7.1 FTC Act and COPPA

Key Takeaways

  • Section 5 of the FTC Act is a general unfair-or-deceptive-acts statute; the United States still has no comprehensive federal consumer-privacy law.
  • Unfairness under 15 U.S.C. § 45(n) requires substantial injury that consumers cannot reasonably avoid and that is not outweighed by countervailing benefits to consumers or competition.
  • Deception is a material representation, omission, or practice that is likely to mislead a consumer acting reasonably under the circumstances.
  • COPPA covers operators of child-directed sites or services and operators with actual knowledge they collect personal information from children under 13; the statutory age is 13.
  • The 2025 COPPA Rule amendments were published 22 April 2025, became effective 23 June 2025, and the operator compliance date of 22 April 2026 is now in force: separate verifiable parental consent for third-party disclosures, written retention limits, a broader personal-information definition, and a written children's security program.
Last updated: August 2026

7.1 FTC Act and COPPA

Domain II.A is the exam's general federal consumer-privacy block. Body of Knowledge 2.6.1 performance indicator 1 asks you to know the Federal Trade Commission Act (FTC Act) and the Children's Online Privacy Protection Act of 1998 (COPPA) as they actually operate in 2026 — not as a stand-in for a comprehensive federal privacy statute that Congress has not enacted.

Section 5 is the general statute, not a privacy code

Section 5(a) of the FTC Act, 15 U.S.C. § 45(a), declares unfair or deceptive acts or practices (UDAP) in or affecting commerce unlawful. The U.S. SAFE WEB Act amendments confirm that Section 5 can reach foreign commerce that causes or is likely to cause reasonably foreseeable injury in the United States, or that involves material conduct in the United States (15 U.S.C. § 45(a)(4)).

That is a general consumer-protection prohibition. It does not, by itself, require a privacy notice, a consent, a data-minimization schedule, or an access or deletion right. A company can violate Section 5 without ever touching a sectoral privacy law, and a company can obey COPPA, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), or the Gramm-Leach-Bliley Act (GLBA) and still violate Section 5 if its remaining consumer-facing statements or security practices are deceptive or unfair. The exam trap is to treat Section 5 as if it were a U.S. version of the EU General Data Protection Regulation. It is not. There is no general federal consumer-privacy statute. The U.S. stack is sectoral statutes plus Section 5 plus state law.

Certain entities sit outside the Commission's Section 5 jurisdiction. Banks, federal credit unions, and certain common carriers are generally excluded and are supervised by their own agencies. Nonprofits that fall outside Section 5 are also generally outside the COPPA Rule, because COPPA borrows the FTC Act's coverage.

The unfairness test

Congress codified modern unfairness in 15 U.S.C. § 45(n). An act or practice is unfair if it:

  1. Causes or is likely to cause substantial injury to consumers,
  2. That injury is not reasonably avoidable by consumers themselves, and
  3. The injury is not outweighed by countervailing benefits to consumers or to competition.

Substantial injury is usually monetary harm or an unavoidable health or safety risk. Large-scale exposure of Social Security numbers, payment-card data, or other identity-theft fuel is the strong fact pattern. A trivial inconvenience or purely speculative embarrassment, standing alone, is the weak one.

Not reasonably avoidable means the consumer could not have shopped around, declined the term, or taken a practical step that would have prevented the injury. Hidden collection, a take-it-or-leave-it practice that was not disclosed, and a security failure the consumer cannot inspect are typical. A clearly disclosed optional feature the consumer can turn off is a harder unfairness case.

Not outweighed by benefits is a balancing test. A checkout delay that prevents card fraud is a benefit the statute recognizes. Calling a game "free" does not offset covert sale of a child's persistent identifier to advertisers.

Worked scenario. A hotel chain stores payment-card numbers in clear text on an internet-facing server. Attackers steal 400,000 cards. Guests had no way to inspect the server. Cost-cutting is not a countervailing benefit § 45(n) protects. That is the classic unreasonable security as unfairness pattern you will see again in Wyndham.

The deception test

The Commission's Policy Statement on Deception (1983) is the official test. A practice is deceptive if it involves a material representation, omission, or practice that is likely to mislead a consumer acting reasonably under the circumstances.

ElementWhat the exam is looking forWeak fact pattern
Likely to misleadA claim, half-truth, or silence that leaves a false net impression. The FTC does not have to prove anyone was actually fooled.A boast so exaggerated no reasonable person would rely on it
Reasonable consumerThe target audience. A claim aimed at children is judged from a child's perspective. Fine print does not cure a bold headline.A sophisticated enterprise customer who negotiated the opposite term
MaterialInformation likely to affect choice or conduct — privacy, security, price, or what happens to the dataAn immaterial logo color

Broken notice is the privacy version of deception. "We never sell your data" plus a live data-broker feed is deceptive. "Bank-grade encryption" plus clear-text backups is deceptive. A privacy policy that describes a practice the company abandoned two releases ago is still a representation.

Unfairness and deception can travel together. They are not mutually exclusive. Many security cases plead both: the privacy policy promised reasonable safeguards (deception) and the actual program caused unavoidable, un-offset substantial injury (unfairness).

