Gamasutra is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Gamasutra: The Art & Business of Making Gamesspacer
View All     RSS
May 17, 2021
arrowPress Releases

If you enjoy reading this site, you might also want to check out these UBM Tech sites:


COPPA 1.0 vs. COPPA 2.0: There's a New Sheriff in Town

by Roy Smith on 03/03/14 12:47:00 pm

The following blog post, unless otherwise noted, was written by a member of Gamasutra’s community.
The thoughts and opinions expressed are those of the writer and not Gamasutra or its parent company.


This week I’m going to talk about common misconceptions about COPPA we hear every day when we talk to game developers.  It’s my goal to get the game development community to better understand the new version of the US COPPA law (or, as we in the business call it, 16 CFR Part 312).

“We’re COPPA compliant, we have a privacy policy.”

I hear this literally every day.  There’s a good reason why developers think they are in compliance with COPPA … they probably are in compliance with the ORIGINAL version of the law, which was put in place in 2000.  The original COPPA (we call it COPPA 1.0) was designed only for web sites (smartphones didn’t exist in 2000), and the intent of the original COPPA was to protect children from web pages that requested private information about them. You can view a summary of COPPA 1.0 here.

To comply with the original COPPA on your website, all you had to do was have an accurate “Privacy Disclosure” page, and get a parent’s approval before you could ask a child for any personally identifiable information (“PII”, in FTC lingo).

A tale of two COPPAs

COPPA 1.0 was an effective law, and the FTC occasionally fined web sites that did not adhere to it.  The potential penalty for non-compliance is big – up to $16,000 per child affected. That can add up.  In 2008, Sony was fined $1,000,000.00 and In May 2011, Disney-owned PlayDom was fined $3,000,000.00 for COPPA violations.

As the iPhone and other smartphones grew to dominate the market, their ability to collect PII gave rise to all sorts of new privacy issues that could not have been envisioned in 2000.  The FTC spent the better part of three years working on an update to the COPPA 1.0 law that would protect children’s privacy as they used mobile devices, either on websites or on apps and games.  The updated law (which we refer to as COPPA 2.0) was approved in December 2012 and it went into effect on July 1, 2013. You can view a summary of COPPA 2.0 here.

There’s a new sheriff in town … COPPA 2.0

Just because you were compliant with COPPA 1.0, you are not automatically compliant with COPPA 2.0.  2.0 goes a LOT farther in protecting children’s privacy, and requires much more of game developers and parents than the original law did.  Here’s the bottom line:

If you think you are not subject to COPPA 2.0 because you don’t “Target Kids Under 13”, you are probably wrong. 

The law says that no matter whether you target kids or not, if you have “actual knowledge” that kids are using your game, you are required to handle them in a COPPA compliant way.  “Actual knowledge” is an inexact legal term but the FTC tried to spell it out better in a FAQ post in July.

Let’s say your new word game has 10 million downloads … what are the chances that not one child under 13 is playing the game? Zero. What are the chances that just 1% of the users are kids? Fairly good. That’s 100,000 kids!  All it takes for the FTC to fine you is one irate parent filing a complaint about your game capturing a screen name, a photo, or an email address. Whether you monetize with IAP or advertising, both of those activities capture PII and therefore fall under the COPPA 2.0 regulations.

The only way you can truthfully say that COPPA 2.0 doesn’t apply to your game is if your game is does not capture any user information at all, use advertising, or in-app purchases.  We know of very few games that meet those criteria.

If you'd like to educate yourself on COPPA, here's a page of history and links AgeCheq has created for game developers. To learn more about COPPA directly from The Federal Trade Commission, check out this list of answers to frequently asked questions:

Related Jobs

Sucker Punch Productions
Sucker Punch Productions — Bellevue, Washington, United States

Senior Tools and Engine Programmers
Sucker Punch Productions
Sucker Punch Productions — Bellevue, Washington, United States

Senior Graphics Programmer
Sucker Punch Productions
Sucker Punch Productions — Bellevue, Washington, United States

Senior Gameplay Programmers
Sucker Punch Productions
Sucker Punch Productions — Bellevue, Washington, United States

Multiplayer/Network Programmer

Loading Comments

loader image