Skip to content
COPPAparental consentFTC16 CFR 312children's privacy

COPPA Verifiable Parental Consent Methods

COPPA parental-verification methods, their notice and disclosure conditions, the 2025 dates, and the distinction between voice recordings and biometric identifiers.

Landfall · Published 5 September 2026 · Updated 6 September 2026

The COPPA Rule requires a covered operator to assess its collection, use and disclosure of children's personal information and obtain verifiable parental consent where required. A verification method establishes who is giving consent; it does not authorize every proposed use. Notice, purpose, disclosure and any exception must be assessed separately.

This guide was checked against the current Rule and the 2025 final amendments on 6 September 2026. The eCFR displayed currency through 3 September 2026. The amended Rule became effective on 23 June 2025, with a general compliance date of 22 April 2026; certain safe-harbor program provisions have different dates. Earlier COPPA duties already applied before those amendments.

What a consent method must establish

Under 312.5(b)(1), the operator must make reasonable efforts, considering available technology, to ensure the person consenting is the child's parent. A method does not qualify merely because a vendor calls it identity verification or age assurance.

The named methods in 312.5(b)(2) must be implemented with their actual conditions. Section 312.12 provides a voluntary Commission approval process for additional methods; an approved safe-harbor program can also approve a member's method under 312.5(b)(3). Do not represent an unreviewed alternative as FTC approved.

The parent must receive the applicable direct notice. For a consent request, 312.4(c)(1) includes the information to be collected, its uses, disclosure recipients or specific categories and purposes, the separate disclosure choice where required, the online-notice link, how to consent and the applicable deletion statement if consent is not obtained. Material changes to previously consented practices require assessment of fresh notice and consent.

The named methods and their conditions

Signed form. The parent signs a consent form and returns it by post, fax or electronic scan. Implement the named return method; a generic click or typed name is not automatically this method.

Payment transaction. The parent uses a credit card, debit card or other online payment system in connection with a transaction that notifies the primary account holder of each discrete transaction. Possession of card details alone does not satisfy those conditions.

Trained telephone or video personnel. A parent calls a staffed toll-free number or connects to trained personnel by video conference. A chatbot or an unstaffed recording does not establish the named method.

Government-ID database check. Check the parent's identification against databases of that information and promptly delete the identification after verification. Keeping the raw ID indefinitely for audit convenience conflicts with that deletion condition.

Knowledge-based authentication. Use dynamic multiple-choice questions with enough questions and possible answers to make guessing unlikely. The questions must be difficult enough that a child aged 12 or younger in the parent's household could not reasonably ascertain the answers.

Facial comparison with photo identification. Verify that the submitted government-issued photographic ID is authentic. Compare it with a phone-camera or webcam image using facial recognition, and have trained personnel confirm the match. Promptly delete the identification and images after confirmation. An automated facial match alone omits an express condition.

Email plus. Where the operator does not disclose children's personal information as defined in 312.2, email consent can be coupled with additional steps that provide assurance the person consenting is the parent. The Rule gives examples such as a confirmatory email or confirmation by letter or telephone. Provide notice that the parent can revoke the consent.

Text plus. The amended Rule provides a corresponding text-message method for operators that do not disclose the information. Additional assurance steps and notice of revocation remain necessary. A single text reply is not automatically sufficient.

For the last two methods, use the 312.2 definition of disclosure. It includes identifiable public availability, not just a vendor transfer. The internal-operations qualification has purpose and use limits; a processor contract or an “internal use” label alone does not settle the assessment.

Separate disclosure consent

Section 312.5(a)(2) requires the option to consent to collection and use without consenting to third-party disclosure, unless that disclosure is integral to the website or service. Where the option is required, obtain separate verifiable parental consent to disclosure.

An integral-disclosure assessment concerns that separate-choice requirement. It does not remove other applicable consent, notice, security or use restrictions. Map recipients, purposes and public features before designing the choices. A stronger verification method cannot cure bundled consent where a separate choice is required.

Voice recordings, biometrics and narrow exceptions

An audio file containing a child's voice is personal information under 312.2 even if it is not used for biometric recognition. The amended definition separately covers biometric identifiers that can be used for automated or semi-automated recognition. A raw voice recording is not automatically a voiceprint, and the Rule does not automatically require a stronger parental-verification method merely because the information is a recording or biometric identifier.

Section 312.5(c)(9) contains a narrow audio exception: the operator collects the child's voice file and no other personal information to respond to the child's specific request, uses it for no other purpose, does not disclose it and deletes it immediately after the response. Direct notice is not required for this exception, but the online-notice requirements still apply. A feature that also collects account identifiers, progress data or other personal information cannot assume it qualifies.

Other exceptions in 312.5(c) have different conditions. Repeated responses, for example, have specific child-and-parent contact and notice requirements. The number of exceptions considered is not a legal test; each actual collection and use must satisfy a valid basis. School authorization remains governed by FTC guidance: the final 2025 Rule did not codify the proposed school exception.

A worked example

A fictional learning app stores progress and a child's voice recording. The team first documents its covered activity, actual identifiers, recipients, purposes and notice. It assesses whether its collection/use flow meets the conditions for email plus, including the legal definition of disclosure and the extra assurance and revocation steps. It does not choose an ID-collecting method simply because a recording exists.

The team separately evaluates a proposed tutoring-marketplace disclosure, whether it is integral and whether separate verifiable consent is required. It tests that refusal actually prevents the proposed disclosure. Its retention policy ties each deletion timeframe to the specific purpose and business need; an arbitrary twelve-month period is not permission to retain unnecessary information. The security program includes the written-program, assessment, testing and recipient-assurance duties in 312.8.

Using Landfall

Landfall organizes source references, scope assessments, tasks and evidence for review. The COPPA source pack is undergoing reconciliation; a generated task or questionnaire answer does not establish consent, complete current-rule coverage or legal approval. Check the exact source and data flow before relying on a recommendation. Use the COPPA explorer to inspect records and the AADC vs COPPA guide to compare the different scope questions.

Explore the underlying obligations

This article is grounded in the obligations Landfall maps from source legal text. Browse them yourself:

Questions this article answers

What is the standard a consent method must meet?
Under 16 CFR 312.5(b)(1), any method must be reasonably calculated, in light of available technology, to ensure that the person providing consent is the child's parent. The methods listed in 312.5(b)(2) are ones the FTC has accepted as meeting that test; others can be proposed under 312.12.
When is email plus enough?
Where the operator does not disclose children’s personal information as defined in 312.2, it may couple email consent with additional assurance steps and notice of revocation. Identifiable public availability and internal-operations limits require assessment; an internal-use label alone is insufficient.
What did the 2025 amendments change about consent?
They added knowledge-based authentication, facial matching to photo identification and a text-message analogue of email plus as named methods, and require separate verifiable parental consent before disclosing a child's data to third parties unless the disclosure is integral to the service. Biometric and government identifiers became personal information.
When do the amended rules apply?
The 2025 amended Rule became effective on 23 June 2025, with a general compliance date of 22 April 2026. Certain safe-harbor program provisions have separate dates. Earlier COPPA duties predated the amendments. Sources were checked on 6 September 2026.

Sources

For informational purposes only. This guide is summary-level, informational writing — not legal advice, not a risk score, and not regulatory approval. It does not create an attorney-client relationship. Always consult qualified legal counsel for compliance decisions about your specific product.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations