Full compliance with the FTC's updated children's privacy rule was due April 22, 2026 — separate parental consent for third-party data sharing, biometric identifiers now counted as personal information, and no EdTech-specific exemption to lean on.
The Rule Actually Changed — and EdTech Wasn't Given a Special Path
On January 16, 2025, the FTC finalized the first substantial amendments to the Children's Online Privacy Protection Rule (COPPA Rule) since 2013, publishing them in the Federal Register on April 22, 2025. The amendments became effective June 23, 2025, with operators given until April 22, 2026 to reach full compliance — a deadline that has now passed. Any EdTech platform, school district vendor, or online learning tool that collects data from children under 13 should treat this as a rule already in force, not an upcoming one.
Notably, the FTC's Notice of Proposed Rulemaking had originally floated EdTech-specific clarifications — particularly around how schools can give verifiable parental consent (VPC) on behalf of parents when procuring EdTech services. The final rule dropped those provisions, explicitly citing the Department of Education's anticipated updates to FERPA regulations and a wish to avoid conflicting requirements. The practical effect: EdTech operators still must comply with COPPA's general requirements, but without the additional clarity the industry had been expecting. Existing FTC guidance on schools acting in loco parentis for EdTech consent purposes continues to apply in the meantime.
What Actually Changed
- Separate consent for third-party disclosure — operators must now obtain distinct verifiable parental consent specifically for disclosing a child's personal information to third parties for targeted advertising or similar purposes, separate from consent for the operator's own primary use of that data.
- Expanded definition of personal information — biometric identifiers and government-issued identifiers are now explicitly included.
- New data retention requirements — operators must maintain a written data retention policy with specified elements, retaining children's personal information only as long as reasonably necessary for the specific purpose collected.
- More prescriptive security requirements and new transparency obligations for FTC-approved Safe Harbor programs.
- New "mixed audience" definition — clarifying how platforms serving both children and general audiences should apply age-screening and COPPA protections, without expanding which sites count as child-directed.
FERPA Still Applies Separately
COPPA and the Family Educational Rights and Privacy Act (FERPA) are separate laws with separate scopes: COPPA governs online collection of personal information from children under 13 generally, while FERPA specifically governs the privacy of student education records held by schools and their vendors. An EdTech platform used by a school typically has to satisfy both — COPPA's consent and data-handling requirements, and FERPA's restrictions on disclosure of education records, which usually flow through the school's own FERPA obligations onto any vendor with access to student data.
Compliance Checklist for EdTech Operators
- Confirm you've reached full compliance with the 2025 amendments — the deadline has passed, so this should already be complete, not in progress.
- Review consent flows: confirm separate, distinct consent is captured for any third-party data disclosure, not bundled into a single general consent.
- Update your written data retention policy to reflect the new required elements and a genuine "reasonably necessary" retention standard.
- Confirm your definition of "personal information" internally now includes biometric and government-issued identifiers.
- Separately confirm your FERPA obligations with any school district customers — COPPA compliance alone does not satisfy FERPA.