# Children's Online Privacy Protection Rule

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2011-24314

## Record

- **Collection:** Federal Register
- **Document type:** Proposed Rule
- **Published:** September 27, 2011
- **Citation:** 76 FR 59804

## Text

FEDERAL TRADE COMMISSION
16 CFR Part 312
RIN 3084-AB20
Children's Online Privacy Protection Rule

AGENCY:

Federal Trade Commission (“FTC” or “Commission”).

ACTION:

Proposed rule; request for comment.

SUMMARY:

The Commission proposes to amend the Children's Online Privacy Protection Rule (“COPPA Rule” or “Rule”), consistent with the requirements of the Children's Online Privacy Protection Act to respond to changes in online technology, including in the mobile marketplace, and, where appropriate, to streamline the Rule. After extensive consideration of public input, the Commission proposes to modify certain of the Rule's definitions, and to update the requirements set forth in the notice, parental consent, confidentiality and security, and safe harbor provisions. In addition, the Commission proposes adding a new provision addressing data retention and deletion.

DATES:

Written comments must be received on or before November 28, 2011.

ADDRESSES:

Interested parties may file a comment online or on paper, by following the instructions in the Request for Comment part of the
SUPPLEMENTARY INFORMATION
section below. Write ``COPPA Rule Review, 16 CFR Part 312, Project No. P104503'' on your comment, and file your comment online at
https://ftcpublic.commentworks.com/ftc/2011copparulereview,
by following the instructions on the Web-based form. If you prefer to file your comment on paper, write “COPPA Rule Review, 16 CFR Part 312, Project No. P104503” on your comment, and mail or deliver your comment to the following address: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex E), 600 Pennsylvania Avenue, NW., Washington, DC 20580.

FOR FURTHER INFORMATION CONTACT:

Phyllis H. Marcus or Mamie Kresses, Attorneys, Division of Advertising Practices, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue, NW., Washington, DC 20580, (202) 326-2854, or (202) 326-2070.

SUPPLEMENTARY INFORMATION:

I. Background

The COPPA Rule, 16 CFR part 312, issued pursuant to the Children's Online Privacy Protection Act (“COPPA” or “COPPA statute”), 15 U.S.C. 6501
et seq.,
became effective on April 21, 2000. The Rule imposes certain requirements on operators of Web sites or online services directed to children under 13 years of age, and on operators of other Web sites or online services that have actual knowledge that they are collecting personal information online from a child under 13 years of age (collectively, “operators”). Among other things, the Rule requires that operators provide notice to parents and obtain verifiable parental consent prior to collecting, using, or disclosing personal information from children under 13 years of age.
1

The Rule also requires operators to keep secure the information they collect from children and prohibits them from conditioning children's participation in activities on the collection of more personal information than is reasonably necessary to participate in such activities.
2

The Rule contains a “safe harbor” provision enabling industry groups or others to submit to the Commission for approval self-regulatory guidelines that would implement the Rule's protections.
3

1

See
Children's Online Privacy Protection Rule, 16 CFR 312.3.

2

See
16 CFR 312.7 and 312.8.

3

See
16 CFR 312.10; Children's Online Privacy Protection Rule, 64 FR 59888, 59906, 59908, 59915 (Nov. 3, 1999),
available at http://www.ftc.gov/os/1999/10/64Fr59888.pdf.

The Commission initiated a review of the Rule on April 21, 2005, pursuant to Section 6507 of the COPPA statute, which required the Commission to conduct a review within five years of the Rule's effective date.
4

After considering extensive public comment, the Commission determined in March 2006 to retain the Rule without change.
5

4

See
15 U.S.C. 6507; 16 CFR 312.11.

5

See
Children's Online Privacy Protection Rule, 71 FR 13247 (Mar. 15, 2006) (retention of rule without modification).

The Commission remains deeply committed to helping to create a safer, more secure online experience for children and takes seriously the challenge to ensure that COPPA continues to meet its originally stated goals, even as online technologies, and children's uses of such technologies, evolve. In light of the rapid-fire pace of technological change since the Commission's 2005 review, including an explosion in children's use of mobile devices, the proliferation of online social networking and interactive gaming, the Commission initiated review of the COPPA Rule in April 2010 on an accelerated schedule.
6

6
The Commission generally reviews each of its trade regulation rules approximately every ten years. Under this schedule, the next COPPA Rule review was originally set for 2017.

On April 5, 2010, the Commission published a document in the
Federal Register
seeking public comment on whether technological changes to the online environment over the preceding five years warranted any changes to the Rule.
7

The Commission's request for public comment examined each aspect of the COPPA Rule, posing 28 questions for the public's consideration.
8

The Commission identified several areas where public comment would be especially useful, including examination of whether: The Rule's existing definitions are sufficiently clear and comprehensive, or warrant modification or expansion, consistent with the COPPA statute; additional technological methods to obtain verifiable parental consent should be added to the COPPA Rule, and whether any of the consent methods currently included should be removed; whether the Rule provisions on protecting the confidentiality and security of personal information are sufficiently clear and comprehensive; and the Rule's criteria and process for Commission approval and oversight of safe harbor programs should be modified in any way. The comment period closed on July 12, 2010. During the comment period, on June 2, 2010, the Commission held a public roundtable to discuss in detail several of the areas where public comment was sought, including the application of COPPA's definitions of “Internet,” “website,” and “online service” to new devices and technologies, the COPPA statute's actual knowledge standard for general audience Web sites and online services, the definition of “personal information,” emerging parental consent mechanisms, and COPPA's exceptions to prior parental consent.
9

7

See
Request for Public Comment on the Federal Trade Commission's Implementation of the Children's Online Privacy Protection Rule (“2010 Rule Review”), 75 FR 17089 (Apr. 5, 2010).

8

Id.

9
Information about the June 2, 2010 COPPA Roundtable is located at
http://www.ftc.gov/bcp/workshops/coppa/index.shtml.

In addition to the dialogue at the public roundtable, the Commission received 70 comments from industry representatives, advocacy groups, academics, technologists, and individual members of the public in response to the April 5, 2010 request for public comment.
10

The comments

addressed the efficacy of the Rule generally, and several possible areas for change.

10
Public comments in response to the Commission's April 5, 2010
Federal Register

document are located at
http://www.ftc.gov/os/comments/copparulerev2010/index.shtm.
Comments have been numbered based upon alphabetical order. Comments are cited herein identified by commenter name, comment number, and, where applicable, page number.

II. COPPA's Definition of “Child”

The COPPA statute, and by extension, the COPPA Rule, defines as a child “an individual under the age of 13.”
11

A few commenters suggested that COPPA's protections be broadened to cover a range of adolescents over age 12 and urged the Commission to seek a statutory change from Congress.
12

By contrast, the majority of commenters who addressed this issue expressed concern that expanding COPPA's coverage to teenagers would raise a number of constitutional, privacy, and practical issues.
13

11

See
15 U.S.C. 6502(1).

12

See
Andrew Bergen (comment 4); Common Sense Media (comment 12).

13

See
Sharon Anderson (comment 2); Kevin Brook (comment 6); Center for Democracy and Technology (“CDT”) (comment 8), at 5; CTIA (comment 14), at 10; Facebook (comment 22), at 2; Elatia Grimshaw (comment 26); Interactive Advertising Bureau (“IAB”) (comment 34), at 6-7; Harold Levy (comment 37); Motion Picture Association of America (“MPAA”) (comment 42), at 4; National Cable & Television Association (comment 44), at 5 n.16; NetChoice (comment 45), at 2; Promotion Marketing Association (“PMA”) (comment 51), at 5; Berin Szoka (comment 59), at 6; Toy Industry Association of America (comment 63), at 5. Five commenters urged the Commission to consider lowering or eliminating COPPA's age to permit younger children access to a variety of educational online offerings.
See
Eric MacDonald (comment 38); Mark Moran (comment 41); Steingreaber (comment 58); Karla Talbot (comment 60); Daniel Widrew (comment 67).

