COPPA for schools: what it actually requires, in plain language
The Children's Online Privacy Protection Act (1998) and the FTC rule that implements it (16 CFR Part 312, substantially updated in 2013) form the backbone of US children's online privacy. For schools the practical questions are narrow: when does it apply, what does it demand, what's the school's role, and what should we ask vendors?
When COPPA applies
COPPA applies to operators of commercial websites and online services that are directed to children under 13, or that have actual knowledge they're collecting personal information from under-13s. Classroom edtech used in primary schools is squarely in scope on both prongs. "Personal information" is broad and got broader in 2013: name, email, address, phone, photos, video, audio of a child, persistent identifiers (cookies IDs, device IDs, IP addresses used to track over time), and geolocation.
Two things teachers often misread:
- COPPA regulates operators, not schools. A school can't violate COPPA; it can, however, sign its pupils up to services that do โ and it inherits the fallout.
- "Compliant" is self-declared. There is no COPPA certificate (safe-harbor programs exist but are membership schemes). The compliance question is always mechanical: what's collected, under what consent, used how.
The core requirements (operator's side)
An in-scope operator must, among other things: post a clear privacy policy enumerating collection and use; obtain verifiable parental consent (VPC) before collecting personal information from a child; give parents review and deletion rights; keep data only as long as needed; and โ the sleeper clause with real design consequences โ not condition a child's participation on collecting more personal information than reasonably necessary for the activity (the data-minimization mandate at ยง312.7).
The school-consent path โ and its two hard limits
The FTC has long taken the position (rule commentary and its COPPA FAQs) that schools may consent on parents' behalf where a service is used solely for the educational benefit of students โ this is how classroom tools operate without collecting parental signatures for every login. The limits matter:
- Educational purpose only. School consent doesn't authorize commercial use of the data โ behavioral advertising, marketing, profile-building beyond the educational context. A vendor whose model needs those has no valid school-consent basis.
- The school must actually be able to consent knowledgeably โ meaning it must know what's collected and how it's used. This turns the school-consent doctrine into homework for the school: the eleven questions in our privacy-policy checklist are, in effect, the diligence the FTC expects a consenting school to have done. Districts frequently formalize this in vendor agreements; many states (California's SOPIPA was the template; dozens followed) layer statutory prohibitions on top.
What breach of all this looks like
Enforcement is real and instructive: the FTC's actions against major platforms for children's-data violations (most famously the 2019 settlement with Google/YouTube โ $170M โ over child-directed content and persistent identifiers) established that scale is no shield and that "we didn't know it was child-directed" fails against evidence. For edtech specifically, FTC policy statements since 2022 have emphasized that COPPA's limits bind edtech vendors regardless of any consent paperwork โ data minimization, use limits, and retention limits aren't waivable by contract.
In practice: the school's five-step routine
- Inventory the under-13 stack โ including the free tools that never passed procurement (they're where trouble lives).
- For each: could you explain to a parent what it collects and why? If not, you can't be consenting knowledgeably. Run the checklist.
- Check the consent theory: is the vendor relying on school consent (then educational-use-only must hold), or parental consent (then who collected it?), or claiming "no personal information collected" (then verify โ persistent identifiers count).
- Mind ยง312.7: a service demanding more data than its function needs is out of bounds even with consent. "Why does a maths game need a birthday?" is a legally grounded question.
- Prefer architectures that make the analysis short. The less personal information a tool touches, the less of COPPA's machinery is even engaged.
How Wiz Kids relates to COPPA
Our answer is architectural: we designed for the strongest reading of ยง312.7's minimization mandate by collecting no personal information from anyone โ students or teachers. No names, no emails (not even hashed โ a deterministic hash is a persistent identifier, the trap explained here), no birthdates, no photos; a student is a class code, a generated pseudonym, and a picture-secret; no third-party trackers exist to leak persistent identifiers. Most of COPPA's machinery โ VPC, parental review rights over personal data โ has nothing to attach to, which we'd argue is the compliance posture a children's service should aspire to: not a well-drafted policy, but an empty inventory.
Reference
- Children's Online Privacy Protection Act of 1998, 15 U.S.C. ยงยง 6501โ6506; FTC Children's Online Privacy Protection Rule, 16 CFR Part 312 (as amended 2013).
- FTC, Complying with COPPA: Frequently Asked Questions โ esp. the "Schools" section (the school-consent doctrine).
- FTC (2022). Policy Statement on Education Technology and the Children's Online Privacy Protection Act.
- United States v. Google LLC and YouTube, LLC (2019 settlement) โ persistent identifiers and child-directed content.
- California SOPIPA (2014) and successor state student-privacy statutes โ the state layer above COPPA.
ยฉ Glu IO Pty. Ltd. โ Wiz Kids (wiz.kids). Link freely; republication requires permission โ see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.