COPPA 2.0 status for schools
COPPA 2.0 passed the Senate in March 2026 but is not yet law. The FTC's amended COPPA Rule and new enforcement already reshape 2026-27 school privacy.
COPPA 2.0 passed the Senate in March 2026 but is not yet law. The FTC's amended COPPA Rule and new enforcement already reshape 2026-27 school privacy.
During the 2024 - 2025 school year, school districts accessed nearly 3,000 distinct education technology tools, with that number climbing every year students go online for class. LearnPlatform by Instructure tracked a nearly 9% year-over-year increase, and every one of those tools touches student data that falls under a patchwork of federal and state privacy rules.
Congress has spent more than two years trying to rewrite the federal rulebook for children's online privacy, and it still hasn't finished the job. Here's the twist: children's online privacy has already changed for the 2026-27 school year, with or without that new law. This post breaks down what's actually different, what's still stuck in Congress, and what it means for schools and the edtech companies serving them.
COPPA 2.0 passed the Senate unanimously on March 5, 2026, but has not become law.
The FTC's amended COPPA Rule already tightened protections for children under 13, with full compliance required by April 22, 2026.
A federal court ordered Disney to pay $10 million in December 2025 over COPPA violations tied to child-directed YouTube videos.
School districts accessed nearly 3,000 distinct edtech tools in the 2024-25 school year, up almost 9% year over year.
FERPA and COPPA can both apply to the same classroom tool, creating overlapping obligations for schools and vendors.
COPPA 2.0 would extend federal privacy protections to teens ages 13 to 16, a gap current law leaves open.
COPPA 2.0, formally the Children and Teens' Online Privacy Protection Act, is the Senate's proposal to update the original 1998 Children's Online Privacy Protection Act, or COPPA. If passed, it would extend federal privacy protections beyond children under 13 years old to teenagers aged 13 to 16, it would restrict targeted advertising to minors, and would create an eraser button that lets young people or their parents request correction or deletion of personal data.
On March 5, 2026, the Senate passed COPPA 2.0 by unanimous consent. Senator Edward Markey's office called it the most significant update to the federal children's privacy framework in more than 25 years. The House hasn't matched that pace. Its companion bill, H.R. 6291, moved from a subcommittee to the full Energy and Commerce Committee in December 2025, but congressional records show no further action as of July 2026.
Extend coverage from under-13 only to ages 13 through 16
Ban targeted advertising that uses a minor's personal information
Add an eraser button, letting minors or parents request data deletion, a right similar in spirit to the data subject request tools many companies already use to handle deletion requests under other privacy laws
Keep enforcement authority with the FTC and state attorneys general
COPPA 2.0's delay hasn't frozen children's privacy regulation. The FTC finalized amendments to the COPPA Rule that took effect June 23, 2025, and operators had until April 22, 2026, to meet every new requirement, a deadline that fell squarely inside the 2025-26 school year. Requirements included:
Expanding the definition of personal information to include biometric identifiers
Requiring separate verifiable parental consent before sharing children's data with third parties for targeted advertising
Setting firmer limits on how long companies can retain children's personal information
In December 2025, a federal judge approved a $10 million settlement with Disney over allegations that the company let personal data be collected from children viewing child-directed videos on YouTube without the parental notice and consent COPPA requires. The order also required Disney to build a program for reviewing which videos should be labeled as made for kids.
Clym has also covered an FTC settlement involving an edtech company accused of similar COPPA violations, a sign that enforcement is reaching beyond household names and into the everyday tools schools use.
Classroom technology adds another layer, because student information can fall under more than one federal privacy law at once. The Family Educational Rights and Privacy Act, or FERPA, protects the privacy of education records at schools and agencies that receive federal funding. U.S. Department of Education guidance directs schools to evaluate third-party online services on a case-by-case basis before sharing student data with them.
COPPA, by contrast, applies to covered online services that collect personal information from children under 13, whether or not a school is involved. The two laws regulate different relationships and different types of data, but they frequently overlap once a school introduces an outside technology vendor into the classroom.