Recognizing the difficulties of extending COPPA to children ages 13 or older, at least one commenter, the Institute for Public Representation, proposed the need for alternative privacy protections for teenagers. This commenter, while not proposing a statutory change to the definition of “child,” called on the Commission to develop a set of privacy protections for teens, consistent with the Fair Information Practices Principles created by the Organization for Economic Cooperation and Development, that would require understandable notices, limited information collection, an opt-in consent process, and access and control rights to data collected from them.
14

14

See
Institute for Public Representation (comment 33), at 42.

In the course of drafting COPPA, Congress looked closely at whether adolescents should be covered by the law. Congress initially considered a requirement that operators make reasonable efforts to provide parents with notice and an opportunity to prevent or curtail the collection or use of personal information collected from children over the age of 12 and under the age of 17.
15

Ultimately, however, Congress decided to define a “child” as an individual under age 13.
16

The Commission supported this assessment at the time, based in part on the view that young children under age 13 do not possess the level of knowledge or judgment to make appropriate determinations about when and if to divulge personal information over the Internet.
17

The Commission continues to believe that the statutory definition of a child remains appropriate.
18

15

See Children's Online Privacy Protection Act of 1998,
S. 2326, 105th Cong. § 3(a)(2)(iii) (1998).

16

See
15 U.S.C. 6502.

17

See Protection of Children's Privacy on the World Wide Web: Hearing on S. 2326 Before the Subcomm. on Communications of the S. Comm. on Commerce, Science & Transportation,
105th Cong. (1998), at 5 (Statement of Robert Pitofsky, Chairman, Federal Trade Commission),
available at http://www.ftc.gov/os/1998/09/priva998.htm
(“Children are not fully capable of understanding the consequences of divulging personal information online.”).

18

See Protecting Youths in an Online World: Hearing Before the Subcomm. on Consumer Protection, Product Safety, and Insurance of the S. Comm. on Commerce, Science & Transportation,
111th Cong. 14-15 (2010) (Statement of Jessica Rich, Deputy Director, Bureau of Consumer Protection, Federal Trade Commission),
available at http://www.ftc.gov/os/testimony/100715toopatestimony.pdf.

Although teens face particular privacy challenges online,
19

COPPA's parental notice and consent approach is not designed to address such issues. COPPA's parental notice and consent model works fairly well for young children, but the Commission continues to believe that it would be less effective or appropriate for adolescents.
20

COPPA relies on children providing operators with parental contact information at the outset to initiate the consent process. The COPPA model would be difficult to implement for teenagers, as many would be less likely than young children to provide their parents' contact information, and more likely to falsify this information or lie about their ages in order to participate in online activities. In addition, courts have recognized that as children age, they have an increased constitutional right to access information and express themselves publicly.
21

Finally, given that adolescents are more likely than young children to spend a greater proportion of their time on Web sites and online services that also appeal to adults, the practical difficulties in expanding COPPA's reach to adolescents might unintentionally burden the right of adults to engage in online speech.
22

For all of these reasons, the Commission declines to advocate for a change to the statutory definition of “child.”

19
For example, research shows that teens tend to be more impulsive than adults and that they may not think as clearly as adults about the consequences of what they do.
See, e.g.,
Transcript of Exploring Privacy, A Roundtable Series (Mar. 17, 2010), Panel 3: Addressing Sensitive Information, available at
http://htc-01.media.globix.net/COMP008760MOD1/ftc_web/transcripts/031710_sess3.pdf;
Chris Hoofnagle, Jennifer King, Su Li, and Joseph Turow,
How Different Are Young Adults from Older Adults When It Comes to Information Privacy Attitudes & Policies?
(April 14, 2010), available at
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1589864.
As a result, they may voluntarily disclose more information online than they should. On social networking sites, young people may share personal details that leave them vulnerable to identity theft.
See
Javelin Strategy and Research, 2010
Identity Fraud Survey Report
(Feb. 2010), available at
https://www.javelinstrategy.com/uploads/files/1004.R_2010IdentityFraudSurveyConsumer.pdf.
They may also share details that could adversely affect their potential employment or college admissions.
See e.g.,
Commonsense Media,
Is Social Networking Changing Childhood? A National Poll
(Aug. 10, 2009), available at
http://www.commonsensemedia.org/teen-social-media
(indicating that 28 percent of teens have shared personal information online that they would not normally share publicly).

20

Id.

21

See, e.g., American Amusement Mach. Ass'n
v.
Kendrick,
244 F.3d 572 (7th Cir. 2001) (citing
Erznoznik
v.
City of Jacksonville,
422 U.S. 205, 212-14 (1975));
Tinker
v.
Des Moines Indep. Sch. Dist.,
393 U.S. 503, 511-14 (1969).

22

See ACLU
v.
Ashcroft,
534 F.3d 181, 196 (3d Cir. 2008) (citing
ACLU
v.
Gonzales,
478 F. Supp. 2d 775, 806 (E.D. Pa. 2007) (“Requiring users to go through an age verification process would lead to a distinct loss of personal privacy.”);
see also Bolger
v.
Youngs Drug Prods. Corp.,
463 U.S. 60, 73 (1983) (citing
Butler
v.
Michigan,
352 U.S. 380, 383 (1957) (“The Government may not reduce the adult population * * * to reading only what is fit for children.”).
See also
Berin Szoka (comment 59), at 6.

Although the Commission does not recommend that Congress expand COPPA to cover teenagers, the Commission believes that it is essential that teens, like adults, be provided with clear information about uses of their data and be given meaningful choices about such uses. Therefore, the Commission is exploring new privacy approaches that will ensure that teens—and adults—benefit from stronger privacy protections than are currently generally available.
23

23

See A Preliminary FTC Staff Report on Protecting Consumer Privacy in an Era of Rapid Change: A Proposed Framework for Businesses and Policymakers,
36-36 (Dec. 1, 2010), available at
http://www.ftc.gov/os/2010/12/101201privacyreport.pdf; Protecting Youths in an Online World,

supra
note 18, at 14-15 (“The FTC believes that its upcoming privacy recommendations based on its roundtable discussions will greatly benefit teens. The Commission expects that the privacy proposals emerging from this initiative will provide teens both a greater understanding of how their data is used and a greater ability to control such data.”).

III. COPPA's “Actual Knowledge” Standard

The COPPA statute applies to two types of operators: (1) Those who operate Web sites or online services directed to children and collect personal information, and (2) those who have
actual knowledge
that they are collecting personal information from a child under age 13.
24

The second prong, commonly known as “the actual knowledge standard,” holds operators of Web sites directed to teenagers, adults, or to a general audience, liable for providing COPPA's protections
only
when they know they are collecting personal information from a COPPA-covered child (
i.e.,
one under age 13). COPPA therefore was never intended to apply to the entire Internet, but rather to a subset of Web sites and online services.
25

24

See
15 U.S.C. 6503(a)(1).

25

See
MPAA (comment 42), at 10 (“Congress deliberately selected the actual knowledge standard because it served the objective of protecting young children without constraining appropriate data collection and use by operators of general audience Web sites. This standard was selected to serve the goals of COPPA without imposing excessive burdens—including burdens that could easily constrain innovation—on general audience sites and online services”).

