
Child privacy law compliance starts the moment your business collects any information from users who might be under 13. TikTok’s recent $400 million settlement with U.S. regulators proves that privacy violations involving children carry consequences that can cripple a business, regardless of size or intent.
For small and mid-sized businesses running apps, websites, educational platforms, or connected devices, the question is not whether you need to comply. It is whether you know the specific rules and whether your current practices would survive an FTC audit.
What does child privacy law compliance actually require?
The Children’s Online Privacy Protection Act (COPPA) sets clear requirements for any business that collects personal information from children under 13. Personal information is broader than you think. It includes names, email addresses, photos, voice recordings, geolocation data, persistent identifiers (cookies, device IDs), and even behavioral tracking.
If your service does not explicitly target children but still attracts them, you are not off the hook. Mixed-audience platforms carry the same obligations. A professional services firm running a family portal, a manufacturer offering a product registration site, or a healthcare practice with a patient app all fall under scrutiny if minors use the service.
COPPA compliance breaks down into five core requirements. First, post a clear, accessible privacy policy that describes what data you collect, how you use it, and your disclosure practices. Second, provide direct notice to parents and obtain verifiable parental consent before collecting data. Third, give parents the right to review their child’s information and delete it. Fourth, establish reasonable security procedures to protect the data. Fifth, retain information only as long as necessary to fulfill the purpose for which it was collected.
The TikTok case centered on failures across multiple requirements. Regulators found that the platform allowed children to create accounts without parental consent, collected persistent identifiers without proper notice, and retained data longer than necessary. The $400 million price tag reflects the FTC’s calculation of per-violation penalties multiplied across millions of affected children.
How do FTC violations happen in small businesses?
Most SMBs do not set out to violate child privacy law compliance standards. Violations happen through gaps in system design, assumptions about user demographics, or reliance on generic terms of service templates that do not address COPPA.
A common scenario: a regional healthcare clinic launches a patient portal with appointment scheduling, prescription refills, and educational content. The clinic assumes adult patients will use it. No age gate exists. A 12-year-old books an appointment using a parent’s login, then creates their own account. The portal collects email, date of birth, health history, and device identifiers. Without verifiable parental consent and a COPPA-compliant privacy notice, the clinic has violated the rule.
Another example comes from manufacturing. A company sells smart home devices and offers a companion app. Families download the app for whole-household use. The app tracks usage patterns, stores voice commands, and collects location data. If the manufacturer does not screen for child users or obtain parental consent, each child using the app represents a separate violation.
Professional services firms face similar risks with client portals, especially in legal, accounting, or financial sectors where families share access. If a minor enters personal information without age verification or parental approval, the firm is liable.
The Federal Trade Commission does not wait for harm to occur. It investigates based on potential risk. An audit can be triggered by a competitor complaint, a consumer tip, or routine monitoring of app stores and websites. Once an investigation begins, the FTC reviews privacy policies, data flows, consent mechanisms, and retention practices. Gaps that seem minor in daily operations become costly violations under formal review.
What does verifiable parental consent actually look like?
Verifiable parental consent is the cornerstone of child privacy law compliance, and it is more rigorous than a simple checkbox. The FTC accepts several methods, each with trade-offs in cost and user friction.
One approved method is a signed consent form sent via postal mail or fax. This provides strong verification but creates significant friction and delays. Few modern services use it as a primary method.
A second method is a credit or debit card transaction. The parent makes a small charge (often later refunded) to verify identity. This works well for paid services but adds a barrier for free platforms.
A third approach is a video-conference call with trained personnel who verify a government-issued ID. This provides high confidence but requires staffing and scheduling.
A fourth method involves the parent providing a copy of a government-issued ID, which the business then deletes after verification. Privacy concerns and storage risks make this less attractive.
A fifth method uses knowledge-based authentication, asking the parent questions that only an adult with access to personal records could answer. This method requires integration with third-party verification services.
For SMBs, the most practical approach often combines age-screening at account creation with email-plus-credit-card verification for parents. An age gate asks the user’s birth year. If under 13, the system blocks further data collection and sends a consent request to a parent-provided email. The parent must complete a small transaction or knowledge-based quiz before the child’s account activates.
Half-measures do not count. Asking a user to check a box saying “I am over 13” is not verifiable consent. Sending an email that requires only a click-through does not verify identity. The FTC has fined companies for these shortcuts.
What are the financial and operational costs of non-compliance?
The FTC can impose civil penalties up to $50,120 per violation. In practice, each instance of collecting data from a child without consent can count as a separate violation. A mobile app with 10,000 underage users who provided email addresses without parental consent faces a theoretical maximum penalty exceeding $500 million. Settlements typically land far lower, but even a fraction of that maximum can bankrupt an SMB.
Beyond fines, non-compliance triggers operational disruption. An FTC investigation requires legal representation, forensic data analysis, policy reviews, and executive time. A mid-sized professional services firm can spend $200,000 to $500,000 in legal and consulting fees during an investigation, even if no formal penalty results.
