Amendment to increase restrictions on the collection, use, and disclosure of children’s personal information
KPMG Regulatory Insights
_____________________________________________________________________________________________________________________________________________________
January 2024
In line with regulatory focus around "big tech", data use/access and data security, the Federal Trade Commission (FTC or “Commission”) issues a notice of proposed rulemaking (NPR) to amend its rule implementing the Children’s Online Privacy Protection Act (COPPA), which requires websites and online services to obtain verifiable parental consent before collecting, using, or disclosing children's personal information (the rule was last updated in 2013).
Key amendments proposed by the FTC include:
1. Definition changes. Proposed definition changes to the FTC’s Children's Online Privacy Protection Rule (COPPA Rule) such as:
The FTC states these proposed modifications aim to clarify the scope, strengthen the protections of the COPPA Rule in response to evolving technology and online practices as well as to address potential compliance “loopholes”.
2. Additional requirements for the “support for internal operations” exemption. The COPPA Rule currently exempts from its notice and consent requirements operators of online services that collect persistent identifiers only for the purpose of “providing support for the internal operations of the website or online service.” The proposed amendments would change this by requiring operators of online services currently exempt from obtaining parental consent to provide notice specifying how collected data is used and prohibiting operators from using or disclosing persistent identifiers to “maximize user engagement” including “sending notifications to prompt the child to engage with the site or service, without verifiable parental consent”.
3. Parental consent mechanisms and disclosures to third parties. The Commission proposes adding knowledge-based authentication and facial recognition technology as additional methods to verify parental consent. Further, updated disclosure requirements entail:
4. Codifying the school authorization exception. The proposed school authorization exception would require operators that collect personal information from children under the school authorization exception to provide an additional notice on their website or online service disclosing that: (1) they obtained authorization from a school to collect a child’s personal information; (2) they will use and disclose the information for only a school-authorized education purpose; and (3) the school may review and request deletion of information collected from a child.
Further, the FTC proposes to prohibit commercial use of children’s information and implement additional safeguards as it relates to the use education technology (ed tech). “The proposed rule would allow schools and school districts to authorize ed tech providers to collect, use, and disclose students’ personal information but only for a school-authorized educational purpose and not for any commercial purpose”.
5. Data retention limits. Under the proposal, the Commission expands on current data minimization requirements, which “prohibit an operator from conditioning a child’s participation in a game, the offering of a prize, or another activity on the child’s disclosing more personal information than is reasonably necessary to participate in such activity”, by proposing:
6. Enhanced data security requirements. Additional data security requirements proposed by the FTC will require operators to at minimum “establish, implement, and maintain a written comprehensive security program containing safeguards appropriate to the sensitivity of children's information and considering the operator's size, complexity, and the nature and scope of its activities”. These requirements are modelled on the Commission’s original Safeguards Rule implemented under the Gramm-Leach-Bliley Act (GLBA).
7. Safe Harbor program reporting requirements. In an effort to increase transparency and accountability of COPPA Safe Harbor programs, the Commission proposes requiring FTC-approved COPPA Safe Harbor programs to:
Comment period. Public comments on the proposed changes must be submitted by March 11, 2024.
Privacy: FTC NPR to Children’s Online Privacy (COPPA)
Amendment to increase restrictions on the collection, use, and disclosure of children’s personal information
Download PDFPoints of View
Insights and analyses of emerging regulatory issues and their impact.
Regulatory Insights View
Series covering regulatory trends and emerging topics
Regulatory Alerts
Quick hitting summaries of specific regulatory developments and their impact.
KPMG Regulatory Insights is the thought leader hub for timely insight on risk and regulatory developments.