Congress did not define the term “actual knowledge” in the COPPA statute, nor did the Commission define the term in the Rule. The case law makes clear that actual knowledge does not equate to “knowledge fairly implied by the circumstances”; nor is actual knowledge “constructive knowledge,” as that term is interpreted and applied legally.
26

Therefore, the Commission has advised that operators of general audience Web sites are not required to investigate the ages of their users.
27

By contrast, however, operators that ask for—or otherwise collect—information establishing that a user is under the age of 13 trigger COPPA's verifiable parental consent and all other requirements.
28

26
The original scope of COPPA, as indicated in S. 2326 and H.R. 4667, would have applied to any commercial Web site or online service used by an operator to “knowingly” collect information from children.
See Children's Online Privacy Protection Act of 1998,
S. 2326, 105th Cong. § 2(11)(A)(iii) (1998);
Electronic Privacy Bill of Rights Act of 1998,
H.R. 4667, 105th Cong. § 105(7)(A)(iii) (1998). Under federal case law, the term “knowingly” encompasses actual, implied, and constructive knowledge.
See Schmitt
v.
FMA Alliance,
398 F.3d 995, 997 (8th Cir. 2005);
Freeman United Coal Mining Co.
v.
Federal Mine Safety and Health Review Comm'n,
108 F.3d 358, 363 (D.C. Cir. 1997).

Upon the consideration of testimony from various witnesses, Congress modified the knowledge standard in the final legislation to require “actual knowledge.”
See Internet Privacy Hearing: Hearing on S. 2326 Before the Subcomm. on Communications of the S. Comm. on Commerce, Science, and Transportation,
105th Cong. 1069 (1998). Actual knowledge is generally understood from case law to establish a far stricter standard than constructive knowledge or knowledge implied from the ambient facts.
See United States
v.
DiSanto,
86 F.3d 1238, 1257 (1st Cir. 1996) (citing
United States
v.
Spinney,
65 F.3d 231, 236 (1st Cir. 1995), for the proposition that “when considering the question of “knowledge” [it is helpful] to recall that “the length of the hypothetical knowledge continuum” is marked by “constructive knowledge” at one end and “actual knowledge” at the other with various “gradations,” such as “notice of likelihood” in the “poorly charted area that stretches between the poles”).

27

See
Children's Online Privacy Protection Rule, Statement of Basis and Purpose (“1999 Statement of Basis and Purpose”), 64 FR 59888, 59889 (Nov. 3, 1999), available at
http://www.ftc.gov/os/1999/10/64Fr59888.pdf.

28

See id.
at 59892 (“Actual knowledge will be present, for example, where an operator learns of a child's age or grade from the child's registration at the site or from a concerned parent who has learned that his child is participating at the site. In addition, although the COPPA does not require operators of general audience sites to investigate the ages of their site's visitors, the Commission notes that it will examine closely sites that do not directly ask age or grade, but instead ask ‘age identifying’ questions, such as ‘what type of school do you go to: (a) elementary; (b) middle; (c) high school; (d) college.' Through such questions, operators may acquire actual knowledge that they are dealing with children under 13”).

In general, commenters to the Rule review expressed widespread support for Congress's retention of the statutory actual knowledge standard. Supporters find that the standard provides necessary certainty regarding the boundaries of operators' legal liability for COPPA violations.
29

Commenters generally felt strongly that a lesser standard,
e.g.,
constructive or implied knowledge, would cause extreme uncertainty for operators of general audience Web sites or online services seeking to comply with the law since they would be obliged either to make guesses about the presence of underage children or to deny access to a wide swath of participants, not only young children.
30

According to commenters, such actions would result in greater data collection from all users, including children, in order to determine who should receive COPPA protections (or, alternatively, be denied access to a site). Commenters viewed this result as contradictory to COPPA's goal of minimizing data collection.
31

29

See
CTIA (comment 14), at 2; Direct Marketing Association (“DMA”) (comment 17), at 8; MPAA (comment 42), at 9; Toy Industry Association, Inc. (comment 63), at 5; Jeffrey Greenbaum, Partner, Frankfurt Kurnit Klein & Selz PC, and J. Beckwith (“Becky”) Burr, Partner, WilmerHale, Remarks from
The “Actual Knowledge” Standard in Today's Online Environment
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online 78-79 (June 2, 2010), available at
http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf.

30

See
Sharon Anderson (comment 2); Boku (comment 5); CDT (comment 9), at 6; CTIA (comment 14), at 2; DMA (comment 17), at 8; Facebook (comment 22), at 7; IAB (comment 34), at 6.

31

See
CTIA (comment 14), at 2; DMA (comment 17), at 8; Facebook (comment 22), at 7-8.

A handful of commenters argued for a different standard. One commenter urged the Commission to require commercial Web site operators to make reasonable efforts to determine if a child is registering online, taking into consideration available technology.
32

According to this commenter, Web site operators otherwise face minimal legal risk and business incentive to proactively institute privacy protections for children online. Other commenters, such as the Institute for Public Representation and Microsoft, urged the Commission to adopt clearer guidance on when an operator will be considered to have obtained actual knowledge that it has collected personal information from a child.
33

32

See
Harry A. Valetk (comment 66), at 4.

33

See
Institute for Public Representation (comment 33), at 34 (urging the Commission to make clear that an operator can gain actual knowledge where it obtains age information from a source other than the child and where it creates a category for behavioral advertising to children under age 13. “Simply, if an operator decides on, or uses, or purports to know the fact that someone is a child, then that operator has actual knowledge that it is dealing with a child.”); Microsoft (comment 39), at 8 (asking the Commission to provide clear guidance on how operators can better meet COPPA's objectives of providing access to rich media content while not undermining parental involvement).

Despite the limitations of the actual knowledge standard, the Commission is persuaded that this remains the correct standard to be applied to operators of Web sites and online services that are not directed to children. Accordingly, the Commission does not advocate that Congress amend the COPPA statute's actual knowledge requirement at this time. Actual knowledge is far more workable, and provides greater certainty, than other legal standards that might be applied to the universe of general audience Web sites and online services. This is because the actual knowledge standard is triggered only at the point at which an operator becomes aware of a child's age. By contrast, imposing a lesser “reasonable efforts” or “constructive knowledge” standard might require operators to ferret through a host of circumstantial information to determine who may or may not be a child.

As described in detail below, with this Notice of Proposed Rulemaking, the Commission is proposing several modifications to the Rule's definition of “personal information.”
34

Were the

Commission to recommend that Congress change COPPA's actual knowledge standard, the changes the Commission proposes to the Rule's definitions might prove infeasible if applied across the entire Internet. The impact of the proposed changes to the definition of personal information are significantly narrowed by the fact that COPPA only applies to the finite universe of Web sites and online services directed to children and Web sites and online services with actual knowledge.

34
For example, the Commission proposes defining as personal information persistent identifiers and screen or user names where they are

used for functions other than or in addition to support for the internal operations of a Web site or online service. The Commission also proposes including identifiers that link the activities of a child across different Web sites or online services, as well as digital files containing a child's image or voice, in the definition.
See infra
Part V.A.(4).

IV. COPPA's Coverage of Evolving Technologies

The Commission's April 5, 2010
Federal Register
document sought public input on the implications for COPPA enforcement raised by technologies such as mobile communications, interactive television, interactive gaming, and other evolving media.
35

The Commission's June 2, 2010 roundtable featured significant discussion on the breadth of the terms “Internet,” “website located on the Internet,” and “online service” as they relate to the statute and the Rule.

35

See
2010 Rule Review,
supra
note 7, at 17090.

Commenters and roundtable participants expressed a consensus that both the COPPA statute and Rule are written broadly enough to encompass many new technologies without the need for new statutory language.
36

First, there is widespread agreement that the statute's definition of “Internet,” covering the “myriad of computer and telecommunications facilities, including equipment and operating software, which comprise the interconnected world-wide network of networks that employ the Transmission Control Protocol/Internet Protocol,” is device neutral.
37

36

See
CDT (comment 8), at 2; Edward Felten, Dir. and Professor of Computer Sci. and Pub. Affairs, Princeton Univ. (currently Chief Technologist at the Federal Trade Commission), Remarks from
The Application of COPPA's Definitions of “Internet,” “Website,” and “Online Service” to New Devices and Technologies
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online 13-14 (June 2, 2010), available at
http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf
(“[T]his was and still is a spot-on definition of what “Internet” means—worldwide interconnection and the use of TCP or IP or any of that suite of protocols.”).

