The COPPA Rule Just Got Its First Real Update in 12 Years. Here's What It Means for Your Kid's Data.

The FTC's updated COPPA rule took effect April 22, 2026, adding biometric data protections and AI training restrictions for kids. Here's what parents need to know and do right now.

My son's favorite game asked him to scan his face last month.

He is nine. He wanted to use the voice chat feature in Roblox, the game where 100 million people log in daily and roughly 40 percent of them are children. To unlock the ability to talk to his friends — kids he already knows from school, kids he sits next to at lunch — the game told him to look into his iPad camera while a third-party company called Persona captured a biometric scan of his face. No parental consent screen. No separate permission. He almost did it before I walked by and saw the prompt.

That company keeps the data for up to three years.

I spent the next two hours reading privacy policies, and what I found made me angry enough to write this. Because three weeks ago, on April 22, 2026, the Federal Trade Commission's updated COPPA Rule finally took effect — the first real overhaul of children's online privacy protections since 2013. And almost no parent I've talked to knows it happened.

What COPPA Is (and What It Wasn't Doing)

COPPA — the Children's Online Privacy Protection Act — has been the only federal law protecting kids' data online since 1998. It requires apps and websites to get parental consent before collecting personal information from children under 13. That sounds good on paper.

The problem is that for 12 years, the rule defining what counts as "personal information" hadn't been updated. It still reflected a world where the biggest privacy threat was a kid typing their home address into a chat room. It said nothing about face scans. Nothing about voiceprints. Nothing about an app harvesting your child's behavioral data to train an artificial intelligence model.

The FTC voted 5-0 on January 16, 2025 to fix that. Companies had until April 22, 2026 to comply. That deadline has passed. The rules are live. And they change several things that matter to you right now.

Your Kid's Face Is Now Legally Protected

The single biggest change is this: biometric data is now explicitly classified as personal information under COPPA.

That means fingerprints, face templates, retina scans, voiceprints, and even gait patterns are now covered. Before April 22, a kids' app could scan your child's face and argue it wasn't collecting "personal information" under the old definitions. That argument is dead.

This matters because face scanning in kids' apps is not hypothetical — it is happening at scale. Roblox rolled out its facial verification system in January 2026, requiring users to scan their faces through a third-party biometric vendor to access voice chat. Disneyland started using facial recognition for park entry in late 2025. Meta has been building facial recognition into its Ray-Ban smart glasses — technology that could identify your child from across a playground.

Under the updated COPPA Rule, any operator collecting biometric data from a child under 13 must get verifiable parental consent first. If your nine-year-old is asked to scan his face to use a feature, the company needs your explicit, separate permission before that scan happens.

I want to be honest about what I don't know yet: whether Roblox's existing facial verification flow actually complies with the updated rule, or whether it was designed under the old framework and hasn't been updated. That's a question the FTC will need to answer, and I suspect they're already looking at it.

No Company Can Train AI on Your Kid's Data Without Asking You

Here is the change that should make every parent sit up.

The updated rule explicitly states that collecting a child's personal information to train artificial intelligence models is never considered "integral to the service." That is the FTC's exact language, and it matters because of how consent works under COPPA.

The old rule allowed companies to bundle consent: if collecting your kid's data was necessary to provide the service (the game, the app, the platform), they could roll it into the general terms of service. One "I agree" covered everything. The updated rule says AI training doesn't qualify for that exemption. Ever. If a company wants to use your child's drawings, voice recordings, chat logs, gameplay patterns, or any other data to train a machine learning model, they need to come back and ask you for separate, verifiable parental consent — a completely different consent interaction from the one that let your kid use the app in the first place.

Think about what that means. Every educational app that feeds student work into an AI model. Every game that records voice chat to train speech recognition. Every "kids' creativity" platform that uses uploaded drawings to improve its generation engine. All of them need to ask you separately, and you have the right to say no without losing access to the core service.

This is a bigger deal than most parents realize, and it arrived without fanfare.