Reputational damage compounds the financial cost. News of a child privacy violation spreads quickly, especially in tight-knit industries or local markets. A law firm investigated for COPPA violations loses client trust. A healthcare practice faces patient attrition. A manufacturer sees retailers drop its products.
Class-action lawsuits often follow FTC settlements. Plaintiffs’ attorneys use the government’s findings as a roadmap for civil claims. A business that settles with the FTC for $2 million may face another $5 million in private litigation over the same conduct.
Compliance carries its own costs, but they are predictable and manageable. Implementing age-verification adds development expense, typically $15,000 to $50,000 for a strong system integrated with third-party verification services. Annual compliance audits run $10,000 to $25,000. Privacy policy updates and staff training add another $5,000 to $15,000. For most SMBs, total first-year child privacy law compliance costs range from $30,000 to $90,000, with ongoing annual costs of $15,000 to $40,000.
Those figures are a fraction of a single FTC penalty or the legal costs of an investigation. More importantly, they buy certainty. A business with documented COPPA compliance can operate without the constant risk of a regulatory landmine.
How should an SMB assess its child privacy law compliance exposure?
Start with a data-collection inventory. List every system, app, website, portal, or device that collects user information. For each, document what data you collect, how you use it, how long you retain it, and whether you share it with third parties.
Next, evaluate your user base. Do you have actual knowledge that children use your service? Do you market to families or offer content that appeals to minors? Do your analytics show users under 13? Actual knowledge is the legal trigger, but the FTC defines it broadly. If your service is likely to attract children, you are expected to design for compliance.
Review your current privacy notice. Does it specifically address children’s privacy? Does it describe parental consent procedures? Is it written in plain language that a parent can understand? A generic privacy policy copied from a template will not satisfy COPPA.
Examine your consent mechanisms. If you collect data from users who might be under 13, how do you verify age? How do you obtain and document parental consent? Can you produce records showing when and how each parent consented? If the answer to any of these questions is unclear, you have a gap.
Test your data retention. Do you automatically delete information when it is no longer needed? Or do you store user data indefinitely? COPPA requires retention limits. A business that keeps children’s email addresses for years after a one-time transaction is out of compliance.
This assessment is not a one-time project. User demographics shift, products evolve, and regulations update. Annual compliance reviews keep you ahead of risk. Many SMBs partner with a compliance-focused IT provider to maintain ongoing monitoring and documentation.
What steps bring an SMB into full compliance?
First, implement age-screening at every data-collection point. A simple birth-year field at account creation flags underage users and triggers the parental consent workflow. Make sure the age gate appears before any data is collected, not after.
Second, design a verifiable parental consent process that balances security and user experience. For most SMBs, email-plus-credit-card or email-plus-knowledge-verification works well. Document every consent transaction with timestamps, IP addresses, and verification method.
Third, update your privacy policy to include a standalone children’s privacy section. Describe what information you collect from children, how you use it, your consent procedures, and parental rights. Link to this policy prominently on your homepage and at every data-collection point.
Fourth, minimize data collection from children. If you do not need an email address, do not ask for it. If you do not need geolocation, do not track it. COPPA requires collecting only information reasonably necessary for the activity. Excess data collection increases both risk and regulatory scrutiny.
Fifth, implement retention limits. Set automatic deletion schedules for children’s data based on the purpose for which it was collected. If a child creates an account to enter a one-time contest, delete their information when the contest ends. Document your retention policies and enforce them through automated processes.
Sixth, train your team. Every employee who works with user data needs to understand COPPA requirements, recognize underage users, and follow your consent and deletion procedures. Make training part of onboarding and conduct annual refreshers.
Seventh, conduct an annual compliance audit. Review your data flows, test your age-screening, verify your consent records, and check your retention practices. An independent audit by a qualified third party provides both assurance and documentation if regulators come calling.
For businesses in healthcare, financial services, or other regulated sectors, child privacy law compliance often overlaps with HIPAA, Gramm-Leach-Bliley, or state privacy laws. Coordinate your COPPA efforts with broader data-protection programs to avoid gaps and duplication.
Do I need a lawyer or can an MSP handle this?
COPPA compliance has both legal and technical components. A privacy attorney should draft or review your privacy policy, consent language, and terms of service. Legal counsel also advises on interpretation of edge cases and helps structure your compliance program to withstand regulatory scrutiny.
A cybersecurity-focused managed service provider handles the technical implementation. Age-screening, consent workflows, data retention automation, access controls, and audit logging all require specialized IT knowledge. An MSP also provides ongoing monitoring to catch compliance drift before it becomes a violation.
For most SMBs, the optimal approach pairs a privacy attorney for policy and guidance with an MSP for systems and operations. Budget $10,000 to $20,000 for initial legal work and $20,000 to $50,000 for technical implementation. Ongoing legal review runs $3,000 to $8,000 annually, while technical management costs $12,000 to $30,000 per year depending on system complexity.
