No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

The Digital Playground: Children’s Online Safety & Privacy Compliance

Laws increasingly call on companies to specially protect kids’ data

by Ryan Smyth, Marygrace Jay and Michael Spadea
December 17, 2024
in Data Privacy
small child using computer

(Editor’s note: This article has been updated to reflect finalization of proposed rule on Jan. 16, 2025.)

Growing concerns from parents surrounding children’s online safety have prompted updates to federal regulation to limit the information that can be collected from and about minors. These evolving regulations necessitate robust compliance strategies to safeguard young users’ data effectively. Ryan Smyth, Marygrace Jay and Michael Spadea of FTI Consulting explore the regulation around children’s online privacy.

Amid an uptick in use of new technologies and platforms that use personal data to customize experiences, organizations, especially those in the social media and gaming industries, must navigate compliance surrounding children’s privacy regulation while still accomplishing their core business missions. In addition to penalties and fines, failure to comply with children’s privacy regulations could jeopardize an organization’s operations and reputation, with noncompliance potentially leading to the suspension of certain business activities and public perception that the organization is irresponsible or untrustworthy.

Current regulations

In keeping with the global trend of increasing data protection regulation and enforcement, many governments are tightening regulations relating to protecting the privacy of children. For example, the UK’s Online Safety Act, passed in October 2023, requires social media platforms to prevent children from accessing harmful and inappropriate content and provides parents and children with clearer processes for reporting content issues.

In the U.S., several states have privacy laws specific to the collection of personal information of minors, but the primary regulation regarding this topic is the Children’s Online Privacy Protection Act (COPPA). Updates to COPPA include new information disclosure restrictions, reflecting a global trend toward stricter data protection standards for minors.

Issued in 1998 by the Federal Trade Commission (FTC), the COPPA regulates how websites, apps and other online operators collect data and personal information from children under the age of 13. In January 2025, the FTC finalized several changes to the rule; notable new requirements include:

  • Separate opt-in consent prior to disclosure of a child’s personal information to third parties.
  • Expanding the definition of personal information to include biometric data, such as Face ID, and online contact information, such as a cell phone number.
  • Increasing security program requirements surrounding children’s information and requiring annual risk assessments for organizations possessing this information.
demystifying data de ID collage
Data Privacy

Demystifying Data De-Identification for US Privacy Compliance

by L. Hannah Ji-Otto, David Chen and Julie Kilgore
October 30, 2024

Read moreDetails

Regulatory challenges

Organizations often face challenges complying with COPPA, as the requirements can be difficult to follow and to enforce on users. A few examples include:

Age verification

While it is necessary for organizations to verify the age of their users for compliance with COPPA, ensuring that users are of appropriate age without collecting excessive data poses a significant challenge. In other words, it is simple for children to misrepresent their age, yet the verification burden falls on the organization collecting this information.

Data minimization

Balancing the need to collect data for functional and legal reasons with the principle of collecting the least amount of data necessary is complex, especially when dealing with children’s information. Organizations must also consider how to adjust data rules for individuals when they age out of COPPA restrictions.

Data encryption

Certain data must be properly maintained to show compliance with regulatory requirements. This data must be encrypted, as a data breach exposing children’s data could have serious and far-reaching implications. 

Securing consent

Obtaining verifiable parental consent in a manner that is compliant with laws like COPPA can be technically and administratively challenging. 

Effectively complying with children’s privacy regulations

Organizations should focus their efforts on several key areas when determining whether their policies around children’s digital privacy are compliant. They should consider: 

  • Collecting only necessary data for the service provided and regularly review data retention policies to ensure data is not retained longer than necessary. 
  • Developing clear and straightforward methods for obtaining verifiable consent using interfaces that are easy for parents to understand and navigate. Note that a check box stating “I am over 13” was deemed ineffective by the FTC, and best practice is to ask for a birthdate with month, date and year.
  • Ensuring any data that cannot be deleted is encrypted.
  • Establishing controls to mitigate risks associated with children’s privacy.
  • Performing regular independent assessments to examine the effectiveness of privacy controls.

Children’s privacy is a serious and growing concern that needs to be addressed by organizations that children regularly interact with online. Companies developing general-use technology that could be repurposed for the educational environment should also closely follow the progress of proposed COPPA updates. By implementing best practices and adhering to regulations, organizations can successfully and compliantly deliver their products and services to young users, reduce legal, operational and reputational risk and play a vital role in keeping children safe online.


Tags: Data Governance
Previous Post

In the World of JavaScript, GDPR Consent Forms Merely Scratching the Surface

Next Post

Science-Based Targets the Next Frontier in Corporate Sustainability

Ryan Smyth, Marygrace Jay and Michael Spadea

Ryan Smyth, Marygrace Jay and Michael Spadea

Ryan Smyth is a managing director at FTI Consulting. He advises clients on a wide range of regulatory and compliance issues, with a specific focus on privacy, information security, data governance and business continuity. He has served in senior leadership positions at IBM, Promontory, and LPL Financial and held roles at UBS and Citigroup.
Marygrace Jay is a senior director in cybersecurity at FTI Consulting. She has more than 10 years of experience in project management, automation, analytics, internal controls and regulatory compliance assessments.
Michael Spadea is a senior managing director at FTI Consulting. He leads the technology segment’s information governance, privacy and security practice for the Americas and works with clients across industries to design and improve governance frameworks.

Related Posts

doj building sign with flags

‘Reasonable Steps’: What the DOJ Expects From Your Bulk Data Transfer Compliance Program

by Alexandra P. Moylan, Alisa L. Chestler and Michael J. Halaiko
May 5, 2025

Sample provisions offer blueprint for compliant data brokerage with foreign entities

data security program concept cameras

Your Sensitive Data Is Now a National Security Matter: The DOJ’s New Data Security Program

by Randall Cook, Vince Mekles and Rachel Woloszynski
April 29, 2025

90-day implementation window closing on regulations affecting companies with genomic, biometric, health and other personal information

Electronic Evidence Collection for eDiscovery and Compliance

Electronic Evidence Collection for eDiscovery and Compliance

by Corporate Compliance Insights
March 30, 2025

Are you prepared to manage modern data sources in your compliance program? Whitepaper Electronic Evidence Collection for eDiscovery and Compliance...

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

Next Post
aerial view of forest

Science-Based Targets the Next Frontier in Corporate Sustainability

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights