Loopholes Remain In 2025 Revision of COPPA
Children’s Online Privacy Protection Act (COPPA)
Historically, K-12 schools were considered safe places for children and teens, including their personally identifiable information (PII), which usually includes significant family information. Three Federal statutes assign responsibility for protecting this information: the Protection of Pupil Rights Amendment (PPRA) (20 U.S.C. § 1232h); the Family Educational Rights and Privacy Act (FERPA) rule (20 U.S.C. § 1232g; 34 CFR Part 99); and the Children’s Online Privacy Protection Act (COPPA), codified (15 U.S.C. §§ 6501–6506), with authority for regulations under the Federal Trade Commission (FTC) Children’s Online Privacy Protection Rule, codified in the Code of Federal Regulations at (16 CFR Part 312). Effective Date: June 23, 2025; Compliance Date: April 22, 2026.
FERPA and PPRA place the responsibility for securing and maintaining student PII on schools that receive federal funding. COPPA places the onus on EdTech companies. It was recently updated by Congress and the FTC to recognize the expansion of electronic data, the modes of acquiring PII, and the growth of potential commercial exchange and use of students’ PII.
Under the 2013 COPPA Rule, schools and teachers act in lieu of parents and consent to EdTech collecting students’ PII for the school’s use, not for commercial purposes. Schools routinely approve an array of digital tools, learning platforms, multiple assessment systems, and AI-powered applications that use biometric data for behavioral and mental health evaluations. Parents may or may not receive notice and are rarely given an option to choose. The “not for commercial purposes” is questionable in the recent past.
On January 16, 2025, the Federal Trade Commission (FTC) finalized amendments to the Children’s Online Privacy Protection Act (COPPA) Rule. It is the first update since 2013. Businesses operating child-directed websites, apps, and services must adjust their practices to comply with these new regulations, which have the full force of law. COPPA provisions apply to children under 13 years of age. Requests to extend COPPA to youth 17 years were denied.
Here’s a brief overview of the key changes the FTC chose to include and the persistent loopholes it chose not to tighten or close.
Educational technology: The FTC kept the education rules that allow school personnel to replace verified parental consent (VPC) in educational settings or contexts. They deferred to the Department of Education, saying it will update FERPA. This “pass the buck” has been used by the FTC since COPPA was first passed in 1998. The Department of Education seems more dedicated to its own elimination than to updating FERPA before its demise. This is an egregious loophole.
Avatars and push notifications: Proposed changes to classify avatars as PII and to restrict push notifications to children without parental consent were rejected. However, the FTC expressed concerns about engagement techniques that could harm children’s mental health. A serious loophole.
Maintained Use of Persistent Identifiers:
The FTC failed to prohibit the use of persistent identifiers that encourage children to remain on a site, through in-game prompts or pop-ups. Serious loophole.
Parental Opt-In Consent for Targeted Advertising and Third-Party Disclosures
Websites and online services directed at children must obtain VPC before sharing children’s personally identifiable information (PII) with third-party vendors/contractors for targeted advertising or other commercial purposes.
Parents must be notified of the specific third parties or the categories of third parties receiving their child’s data and the purposes for such disclosures. Categories, are too broad to be informative.
Expanded Definition of Personal Information
Biometric identifiers, such as fingerprints, facial templates, retina patterns, and genetic data are now included as PII under COPPA, as are government-issued identifiers.
New Requirements for “Mixed Audience” Sites
The COPPA Rule defines “mixed audience” sites as those directed at children but not targeting them as their primary audience.
Mixed audience sites may collect PII to determine a user’s age.
Updated Privacy Notice and Parental Consent Requirements
Direct notices to parents must explicitly state how children’s PII will be used.
Privacy policies must include a data retention policy detailing the retention term and use/reasons for retention of children’s PII.
Approved Methods for Initiating and Obtaining VPC
Facial recognition technology to match a parent’s selfie to their official photo ID.
Unique, personal, knowledge-based questions to verify a parent’s identity.
A “text plus” method to obtain VPC, similar to the “email plus” method. The text plus method is only utilized when an operator does not “disclose” children’s PII and must be coupled with additional steps to vet that the person providing consent is the parent.
Data Retention and Security Policy with Actionable Plan
Operators must establish a written data retention policy specifying why children’s PII is collected and its retention term.
Indefinite data retention is strictly prohibited.
A written information security program for operators must be implemented to protect children’s PII, including regular testing and monitoring. It is provided to parents and involved schools. Lacks specifics: when and how often.
Transparency in Safe Harbor Programs (Tech companies form cluster groups of contractors)
FTC-approved Safe Harbor programs must disclose membership and submit additional reports. These programs and reports must be posted on their websites. There are six approved Safe Harbor participants: PRIVO, kidSAFE, ESRB, CARU, iKeepSafe, and TrustArc.
TIE Analysis: Some definitions and language within COPPA are subject to broad interpretation, which can influence how the law is implemented and enforced.
EdTech programs may be Public/Private Partnerships (PPPs) which involve nonprofits, for profits, government entities (schools, school districts, state ed departments, etc.) working under mutually agreed upon Memorandums of Understanding (MOUs) – may include a council of “stakeholders” persons receiving some type of benefits (students, parents, school personnel, etc.). There is opportunity for financial conflicts of interests in PPPs. FTC imposes direct liability on Tech and third party Tech contractor companies after they investigate and find cause. Violations can incur FTC enforcement actions of fines up to $53,088 per violation.
Barbara Bush is a Research Analyst for Truth In Education (TIE), a Christian, Atlanta-based nonprofit organization that exposes harmful ideologies and Marxist globalist agendas in America’s schools and advocates for parental rights.
©2026 All rights reserved. Short quotations may be used with proper attribution. This article may be shared in full, unaltered, with clear attribution to Truth In Education.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.