What Is COPPA?

Learn what teachers need to know about this important law.

The Children's Online Privacy and Protection Act, more commonly known as COPPA, is a law dealing with how websites, apps, and other online operators collect data and personal information about kids under the age of 13.

COPPA basically says — among other things — that tech companies making apps, websites, and online tools for kids under 13 must:

  • Have a "clear and comprehensive" privacy policy.
  • Get parental consent before collecting information about kids.
  • Not use kids' data for marketing-related purposes.

For a more detailed, yet still accessible overview of the law, be sure to check out EdWeek's "COPPA and Schools: The (Other) Federal Student Privacy Law, Explained." The article also gets into the somewhat confusing and contentious issue of whether or not schools can stand in for kids' parents when giving consent. In short, schools can grant COPPA consent if — here's the tricky part — the tool is used specifically for an educational purpose. And it can often be hard to tell what's specifically educational and what isn't.

Beyond COPPA's parental consent issue, it's important to know that even though the law specifically regulates technology companies, teachers and schools aren't off the hook when it comes to understanding the law and its intent. Here's why:

COPPA was originally enacted in 1998 — nearly 20 years ago! Technology has changed a lot during that time. And the technologies that kids use both on their own and in school are no exception.

Many edtech companies and websites tout a seal of COPPA compliance as part of their marketing. But in some cases, COPPA compliance might depend more on how teachers and students actually use the tool at the classroom level. Some edtech tool developers are even being creative in how they highlight their compliance with the law. In certain cases this essentially means shifting responsibility for COPPA compliance and obtaining parental consent directly to schools and individual teachers.

Innovative teachers — many of whom tend to be early adopters of new tech — are likely to try out tools that haven't been made specifically for kids or haven't been made with educational use in mind. Along with innovative teaching comes the responsibility to understand how our students' data is being collected and used.

What can teachers do?

1. Know your school's policies on adopting new technologies and follow them. Does your school or district have an approved list of apps and sites for student use? Chances are, students' data privacy issues were a big part of the decision to approve — or not approve — a tool.

2. Choose your classroom tech wisely.

  • Stick to tools designed with education in mind, especially if kids are going to sign up and create accounts.
  • When you bring new tech into your classroom, be mindful about how the tools ask kids to sign up, enter personal information, or share anything online.
  • Always get parental consent first — send a note home to ask for permission.
  • Avoid apps, games, or websites that seem focused on advertising.
  • Be cautious with tools that claim to be for education, but are also aimed at consumers or the business world.

3. Not sure about a technology tool? Our Privacy Evaluations (privacy.commonsense.org) can help! We have evaluations for many of the most popular ed tech tools that help identify the privacy risks in ways that are easy to understand.

About the Author

Jeff Knutson is senior editor of education reviews for Common Sense Media.

Common Sense Education helps educators find the best edtech tools, learn best practices for teaching with tech, and equip students with the skills they need to use technology safely and responsibly. Go to Common Sense Education for free resources including full reviews of digital tools, ready-made lesson plans, videos, webinars, and more.


Featured

  • Digital Network of User Profiles and Data Connections

    Microsoft, RSA Updates Focus on Identity Security in the Age of AI

    Two authentication announcements coming out of the recent RSA Conference both point in the same direction: Organizations need a more flexible, unified approach to identity security, especially as AI agents start acting alongside human workers.

  • interconnected nodes with currency symbols

    Report: Half of Gen AI Projects Could Exceed Budget by 2028

    Organizations may be underestimating the cost of generative AI as they move from experimentation to production, according to Gartner's "10 Best Practices for Optimizing Generative and Agentic AI Costs" report.

  • Engineering team implements digital guardrails on AI

    3 Starting Points for Integrating AI Guardrails in K-12 Districts

    As education leaders start to craft an AI policy that is both practical and flexible enough to evolve with this fast-changing technology, there is at least one principle that should be foundational: AI should serve to augment human critical thinking and creativity but never replace human interaction and decision-making.

  • businessman holding tablet with holographic AI icons

    Google Moving AI Agents into Mainstream Product Portfolio

    At its recent I/O developer conference, Google positioned artificial intelligence agents not as a distant research project, but as a product strategy spanning Search, personal assistants, productivity software, developer tools, and smart glasses.