37

See
CDT (comment 8), at 2. However, two commenters urged the Commission to consider modifying or expanding the definition of “Internet” so as to expressly acknowledge the convergence of technologies,
e.g.,
mobile devices and other applications that are platform neutral or capable of storing and transmitting data in the manner of a personal computer.
See
Electronic Privacy Information Center (“EPIC”) (comment 19), at 7-8; Jayne Hitchcock (comment 29).

While neither the COPPA statute nor the Rule defines a “Web site located on the Internet,” the term is broadly understood to cover content that users can access through a browser on an ordinary computer or mobile device.
38

Likewise, the term “online service” broadly covers any service available over the Internet, or that connects to the Internet or a wide-area network.
39

The Commission agrees with commenters that a host of current technologies that access the Internet or a wide area network are “online services” currently covered by COPPA and the Rule. This includes mobile applications that allow children to play network-connected games, engage in social networking activities, purchase goods or services online, receive behaviorally targeted advertisements, or interact with other content or services.
40

Likewise, Internet-enabled gaming platforms, voice-over-Internet protocol services, and Internet-enabled location based services, also are online services covered by COPPA and the Rule. The Commission does not believe that the term “online service” needs to be further defined either in the statute or in the Rule.
41

38

See
AT&T (comment 3), at 5; Spratt (comment 57); Edward Felten,
supra
note 36, at 15.

39

See
John B. Morris, Jr., General Counsel and Director, Internet Standards, Technology and Policy Project, CDT, and Angela Campbell, Institute for Public Representation, Georgetown Univ. Law Ctr., Remarks from
The Application of COPPA's Definitions of “Internet,” “Web site,” and “Online Service” to New Devices and Technologies
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online 16-17 (June 2, 2010), available at
http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf.
One commenter mentioned that the terms “Internet” and “online” were seemingly intended by Congress to be used interchangeably to mean “the interconnected world-wide network of networks.”
See
Entertainment Software Association (comment 20), at 15 (citing the legislative history, 144 Cong. Rec. S8482-83, Statement of Sen. Bryan (1998)).
But see
Edward Felten,
supra
note 36, at 19.

40

See, e.g.,
Angela Campbell,
supra
note 39, at 30-31.

41
The FTC has brought a number of cases alleging violations of COPPA in connection with the operation of an online service, including:
United States
v.
W3 Innovations LLC,
No. CV-11-03958 (N.D. Cal., filed Aug. 12, 2011) (child-directed mobile applications);
United States
v.
Playdom, Inc.,
No. SA CV-11-00724 (C.D. Cal., filed May 11, 2011) (online virtual worlds);
United States
v.
Sony BMG Music Entertainment,
No. 08 Civ. 10730 (S.D.N.Y, filed Dec. 10, 2008) (social networking service);
United States
v.
Industrious Kid, Inc.,
No. CV-08-0639 (N.D. Cal., filed Jan. 28, 2008) (social networking service);
United States
v.
Xanga.com, Inc.,
No. 06-CIV-6853 (S.D.N.Y., filed Sept. 7, 2006) (social networking service); and
United States
v.
Bonzi Software, Inc.,
No. CV-04-1048 (C.D. Cal., filed Feb. 14, 2004) (desktop software application).

Although many mobile activities are online services, it is less clear whether all short message services (“SMS”) and multimedia messaging services (“MMS”) are covered by COPPA.
42

One commenter maintained that SMS and MMS text messages cross wireless service providers' networks and short message service centers, not the public Internet, and therefore that such services are not Internet-based and are not “online services.”
43

However, another panelist at the Commission's June 2, 2010 roundtable cautioned that not all texting programs are exempt from COPPA's coverage.
44

For instance, mobile applications that enable users to send text messages from their web-enabled devices without routing through a carrier-issued phone number constitute online services.
45

Likewise, retailers' premium texting and coupon texting programs that register users online and send text messages from the Internet to users' mobile phone numbers are online services.
46

42

See
2010 Rule Review,
supra
note 7, at 17090 (Question 11);
see also
Denise Tayloe, President, Privo, Inc., Remarks from
Emerging Parental Verification Access and Methods
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online 27 (June 2, 2010),
available at http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf
(questioning whether a “text to vote” marketing campaign is covered by COPPA).

43

See
CTIA (comment 14), at 2-5 (citing the Federal Communications Commission's rules and regulations implementing the CAN-SPAM Act of 2003 and the Telephone Consumer Protection Act of 1991, finding that phone-to-phone SMS is not captured by Section 14 of CAN-SPAM because such messages do not have references to Internet domains). The Commission agrees that where mobile services do not traverse the Internet or a wide-area network, COPPA will not apply.
See
Michael Altschul, Senior Vice President and Gen. Counsel, CTIA, Remarks from
The Application of COPPA's Definitions of “Internet,” “Web site,” and “Online Service” to New Devices and Technologies
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online at 19-21 (June 2, 2010), available at
http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf.

44

See
Edward Felten,
supra
note 36, at 27-28.

45
For example, online texting services offered by TextFree, Textie, and textPlus+ that permit users to communicate via text message over the Internet.

46
For example, text alert coupon and notification services offered by retailers such as Target and JC Penney.

The Commission will continue to assess emerging technologies to determine whether or not they constitute “Web sites located on the Internet” or “online services” subject to COPPA's coverage.

V. Proposed Modifications to the Rule

As discussed above, commenters expressed a consensus that, given its flexibility and coverage, the COPPA Rule continues to be useful in helping

to protect children as they engage in a wide variety of online activities. The Commission's experience in enforcing the Rule, and public input received through the Rule review process, however, demonstrate the need to update certain Rule provisions. After extensive consideration, the Commission proposes modifications to the Rule in the following five areas: Definitions, Notice, Parental Consent, Confidentiality and Security of Children's Personal Information, and Safe Harbor Programs. In addition to modifying these provisions, the Commission proposes adding a new Rule section addressing data retention and deletion. Each of these changes is discussed in detail below.

A. Definitions (16 CFR 312.2)

The Commission proposes to modify particular definitions to update the Rule's coverage and, in certain cases, to streamline the Rule's language. The Commission proposes modifications to the definitions of “collects or collection,” “online contact information,” “personal information,” “support for the internal operations of the Web site or online service,” and “Web site or online service directed to children.” The Commission also proposes a minor structural change to the Rule's definition of “disclosure.”

(1) Collects or Collection

Section 312.2 of the Rule defines “collects or collection” as:

[T]he gathering of any personal information from a child by any means, including but not limited to:

(a) Requesting that children submit personal information online;

(b) Enabling children to make personal information publicly available through a chat room, message board, or other means, except where the operator deletes all individually identifiable information from postings by children before they are made public, and also deletes such information from the operator's records; or

(c) The passive tracking or use of any identifying code linked to an individual, such as a cookie.

The Commission proposes amending paragraph (a) to change the term “requesting that children submit personal information online” to “requesting, prompting, or encouraging a child to submit personal information online” in order to clarify that the Rule covers the online collection of personal information both when an operator mandatorily requires it, and when an operator merely prompts or encourages a child to provide such information.

Section 312.2(b) currently defines “collects or collection” to include enabling children to publicly post personal information (
e.g.,
on social networking sites or on blogs), “except where the operator deletes all individually identifiable information from postings by children before they are made public, and also deletes such information from the operator's records.”
47

This aspect of COPPA's definition of “collects or collection” has come to be known as the “100% deletion standard.”
48

Several commenters indicated that this standard, while well-meaning, serves as an impediment to operators' implementation of sophisticated filtering technologies that might aid in the detection and removal of personal information.
49

Some commenters urged the Commission to revise the Rule to specify the particular types of filtering mechanisms—for example, white lists, black lists, or algorithmic systems—that the Commission believes conform to the Rule's current 100% deletion requirement.
50

One commenter urged the Commission to exercise caution in modifying the Rule to permit the use of automated filtering systems to strip personal information from posts prior to posting; this commenter urged the Commission to make clear that the use of an automated system
would not
provide an operator with a safe harbor from enforcement action in the case of an inadvertent disclosure of personal information.
51

47
Operators who offer services such as social networking, chat, bulletin boards and who do not pre-strip (
i.e.,
completely delete) such information are deemed to have “disclosed” personal information under COPPA's definition of “disclosure.”
See
16 CFR 312.2.

