Two different systems, easy to conflate
COPPA (the Children's Online Privacy Protection Act) is a federal law, enforced by the FTC since 1998, built around a specific rule: 16 CFR Part 312. The state laws covered in our companion article -- Texas's SB 2420, Utah's and Louisiana's App Store Accountability Acts, and California's Digital Age Assurance Act (AB 1043) -- are recent, separate statutes, most passed in 2025, running through state attorneys general or private lawsuits rather than the FTC. They frequently get treated as one "kids' privacy compliance" bucket. They aren't the same bucket.
What COPPA actually requires, and who it applies to
The FTC's own COPPA Rule guidance states it applies to "operators of websites or online services directed to children under 13 years of age, and on operators of other websites or online services that have actual knowledge that they are collecting personal information online from a child under 13 years of age." Two separate triggers, in other words: your app is designed for children under 13 (audience-based), or you happen to have actual knowledge a specific user is under 13, regardless of your intended audience. Either trigger requires, among other things, a compliant privacy policy, direct notice to parents, and verifiable parental consent before collecting a child's personal information.
Critically, COPPA does not require every app to verify every user's age at signup. A general-audience app with no reason to think any user is under 13 has historically had no COPPA age-verification obligation at all -- "actual knowledge" has to come from somewhere (a user's own stated birth year, a parent's complaint, or similar), not from a mandatory universal check.
What the state laws actually require -- and why that's a different shape entirely
The state app-store laws don't ask whether your app is directed to children. They apply to app marketplaces (and, downstream, developers) covering all users in that state, and require the app store to verify age at the account level for everyone, then share an age category and parental-consent status with developers who request it. See our companion article, App Age-Verification Laws: Which States Apply to Your App and When, for the exact compliance dates and enforcement mechanisms state by state -- the short version is Texas is enforceable now, and Utah, Louisiana, and California all take effect at various points in 2027. None of the four conditions this on whether your app is child-directed.
A general-audience app can be squarely covered by a state law and have zero COPPA exposure -- until it doesn't
A budgeting app, a puzzle game, or a productivity tool with no child-directed content and no reason to think any user is under 13 can still be required to integrate a state's age-signal API, simply because it's distributed in that state through a covered app store. On its own, that's a state-law compliance question, not a COPPA one -- until the app store hands back a signal saying a specific account belongs to a 9-year-old. At that moment, the compliance picture changes.
The real interaction: a state-mandated signal can create the "actual knowledge" COPPA runs on
This is the part most "pick one law and comply with it" mental models miss. Attorney Nerissa Coyle McGinn, writing for Loeb & Loeb in December 2025, put it directly: "If an app developer has actual knowledge that a child is under the age of 13 because the app store has given the app developer the child's age, the app developer will now have to comply with COPPA for that user" -- including, per the same analysis, obtaining verifiable parental consent and deleting personal information already collected from that user. The same piece notes the practical shift this closes: developers who previously avoided COPPA's actual-knowledge trigger simply by never asking a user's age can no longer rely on that gap once a state-mandated signal supplies the age for them.
In plain terms: passing your state-law age-verification integration doesn't just satisfy the state law. It can simultaneously hand you information that switches on a separate, federal COPPA obligation for that specific user -- one your app may never have had to think about before the signal arrived, if your audience genuinely wasn't child-directed.
The FTC's own February 2026 policy statement narrows one specific risk -- read the conditions carefully
On February 25, 2026, the FTC issued a COPPA enforcement policy statement stating the Commission will not bring an enforcement action against general-audience or mixed-audience operators that collect, use, or disclose personal information solely to determine a user's age via age-verification technology -- a direct response to exactly the age-signal-integration scenario above. That relief comes with conditions, consistently described across multiple law-firm summaries of the statement: the age-verification data can't be used or disclosed for any other purpose, it can't be retained longer than necessary before being deleted, and any third party it's shared with must be reasonably vetted for confidentiality and security. The policy explicitly does not apply to operators whose primary audience is children -- it's relief for the general-audience case described above, not a blanket exemption. The statement also arrives ahead of an April 22, 2026 compliance deadline for a separate set of COPPA Rule amendments the FTC finalized in January 2025 -- a second, independent date worth tracking regardless of anything in this article.
What this means for your compliance checklist
- Treat these as two checklists, not one. Finishing your state-law age-signal integration is a real, separate item from a COPPA compliance review -- don't let one get marked "done" because the other is.
- Decide in advance what happens when a signal identifies a user under 13. Per the interaction above, that's the moment a COPPA obligation can attach -- have a plan (consent flow or deletion) ready before it happens in production, not improvised the first time it does.
- If you use age-verification data, use it only to determine age. That's the condition the FTC's February 2026 policy statement actually asks for in exchange for its enforcement forbearance -- any secondary use forfeits that protection.
- Track the April 22, 2026 COPPA Rule amendment deadline separately from any state app-store law's own compliance date -- they're unrelated timelines that happen to be converging on the same general subject.
Sources checked directly for this article: the FTC's own COPPA Rule guidance (ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions and ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa); Nerissa Coyle McGinn (Loeb & Loeb LLP), "App Store Age Verification Laws Trigger New Federal and State Children's Privacy Requirements," December 2025; and the FTC's February 25, 2026 press release, "FTC Issues COPPA Policy Statement to Incentivize the Use of Age Verification Technologies to Protect Children Online," cross-checked against independent summaries from Hunton Andrews Kurth, Mayer Brown, DLA Piper (Privacy Matters), and Ogletree Deakins, all describing the same conditions and April 22, 2026 amendment deadline.