COPPA, the Children's Online Privacy Protection Act, is the US law that requires verifiable parental consent before an online service collects personal data from children under 13. It shapes how any service that might reach kids handles age, consent, and data, and it intersects with fraud through age falsification and identity risk.
What is COPPA?
COPPA governs how online services handle the personal data of children under 13 in the US. If a service is aimed at children, or knows it is collecting data from a child under 13, it must get verifiable consent from a parent before gathering that data, tell parents what it collects and why, and let them review or delete it.
The law also limits what can be done with children's data: services should collect only what they need, keep it no longer than necessary, and protect it. The Federal Trade Commission enforces it, and the penalties for getting it wrong are significant, which is why many services build age gates and simply avoid serving under-13 users at all.
For fraud teams, COPPA sits at an interesting crossroads. It forces services to reason about age, which pulls age verification and identity into the product, and it creates an incentive for underage users to lie about their age, which is a small but real form of identity falsification that has downstream consequences.
What the law actually requires
The obligations cluster around consent, transparency, and data minimization.
Requirement | What it means |
Parental consent | Get verifiable consent from a parent before collecting a child's personal data. |
Clear notice | Explain what is collected, how it is used, and who it is shared with. |
Data minimization | Collect only what the service genuinely needs from a child. |
Parental control | Let parents review, delete, and stop further collection of their child's data. |
Security and retention | Protect the data and keep it no longer than necessary. |
What it looks like in practice
A consumer app that was never meant for children starts seeing signups where the stated age, the content interests, and the device pattern all suggest young users slipping past a weak age gate. Because those accounts may involve under-13 users, they create COPPA exposure the company never intended to take on.
The trust and safety team strengthens the age gate, adds signals to detect likely underage accounts, and routes them to a compliant flow or closes them. The same work helps fraud, because the tools that estimate real age and catch falsified birthdates overlap with the tools that catch identity mismatches and fabricated profiles elsewhere in the product.
What it means for operators day to day
If there is any chance your service reaches children, COPPA turns age and consent into product requirements rather than afterthoughts. You need a defensible way to know or estimate age, a real consent path for parents where relevant, and data practices that minimize what you hold on young users. The penalties are large enough that many teams deliberately design to exclude under-13 users to sidestep the burden entirely.
For fraud and identity teams, the connection is age falsification. COPPA gives minors a strong reason to misstate their birthdate, and the same age-estimation and document checks used for compliance are the ones that catch falsified ages and mismatched identities more broadly. Building age verification well serves both the legal requirement and the fraud program at once.
What to watch in the data
- Age gate evasion. Signups where stated age conflicts with behavior, content, or device signals suggest falsified birthdates.
- Just-over-the-line ages. A cluster of accounts claiming to be exactly old enough to pass a gate can indicate coaching or evasion.
- Inconsistent identity data. Birthdates that do not match other identity signals are both a COPPA and a fraud concern.
- Parental consent friction. Drop-off or workarounds at the consent step may mean users are bypassing rather than completing it.
- Data you should not hold. Collection of sensitive fields from likely-underage accounts is a compliance red flag worth alerting on.
Quick questions
Who does COPPA apply to?
Operators of online services directed to children under 13, and any service that has actual knowledge it is collecting data from a child under 13. It applies regardless of whether the company intended to serve children, which is why unintended underage signups create real exposure.
What counts as verifiable parental consent?
It is a step that reasonably confirms an actual parent is consenting, not just a checkbox. Accepted methods include measures that tie consent to a verifiable adult, and the required rigor scales with how the child's data will be used.
How does COPPA relate to fraud?
It creates a strong incentive for minors to lie about their age, a form of identity falsification. The age-estimation and document-check tools used to comply are the same ones that catch falsified ages and mismatched identities across the wider fraud program.
Why do so many services just ban under-13 users?
Because meeting COPPA's consent and data obligations is costly and the penalties are steep. Excluding under-13 users with a solid age gate is often simpler than building a fully compliant children's data flow.
Does COPPA cover teenagers?
Its core requirements focus on children under 13. Older minors are addressed by other privacy laws and evolving rules, so a full program usually layers COPPA with broader youth-privacy and data-protection obligations.
O que saber junto com COPPA

Relatório de Fraude e AML 2026
Esqueça as previsões. Este relatório detalha com o que as equipes de fraude e AML estão realmente lidando, e como responder.

