Get a Quote
Compliance › COPPA & FERPA

COPPA & FERPA Compliance for AI-Built Apps

Kids' and edtech apps face two distinct federal regimes. COPPA (FTC-enforced) applies to any service directed to children under 13, requiring verifiable parental consent before collecting personal information — violations run up to per child, per day. FERPA (Dept. of Education) applies to schools and reaches vendors through the "school official" exception; it carries no fines and no private lawsuit right, but non-compliance means losing district contracts. AI app builders scaffold neither consent flow, and the amended COPPA Rule's full-compliance deadline lands 2026-04-22.

Get a Free Compliance Scan See Audit Pricing
Who It Applies To

Triggers & penalties — two separate laws

COPPA triggers when a service is "directed to children" under 13 (the FTC weighs subject matter, visuals, animated characters, music, child models, ads, and audience evidence), or when a general-audience service has actual knowledge it's collecting personal information from an under-13 user. "Personal information" now includes biometric identifiers under the 2025 amendments, alongside names, emails, geolocation, photos/video/audio, and persistent identifiers like cookies and device IDs.

LawPenaltyNotable cases
COPPA (FTC)Up to per violation — each child, each day can count (2025 inflation figure, carried into 2026 after the adjustment was cancelled)Cognosphere/Genshin M (Jan 2025); Disney M (Sept 2025, approved Dec 2025); Apitor K suspended (2025); TikTok/ByteDance suit pending (filed Aug 2024)
FERPA (Dept. of Ed)No fines, no private lawsuit (Gonzaga Univ. v. Doe, 2002) — the lever is loss of federal funding and exclusion from district contractsED Student Privacy Policy Office can require corrective action; funding withholding has never actually been used
NY Education Law §2-d first violation / second / subsequent, against contractorsAdds direct, penalizable vendor obligations FERPA itself lacks
California SOPIPAAG-enforced via the Unfair Competition Law (no set penalty schedule)Bans targeted ads, profiling, and sale of K-12 student data (effective 2016-01-01)

Sources: federalregister.gov 2025/04/22 (amended COPPA Rule); ftc.gov (2025 civil penalty inflation adjustment, ); davispolk.com (Cognosphere); hunton.com (Disney); supreme.justia.com (Gonzaga v. Doe, 536 U.S. 273); nysenate.gov EDN §2-d; leginfo.legislature.ca.gov (SOPIPA).

The Rule

What each law actually requires

RequirementDetail
Direct notice + privacy policy (COPPA)Must list all data collected and every third-party recipient.
Verifiable parental consent (COPPA)An approved method — signed form, payment-card or gov-ID verification, knowledge-based auth, face-match-to-ID, or a phone/video call — before collecting a child's data.
Separate opt-in for third-party disclosure (COPPA, new)The amended Rule requires distinct consent before sharing a child's data for targeted ads — on top of the base VPC.
Written security & retention programs (COPPA, new)A designated coordinator, annual risk assessments, and a written data-retention policy that bans indefinite retention — full compliance required by 2026-04-22.
School official exception (FERPA)A vendor may access education records only if it performs a school function, stays under the school's direct control (written agreement, including deletion rights), and never re-discloses or reuses data commercially.
NY §2-dEncryption of student PII in transit AND at rest, a Parents' Bill of Rights attached to every contract, employee training, and subcontractor flow-down.

Sources: federalregister.gov/documents/2025/04/22/2025-05904; ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions; studentprivacy.ed.gov Vendor FAQ; nysenate.gov EDN §2-d.

The Core Problem

Why AI-built kids'/edtech apps fail

  • Analytics/ad SDKs fire on kids' data by default. Google Analytics, Firebase Analytics, and ad SDKs collect device IDs and persistent identifiers — all COPPA personal information — with no child-directed configuration. Firebase "doesn't offer any of the functionality needed to comply with COPPA" out of the box, and Tilting Point Media was fined K by the California AG in 2024 for misconfigured SDKs in a kids' game.
  • No parental-consent flow. Verifiable parental consent is nontrivial to build, and AI generators never scaffold it — the FTC treats a bypassable age gate as a violation in itself.
  • No deletion mechanism. The amended Rule requires a written retention policy and deletion timelines; FERPA's "direct control" standard requires schools to be able to order deletion on demand.
  • No signed student-data agreement. Using an app with a school without one breaks the FERPA school-official exception outright — and under NY §2-d, the missing contract itself is penalizable.
  • PII lands in logs and prompts. Vibe-coded apps log request bodies containing names, emails, and student records, and pass that data through LLM APIs — an unauthorized disclosure with no retention control.
  • Ad monetization defaults expose kids. AdMob requires an explicit setTagForChildDirectedTreatment(true) call plus G-rated content; left unset, the ad ID still transmits for child users.
  • The written security program itself is missing. Amended COPPA's requirement for a coordinator, risk assessments, and documented testing is an artifact no AI builder produces.

Sources: respectlytics.com (SDK leakage, Tilting Point K 2024); support.google.com/admob/answer/6219315; studentprivacy.ed.gov Vendor FAQ; bassberry.com (amended-Rule retention/security).