48

See
Phyllis Marcus, Remarks from
COPPA's Exceptions to Parental Consent
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online 310 (June 2, 2010),
available at http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf.

49

See
Entertainment Software Association (comment 20), at 13-14; Rebecca Newton (comment 46), at 4;
see also
WiredSafety.org (comment 68), at 15.

50

See
Berin Szoka (comment 59), Szoka Responses to Questions for the Record, at 19 (“[T]he FTC could * * * allow operators, at least in some circumstances, to use “an automated system of review and/or posting” to satisfy the existing “deletion exception to the definition of collection.” In other words, sites could potentially allow children to communicate with each other through chat rooms, message boards, and other social networking tools
without
having to obtain verifiable parental consent if they had in place algorithmic filters that would automatically detect personal information such as a string of seven or ten digits that seems to correspond to a phone number, a string of eight digits that might correspond to a Social Security number, a street address, a name, or even a personal photo—and prevent children from sharing that information in ways that make the information “publicly available”);
see also
Privo (comment 50), at 5.

51

See
EPIC (comment 19), at 6-7.

The Commission has undertaken this Rule review with an eye towards encouraging the continuing growth of engaging, diverse, and appropriate online content for children that includes strong privacy protections by design. Children increasingly seek interactive online environments where they can express themselves, and operators should be encouraged to develop innovative technologies to attract children to age-appropriate online communities while preventing them from divulging their personal information. Unfortunately, Web sites that provide children with only limited communications options often fail to capture their imaginations for very long. After careful consideration, the Commission believes that the 100% deletion standard has set an unrealistic hurdle to operators' development and implementation of automated filtering systems.
52

In its place, the Commission proposes a “reasonable measures” standard whereby operators who employ technologies reasonably designed to capture
all or virtually all
personal information inputted by children should not be deemed to have “collected” personal information. This proposed change is intended to encourage the development of systems, either automated, manual, or a combination thereof, to detect and delete all or virtually all personal information that may be submitted by children prior to its public posting.
53

52
In fact, inquiries about automated filtering systems, and whether they could ever meet the Commission's current 100% deletion standard, are among the most frequent calls to the Commission's COPPA hotline.

53
In the Commission's experience, establishing a broad standard of reasonableness permits industry to innovate specific security methods that best suit particular needs, and the Commission has set similar “reasonableness” standards in other enforcement arenas. For example, in its law enforcement actions involving breaches of data security, the Commission consistently has required respondents to establish and maintain comprehensive information security programs that are “reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers.”
See, e.g., Ceridian Corp.,
FTC Dkt. No. C-4325 (June 15, 2011)
; Lookout Servs., Inc.,
FTC Dkt. No. C-4326 (June 15, 2011).

Finally, the Commission proposes simplifying paragraph (c) of the Rule's definition of “collects or collection” to clarify that it includes all means of passive tracking of a child online, irrespective of the technology used. The proposed paragraph removes the language “or use of any identifying code linked to an individual, such as a cookie” and simply states “passive tracking of a child online.”

Therefore, the Commission proposes to amend the definition of “collects or collection” so that it reads:

Collects
or
collection
means the gathering of any personal information from a child by any means, including but not limited to:

(a) Requesting, prompting, or encouraging a child to submit personal information online;

(b) Enabling a child to make personal information publicly available in identifiable form. An operator shall not be considered to have collected personal information under this paragraph if it takes reasonable measures to delete all or virtually all personal information from a child's postings before they are made public and also to delete such information from its records; or,

(c) The passive tracking of a child online.
54

54
One commenter, EPIC, expressed the opinion that the Rule's reference to information collected “by any means” in the definition of “collects or collection” is ambiguous with regard to information acquired offline that is uploaded, stored, or distributed to third parties by operators.
See
EPIC (comment 19), at 5. However, Congress limited the scope of COPPA to information that an operator collects
online
from a child; COPPA does not govern information collected offline.
See
15 U.S.C. 6501(8) (defining the personal information as “individually identifiable information about an individual collected online. * * *”); 144 Cong. Rec. S11657 (Oct. 7, 1998) (Statement of Sen. Bryan) (“This is an online children's privacy bill, and its reach is limited to information collected online from a child.”).

(2) Disclosure

Section 312.2 of the Rule defines “disclosure” as:

(a) The release of personal information collected from a child in identifiable form by an operator for any purpose, except where an operator provides such information to a person who provides support for the internal operations of the Web site or online service and who does not disclose or use that information for any other purpose. For purposes of this definition:

(1) Release of personal information means the sharing, selling, renting, or any other means of providing personal information to any third party, and

(2) Support for the internal operations of the Web site or online service means those activities necessary to maintain the technical functioning of the Web site or online service, or to fulfill a request of a child as permitted by §§ 312.5(c)(2) and (3); or, (b) Making personal information collected from a child by an operator publicly available in identifiable form, by any means, including by a public posting through the Internet, or through a personal home page posted on a Web site or online service; a pen pal service; an electronic mail service; a message board; or a chat room.

The Commission proposes making several minor modifications to this definition that are consistent with the statutory definition. First, the Commission proposes broadening the title of this definition from “disclosure” to “disclose or disclosure” to clarify that in every instance in which the Rule refers to instances where an operator “disclose[s]” information, the definition of disclosure shall apply. In addition, the Commmission proposes moving the definitions of “release of personal information” and “support for the internal operations of the Web site or online service” contained within the definition of “disclosure” to stand-alone definitions within ' 312.2 of the Rule.
55

This change will clarify what is intended by the terms “release of personal information” and “support for the internal operations of the Web site or online service” where those terms are referenced elsewhere in the Rule and where they are not directly connected with the terms “disclose” or “disclosure.”
56

55
The Commission also proposes minor changes to the definition of “support for the internal operations of a Web site or online service,” as described in Part V.A(5). below.

56
For example, the term “support for the internal operations of the Web site or online service” is included within the proposed revisions to the definition of “personal information.”
See infra
Part V.A.(5). The term “release of personal information” is included within the proposed revised provision to ' 312.8 regarding “Confidentiality, security, and integrity of personal information collected from children.”
See infra
Part V.D.

Therefore, the Commission proposes to amend the definition of “disclosure” to read:

Disclose or disclosure
means, with respect to personal information:

(a) The release of personal information collected by an operator from a child in identifiable form for any purpose, except where an operator provides such information to a person who provides support for the internal operations of the Web site or online service; and,

(b) Making personal information collected by an operator from a child publicly available in identifiable form by any means, including but not limited to a public posting through the Internet, or through a personal home page or screen posted on a Web site or online service; a pen pal service; an electronic mail service; a message board; or a chat room.

(3) “Release of personal information”

The Commission proposes to define the term “release of personal information” separately from its current inclusion within the definition of “disclosure.” Since the term applies to provisions of the Rule that do not relate solely to disclosures,
57

this stand-alone definition will provide greater clarity as to the terms' applicability throughout the Rule. In addition, the Commission proposes technical changes to clarify that the term “release of personal information” primarily addresses business-to-business uses of personal information. Public disclosure of personal information is covered by paragraph (b) of the definition of “disclosure.” Therefore, the Commission proposes to revise the definition of “release of personal information” so that it reads:

57

See, e.g.,
discussion regarding 16 CFR 312.8 (confidentiality, security and integrity of children's personal information),
infra
Part V.D.

Release of personal information
means the sharing, selling, renting, or transfer of personal information to any third party.

