Regulation Neutral 6

COPPA 2.0 Stalled, But FTC’s 2025 Rule Rewrite Hits 2,982 School Apps

Congress's failure to pass COPPA 2.0 leaves a gap, but the FTC’s rulemaking and enforcement have already reshaped children’s online privacy law. The school year begins under a legal patchwork that imposes significant new obligations on operators of thousands of apps.

· 4 min read ·
Share

Key Takeaways

  • Congress's failure to pass COPPA 2.0 leaves a gap, but the FTC’s rulemaking and enforcement have already reshaped children’s online privacy law.
  • The school year begins under a legal patchwork that imposes significant new obligations on operators of thousands of apps.

Mentioned

COPPA (Children's Online Privacy Protection Act) product COPPA 2.0 product U.S. Senate company U.S. House of Representatives company Sen. Edward Markey person Federal Trade Commission company LearnPlatform by Instructure company Instructure company Clym company

Key Intelligence

Key Facts

  1. 1School districts accessed an average of 2,982 distinct educational technology tools during the 2024-25 school year, a 9% increase from the previous year (LearnPlatform by Instructure).
  2. 2The U.S. Senate unanimously passed COPPA 2.0 on March 5, 2026, aiming to extend COPPA protections to teens aged 13–16 and ban targeted advertising to minors.
  3. 3As of August 2026, the House has not taken up its companion bill, leaving the 1998 COPPA as the governing federal statute.
  4. 4The FTC finalized updates to the COPPA Rule in 2025, introducing stricter parental consent requirements, data minimization rules, and expanded definitions of personal information.
  5. 5Existing COPPA (1998) requires verifiable parental consent for collecting personal information from children under 13 but does not cover teenagers.
  6. 6COPPA 2.0 includes an “eraser button” provision allowing children and parents to request deletion or correction of personal information.

the most significant proposed update in more than 25 years to the federal privacy framework for young people

Sen. Edward Markey’s Office United States Senator, Massachusetts

Statement following Senate passage of COPPA 2.0 in March 2026

Analysis

Stronger Protections
  • FTC’s 2025 rule imposes immediate, enforceable safeguards for under-13 users
  • Enforcement actions signal zero tolerance for violations
  • Schools gain leverage to demand privacy-safe tools
Compliance Gaps
  • No federal teen privacy framework leaves 13-16-year-olds unprotected
  • Patchwork of state laws increases compliance complexity for multi-state operators
  • Statutory ambiguity under 1998 law may invite legal challenges

Analysis

For legal counsels advising edtech and digital platforms, the stalled COPPA 2.0 is only half the story. While the House deliberates, the FTC’s 2025 amendments to the COPPA Rule have already moved the compliance goalposts — tightening consent, data retention, and advertising restrictions across the 2,982 tools kids encounter daily.

American students returning to classrooms for the 2026-27 school year are entering a digital environment where children’s online privacy is governed by rules that have evolved significantly—despite the fact that Congress has not yet passed COPPA 2.0. On March 5, 2026, the Senate unanimously approved the Children and Teens’ Online Privacy Protection Act, a sweeping update that would extend the 1998 COPPA’s protections from children under 13 to teenagers up to age 16. The bill, championed by Senator Edward Markey, would ban targeted advertising to minors using their personal information and create a so-called “eraser button” enabling children and parents to request deletion or correction of data. However, as of August 2026, the House of Representatives has not acted on its companion bill, leaving the Senate’s landmark legislation in limbo. Corporate counsels, school administrators, and edtech providers are therefore preparing for the new academic year under a framework that is both old and new: the 1998 statute remains, but the Federal Trade Commission has used its rulemaking authority to modernize COPPA’s requirements, and the growing scale of educational technology has put a spotlight on compliance.

Recent high-profile settlements—such as the $6 million penalty paid by edtech platform Edmodo in 2022 for collecting children’s data without consent—have sent a clear signal that the agency will pursue violators aggressively.

Data from LearnPlatform by Instructure underscores the magnitude of the issue. During the 2024-25 school year, U.S. school districts accessed an average of 2,982 distinct educational technology tools—a nearly 9% increase over the prior year. This explosion means that students’ personal information, from names and location data to browsing habits and learning patterns, is collected by a vast array of apps, platforms, and services. The legacy COPPA of 1998, enacted when the internet was a fraction of its current size, requires operators of websites and online services directed to children under 13 to obtain verifiable parental consent before collecting personal information. But it does not cover teenagers, nor does it directly address the sophisticated advertising and data-sharing ecosystems that have emerged since.

Recognizing the strain, the FTC has been assertive in updating its COPPA Rule. In 2025, the agency finalized amendments that, among other things, require separate verifiable parental consent for the disclosure of children’s personal information to third parties, impose strict data retention limits, and expand the definition of personal information to include biometric data and identifiers that can track a child across sites. Compliance deadlines for many of these provisions were set ahead of the 2026-27 school year, meaning that for the thousands of edtech tools used in classrooms, operators now face a more stringent legal environment even without a statutory overhaul. The FTC has also stepped up enforcement. Recent high-profile settlements—such as the $6 million penalty paid by edtech platform Edmodo in 2022 for collecting children’s data without consent—have sent a clear signal that the agency will pursue violators aggressively. These actions, combined with the new rule, have effectively raised the bar for children’s privacy protection in the absence of Congressional action.

While COPPA 2.0 would codify many of these protections for teenagers and introduce a nationwide standard, the current patchwork of state laws adds another layer. California’s Age-Appropriate Design Code, for example, was enjoined in 2023 but inspired similar bills in other states. Some states have enacted their own children’s privacy statutes, creating a compliance maze for operators. For edtech companies, this means navigating a federal baseline that applies only to under-13 users, while filling gaps for older students through state laws or voluntary measures. For schools, the challenge is vetting an ever-growing roster of tools to ensure they comply with both legal requirements and district policies.

What to Watch

The practical implications for the 2026-27 school year are substantial. Edtech providers must now implement technical mechanisms for parental consent that are not just checkboxes but robust and verifiable, and they must audit their data practices to ensure they are not retaining information indefinitely. The FTC’s rule also limits the use of persistent identifiers and geolocation data, forcing companies to redesign features that rely on such tracking. Meanwhile, schools must allocate resources for privacy training and vendor assessments, often with limited budgets.

Looking ahead, the regulatory momentum is unlikely to reverse. Even if COPPA 2.0 eventually becomes law, the FTC’s proactive stance and the sheer scale of edtech adoption mean that children’s online privacy will remain a high-stakes issue. The next frontier may be AI-powered learning tools, which raise even more complex questions about data collection, algorithmic bias, and children’s autonomy. For now, the 2026-27 school year begins under a transformed privacy regime—one that was shaped not by one big legislative act but by administrative rulemaking, enforcement, and the relentless digitization of the classroom.

Cite This Page

"COPPA 2.0 Stalled, But FTC’s 2025 Rule Rewrite Hits 2,982 School Apps." Legal & RegTech Intelligence Brief, August 4, 2026. https://getlegalbrief.com/story/legal-coppa2-stall-ftc-rule

How we covered this story

Every story in our legal coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the legal space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.