Platform By Platform

Student-data & kids'-app posture, by platform

PlatformCOPPA / FERPA posture
LovableUsers must be 18+ ("not intended for under 18"); has SOC 2 Type II and GDPR/CCPA coverage, but no COPPA/FERPA mention and no student-data agreement — the app's compliance is entirely on you.
Bolt (StackBlitz)SOC 2 Type II; Enterprise adds SSO/audit logs and own-tenant deploy, but no COPPA/FERPA posture or student-data agreement is published.
ReplitStates it's "not directed to under-13" and will delete under-13 data or seek consent; historically offered Teams for Education, but whether it currently signs district or NY §2-d DPAs is unverified.
v0 / VercelUsers must be 16+; GDPR/CCPA DPA available on Pro/Enterprise, but no FERPA/COPPA program or student-data agreement.
SupabaseSOC 2 Type 2 + HIPAA BAA on Team+, standard DPA, AES-256 encryption — supports the security prong if you implement consent, retention, and deletion yourself, but has no FERPA/COPPA-specific offering.
Google Workspace for EducationThe gold standard — Google contractually acts as the FERPA "school official" and supports school-consent-on-behalf-of-parents for COPPA, with ISO 27001/27701/42001.

None of the general-purpose AI builders offer a COPPA/FERPA compliance program out of the box — that layer has to be built and, for schools, contracted separately with each district.

Sources: lovable.dev/privacy; stackblitz.com/privacy-policy; replit.com/privacy-policy; vercel.com/legal/dpa; supabase.com/docs/guides/security/soc-2-compliance; workspace.google.com/terms/education_terms; cloud.google.com/security/compliance/ferpa.

The Fix

Remediation path

  • Audit data flows — inventory every SDK, tag, ad network, log sink, and LLM call touching under-13 users or student records, including persistent IDs and IPs.
  • Kill or configure trackers — remove behavioral-ad SDKs from kid-facing surfaces, set child-directed flags, and scrub PII from logs.
  • Determine audience status — child-directed, mixed-audience with a neutral age screen, or general-audience with an actual-knowledge procedure.
  • Build the consent stack — direct parental notice plus COPPA VPC via a consent vendor, and a separate opt-in toggle for any third-party disclosure.
  • Build deletion and retention — a parent review/delete mechanism, a written retention policy with deletion timelines, and an automated purge.
  • Write the security program — a named coordinator, annual risk assessment, access controls, and encryption in transit and at rest (mandatory under NY §2-d).
  • Paper school relationships — a signed student-data agreement per district covering purpose limitation, direct control, no re-disclosure, and deletion at term end, with a Parents' Bill of Rights under NY §2-d.
  • Update the privacy policy to list all data collected and every third-party recipient.
  • Prioritize the 2026-04-22 amended-COPPA deadline items first — the line the FTC has flagged for enforcement.
What changed recently: The amended COPPA Rule was published 2025-04-22, took effect 2025-06-23, and requires full compliance by 2026-04-22 — adding biometrics as personal information, a separate opt-in for third-party/targeted-ad disclosures, a written security program, and a written retention policy. The 2026 civil-penalty inflation adjustment was cancelled by an appropriations lapse, so the maximum stays at . Five states now have Age-Appropriate Design Code laws (Nebraska effective 2026-01-01, South Carolina signed 2026-02-05), and the FTC has signaled COPPA as a 2026 enforcement priority.
FAQ

COPPA & FERPA questions, answered

Does my app need COPPA compliance?

Yes, if it's "directed to children" under 13 by the FTC's multi-factor test, or if it's a general-audience app with actual knowledge it's collecting personal information from an under-13 user. Persistent identifiers like device IDs and cookies count as personal information, not just names and emails.

What's new in the 2025 COPPA Rule changes, and when's the deadline?

The amended Rule (published 2025-04-22, effective 2025-06-23) adds biometrics as personal information, a separate opt-in before disclosing kids' data to third parties for targeted ads, a written information-security program, and a written data-retention policy. Full compliance is required by 2026-04-22.

Is Firebase COPPA compliant out of the box?

No. Firebase "doesn't offer any of the functionality needed to comply with COPPA" by default — you have to actively configure it, disabling ad personalization and setting the appropriate child-directed flags, or use Google AdMob's setTagForChildDirectedTreatment(true) alongside G-rated content.

What's the FERPA "school official" exception, and why does it matter for vendors?

It lets a vendor access education records without separate parental consent only if it performs a school function, stays under the school's direct control via a written agreement, and doesn't re-disclose or commercially reuse the data. Skipping the written agreement breaks the exception and can get an app banned from district use.

Can I get sued or fined for a FERPA violation?

Not directly. FERPA carries no monetary fines and no private right of action (Gonzaga Univ. v. Doe, 2002) — the Department of Education's real lever is withholding federal funding, which has never actually been used, or excluding the vendor from future district contracts. State laws like NY Education Law §2-d add real per-violation fines that FERPA itself lacks.

Do I need a separate agreement for every school district that uses my app?

Yes. The FERPA school-official exception and laws like NY §2-d require a signed, district-specific student-data agreement covering permitted purposes, direct control, no re-disclosure, and deletion at contract end — a generic terms-of-service page doesn't satisfy this.

Would your kids' or edtech app pass an FTC or district review?

We audit AI-built apps against COPPA and FERPA — consent flows, SDK configuration, student-data agreements — and hand you a fix-it list before the 2026-04-22 deadline or a district review finds the gap.

Get a Free Compliance Scan

Related searches: COPPA compliance checklist for apps · does my app need COPPA compliance · new COPPA rule 2025 changes · COPPA fines per violation 2026 · verifiable parental consent methods COPPA · is Firebase COPPA compliant · FERPA school official exception vendor · student data privacy agreement template · NY Ed Law 2-d vendor requirements