(4) “Support for the internal operations of the Web site or online service”

The Commission also proposes separating out the term “support for the internal operations of the Web site or online service” from the definition of “disclosure.” The Commission recognizes that the term “support for internal operations of the Web site or online service”—
i.e.,
activities necessary to maintain the technical functioning of the Web site or online service—is an important limiting concept that warrants further explanation. The Rule recognizes that information that is collected by operators for the sole purpose of support for internal operations should be treated differently than information that is used for broader purposes.

The term currently is a part of the definitions of “disclosure” and “third party” within the Rule. As explained below, the Commission proposes to expand the definition of “personal information” to include “screen or user names” and “persistent identifiers,” when such items are used for functions other than or in addition to “support for the internal operations of the Web site or online service.”
58

In proposing to create a separate definition of “support for the internal operations of a Web site or online service,” the Commission also proposes to expand that definition to include “activities necessary to protect the security or integrity of the Web site or online service.” With this change, the Commission recognizes operators' need to protect themselves or their users from security threats, fraud, denial of service attacks, user misbehavior, or other threats to operators' internal operations.
59

In addition, the Commission proposes adding the limitation that information collected for such purposes may not be used or disclosed for any other purpose, so that if there is a secondary use of the information, it becomes “personal information” under the Rule.

58

See infra
Part V.(5)(b) and (c).

59

See
WiredSafety.org (comment 68), at 17.

The Commission recognizes that operators use persistent identifiers and screen names to aid the functionality and technical stability of Web sites and online services and to provide a good user experience, and the Commission does not intend to limit operators'

ability to collect such information from children for those purposes. However, the Commission also recognizes that such identifiers may be used in more expansive ways that affect children's privacy. In the sections that follow, the Commission sets forth the parameters within which operators may collect and use screen names and persistent identifiers without triggering COPPA's application.
60

60

Id.

The Commission proposes to revise the definition of “support for the internal operations of Web site or online service” so that it states:

Support for the internal operations of the Web site or online service
means those activities necessary to maintain the technical functioning of the Web site or online service, to protect the security or integrity of the Web site or online service, or to fulfill a request of a child as permitted by § 312.5(c)(3) and (4), and the information collected for such purposes is not used or disclosed for any other purpose.

(5) Online Contact Information

Section 312.2 of the Rule defines “online contact information” as “an e-mail address or any other substantially similar identifier that permits direct contact with a person online.” The Commission proposes to clarify this definition to flag that the term covers
all
identifiers that permit direct contact with a person online, and to eliminate any inconsistency between the stand-alone definition of online contact information and the use of the same term within the Rule's definition of “personal information.”
61

The revised definition set forth below adds commonly used forms of online identifiers, including instant messaging user identifiers, voice over internet protocol (VOIP) identifiers, and video chat user identifiers. The proposed definition makes clear, however, that the identifiers included are not intended to be exhaustive, and may include other substantially similar identifiers that permit direct contact with a person online.

61
The Rule currently defines as personal information “an e-mail address or other online contact information, including but not limited to an instant messaging user identifier, or a screen name that reveals an individual's e-mail address.” 16 CFR 312.2 (paragraph (c), definition of “personal information”). The Commission also proposes removing the listing of identifiers from the definition of personal information and substituting the simple phrase “online contact information” instead.
See infra
Part V.A.(4)(a). By doing so, the Commission hopes to streamline the Rule's definitions in a way that is useful and accessible for operators.

Therefore, the Commission proposes to amend the definition of “online contact information” to state:

Online contact information
means an e-mail address or any other substantially similar identifier that permits direct contact with a person online, including but not limited to, an instant messaging user identifier, a voice over internet protocol (VOIP) identifier, or a video chat user identifier.

(6) Personal Information

The COPPA statute defines personal information as individually identifiable information about an individual collected online, including:

(A) A first and last name;

(B) A home or other physical address including street name and name of a city or town;

(C) An e-mail address;

(D) A telephone number;
62

62
The term “telephone number” includes landline, web-based, and mobile phone numbers.

(E) A Social Security number;

(F) Any other identifier that the Commission determines permits the physical or online contacting of a specific individual; or

(G) information concerning the child or the parents of that child that the Web site collects online from the child and combines with an identifier described in this paragraph.
63

63
15 U.S.C. 6502(8). The Federal Trade Commission originally used the authority granted under Section 6502(8)(F) to define personal information under the COPPA Rule to include the following pieces of information not specifically listed in the statute:

• Other online contact information, including but not limited to an instant messaging user identifier;

• A screen name that reveals an individual's e-mail address;

• A persistent identifier, such as a customer number held in a cookie or a processor serial number, where such identifier is associated with individually identifiable information; and,

• A combination of a last name or photograph of the individual with other information such that the combination permits physical or online contacting.

As explained below, the Commission proposes to use this statutorily granted authority in paragraph (F) to modify, and in certain cases, expand, upon the Rule's definition of “personal information” to reflect technological changes.

a. Online Contact Information (Revised Paragraph (c))

The Commission proposes to replace existing paragraph (c) of the Rule's definition of “personal information,” which refers to “an e-mail address or other online contact information including but not limited to an instant messaging user identifier, or a screen name that reveals an individual's e-mail address,” with the broader term “online contact information,” as newly defined.
64

Moreover, as discussed immediately below, the Commission proposes to move the existing reference to a “screen name” to a separate item within the definition of “personal information.”

64

See supra
Part V.A.(4)(a).

b. Screen or User Names (Revised Paragraph (d))

Currently, screen names are considered “personal information” under COPPA only when they reveal an individual's e-mail address. The Commission proposes instead that screen (or user) names be categorized as personal information when they are used for functions other than, or in addition to, support for the internal operations of the Web site or online service. This change reflects the reality that screen and user names increasingly have become portable across multiple Web sites or online services, and permit the direct contact of a specific individual online regardless of whether the screen or user names contain an e-mail address.
65

65

See, e.g.,
OpenId, Windows Live ID, and the Facebook Platform.

The proposed definition exempts screen or user names that are used solely to maintain the technical functioning of the Web site or online service. This qualification is intended to retain operators' ability to utilize screen or user names
within
a Web site or online service (absent the collection, use, or disclosure of
other
personal information) without obtaining prior parental consent. Accordingly, an operator may allow children to establish screen names for use within a site or service. Such screen names may be used for access to the site or service, to identify users to each other, and to recall user settings. However, where the screen or user name is used for purposes other than to maintain the technical functioning of the Web site or online service, the screen name becomes “personal information” under the proposed Rule.

c. Persistent Identifiers (Revised Paragraph (g)) and Identifiers Linking a Child's Online Activities (New Paragraph (h))

The existing Rule includes as personal information “a persistent identifier, such as a customer number held in a cookie or a processor serial number, where such identifier is associated with individually identifiable information.”
66

In its 1999 Statement of Basis and Purpose, the Commission discussed persistent identifiers that automatically are collected by Web sites, such as static IP addresses and

processor serial numbers, stating that “unless such identifiers are associated with other individually identifiable personal information, they would not fall within the Rule's definition of ‘personal information.’ ” Moreover, with respect to information stored in cookies, the Commission stated that “[i]f the operator either collects individually identifiable information using the cookie or collects non-individually identifiable information using the cookie that is combined with an identifier, then the information constitutes ‘personal information’ under the Rule, regardless of where it is stored.”
67

Taken together, these statements limit COPPA's coverage of persistent identifiers solely to those identifiers that are otherwise linked to “personal information” as defined by the Rule.

66

See
paragraph (f) to the definition of “personal information.” 16 CFR 312.2.

67

See
1999 Statement of Basis and Purpose, 64 FR 59888, 59892-93.

