Most EdTech vendors treat COPPA as a stable 1998 rule they built to once and moved on from. That stopped being true on January 16, 2025, when the FTC unanimously finalized the first substantive update to the Children’s Online Privacy Protection Rule in more than a decade. The amendments were published on April 22, 2025, became effective June 23, 2025, and full compliance is required by April 22, 2026. The 2026-27 school year is the first academic cycle where the updated rule is in force, and the 2027-28 filing window is the first full cycle where district DPAs and procurement teams draft against it. Vendors that adjust during 2026-27 renew smoothly. Vendors that don’t get sent back for evidence they haven’t built the mechanisms to produce.
Below are the six adjustments EdTech vendors need to make before district DPAs get renegotiated, ranked by how often we see them cause avoidable district-side friction. If your product touches under-13 student data through an LLM or any other AI feature, walk this list alongside the AI-in-the-classroom vendor responsibility framework. The COPPA questions and the AI-governance questions arrive at DPA review together, and the answers travel together.
If you’re building to COPPA from scratch, our COPPA Compliance Checklist for EdTech is the day-1 walkthrough. This piece is for the vendor already compliant under the pre-2025 rule and catching up to the amendments.
Six adjustments before the 2027 school year
The six items below are the ones that reliably matter in a district DPA cycle now that the amended rule is in force. Walk the list before the district refreshes its DPA template for the 2027-28 filing window. Each item is an artifact your product and your compliance packet need to produce, not a policy paragraph.
- Separate the third-party disclosure consent flow.Verifiable parental consent for the operator’s own collection is no longer sufficient to share the child’s data with a third party for that third party’s purposes. Move the third-party sharing opt-in out of the primary consent screen into its own explicit affirmative action. A single “Yes, I consent” checkbox that covers your data collection and your third-party sharing is now non-compliant.
- Publish a written per-category data-retention policy.For each personal-information category, name what you retain, for what purpose, and for how long. Explicitly cover deletion triggers (account closure, school-year end, extended inactivity). Indefinite retention is no longer defensible; the FTC’s staff commentary explicitly names “we might need it later” as an inadequate retention rationale.
- Extend your personal-information inventory to include biometric identifiers and government IDs.The updated definition explicitly includes fingerprints, voiceprints, iris patterns, gait patterns, and government-issued identifiers. Any voice-interaction feature, face-detection for authentication, or ID-verification workflow touching under-13 users now sits inside COPPA scope, even if you don’t retain the raw file. Data-flow map, retention policy, and consent flow all update accordingly.
- Narrow the school-authorization exception to its educational-purpose boundary.The FTC formally recognized that schools can consent on behalf of parents for services used for a school-authorized educational purpose. The exception is narrower than most EdTech vendors assumed: data collected under it can only be used for that specific purpose. Behavioral advertising, cross-product analytics for product improvement in ways the school didn’t authorize, and internal sharing with sibling business units all move to a separate consent basis or come out of the exception entirely.
- Formalize a written information-security program. Named responsible employee, documented risk assessment, control set, review cadence. This overlaps entirely with what SOC 2 and ISO 27001 already require, but the FTC now expects it as a COPPA artifact, produced on request, without a separate audit trigger.
- Rebuild the sub-processor register with per-vendor consent posture. For every third-party service touching under-13 data (the model provider on any AI feature, any RAG store, any moderation API, any analytics or advertising vendor), document what data flows through, under what consent basis (parental, school-authorization, opt-in disclosure), and what the retention and deletion commitment is. Districts catch this at DPA review and refuse signatures without it.
The separated consent flow, in practice
Of the six adjustments above, the separated consent flow is the one district procurement teams will catch first, because it is a UX change visible in the product itself. The version that fails DPA review is a single “I consent” checkbox that quietly covers primary collection, third-party analytics sharing, and behavioral advertising in one action. The version that clears review separates those disclosures visually, requires distinct affirmative actions for each purpose, and produces a per-parent audit trail of which specific disclosures were consented to and when. Something like:
“[Vendor Product] collects your child’s name, email, and learning-progress data to deliver the service. Do you consent to this collection? ☐ Yes ☐ No”
“[Vendor Product] shares aggregated learning-outcome data with [Named Sub-processor], a research analytics vendor. This sharing is not required for the service to function and can be declined without affecting your child’s access. Do you consent to this sharing? ☐ Yes ☐ No”
“[Vendor Product] does not use your child’s data for behavioral advertising. If this changes, you will be re-prompted for explicit consent before the change takes effect.”
The other five adjustments hold to the same rule: specific over general, dated over undated, named accountable person over “the vendor’s compliance team,” and district-accessible interface over “submit a support ticket.” That is what separates the vendors that clear a district DPA in the first review cycle from the vendors that don’t.
All six adjustments double as CIPA and FERPA evidence, and they map cleanly to the state student-privacy laws (SOPPA, SOPIPA, NY Ed Law 2-d) that overlay federal frameworks per state. Vendors that adjust once evidence across every district DPA, whether federal or state, K-12 or higher-ed.
What COPPA actually requires (as of 2027)
COPPA has been the federal rule for under-13 online privacy since it was enacted in 1998, with the FTC’s implementing rule adopted in 2000 and last substantively updated in 2013 before this year. The rule requires operators of websites and online services that collect personal information from children under 13 to provide notice, obtain verifiable parental consent, honor parental review and deletion requests, maintain reasonable security, and limit retention to what’s necessary for the service. The definition of “operator” reaches vendors whose services are directed at children, and vendors of general-audience services with actual knowledge that they are collecting information from a child under 13.
