Clym Logo

Children's Online Privacy Looks Different This School Year, Even Without COPPA 2.0

Published
AS
AuthorAdam Safar
9 min read

COPPA 2.0 status for schools

COPPA 2.0 passed the Senate in March 2026 but is not yet law. The FTC's amended COPPA Rule and new enforcement already reshape 2026-27 school privacy.

Summarize full article with:

During the 2024 - 2025 school year, school districts accessed nearly 3,000 distinct education technology tools, with that number climbing every year students go online for class. LearnPlatform by Instructure tracked a nearly 9% year-over-year increase, and every one of those tools touches student data that falls under a patchwork of federal and state privacy rules.

Congress has spent more than two years trying to rewrite the federal rulebook for children's online privacy, and it still hasn't finished the job. Here's the twist: children's online privacy has already changed for the 2026-27 school year, with or without that new law. This post breaks down what's actually different, what's still stuck in Congress, and what it means for schools and the edtech companies serving them.

Key takeaways

  • COPPA 2.0 passed the Senate unanimously on March 5, 2026, but has not become law.

  • The FTC's amended COPPA Rule already tightened protections for children under 13, with full compliance required by April 22, 2026.

  • A federal court ordered Disney to pay $10 million in December 2025 over COPPA violations tied to child-directed YouTube videos.

  • School districts accessed nearly 3,000 distinct edtech tools in the 2024-25 school year, up almost 9% year over year.

  • FERPA and COPPA can both apply to the same classroom tool, creating overlapping obligations for schools and vendors.

  • COPPA 2.0 would extend federal privacy protections to teens ages 13 to 16, a gap current law leaves open.

What is COPPA 2.0, and why hasn't it passed?

COPPA 2.0, formally the Children and Teens' Online Privacy Protection Act, is the Senate's proposal to update the original 1998 Children's Online Privacy Protection Act, or COPPA. If passed, it would extend federal privacy protections beyond children under 13 years old to teenagers aged 13 to 16, it would restrict targeted advertising to minors, and would create an eraser button that lets young people or their parents request correction or deletion of personal data.

On March 5, 2026, the Senate passed COPPA 2.0 by unanimous consent. Senator Edward Markey's office called it the most significant update to the federal children's privacy framework in more than 25 years. The House hasn't matched that pace. Its companion bill, H.R. 6291, moved from a subcommittee to the full Energy and Commerce Committee in December 2025, but congressional records show no further action as of July 2026.

What COPPA 2.0 would change for teens

  • Extend coverage from under-13 only to ages 13 through 16

  • Ban targeted advertising that uses a minor's personal information

  • Add an eraser button, letting minors or parents request data deletion, a right similar in spirit to the data subject request tools many companies already use to handle deletion requests under other privacy laws

  • Keep enforcement authority with the FTC and state attorneys general

The rules for children under 13 already changed

COPPA 2.0's delay hasn't frozen children's privacy regulation. The FTC finalized amendments to the COPPA Rule that took effect June 23, 2025, and operators had until April 22, 2026, to meet every new requirement, a deadline that fell squarely inside the 2025-26 school year. Requirements included:

  • Expanding the definition of personal information to include biometric identifiers

  • Requiring separate verifiable parental consent before sharing children's data with third parties for targeted advertising

  • Setting firmer limits on how long companies can retain children's personal information

Enforcement hasn't waited either

In December 2025, a federal judge approved a $10 million settlement with Disney over allegations that the company let personal data be collected from children viewing child-directed videos on YouTube without the parental notice and consent COPPA requires. The order also required Disney to build a program for reviewing which videos should be labeled as made for kids.

Clym has also covered an FTC settlement involving an edtech company accused of similar COPPA violations, a sign that enforcement is reaching beyond household names and into the everyday tools schools use.

Schools sit at the intersection of COPPA and FERPA

Classroom technology adds another layer, because student information can fall under more than one federal privacy law at once. The Family Educational Rights and Privacy Act, or FERPA, protects the privacy of education records at schools and agencies that receive federal funding. U.S. Department of Education guidance directs schools to evaluate third-party online services on a case-by-case basis before sharing student data with them.

