6 Step Approach To Ensure COPPA Compliance

Introduction:

COPPA (Children’s Online Privacy Protection Act), was proposed in 1998 to address a new type of cyber-marketing technique in which marketing agencies specifically targeted young internet users. Congress passed a bill more than 20 years ago to protect young internet users from companies that collect, maintain, or sell personal data. 

These laws, drafted and enforced by the Federal Trade Commission (FTC), were extremely foresighted, as internet use in the United States has increased by more than 200 percent since the turn of the century, and children today are beginning to explore the worldwide web at an increasingly young age, with almost everyone on their mobile devices. So, why is this important for today’s business owners?

Understanding COPPA and other U.S. privacy laws are critical for any small business owner. Ensuring that your company complies with privacy regulations begins with a thorough understanding of the applicable regulations and a well-written privacy policy.

What is COPPA?

In simple terms, COPPA prohibits website operators from collecting personal information from children under the age of 13 without explicit parental consent. Personal information can range from simple names and addresses to more complex identifiers such as geolocation identifiers, pictures, or audio files containing the child’s voice.

  • What does COPPA define as personal information?

Personal information is defined under the Rule as:

  • Names and last name;
  • A home or other physical address that includes the street name and city or town name;
  • Contact information  available on the internet;
  • A screen name or user name that serves as an online contact address;
  • A contact number;
  • A permanent identifier that can be used to track a user across multiple websites or online services over time;
  • A photograph, video, or audio file containing the image or voice of a child;
  • Geolocation data sufficient to determine street names and a city’s or town’s name; or
  • Information about the child or the child’s parents that the operator collects online from the child and combines with the above-mentioned identification.

The main reason that Facebook and many other popular websites do not allow users under the age of 13 is because of COPPA.

The law, passed by Congress in 1998, specifies what website operators must include in a privacy policy, when and how to obtain parental or guardian consent, and what an operator must do to protect children’s privacy and safety online. It also prohibits marketing to children under the age of thirteen.

The primary goal of COPPA, per the FTC website, is to give parents control over what information is collected from their young children online. The Rule was created to protect children under the age of 13 while taking into account the ever-changing nature of the Internet.

The Rule would apply to operators of commercial websites and online services (including mobile apps) directed to children under 13 that collect, use, or make public personal information from children, as well as operators of general audience websites or online services who have actual knowledge that they are collecting, using, or disclosing personal information from children under 13.

The law also applies to third parties of “child-directed sites,” including plug-ins and advertising networks, that collect personal information from visitors, according to FTC guidelines adopted in 2013.

How does COPPA affect small businesses?

Small businesses must exercise caution. If you operate a website, an online service, or a mobile app that collects information from children under the age of 13, you could face steep fines if you do not follow the Children’s Online Protection Privacy Act (COPPA).

COPPA compliance is not required of all businesses. In general, if your website or service serves children under the age of 13 and you or anyone else collects personal information from them, you must comply with COPPA.

Also, if your website or service is intended for a general audience but you are aware that some children under the age of 13 use it and their personal information is collected, or if you run ads or an ad network and are aware that you are collecting personal information from users, including children under the age of 13, you must comply with COPPA.

If you know or suspect that any of your customers, website users, or online community members are under the age of 13, you can take concrete steps to achieve COPPA compliance.

How to make sure your business is COPPA compliant?

Today’s COPPA regulations are unexpectedly applicable to a wide range of US businesses. As a result, the agency issued a 6-step compliance plan for any company that may be subject to child privacy-protection regulations:

1. Determine whether your company has a website or an online service that collects personal information from children under the age of 13:

The first step is to determine which regulations apply to your business. Although this may seem obvious, a significant number of consumer lawsuits are the result of ignorance or simple misinterpretation of privacy laws. If your website collects personal data (or allows a third party to collect data) and is accessible to children under the age of 13, it must comply with COPPA.

2. Put up a COPPA compliant privacy policy:

The policy is only as strong as its language. Businesses that collect or store personal information about children must be COPPA-compliant, which means they must include the following:

  • What information is being gathered?
  • How is this Data Collected?
  • How is this Data Being Used?
  • If it is being released/sold to third parties.

3. Before collecting personal information from children, notify parents directly:

This is possible with a few provisions in the privacy policy. Again, the parental notification, like the rest of the privacy policy, should be simple and free of jargon.

4. Obtain verifiable consent from parents before collecting personal Information from their children:

This is a COPPA compliance requirement designed to ensure that parents understand who is collecting personal information about their children and for what purpose. Before web operators collect personal information about children, they must obtain parental consent.

According to COPPA compliance guidelines, personal information includes children’s names, addresses, online contact information, social security numbers, a universal identifier that can be used to recognise users across multiple websites, and photographs.

5. Recognize parents’ ongoing rights regarding personal Information collected from their children:

Even after parental consent is obtained and data is collected, operators must respect the rights and safeguards associated with personal information. For example, if a parent requests that you delete the information, you must comply.

6. Implement reasonable procedures to protect the personal Information of children:

Compliance with COPPA does not end when data is collected, stored, or sold. The operator’s responsibility is to ensure that this personally identifiable information is secure and accessible only to the third parties listed in the privacy policy.

Conclusion:

As a small business owner, if you know or suspect that anyone using your website or services is under the age of 13, now is the time to update your staff training, policies, and procedures to protect both your audience and your business. Given the extent of cybersecurity attacks on small businesses, it’s imperative to take suitable steps to safeguard your business. We at Security Pilgrim are here to guide you and assist you in becoming compliant with various compliances and norms that protect your business.

Please follow and like us:

Leave a Comment

Your email address will not be published. Required fields are marked *

RSS
Follow by Email
Facebook
Facebook
fb-share-icon
Twitter
Visit Us
Follow Me
Tweet
YouTube
YouTube
LinkedIn
LinkedIn
Share
WhatsApp