Developments in technology in the intervening twelve years since the COPPA Rule was issued, and the resulting implications for consumer privacy, have led to a widespread reexamination of the concept of “personal information” and of the types of information COPPA should cover.
68

While it is clear that COPPA always was intended to regulate an operator's ability to obtain information from, and market back to, children,
69

methods of marketing online have burgeoned in recent years. In this regard, the Commission sought comment on whether certain identifiers, such as IP address, zip code, date of birth, gender, and information collected in connection with online behavioral advertising, should now be included within the Rule's definition of “personal information.”
70

68
Commission staff recognized in its 2009 online behavioral advertising report that, “in the context of online behavioral advertising, the traditional notion of what constitutes PII versus non-PII is becoming less and less meaningful and should not, by itself, determine the protections provided for consumer data.” FTC Staff Report: Self-Regulatory Principles for Online Behavioral Advertising, 21-22 (Feb. 2009),
available at http://www.ftc.gov/os/2009/02/P085400behavadreport.pdf.
Similarly, the Federal Trade Commission 2010 Staff Privacy Report cited widespread recognition among industry and academics that the traditional distinction between the two categories of data has eroded, and that information practices and restrictions that rely on this distinction are losing their relevance.
See
Protecting Consumer Privacy in an Era of Rapid Change,
supra
note 23, at 35-36.

69

See
144 Cong. Rec. S8482 (July 17, 1998) (Statement of Sen. Bryan) (“Unfortunately, the same marvelous advances in computer and telecommunication technology that allow our children to reach out to new resources of knowledge and cultural experiences are also leaving them unwittingly vulnerable to exploitation and harm by deceptive marketers and criminals * * *. Much of this information appears to be harmless, but companies are attempting to build a wealth of information about you and your family without an adult's approval—a profile that will enable them to target and to entice your children to purchase a range of products. The Internet gives marketers the capability of interacting with your children and developing a relationship without your knowledge”).

70

See
2010 Rule Review,
supra
note 7, at 17090.

Numerous comments to the Rule review addressed this question.
71

Several commenters opposed such an expansion, pointing out that the collection of certain identifiers, such as IP addresses, are integral to the delivery of online content.
72

According to these commenters, if an IP address, on its own, were to be included within the definition of “personal information,” virtually every Web site or online service directed to children would be subject to COPPA's requirements, regardless of whether any additional information is collected, used, or disclosed, because a browser's communication with a Web site typically reveals the user's IP address to the Web site operator. Commenters especially expressed concern about operators' ability to obtain prior verifiable parental consent in such situations.
73

In addition, some commenters noted that an IP address may not lead an operator to a specific individual, but rather, indicate only a particular computer or computing device shared by a number of individuals.
74

71

See, e.g.,
BOKU (comment 5); CDT (comment 8); DMA (comment 17), at 6-9; Entertainment Software Association (comment 20), at 17-18; Google, Inc. (comment 24), at 6-7; Institute for Public Representation (comment 33), at 21; IAB (comment 34), at 3-5; Interstate Commerce Coalition (comment 35), at 2; Microsoft Corporation (comment 39), at 9-10; MPAA (comment 42), at 6-7; NetChoice (comment 45), at 6-7; Paul Ohm (comment 48); TechAmerica (comment 61), at 5-6; Toy Industry Association, Inc. (comment 63), at 7-10; TRUSTe (comment 64), at 3-5.

72

See
Google, Inc. (comment 24), at 7; Internet Commerce Coalition (comment 35), at 2-3.

73

See, e.g.,
Entertainment Software Association (comment 20), at 18; Interstate Commerce Coalition (comment 35), at 2.

74

See
Toy Industry Association, Inc. (comment 63), at 9; TRUSTe (comment 64), at 5.

Several other commenters addressed the question of whether identifiers such as cookies or other technologies used to track online activities should be included within the definition of “personal information.” As with the comments regarding IP addresses, these commenters maintained that uses of cookies and other tracking devices do not result in the contacting of specific individuals online as contemplated by Congress in the COPPA statute.
75

Moreover, some commenters asserted that these technologies can be used for a number of beneficial purposes,
e.g.,
some operators use cookies to protect children from inappropriate advertising (and conversely, to deliver only appropriate advertising); other operators use cookies to personalize children's online experiences. Finally, these commenters contended that expanding COPPA to include cookies and other online behavioral advertising technologies is unnecessary because existing self-regulatory principles for online behavioral advertising are sufficient to curtail targeted advertising to children.
76

75

See
Facebook (comment 22), at 6; Microsoft Corporation (comment 39), at 9; Toy Industry Association, Inc. (comment 63), at 7.

76

See
CDT (comment 8, at 8) (referring to the Network Advertising Initiative's
2008 NAI Principles Code of Conduct
); Entertainment Software Association (comment 20), at 19 (referring to the
Self-Regulatory Principles for Online Behavioral Advertising
issued by the American Association of Advertising Agencies, Association of National Advertisers, Direct Marketing Association, Interactive Advertising Bureau, and Council of Better Business Bureaus in July 2009); Facebook (comment 22), at 7.

By contrast, several commenters asserted that identifiers such as cookies and IP addresses can be used by online operators to track and communicate with
specific
individuals and should be included within COPPA's categories of information considered to be personal.
77

77

See
Common Sense Media (comment 12), at 8; EPIC (comment 19), at 9; Institute for Public Representation (comment 33), at 21.

After careful consideration, the Commission believes that persistent identifiers can permit the contacting of a specific individual, and thus, with the limitations described below, should be included as part of a revised definition of “personal information” in the COPPA Rule. The Commission does not agree with commenters who argue that persistent identifiers only allow operators to contact a specific device or computer. Information that “permits the physical or online contacting of a specific individual” does not mean information that permits the contacting of only a single individual, to the exclusion of all other individuals. For example, the COPPA statute includes within the definition of “personal information” a home address alone or a phone number alone—information that is often applicable to an entire household. The Commission believes this reflects the judgment of Congress that an operator who collects this information is reasonably likely to be able to contact a specific individual, even without having collected other identifying information. The Commission believes the same is true of persistent identifiers.

Moreover, increasingly, consumer access to computers is shifting from the model of a single, family-shared,

personal computer to the widespread distribution of person-specific, Internet-enabled, handheld devices to each member within a household, including children.
78

Such handheld devices often have one or more unique identifiers associated with them that can be used to persistently link a user across Web sites and online services, including mobile applications.
79

With this change in computing use, operators now have a better ability to link a particular individual to a particular computing device.

78

See
Common Sense Media,
Do Smart Phones = Smart Kids? The Impact of the Mobile Explosion on America's Kids, Families, and Schools
(Apr. 2010),
available at http://www.commonsensemedia.org/smartphones-smartkids
(citing a study from the NPD Group, Inc. finding that 20% of U.S. children ages 4-14 owned a cell phone in 2008); N. Jackson, “More Kids Can Work Smartphones Than Can Tie Their Own Shoes,” The Atlantic (Jan. 24, 2011), available at
http://www.theatlantic.com/technology/archive/2011/01/more-kids-can-work-smartphones-than-can-tie-their-own-shoes/70101/; see also
S. Smith, “Now It's Personal: Mobile Nears the Privacy Third Rail,” Behavioral Insider (Apr. 22, 2011),
available at http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=149196
(warning that “[m]any of the arguments used to assuage worries about digital privacy online are simply less effective [in the mobile space]. When data can be tied to specific device IDs, times and location, insistence that the resulting data is ‘anonymized’ (no matter how true it may be) is very hard for the layman to swallow.”).

79
Sometimes called “processor serial numbers,” “device serial numbers,” or “unique device identifier,” unique identifiers refer to software-readable or physical numbers embedded by manufacturers into individual processors or devices.
See, e.g.,
J. Valentino-DeVries,
Unique Phone ID Numbers Explained,
Wall St. J. (Dec. 19, 2010),
available at http://blogs.wsj.com/digits/2010/12/19/unique-phone-id-numbers-explained/.

