Skip to main content

The FTC Approves New Method to Verify Parental Consent



Imperium®, already an industry heavyweight when it comes to identity verification, received approval on December 23, 2013 from the Federal Trade Commission (FTC) for its knowledge-based authentication mechanism, which can be used to obtain verifiable parental consent for children.  The Children’s Online Privacy Protection Act (COPPA) Rule requires operators of websites or online services directed to kids under 13 to provide notice and obtain verifiable parental consent before collecting, using or disclosing personal information from children.

In addition to the methods COPPA lays out in the rule, it also includes a provision allowing companies to submit new verifiable parental consent methods for approval from the FTC. This gives the rule some flexibility so the industry has a chance to create mechanisms that work for them. .
Knowledge-based identification allows verification of a user’s identity by asking a series of questions that rely on “out-of-wallet” information. “Out-of-wallet” information is information that is difficult for someone other than the individual to answer--in other words, facts that cannot be determined by looking in an individual’s wallet.

The FTC approved Imperium’s® knowledge-based authentication as an acceptable method of obtaining parental consent as long as it uses dynamic, multiple-choice questions that include enough options to ensure that the chances of a child guessing the correct answer is low. Imperium® provided a couple of examples of knowledge-based authentication questions in its application like asking about old phone numbers, addresses, etc. Knowledge-based authentication has been used by financial and credit institutions for years, as the FTC noted in its approval letter.


To read the FTC’s press release about Imperium® click here

Popular posts from this blog

20 Years Young: The History and Maturing of COPPA in a Privacy-Conscious Age

1998: A Concern for Children’s Privacy Was Born From the moment home computers had the capacity to connect to the Internet, children had the ability to use these technologies to access online websites and services. In the 1990s, concerns about children’s privacy and safety online arose amid fears of marketing practices around selling children’s personal information and exposing children’s information to predators. The Children’s Advertising Review Unit (CARU), founded in 1974, has always been on the forefront of safeguarding children’s privacy. CARU is the self-regulatory arm of the children’s advertising industry, tasked with promoting truth in children’s advertising by reviewing and evaluating child-directed ads in all media to ensure they are truthful, accurate and appropriate. CARU also monitors online privacy practices as they affect children. Before there was any legislation on the matter, CARU monitored a burgeoning Internet and observed how children’s privacy and sa...

Kids Internet Design and Safety Act Seeks to Protect Children from Harmful Online Content

United States Senators, Mr. Richard Blumenthal from Connecticut and Mr. Edward Markey from Massachusetts, introduced a new bill referred to as the Kids Internet Design and Safety Act (the “KIDS Act”). One of the Senator’s introducing the KIDS Act, Mr. Edward Markey, was the co-author of the Children’s Online Privacy Protection Act (“COPPA”). The KIDS Act seeks to include noteworthy advertising rules and create new protections for children online, specifically for online users under the age of 16. The proposed advertising rules within the KIDS Act are to ban websites from: (1) exposing young online users to advertisements “with embedded interactive elements”; (2) recommending any content involving alcohol, nicotine, or tobacco to young online users; and (3) recommending content that includes influencer marketing, like unboxing videos, or host-selling to young online users. Additionally, the KIDS Act seeks to prohibit certain online features to protect children, like prohibiting...

After Review, CARU Finds Snapchat Compliant with COPPA

In a recent decision, CARU found Snap Inc.’s (Snap) Snapchat app to be compliant with both the CARU Guidelines and the Children's Online Privacy Protection Act (COPPA).  “The company goes beyond minimal procedures to prevent under-age use” CARU stated. CARU determined that Snapchat is an app directed to a general audience, not intended for use by children. In reaching this conclusion, CARU considered that Snap’s Terms of Service clearly prohibit users under 13 years of age and makes no effort to market the app to children or provide them with an appealing user experience.  With that understanding, Snapchat is permitted under the Guidelines and Children’s Online Privacy Protection Act (“COPPA”) to age-gate and block children under 13 from using its services, which it does. CARU then examined whether Snapchat does so effectively. CARU observed that Snapchat utilizes age-gates and many safeguards to ensure that if children manage to breach the existing age-...