Training & Education · EdTech Compliance

COPPA 2025 Amendments: What EdTech Platforms Must Do Now

Full compliance with the FTC's updated children's privacy rule was due April 22, 2026 — separate parental consent for third-party data sharing, biometric identifiers now counted as personal information, and no EdTech-specific exemption to lean on.

The Rule Actually Changed — and EdTech Wasn't Given a Special Path

On January 16, 2025, the FTC finalized the first substantial amendments to the Children's Online Privacy Protection Rule (COPPA Rule) since 2013, publishing them in the Federal Register on April 22, 2025. The amendments became effective June 23, 2025, with operators given until April 22, 2026 to reach full compliance — a deadline that has now passed. Any EdTech platform, school district vendor, or online learning tool that collects data from children under 13 should treat this as a rule already in force, not an upcoming one.

Notably, the FTC's Notice of Proposed Rulemaking had originally floated EdTech-specific clarifications — particularly around how schools can give verifiable parental consent (VPC) on behalf of parents when procuring EdTech services. The final rule dropped those provisions, explicitly citing the Department of Education's anticipated updates to FERPA regulations and a wish to avoid conflicting requirements. The practical effect: EdTech operators still must comply with COPPA's general requirements, but without the additional clarity the industry had been expecting. Existing FTC guidance on schools acting in loco parentis for EdTech consent purposes continues to apply in the meantime.

What Actually Changed

FERPA Still Applies Separately

COPPA and the Family Educational Rights and Privacy Act (FERPA) are separate laws with separate scopes: COPPA governs online collection of personal information from children under 13 generally, while FERPA specifically governs the privacy of student education records held by schools and their vendors. An EdTech platform used by a school typically has to satisfy both — COPPA's consent and data-handling requirements, and FERPA's restrictions on disclosure of education records, which usually flow through the school's own FERPA obligations onto any vendor with access to student data.

Compliance Checklist for EdTech Operators

  1. Confirm you've reached full compliance with the 2025 amendments — the deadline has passed, so this should already be complete, not in progress.
  2. Review consent flows: confirm separate, distinct consent is captured for any third-party data disclosure, not bundled into a single general consent.
  3. Update your written data retention policy to reflect the new required elements and a genuine "reasonably necessary" retention standard.
  4. Confirm your definition of "personal information" internally now includes biometric and government-issued identifiers.
  5. Separately confirm your FERPA obligations with any school district customers — COPPA compliance alone does not satisfy FERPA.

Related Kibbo Tools

Sources