If your website or app is aimed at children under 13, or you know some of your users are that young, the US Children's Online Privacy Protection Act reaches your analytics and advertising tags. The rules under it were tightened, and the new version has applied in full since 22 April 2026.
Who it applies to.
COPPA covers websites and online services directed to children under 13, and general sites that know they collect personal information from children that age. Toy brands, games, education sites and family entertainment are the obvious cases. A general store with a children's section can be caught too, depending on how it's designed and marketed.
Why tracking is involved.
Under COPPA, personal information includes persistent identifiers: cookie IDs, device IDs and similar values that recognise a user over time and across sites. That's exactly what analytics and advertising tags use. So a pixel on a child-directed page collects personal information from children, and needs a parent's verifiable consent, unless an exception applies.
The main exception is "support for internal operations": using an identifier only to run the site, such as keeping it working, measuring how it performs, or preventing fraud. It doesn't cover behavioural advertising or building profiles.
What the 2026 rules change.
- Separate consent for third parties. Sharing children's personal information with third parties for targeted advertising, or other purposes that aren't part of the service, now needs its own verifiable parental consent, apart from consent to use the service.
- More detail in notices. Sites relying on the internal operations exception must say what they use identifiers for, and how they stop them being used for advertising.
- Named recipients. The notice to parents has to say who receives children's information, by name or by category, and why.
- Limits on keeping data. Children's personal information can be kept only as long as it's needed, under a written retention policy.
What that means for your tags.
- Advertising pixels on child-directed pages, such as Meta, TikTok and remarketing tags, need the separate parental consent or need to come off.
- Analytics can sit within the internal operations exception only when it's genuinely limited to running and improving the site, with no advertising features or sharing switched on.
- Google's ad products have a setting to mark traffic as directed to children, which limits how the data is used. It should be on where it applies.
- Mixed sites, with some pages for children and some for adults, need tags set by page or section, not one setup for everything.
What to check.
- List the pages and sections that could count as directed to children.
- Check which tags fire there, and what each one sends and to whom.
- Turn off advertising features, such as GA4's Google signals and ads personalisation, where they don't belong.
- Make sure your notices name the third parties and say what identifiers are used for.
- Keep a dated record of what each tag does.
Whether COPPA applies to your site, and what your notices must say, is for your lawyers. Marc Alexander sets the tags to match their decisions, for US businesses. The wider rules are in US state privacy laws and your GA4 setup, and the GA4 mini audit shows what your tags send today.