Children's Online Privacy Protection Rule
- Document
- 22 April 2025
- Event
- 22 April 2025
- Retrieved
- 16 September 2026
The classroom note
A primary school buys a reading app. The vendor's onboarding email tells the office manager not to worry about parental consent, since the school can sign for that. That shortcut predates any AI feature the app might add. Since the Children's Online Privacy Protection Rule was first written, a school-consent option has let a school stand in for a parent where an operator collects a child's information solely for the school's own educational purposes. On 22 April 2025, the Federal Trade Commission published final amendments to that rule, effective 23 June 2025, leaving the shortcut in place but adding a duty beside it: an operator must keep a written data-retention policy stating why it holds a child's information and when it will delete it.
What the evidence says
The rule text is the primary record of what changed, and it is narrower than a headline about a children's-privacy overhaul suggests. The amendment to section 312.10 stops an operator from retaining a child's data indefinitely by requiring a stated business need and a deletion timeframe, disclosed in the operator's public notice. It does not touch the school-consent mechanism, which the Commission's long-standing FAQ still explains: a school may consent only where an operator collects data for the school's use and no other purpose, must give the school the same notice it would give a parent, and must let the school review and delete what was collected. The FAQ is explicit that this authority is limited to the educational context the school authorised.
The implementation question
Put plainly, a district relying on school consent takes on two jobs at once: vetting whether a tool's data use is genuinely limited to school purposes, and confirming the vendor has a written retention schedule it will follow. The FAQ recommends this decision sit with a district's review process, not an individual teacher approving a tool between classes, because only that process can track which operators were authorised, on what terms, and for how long. A vendor's marketing claim of being COPPA compliant is not evidence of any of this; the retention policy itself is.
What holds and what fails
The shortcut holds where a vendor's feature serves only the school's educational purpose and the district can point to the operator's notice and retention policy on file. It fails wherever a tool blends a school-procured mode with a free consumer version, since data collected under consumer terms sits outside the school's authority to consent to. It also fails, in practice, wherever no one at the district reads the retention policy the amended rule now requires.
- Does this vendor's notice state a business reason and deletion timeframe for children's data, not just a general privacy policy?
- Is every feature limited to the school's educational purpose, or does part of it run on separate, consumer-facing terms?
- Who at the school keeps the record of which tools were authorised under school consent, and can they produce it?
A signed permission slip was never really the point; the point is a data policy the school can name, check and hold the vendor to.
Sources & reading trail
Final rule text: amends 16 CFR 312.10 to require a written data-retention policy and deletion timeframe; effective 23 June 2025.
Source published: 22 April 2025 · Retrieved: 16 September 2026
FAQ Section N explains the conditions under which a school may consent on a parent's behalf, and its limits, as a living document.
Source published: Not established · Retrieved: 16 September 2026
Departments, studies and vendor documents establish the record; the implementation reading and the boundary are School AI Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.