COPPA, by contrast, applies to covered online services that collect personal information from children under 13, whether or not a school is involved. The two laws regulate different relationships and different types of data, but they frequently overlap once a school introduces an outside technology vendor into the classroom.

Edtech vendors juggling COPPA, FERPA, and a growing list of state student privacy laws at the same time often need a way to manage access, correction, and deletion requests without building a separate process for each one. Clym's data subject request management, linked above, centralizes those workflows so requests don't fall through the cracks as obligations stack up.

COPPA vs. COPPA 2.0 at a glance

Aspect

COPPA (current law)

COPPA 2.0 (proposed)

Age covered

Under 13

Under 13, plus teens 13 to 16

Targeted advertising

Not directly addressed

Banned using minors' personal information

Data deletion

Parental review and deletion rights

"Eraser button" for minors or parents

Status as of July 2026

Law since 1998, amended by the FTC in 2025

Passed the Senate in March 2026, pending a House vote

Enforcement

FTC and state attorneys general

FTC and state attorneys general

The debate keeps shifting toward teenagers

The gap COPPA 2.0 targets sits right after a child turns 13. A 12-year-old and a 14-year-old can use the same social app, game, or classroom platform, but only one of them is covered by COPPA today.

That distinction matters more every year digital tools become part of school, entertainment, and social life. States haven't waited for Congress either. A growing number have passed their own youth privacy and online safety laws, and Clym's comparison of U.S. state privacy laws tracks how those requirements differ from state to state. The result is a children's privacy landscape shaped as much by state legislatures and FTC rulemaking as by the original 1998 statute.

What schools and edtech companies should do now

  • Map which of your products or services collect data from users under 13, and separately, under 18.

  • Confirm your verifiable parental consent process reflects the FTC's 2025 amendments, including consent for third-party data sharing, now that the April 22, 2026 deadline has passed.

  • Review how long you retain children's personal information and tighten retention schedules where needed.

  • Coordinate with school partners on FERPA's data-sharing requirements before rolling out new classroom tools.

  • Keep an eye on COPPA 2.0 and state-level youth privacy bills, since either could change what's required with little notice.

How Clym supports children's and student privacy efforts

Clym's platform is built to help privacy teams manage more than one framework at once instead of standing up a new process every time a law changes. Beyond consent management and data subject requests, tools like age gating help apply the right experience based on a visitor's declared age, which matters as more services try to separate how they treat child, teen, and adult users. None of this replaces legal advice or guarantees a particular compliance outcome, but it does give privacy and engineering teams a single place to manage the moving pieces.

Conclusion

COPPA 2.0's unanimous Senate passage shows there's broad agreement that a law written in 1998 doesn't cover every way children and teenagers interact with digital services today. What's still unresolved is whether the House will follow the Senate's lead, and how a new federal law would sit alongside the state rules already in place.

For students heading into the 2026-27 school year, though, children's online privacy is already different without a new act of Congress. The FTC has tightened the rules for services covered by COPPA, enforcement has reached a company as large as Disney, and schools are managing thousands of digital tools under obligations that come from more than one direction at once.

The debate over teenagers and online privacy isn't finished, but the ground has already shifted under everyone currently building for, or buying from, the K-12 and youth technology market.

Frequently asked questions

COPPA 2.0 is the Children and Teens' Online Privacy Protection Act, a Senate bill that would extend federal privacy protections to teens ages 13 to 16, ban targeted advertising to minors, and let young people or parents request deletion of personal data. It passed the Senate in March 2026 but is not yet law.

Not as of July 2026. The Senate passed COPPA 2.0 unanimously on March 5, 2026, but the House companion bill, H.R. 6291, has only advanced to committee and has not reached a full House vote.

The FTC finalized amendments to the COPPA Rule that expanded the definition of personal information to include biometric identifiers, added consent requirements for sharing children's data with third parties, and limited how long that data can be retained. Operators had until April 22, 2026, to fully comply.

COPPA applies to online services that collect personal information from children under 13, whether or not a school is involved. Schools themselves are more directly governed by FERPA, though the two laws often overlap when a school uses outside classroom technology.

COPPA regulates how online services collect data from children under 13. FERPA protects the privacy of student education records at schools and agencies that receive federal funding. They cover different relationships and types of data, but can both apply to the same classroom tool.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam