On December 20, 2023, the Federal Trade Commission (FTC) announced proposed changes to the Children’s Online Privacy Protection Rule (COPPA Rule) that would place significant new restrictions on companies that collect personal information from children under 13.

The COPPA Rule applies to operators of websites and online services that are directed to children under 13 or that have “actual knowledge” that they are collecting personal information from children under 13. It imposes notice, consent, data security, and data minimization requirements, among other things. The FTC last updated the Rule in 2013, when it made a number of changes to reflect the increasing use of mobile devices and social networks (e.g., by expanding the definition of “personal information” to include persistent identifiers such as cookies that track a child’s activity online, as well as geolocation information, photos, videos, and audio recordings). The FTC initiated the current Rule review in 2019, during the prior administration. In response to its request for public comment on updating the Rule, the FTC received over 175,000 comments from industry, consumer advocacy groups, regulators, technologists, and others. We expect to see a similarly robust response to the request for public comment on the proposed changes to the Rule.

The FTC is proposing to modify most of the Rule’s provisions. Key changes to the Rule are summarized below.

Key Changes:

  • Expanded definition of “personal information” covered by COPPA: The FTC is proposing to expand the definition of “personal information” to include biometric identifiers that can be used for the automated or semi-automated recognition of an individual, including fingerprints or handprints; retina and iris patterns; genetic data, including a DNA sequence; or data derived from voice data, gait data, or facial data.
  • New factors added to “directed to children” test: The FTC is proposing to add language indicating that it will consider marketing materials, representations to consumers or third parties, reviews by users or third parties, and the age of users on similar websites or services when determining whether a website or online service is directed to children.
  • New data security requirements: The FTC’s proposal includes a requirement that covered entities establish, implement, and maintain a written comprehensive security program that contains specific elements, such as annual risk assessments and procedures for testing and monitoring the effectiveness of safeguards.
  • Limits on data retention: The modified Rule would expressly state that children’s personal information may not be retained indefinitely, and it would clarify that personal information may be retained for only as long as it is reasonably necessary for the specific purpose for which it was collected, and not for any secondary purpose. The FTC is also proposing to require covered entities to establish, maintain, and make public a written data retention policy that specifies the business need for retaining children’s personal information and the timeframe for deleting it.

The FTC is accepting public comment on the proposed changes to the Rule for 60 days after publication in the Federal Register, which should be in the next few weeks.

Wilson Sonsini Goodrich & Rosati routinely advises companies on significant FTC developments and on compliance with the COPPA Rule. For additional guidance on the proposed changes to the COPPA Rule, or if you would like to submit a comment, please contact Chris OlsenLibby WeingartenManeesha MithalKelly Singleton, or another member of the firm’s privacy and cybersecurity practice.