Skip to main content

Why Everyone Still Needs to Be Worried About Children's Privacy


Last week, Allison Fitzpatrick from Davis & Gilbert LLP wrote an article in Ad Age essentially warning folks that it's not just the apps and websites targeting children that need to worry about the FTC and other regulators when it comes to children's privacy. Although the Children's Online Privacy Protection Act (COPPA) revisions went into effect all the way back in July 2013, it was generally understood that there was a bit of a grace period as companies grappled with how to implement changes that at the time much of the industry did not entirely grasp. However, it seems clear that in the coming year, that grace period has ended and that the FTC may be increasing its actions not only exclusively in the child space anymore but also in a more overlapping gray area where companies may not expect it.

In the article, Fitzpatrick has several predictions for 2015, which include more COPPA actions on a state level, COPPA actions that no longer apply to only child-directed websites, behavioral targeting on kid sites and more scrutiny of social media. Advocacy groups have been on the FTC for years, urging them to take a harder line when it comes to children's privacy. Will 2015 be the year?

To read the full article, be sure to check out Ad Age. For more information about the author, Allison Fitzpatrick, check out her bio here.

Popular posts from this blog

20 Years Young: The History and Maturing of COPPA in a Privacy-Conscious Age

1998: A Concern for Children’s Privacy Was Born From the moment home computers had the capacity to connect to the Internet, children had the ability to use these technologies to access online websites and services. In the 1990s, concerns about children’s privacy and safety online arose amid fears of marketing practices around selling children’s personal information and exposing children’s information to predators. The Children’s Advertising Review Unit (CARU), founded in 1974, has always been on the forefront of safeguarding children’s privacy. CARU is the self-regulatory arm of the children’s advertising industry, tasked with promoting truth in children’s advertising by reviewing and evaluating child-directed ads in all media to ensure they are truthful, accurate and appropriate. CARU also monitors online privacy practices as they affect children. Before there was any legislation on the matter, CARU monitored a burgeoning Internet and observed how children’s privacy and sa...

After Review, CARU Finds Snapchat Compliant with COPPA

In a recent decision, CARU found Snap Inc.’s (Snap) Snapchat app to be compliant with both the CARU Guidelines and the Children's Online Privacy Protection Act (COPPA).  “The company goes beyond minimal procedures to prevent under-age use” CARU stated. CARU determined that Snapchat is an app directed to a general audience, not intended for use by children. In reaching this conclusion, CARU considered that Snap’s Terms of Service clearly prohibit users under 13 years of age and makes no effort to market the app to children or provide them with an appealing user experience.  With that understanding, Snapchat is permitted under the Guidelines and Children’s Online Privacy Protection Act (“COPPA”) to age-gate and block children under 13 from using its services, which it does. CARU then examined whether Snapchat does so effectively. CARU observed that Snapchat utilizes age-gates and many safeguards to ensure that if children manage to breach the existing age-...

i-Dressup Shuts Down in Wake of Privacy Breach and COPPA Violation

I-Dressup, a fashion-themed social website for teens, has completely shut down as part of a settlement with the New Jersey Department of Consumer Affairs, following a massive privacy breach and violations of the federal Children's Online Privacy Protection Act (COPPA) and New Jersey state law. In September 2016, a hacker sent 2.2 million i-Dressup account credentials to technology blog Arstechnica as well as to haveibeenpwned.com, a searchable online database of data breaches. Responding to the news, New Jersey investigators discovered that 2,519 of the compromised accounts belonged to New Jersey children below age 13. I-Dressup, allegedly aware that it had child users, had violated COPPA by failing to obtain verifiable parental consent prior to collecting and processing personal information from the children, including first and last names and email addresses. In a consent decree with the New Jersey Attorney General Gurbir Gerwal, parent company...