Assess Applicability: First, confirm whether the website is indeed directed at children under 13, or if it has actual knowledge that it is collecting personal information from children under 13. If not, document this assessment.
Update Privacy Policy: If COPPA applies, revise the website’s privacy policy to include all required elements in a clear and prominent manner:
Explicitly state the types of personal information collected from children (e.g., name, email, photos, persistent identifiers), whether directly or from third parties.
Provide the name, address, email address, and telephone number of all operators collecting or maintaining children’s information.
Describe how the collected information is used by the website or organization.
Explain if children can make their information publicly available.
Provide clear instructions on how parents can review, edit, or delete information shared by their children and how to refuse further collection.
Implement Verifiable Parental Consent (VPC): Before collecting, using, or disclosing any personal information from children under 13, implement a robust and verifiable parental consent mechanism. Methods include obtaining a signed consent form, using a credit card or other payment method, verifying a government-issued ID, or employing knowledge-based authentication.
Data Minimization & Retention: Collect only the information reasonably necessary for the child’s participation in an activity. Establish and adhere to strict data retention policies, deleting children’s information once its purpose is fulfilled.
Parental Control Mechanisms: Provide parents with ongoing control over their child’s information, including the ability to:
Review the personal information collected from their child.
Request deletion of their child’s personal information.
Refuse further collection or use of their child’s information.
Secure Data Handling: Ensure all personal information collected from children is maintained securely and protected against unauthorized access or disclosure.
Age-Gating (If Applicable): If the website is not intended for children under 13, implement an effective age-screening mechanism (e.g., asking for date of birth) to prevent children from accessing or submitting personal information, thereby avoiding COPPA applicability altogether. Be aware that simple age-gates that are easily bypassed may not be sufficient.