Search "COPPA child care" and you find law-firm summaries, so here is the center-owner version: what the rule covers, what it skips, and where your website, forms and parent app sit.
It is also the rule people reach for when the real question is photos; photos are governed closer to home by state licensing rules and your daycare photo release form, and the shots that earn trust are in our daycare website photos guide.
Does COPPA apply to a child care website?
COPPA covers operators of commercial websites and online services, apps included, that are directed to children under 13 and collect personal information from them, and general-audience operators only with actual knowledge that a child under 13 is providing it (Complying with COPPA: FTC FAQ, as of October 2026).
"Child" means an individual under 13 (16 CFR 312.2), and the rule does not require asking visitors' ages.
Whether a site is "directed to children" is a factors test: the FTC weighs subject matter, visual content, animated characters, child-oriented activities, music, the age of models, language and child-directed advertising, plus evidence about the actual audience (16 CFR 312.2).
A typical center site is written for parents (tuition, programs, tour booking), which points away from child-directed, an inference from the factors rather than an FTC statement about child care sites.
The edge is a kids' corner with games or child-oriented video, the same factors pointing the other way; a site that is child-directed without targeting children as its primary audience can be "mixed audience" and may age-screen.
COPPA reaches
- Websites and apps directed to children under 13 that collect personal information from them
- General-audience operators, once they know a child under 13 is providing it
- Photos, video or audio containing a child's image or voice, when collected from a child
Other rules govern
- Information parents submit about their children: the FTC's FAQ says COPPA covers information collected from children, not from parents, which is how tour and enrollment forms work
- Photos of enrolled children on your site and social accounts: state licensing rules and your photo release, not COPPA, which the FTC's FAQ says an adult uploading photos does not trigger
- Student records at Education-Department-funded schools: FERPA (34 CFR 99.1), a different statute
What COPPA requires when it does apply
A covered operator carries four core duties under 16 CFR 312.3: post a clear notice, get verifiable parental consent before collecting from a child, give parents access and deletion rights, and keep children's data reasonably secure.
Its definition of personal information is broad: name, contact details, persistent identifiers, photos, video or audio containing a child's image or voice and, since the 2025 amendments, biometric identifiers such as facial templates (16 CFR 312.2).
That breadth matters only where the rule reaches: a parent typing a child's birth date into your tour form is not a child providing it.
The 2025 amendments, and an April 2026 deadline that has passed
The amended COPPA Rule was published April 22, 2025 (90 FR 16918), took effect June 23, 2025, and gave regulated entities until April 22, 2026 to comply, a date now behind us (Federal Register, document 2025-05904).
Three changes carry the weight: separate verifiable parental consent before disclosing children's personal information to third parties, such as for targeted advertising, unless the disclosure is integral to the service (16 CFR 312.5(a)(2)); retention only as long as reasonably necessary, with no indefinite retention and the policy in the online notice (16 CFR 312.10, 312.4(d)(2)); and a written information security program (16 CFR 312.8(b)).
Those duties bind covered operators, and many parent-facing center sites may not be covered at all.
Parent apps: online services, same test
The FTC treats mobile and connected apps as online services covered by COPPA (FTC COPPA FAQ, as of October 2026).
For a parent-communication app, the question is the same: does it collect personal information from children under 13, or is it directed to them?
An app only parents and staff use falls under the information-from-adults principle, an inference from the FAQ rather than an FTC statement about child care.
The FAQ also lets schools consent on parents' behalf to an operator's collection of students' information, but only in the educational context, and it does not address child care centers acting in that role.
If you are choosing software for the pipeline, our child care CRM guide covers what to track; what each vendor collects is one more question to ask in writing.
Where children's privacy bites your marketing
Meta's rules prohibit sending health, financial or children's data through the Meta Pixel: no child names, ages or birth dates in thank-you page URLs or event parameters like "?child_dob=" (Meta, as of October 2026); the retargeting mechanics sit in our daycare retargeting guide.
Meta instant forms will not run if they ask for a child's date of birth or health information, so ask age group or desired start date instead; every lead ad also needs a live privacy policy URL, not a PDF (Meta, as of October 2026).
Google Ads bars targeting aimed only at children under 13 or teens under 18, and users under 18 get no personalized ads, which matters most for school-age and camp campaigns (Google, as of October 2026).
Our Facebook ad rules for daycares guide works through the ad-side rules.
- Walk your site as a child would: games, printables or video aimed at children can shift the directed-to-children analysis
- List every form and who fills it in: the FTC says information collected from parents, rather than from children, is not what COPPA covers
- Check thank-you pages and pixel parameters: child names, ages or birth dates in URLs are what Meta's pixel rules call out
- If you run Meta lead forms: no child date-of-birth or health questions, and a live privacy policy URL, not a download
- Ask each vendor the consent question: what the tool collects, from whom, and how parental consent happens
Confirm what applies to your center
Everything cited here is federal rule text, FTC guidance and platform policy as of October 2026; state privacy laws and state licensing rules on children's records sit on top of them.
Confirm what applies to your center with your state licensing agency, and have a lawyer review anything you are unsure about.
More Booked Enrollments works on the marketing side of the line: what your website asks families for, and how many requests become booked tours, with current prices on the pricing page.
Frequently asked questions
What does COPPA require when it applies to a website?
Notice, verifiable parental consent before collecting personal information from a child under 13, parental access and deletion rights, and reasonable security (16 CFR 312.3). Covered operators have also needed separate consent for most third-party disclosures, retention limits and a written security program since April 22, 2026.
Does COPPA cover a 12-year-old?
Yes: COPPA's definition of child is an individual under 13 (16 CFR 312.2), so a covered operator needs verifiable parental consent before collecting personal information from a 12-year-old. The rule does not require operators to ask visitors' ages.
What is the difference between FERPA and COPPA?
FERPA's regulations apply to educational agencies and institutions that receive funds under U.S. Department of Education programs (34 CFR 99.1), while COPPA covers online collection of personal information from children under 13. Most private centers take no Education Department money, though that last step is an inference worth confirming.
Do parent communication apps fall under COPPA?
The FTC treats apps as online services covered by the rule, so the question is whether the app collects personal information from children under 13 or is directed to them. An app only parents and staff use falls under the information-from-adults principle, which is an inference from the FAQ, not an FTC statement about child care.
What changed in the 2025 COPPA amendments?
Published April 22, 2025 and effective June 23, 2025, the amendments added separate verifiable parental consent before disclosing children's data to third parties, retention only as long as reasonably necessary, and a written information security program. Covered entities had until April 22, 2026 to comply, and that date has passed.
My site has a kids' games page. Does that make it child-directed under COPPA?
It is one factor pointing that way: the FTC weighs subject matter, visual content, animated characters, child-oriented activities and similar evidence in the directed-to-children test (16 CFR 312.2). A site that is child-directed without targeting children as its primary audience can be mixed audience and may age-screen, so have a lawyer look at the page.