COPPA does not apply to schools or libraries operating in their governmental capacity, and it does not preempt state student-privacy laws. It binds the operator. When schools consent on behalf of parents under the school-authorization exception (formally recognized in the 2025 rule update), the data-use scope is narrower than most EdTech vendors have historically assumed: educational-purpose only. Behavioral advertising, product improvement in ways the school didn’t authorize, and sharing with sibling business units all fall outside the exception.
What the FTC changed in January 2025
The FTC’s amendments, adopted unanimously on January 16, 2025 and published April 22, 2025, tightened five specific areas of the pre-existing rule. The amended rule became effective June 23, 2025; full compliance is required by April 22, 2026. If your product hasn’t touched its consent flows, data-retention policy, or sub-processor register in the last 18 months, at least one of the five applies to you.
First, the separate-opt-in requirement for third-party disclosure. Verifiable parental consent for the operator’s own collection is no longer sufficient for the operator to share the child’s data with a third party for that third party’s purposes. That disclosure now requires its own opt-in, distinct from the primary consent flow.
Second, explicit data-retention limits. Operators must maintain a written retention policy defining what personal information is retained, for what purpose, and for how long. Indefinite retention is no longer defensible.
Third, expanded personal-information categories. The definition now explicitly includes biometric identifiers (fingerprints, voiceprints, iris patterns, gait patterns) and government-issued identifiers. Voice interaction with under-13 users is now inside COPPA scope even if you don’t retain the raw audio file.
Fourth, the school-authorization exception codified with limits. The FTC formally recognized that schools can consent on behalf of parents for services used for a school-authorized educational purpose. The exception is narrower than most EdTech vendors assumed: the data can only be used for that educational purpose. Behavioral advertising, product improvement in ways the school didn’t authorize, and sharing with sibling business units all fall outside.
Fifth, a written information-security program requirement. Every COPPA-covered operator must maintain a written program that names a responsible employee, documents a risk assessment, and specifies controls appropriate to the risk. This is not new to careful operators. It is newly required to be documented and produced on request.
What the 2027 enforcement posture actually cares about
The FTC and DOJ enforcement arc since 2019 is instructive. Musical.ly settled for $5.7 million in February 2019, then the record. Google and YouTube settled for $170 million in September 2019, taking the record. Epic Games broke both in December 2022 with a $275 million COPPA slice of a $520 million total settlement. Then in 2026, the Department of Justice announced a $400 million settlement with TikTok and ByteDance resolving related COPPA litigation. Each escalation came back to the same failure mode: the operator collected data from under-13 users without adequate consent, then used it for purposes the parent or school never authorized.
The 2025 rule updates make that failure mode easier to prove. When third-party disclosure requires a separate opt-in and you don’t have one, the violation is visible in your consent flow, not inferred from downstream data use. When your retention policy is required to be written and you can’t produce it, the gap is documentary. Enforcement gets faster and cheaper for the FTC to bring; the vendor’s cost of defense goes up.
For 2027, the practical question isn’t whether you are COPPA-compliant. It is whether you can prove it on demand to a district’s procurement team, to a parent’s attorney, and to the FTC without three months of engineering work to assemble the evidence.
The KOSA overlay
The Kids Online Safety Act (KOSA) adds a duty-of-care obligation on top of COPPA: platforms would be required to take reasonable measures to prevent and mitigate harms to minors from addictive design, self-harm content, disordered-eating content, and related categories, extending up to age 17 rather than only under 13. The U.S. House passed the KIDS Act (H.R. 7757) on June 29, 2026, consolidating KOSA and COPPA 2.0 into a single bipartisan package. Senate passage remains uncertain, with sponsors publicly citing weakened duty-of-care language as a blocker.
Several states have already enacted similar frameworks that apply to platforms serving minors in their jurisdictions: California AB 2273 (the Age-Appropriate Design Code Act, enforceable since July 1, 2024); Utah’s Social Media Regulation Act (originally SB 152 in 2023, since amended and expanded through the 2025 and 2026 sessions); and Texas HB 18 (the Securing Children Online through Parental Empowerment Act, effective September 1, 2024). Vendors serving multiple states cannot wait for federal KOSA to resolve their approach.
The bottom line
COPPA in 2027 is stricter, better-documented, and easier for the FTC to enforce than the pre-2025 version most EdTech vendors built to. The vendors that make the six adjustments above during the 2026-27 school year will renew their district contracts smoothly. The vendors that wait, expecting either KOSA to displace the conversation or the FTC to soften enforcement, will spend the 2027-28 filing window defending consent-flow decisions they made in 2019 to a district procurement team that has already updated its DPA template to reflect the new rule.
The adjustment work is real. It is also finite: six changes, each documented, each defensible. That is the 2027-ready posture.
Put the playbook to work
The six-adjustment vendor packet builds on the same six-dimension foundation the AI-in-the-classroom vendor responsibility framework walks through: data flows, consent posture, training-data attestation, human decision authority, auditability, and incident response. vCISO Lite ships the compliance surface that assembles those artifacts (multi-framework tracking across COPPA + CIPA + FERPA + state student-privacy laws, sub-processor register with per-vendor consent posture, district-ready security-questionnaire responses, and the cryptographic hash-per-artifact structure procurement teams now prefer). See how the packet gets assembled at vcisolite.com.