Edtech vendors juggling COPPA, FERPA, and a growing list of state student privacy laws at the same time often need a way to manage access, correction, and deletion requests without building a separate process for each one. Clym's data subject request management, linked above, centralizes those workflows so requests don't fall through the cracks as obligations stack up.
Aspect | COPPA (current law) | COPPA 2.0 (proposed) |
|---|---|---|
Age covered | Under 13 | Under 13, plus teens 13 to 16 |
Targeted advertising | Not directly addressed | Banned using minors' personal information |
Data deletion | Parental review and deletion rights | "Eraser button" for minors or parents |
Status as of July 2026 | Law since 1998, amended by the FTC in 2025 | Passed the Senate in March 2026, pending a House vote |
Enforcement | FTC and state attorneys general | FTC and state attorneys general |
The gap COPPA 2.0 targets sits right after a child turns 13. A 12-year-old and a 14-year-old can use the same social app, game, or classroom platform, but only one of them is covered by COPPA today.
That distinction matters more every year digital tools become part of school, entertainment, and social life. States haven't waited for Congress either. A growing number have passed their own youth privacy and online safety laws, and Clym's comparison of U.S. state privacy laws tracks how those requirements differ from state to state. The result is a children's privacy landscape shaped as much by state legislatures and FTC rulemaking as by the original 1998 statute.
Map which of your products or services collect data from users under 13, and separately, under 18.
Confirm your verifiable parental consent process reflects the FTC's 2025 amendments, including consent for third-party data sharing, now that the April 22, 2026 deadline has passed.
Review how long you retain children's personal information and tighten retention schedules where needed.
Coordinate with school partners on FERPA's data-sharing requirements before rolling out new classroom tools.
Keep an eye on COPPA 2.0 and state-level youth privacy bills, since either could change what's required with little notice.
Clym's platform is built to help privacy teams manage more than one framework at once instead of standing up a new process every time a law changes. Beyond consent management and data subject requests, tools like age gating help apply the right experience based on a visitor's declared age, which matters as more services try to separate how they treat child, teen, and adult users. None of this replaces legal advice or guarantees a particular compliance outcome, but it does give privacy and engineering teams a single place to manage the moving pieces.
COPPA 2.0's unanimous Senate passage shows there's broad agreement that a law written in 1998 doesn't cover every way children and teenagers interact with digital services today. What's still unresolved is whether the House will follow the Senate's lead, and how a new federal law would sit alongside the state rules already in place.
For students heading into the 2026-27 school year, though, children's online privacy is already different without a new act of Congress. The FTC has tightened the rules for services covered by COPPA, enforcement has reached a company as large as Disney, and schools are managing thousands of digital tools under obligations that come from more than one direction at once.
The debate over teenagers and online privacy isn't finished, but the ground has already shifted under everyone currently building for, or buying from, the K-12 and youth technology market.
COPPA 2.0 is the Children and Teens' Online Privacy Protection Act, a Senate bill that would extend federal privacy protections to teens ages 13 to 16, ban targeted advertising to minors, and let young people or parents request deletion of personal data. It passed the Senate in March 2026 but is not yet law.
Not as of July 2026. The Senate passed COPPA 2.0 unanimously on March 5, 2026, but the House companion bill, H.R. 6291, has only advanced to committee and has not reached a full House vote.
The FTC finalized amendments to the COPPA Rule that expanded the definition of personal information to include biometric identifiers, added consent requirements for sharing children's data with third parties, and limited how long that data can be retained. Operators had until April 22, 2026, to fully comply.
COPPA applies to online services that collect personal information from children under 13, whether or not a school is involved. Schools themselves are more directly governed by FERPA, though the two laws often overlap when a school uses outside classroom technology.
COPPA regulates how online services collect data from children under 13. FERPA protects the privacy of student education records at schools and agencies that receive federal funding. They cover different relationships and types of data, but can both apply to the same classroom tool.