The COPPA Rule requires a covered operator to assess its collection, use and disclosure of children's personal information and obtain verifiable parental consent where required. A verification method establishes who is giving consent; it does not authorize every proposed use. Notice, purpose, disclosure and any exception must be assessed separately.
This guide was checked against the current Rule and the 2025 final amendments on 6 September 2026. The eCFR displayed currency through 3 September 2026. The amended Rule became effective on 23 June 2025, with a general compliance date of 22 April 2026; certain safe-harbor program provisions have different dates. Earlier COPPA duties already applied before those amendments.
What a consent method must establish
Under 312.5(b)(1), the operator must make reasonable efforts, considering available technology, to ensure the person consenting is the child's parent. A method does not qualify merely because a vendor calls it identity verification or age assurance.
The named methods in 312.5(b)(2) must be implemented with their actual conditions. Section 312.12 provides a voluntary Commission approval process for additional methods; an approved safe-harbor program can also approve a member's method under 312.5(b)(3). Do not represent an unreviewed alternative as FTC approved.
The parent must receive the applicable direct notice. For a consent request, 312.4(c)(1) includes the information to be collected, its uses, disclosure recipients or specific categories and purposes, the separate disclosure choice where required, the online-notice link, how to consent and the applicable deletion statement if consent is not obtained. Material changes to previously consented practices require assessment of fresh notice and consent.
The named methods and their conditions
Signed form. The parent signs a consent form and returns it by post, fax or electronic scan. Implement the named return method; a generic click or typed name is not automatically this method.
Payment transaction. The parent uses a credit card, debit card or other online payment system in connection with a transaction that notifies the primary account holder of each discrete transaction. Possession of card details alone does not satisfy those conditions.
Trained telephone or video personnel. A parent calls a staffed toll-free number or connects to trained personnel by video conference. A chatbot or an unstaffed recording does not establish the named method.
Government-ID database check. Check the parent's identification against databases of that information and promptly delete the identification after verification. Keeping the raw ID indefinitely for audit convenience conflicts with that deletion condition.
Knowledge-based authentication. Use dynamic multiple-choice questions with enough questions and possible answers to make guessing unlikely. The questions must be difficult enough that a child aged 12 or younger in the parent's household could not reasonably ascertain the answers.
Facial comparison with photo identification. Verify that the submitted government-issued photographic ID is authentic. Compare it with a phone-camera or webcam image using facial recognition, and have trained personnel confirm the match. Promptly delete the identification and images after confirmation. An automated facial match alone omits an express condition.
Email plus. Where the operator does not disclose children's personal information as defined in 312.2, email consent can be coupled with additional steps that provide assurance the person consenting is the parent. The Rule gives examples such as a confirmatory email or confirmation by letter or telephone. Provide notice that the parent can revoke the consent.
Text plus. The amended Rule provides a corresponding text-message method for operators that do not disclose the information. Additional assurance steps and notice of revocation remain necessary. A single text reply is not automatically sufficient.
For the last two methods, use the 312.2 definition of disclosure. It includes identifiable public availability, not just a vendor transfer. The internal-operations qualification has purpose and use limits; a processor contract or an “internal use” label alone does not settle the assessment.
Separate disclosure consent
Section 312.5(a)(2) requires the option to consent to collection and use without consenting to third-party disclosure, unless that disclosure is integral to the website or service. Where the option is required, obtain separate verifiable parental consent to disclosure.
An integral-disclosure assessment concerns that separate-choice requirement. It does not remove other applicable consent, notice, security or use restrictions. Map recipients, purposes and public features before designing the choices. A stronger verification method cannot cure bundled consent where a separate choice is required.
Voice recordings, biometrics and narrow exceptions
An audio file containing a child's voice is personal information under 312.2 even if it is not used for biometric recognition. The amended definition separately covers biometric identifiers that can be used for automated or semi-automated recognition. A raw voice recording is not automatically a voiceprint, and the Rule does not automatically require a stronger parental-verification method merely because the information is a recording or biometric identifier.
Section 312.5(c)(9) contains a narrow audio exception: the operator collects the child's voice file and no other personal information to respond to the child's specific request, uses it for no other purpose, does not disclose it and deletes it immediately after the response. Direct notice is not required for this exception, but the online-notice requirements still apply. A feature that also collects account identifiers, progress data or other personal information cannot assume it qualifies.
Other exceptions in 312.5(c) have different conditions. Repeated responses, for example, have specific child-and-parent contact and notice requirements. The number of exceptions considered is not a legal test; each actual collection and use must satisfy a valid basis. School authorization remains governed by FTC guidance: the final 2025 Rule did not codify the proposed school exception.
A worked example
A fictional learning app stores progress and a child's voice recording. The team first documents its covered activity, actual identifiers, recipients, purposes and notice. It assesses whether its collection/use flow meets the conditions for email plus, including the legal definition of disclosure and the extra assurance and revocation steps. It does not choose an ID-collecting method simply because a recording exists.
The team separately evaluates a proposed tutoring-marketplace disclosure, whether it is integral and whether separate verifiable consent is required. It tests that refusal actually prevents the proposed disclosure. Its retention policy ties each deletion timeframe to the specific purpose and business need; an arbitrary twelve-month period is not permission to retain unnecessary information. The security program includes the written-program, assessment, testing and recipient-assurance duties in 312.8.
Using Landfall
Landfall organizes source references, scope assessments, tasks and evidence for review. The COPPA source pack is undergoing reconciliation; a generated task or questionnaire answer does not establish consent, complete current-rule coverage or legal approval. Check the exact source and data flow before relying on a recommendation. Use the COPPA explorer to inspect records and the AADC vs COPPA guide to compare the different scope questions.