology

Official Sources

Source Evidence

Entity Name
"website and online service operators covered by COPPA"
Laws Cited
"Children’s Online Privacy Protection Act (COPPA)"
Statute Sections
"section 312.5"
Violation Types
"addressing the evolving ways personal information is being collected, used, and disclosed, including to monetize children’s data"

Related Enforcement Actions

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.

FTC

Chase Nissan LLC

$4.0M

The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

FTC

Federal Trade Commission

The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.

FTC

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.