Your Kid's Data Can't Be Kept Forever Anymore

The old COPPA Rule said almost nothing about how long companies could hold your child's data. An app could collect information from your six-year-old and keep it indefinitely — through their teenage years, into adulthood, forever.

That's over. The updated rule requires every operator to establish and maintain a written data retention policy specifically for children's data. They must delete personal information when it's no longer needed for the purpose it was collected. No more indefinite storage.

Here's the practical test: go to any app your child uses. Pull up the privacy policy. If it says data is retained "indefinitely" or doesn't specify a retention period, that app may now be in violation of federal law. You can report it.

The Penalties Are Not Small

COPPA violations now carry penalties of up to $53,088 per violation, per child, per instance. The FTC has publicly stated that COPPA enforcement is a top priority for 2026.

This is not an empty threat. Recent enforcement history includes Epic Games paying $520 million to settle COPPA-related charges. Google paid $170 million over YouTube violations. Cognosphere (the Genshin Impact developer) agreed to $20 million for collecting kids' data without parental consent. These are real numbers from real cases, and the updated rule gives the FTC substantially more surface area to pursue them.

But I want to be clear about something that frustrates me: enforcement is reactive. The FTC investigates complaints. It doesn't monitor every app in real time. Which means parents are still the first line of detection, even under a stronger rule. That hasn't changed, and pretending it has would be dishonest.

What You Should Do This Week

I'm going to be specific, because vague advice is useless advice.

Check your child's app permissions tonight. On iOS, go to Settings > Privacy & Security and review which apps have access to the camera, microphone, and location. On Android, go to Settings > Apps > Permissions. If a game doesn't need the camera, revoke it. Do this for every app, and it will take you about fifteen minutes. I timed it.

Read the privacy policy of your child's three most-used apps. I know that sounds terrible. Look for three things: (1) whether they mention biometric data, (2) whether they mention AI or machine learning, and (3) what their data retention period is. If any app collects biometric data or uses data for AI training, it should be asking for your separate consent. If it isn't, that's a red flag.

Talk to your kids about face scanning. My son didn't think twice about the Roblox prompt. It looked like any other pop-up. Kids need to understand that scanning their face is giving away something they can never take back — it's not the same as entering a username. Have this conversation before it comes up, not after.

Know how to file a complaint. If an app is collecting your child's biometric data without consent, or keeping data indefinitely, or training AI on your kid's information without separate permission, file a complaint at reportfraud.ftc.gov. The FTC acts on complaint volume. Your report matters more than you think.

What This Rule Cannot Do

I could end here on a positive note — the rule is stronger, protections are real, parents have new rights. That would be the comfortable ending.

But the honest one is harder.

The updated COPPA Rule only applies to children under 13. The moment your kid turns thirteen, these protections vanish. COPPA 2.0 — the legislation that would extend protections to teens under 17 — passed the Senate unanimously in March 2026 but hasn't been signed into law. Your thirteen-year-old is still exposed.

The rule also can't fix the fundamental problem that enforcement depends on companies being caught. A small app developer in another country collecting your child's voice data to train a model? The FTC has limited jurisdiction and limited resources. The February 2026 FTC policy statement on age verification tries to address some of this, but the reality is that a law is only as strong as its enforcement.

And the rule can't replace the conversation you have with your kids. No regulation can teach a nine-year-old why he shouldn't scan his face for a video game. That's on us. That will always be on us.

The COPPA Rule update is a genuine, meaningful step. It protects data that didn't exist when the original law was written. It creates rights that parents didn't have three weeks ago. Use them. But don't mistake them for the whole solution.

Your kid still needs you more than they need a regulation.

Digipalz helps parents and educators stay ahead of the threats kids face online — from AI chatbots to biometric data collection. We break down what's real, what's hype, and what you should do about it. Start your free trial today.

If your child is in crisis or you are concerned about their safety online, contact the Childhelp National Child Abuse Hotline at 1-800-422-4453 or the Crisis Text Line by texting HOME to 741741.

Sources