COPPA: who is an operator, and why the age is 13

COPPA is the statute. The COPPA Rule, 16 C.F.R. Part 312, is the implementing regulation. The official FTC COPPA FAQ states that the COPPA Rule was amended on 22 April 2025. The Federal Register published those amendments on that date. They became effective 23 June 2025. Covered operators had until 22 April 2026 to come into full compliance. That operator compliance date is now in force. Teach the live Rule, not the 2013 text.

COPPA applies to operators of:

  • Websites or online services directed to children under 13, and
  • Other websites or online services that have actual knowledge they are collecting personal information online from a child under 13.

Child means an individual under the age of 13. The statute does not create a second COPPA age for teens. State comprehensive laws, app-store policies, and non-U.S. regimes may use 16 or other figures; they are not COPPA. Do not invent a "COPPA 16."

Directed to children is a totality-of-the-circumstances test: subject matter, visual content, animated characters or child-oriented activities, music, age of models, advertising, and how the service is described. A general-audience service that is not child-directed is not automatically in COPPA. It enters when it has actual knowledge it is collecting personal information from a child under 13. Mixed-audience services often use an age screen and then apply COPPA to users who identify as under 13.

Verifiable parental consent and the 2025 third-party rule

With limited exceptions in § 312.5 (including specified one-time contact and internal-operations exceptions), an operator must give direct notice to a parent and obtain verifiable parental consent (VPC) before collecting, using, or disclosing a child's personal information.

The live Rule requires separate VPC before the operator discloses that information to third parties — including for targeted advertising — unless the disclosure is integral to the site or service the parent is consenting to. A parent may consent to the operator's own collection and use without consenting to third-party disclosure. The operator may not condition participation on a non-integral disclosure.

Approved VPC methods include a signed consent form, a credit-card or other online payment tied to a monetary transaction, a government-ID check plus deletion of the ID, a video conference with trained staff, and other methods the Commission has approved. Email plus (an email plus a delayed confirmatory email) is available only when the operator will use the information internally and will not disclose it or make it public.

What "personal information" now includes

The Rule defines personal information as individually identifiable information collected online. The live list includes:

CategoryLive Rule examples
Identity and contactFirst and last name; home or other physical address; online contact information; telephone number
Government identifiersSocial Security number and, after the 2025 amendments, other government-issued identifiers such as state identification cards, birth certificates, and passport numbers
Persistent identifiersA cookie ID, IP address, device serial number, or other identifier that can recognize a user over time and across sites or services
Media of the childA photograph, video, or audio file that contains a child's image or voice
LocationGeolocation sufficient to identify street name and name of a city or town
Biometrics (2025)An identifier usable for automated or semi-automated recognition of an individual — fingerprints, handprints, retina or iris patterns, genetic data including a DNA sequence, voiceprints, gait patterns, facial templates, or faceprints

A child-directed game that stores a faceprint for "avatar login" is collecting personal information even if it never asks for a name.

Retention and security under the live Rule

§ 312.10 now says the operator may retain a child's personal information only as long as is reasonably necessary to fulfill the specific purpose(s) for which it was collected, must delete it with reasonable measures when that purpose ends, and may not retain it indefinitely. The operator must establish, implement, and maintain a written data-retention policy that states the purposes, the business need to retain, and a deletion timeframe, and must provide that policy in the online notice required by § 312.4(d).

§ 312.8 still requires reasonable procedures to protect confidentiality, security, and integrity. The 2025 amendments specify a written children's personal-information security program with safeguards appropriate to the sensitivity of the data and to the operator's size, complexity, and nature and scope of activities. At minimum, designate employees to coordinate the program, assess risks at least annually, implement safeguards, test and monitor them, and evaluate the program. Release children's information only to parties capable of maintaining its confidentiality and security, and obtain written assurances from those parties.

COPPA is a trade-regulation rule. Knowing violations support civil penalties. The official FTC COPPA FAQ cites a maximum of $53,088 per violation (the inflation-adjusted Section 5(m) figure published for 2025; federal civil-penalty inflation adjustments were not implemented for 2026, so that published maximum remains the figure in the Commission's FAQ). Penalty size turns on egregiousness, prior history, number of children, type of information, third-party sharing, and company size. COPPA does not create a general private right of action.

Worked scenario. A mixed-audience creative app is not child-directed, but support logs show thousands of under-13 accounts that uploaded voice notes and face-mapped avatars. The operator has actual knowledge. It obtained one VPC for "account creation" and then sold voiceprints to an ad-tech partner. Under the live Rule it needed separate VPC for that third-party disclosure, a written retention schedule that is not "keep forever for model training," and a written children's security program. "We thought COPPA stopped at name and email" is not a defense.

Exam traps

Section 5 is not a general privacy statute. Unfairness is three statutory elements, not "the FTC thinks it is unfair." Deception is likely to mislead a reasonable consumer and material. COPPA's age is 13. The 2025 amendments are in force as of 22 April 2026. Separate VPC for third-party disclosures, written retention limits, biometric and government-ID personal information, and a written children's security program are live duties.

Loading diagram...
Section 5 Tests and Live COPPA Coverage
Test Your Knowledge

Which statement correctly states the statutory unfairness test under Section 5 of the FTC Act?

A
B
C
D
Test Your Knowledge

A child-directed game wants to send players' persistent identifiers and voiceprints to an advertising network. Under the COPPA Rule that operators had to meet by 22 April 2026, which statement is accurate?

A
B
C
D
Test Your Knowledge

Which operators are covered by COPPA?

A
B
C
D