Trying to handle COPPA compliance without specialized help is risky. The rule is complex, enforcement is active, and stakes are high. A mid-sized professional services firm that saves $30,000 by skipping expert guidance may face a $500,000 settlement when gaps emerge during an FTC investigation.
What happens if the FTC investigates your business?
An FTC investigation typically begins with a Civil Investigative Demand (CID), a formal request for documents, data, and testimony. The CID will ask for privacy policies, consent records, data-flow diagrams, system architecture, and communications about COPPA compliance. You have 20 days to respond, though extensions are common.
Failing to respond or providing incomplete information escalates the investigation. The FTC has subpoena power and can compel production. Obstruction or false statements carry separate penalties.
Once the FTC reviews your submission, it will identify areas of concern. Investigators may request interviews with executives, IT staff, and legal counsel. They will compare your documented policies against actual practices, looking for gaps.
If the FTC finds violations, it will propose a settlement. Settlement terms typically include a financial penalty, injunctive relief (requirements to change practices), third-party monitoring, and regular compliance reporting. The settlement becomes a consent order subject to public comment and final approval.
Businesses that refuse settlement face litigation. The FTC files a complaint in federal court seeking civil penalties, injunctions, and disgorgement of ill-gotten gains. Court cases are public, costly, and time-consuming. Most businesses settle.
The best defense is not needing one. Proactive child privacy law compliance, documented through policies, system controls, and audit trails, allows you to respond confidently to any inquiry. A business that can produce timestamped consent records, demonstrate age-verification, and show automated retention limits will face far less scrutiny than one scrambling to reconstruct its practices after the fact.
How does child privacy compliance fit into your broader data strategy?
COPPA is one piece of a larger data-governance puzzle. Many SMBs discover child privacy gaps while addressing other regulations like HIPAA, state breach-notification laws, or cybersecurity insurance requirements.
The systems you build for COPPA improve overall data protection. Age-verification, consent management, data minimization, and retention automation all reduce risk across your entire user base, not just children. A professional services firm that implements strong consent workflows for COPPA finds those same workflows satisfy client-intake requirements under attorney-client privilege or accountant-client confidentiality rules.
Similarly, the audit discipline required for COPPA strengthens your cybersecurity posture. Regular reviews of data flows, access controls, and retention practices catch vulnerabilities before they become breaches. A manufacturing company that audits its COPPA compliance quarterly will spot a misconfigured database or excessive data collection long before an attacker does.
Integrating child privacy law compliance into your broader IT strategy also controls costs. Building a standalone COPPA program in isolation means duplicate tools, separate training, and fragmented documentation. Building it as part of a unified data-protection and IT management program uses shared systems and expertise.
Frequently Asked Questions
Does COPPA apply to my business if I do not specifically target children?
Yes, if your service has actual knowledge that it collects information from children under 13. Actual knowledge includes situations where your service is likely to attract children or where your analytics show underage users. Mixed-audience platforms carry the same obligations as child-directed services.
What counts as personal information under COPPA?
Personal information includes first and last name, postal address, email, phone number, Social Security number, persistent identifiers (cookies, device IDs, IP addresses), photos, audio recordings, geolocation data, and any other identifier that permits contact or tracking. Behavioral data and browsing history also qualify when linked to an individual.
How much does it cost to achieve child privacy law compliance?
Initial compliance typically costs $30,000 to $90,000 for an SMB, covering legal review ($10,000 to $20,000), technical implementation ($15,000 to $50,000), policy updates, and training. Ongoing annual costs range from $15,000 to $40,000 for audits, monitoring, and system maintenance. These costs are far lower than FTC penalties, which start at $50,120 per violation.
Can I use a simple age checkbox instead of verifiable parental consent?
No. A user self-declaring their age does not satisfy COPPA’s verifiable consent requirement. The FTC requires methods that actually verify parental identity, such as credit-card transactions, knowledge-based authentication, video-conference ID checks, or signed consent forms. Checkbox attestations have resulted in enforcement actions and penalties.
What happens to my business if the FTC finds COPPA violations?
The FTC typically seeks a settlement that includes financial penalties (up to $50,120 per violation), injunctive relief requiring you to change practices, third-party compliance monitoring, and regular reporting. Settlements become public consent orders. Businesses that refuse settlement face litigation in federal court, which is public, expensive, and often results in higher penalties.
How often should I audit my child privacy law compliance?
At minimum, conduct an annual compliance audit that reviews data collection, consent records, retention practices, and privacy policies. Many businesses audit quarterly, especially if they frequently update products or see shifting user demographics. Any time you launch a new feature, app, or service that collects data, conduct a targeted COPPA review before release.
Keep reading
Sources
Source: TikTok Settles U.S. Child Privacy Case for $400 Million