At the same time, the Commission is mindful of the concerns raised by commenters that including persistent identifiers within the definition of personal information, without further qualification, would hinder operators' ability to provide basic online services to children. Several commenters indicated that Web sites and online services must identify and use IP addresses to deliver content to computers; if IP addresses, without more, were treated as “personal information” under COPPA, a site or service would be liable for collecting personal information as soon as a child landed on its home page or screen.
80

The Commission agrees that such an approach is over-broad and unworkable.
81

80

See
CDT (comment 9), at 7-8; DMA (comment 17), at 6; Entertainment Software Association (comment 20), 17-18; Google (comment 24), 7; Internet Commerce Coalition (comment 35), at 2-3; and TechAmerica (comment 61), at 6.

81
As some commenters noted, it would be impracticable to obtain verifiable parental consent prior to the collection of an IP address for purposes of delivering online content, since Web site operators would not know at that point in time that the Web site visitor was a child, and would have no means of obtaining consent from that child's parent.
See, e.g.,
Internet Commerce Coalition (comment 35), at 2.

The Commission believes that when a persistent identifier is used only to support the internal operations of a Web site or online service, rather than to compile data on specific computer users, the concerns underlying COPPA's purpose are not present.
82

Accordingly, the Commission proposes to modify the definition of “personal information” by revising paragraph (g), and adding a paragraph (h), as follows:

82

See
144 Cong. Rec. S8482 (July 17, 1998) (Statement of Sen. Bryan).

(g) A persistent identifier, including but not limited to, a customer number held in a cookie, an Internet Protocol (IP) address, a processor or device serial number, or unique device identifier, where such persistent identifier is used for functions other than or in addition to support for the internal operations of the Web site or online service;

(h) an identifier that links the activities of a child across different Web sites or online services;

Proposed paragraph (g)—which covers persistent identifiers
where they are used for functions other than, or in addition to, support for the internal operations of the Web site or online service
—is designed not to interfere with operators' ability to deliver content to children within the ordinary operation of their Web sites or online services. This limitation takes into account the comments expressing concern about the potential for COPPA to interfere with the ordinary operation of Web sites or online services.
83

The new language in the definition would permit operators' use of persistent identifiers for purposes such as user authentication, improving site navigation, maintaining user preferences, serving contextual advertisements, and protecting against fraud or theft. However, the new language would require parental notification and consent prior to the collection of persistent identifiers where they are used for purposes such as amassing data on a child's online activities or behaviorally targeting advertising to the child. Therefore, operators such as network advertisers may not claim the collection of persistent identifiers as a technical function under the “support for internal operations” exemption.

83

See
Boku (comment 5) (encouraging the Commission to regulate the use of identifiers such as IP address, device data, or any other data automatically captured during interaction with a user and a web site rather than the data capture itself or the storage of such data;
see also
CDT (comment 8), at 8 (asserting that a prohibition on the
mere collection
of this data would undermine the very functioning of the Internet).

New paragraph (h) of the definition of “personal information” is intended to serve as a catch-all category covering the online gathering of information about a child over time for the purposes of either online profiling or delivering behavioral advertising to that child.
84

For example, an advertising network or analytics service that tracks a child user across a set of Web sites or online services, but stores this information in a separate database rather than with the persistent identifier, would be deemed to have collected personal information from the child under this proposed paragraph.

84
“Online behavioral advertising” is the practice of tracking an individual's online activities in order to deliver advertising tailored to the individual's interests.
See
Self-Regulatory Principles for Online Behavioral Advertising,
supra
note 68, at
i.

Several commenters stated that industry self-regulatory efforts more effectively address the treatment of online behavioral advertising to children than would regulation in this area. For example, citing the industry's 2009
Self-Regulatory Principles for Online Behavioral Advertising,
the Direct Marketing Association asserted that “robust self-regulation is the best and most appropriate way to address privacy concerns in connection with online behavioral advertising, including concerns related to children.”
85

85
DMA (comment 17), at 7 (directing the Commission's attention to
Self-Regulatory Principles for Online Behavioral Advertising
(July 2009), at 16-17, available at
http://www.the-dma.org/government/ven-principles%2007-01-09%20FINAL.pdf. See also
Entertainment Software Association (comment 20), at 19; Facebook (comment 22), at 7; IAB (comment 34), at 3; Microsoft (comment 39), at 9-10; Mobile Marketing Association (comment 40), at 3; Toy Industry Association (comment 63), at 9.

The Commission finds this argument unpersuasive. Although self-regulation can play an important role in consumer protection, Congress specifically directed the Commission to promulgate and implement regulations covering the online collection, use, and disclosure of children's personal information. To the extent that children's personal information is collected in connection with behavioral advertising, such information should be protected under the Rule. While self-regulatory programs can be valuable in promoting compliance, the proposed revision implements the COPPA statute and is enforceable by law.
86

86
Although it is unclear from the record before the Commission whether operators currently are directing online behavioral advertising to children (various members of industry have informed Commission staff that they do not believe such activity is occurring while media reports have indicated the widespread presence of tracking tools

on children's Web sites,
see
Steven Stecklow,
On the Web, Children Face Intensive Tracking,
Wall St. J., Sept. 17, 2010), the Commission notes that the self-regulatory guidelines cited by the commenters do not expressly require prior parental consent for such advertising to occur. Rather, operators who adhere to such guidelines are merely cautioned that they should comply with COPPA when engaging in online behavioral advertising.
See Self-Regulatory Principles for Online Behavioral Advertising, supra
note 85, at 16-17 (“Entities should not collect ‘personal information’, as defined in the Children's Online Privacy Protection Act (‘COPPA’), from children they have actual knowledge are under the age of 13 or from sites directed to children under the age of 13 for Online Behavioral Advertising, or engage in Online Behavioral Advertising directed to children they have actual knowledge are under the age of 13 except as compliant with the COPPA”). Moreover, the self-regulatory standards cited by commenters do not collectively represent all operators subject to COPPA.

d. Photographs, Videos, and Audio Files (New Paragraph (i))

The Rule's existing definition of “personal information” includes photographs only when they are combined with “other information such that the combination permits physical or online contacting.” Given the prevalence and popularity of posting photos, videos, and audio files online, the Commission has reevaluated the privacy and safety implications of such practices as they pertain to children. Inherently, photos can be very personal in nature. Also, photographs of children, in and of themselves, may contain information, such as embedded geolocation data, that permits physical or online contact.
87

In addition, facial recognition technology can be used to further identify persons depicted in photos.
88

87
In addition to the personal information that may be viewable in a photograph or video, geolocation data is commonly embedded as hidden “metadata” within these digital images. These data usually consist of latitude and longitude coordinates, and may also include altitude, bearing, distance, and place names. Such geolocation information may be used by operators and may also be accessed by the viewing public. The Commission proposes to specifically enumerate “geolocation information” as a separate category of “personal information” under the Rule.
See infra
Part V.A.(4)(e).

88

See
M. Geuss, “Facebook Facial Recognition Could Get Creepy: new facial recognition technology used to identify your friends in photos could have some interesting applications—and some scary possibilities,” PC World (Apr. 26, 2011), available at
http://www.pcworld.com/article/226228/facebook_facial_recognition_its_quiet_rise_and_dangerous_future.html
(discussing Facebook's facial recognition technology, and similar technologies offered by services such as Viewdle, Fotobounce, Picasa, iPhoto, and Face.com).

The Commission believes that, with respect to the subset of Web sites and online services directed to children or having actual knowledge of collecting personal information from children, broader Rule coverage of photos is warranted.
89

In addition, the Commission believes that the Rule's definition of “personal information” should be expanded to include the posting of video and audio files containing a child's image or voice, which, similarly to photos, may enable the identification and contacting of a child. Therefore, the Commission proposes to create a new paragraph (i) of the definition of “personal information” that states:

89
Although the Commission received little comment on this topic, one individual commenter, as well as the Commission-approved COPPA safe harbor, TRUSTe, strongly supported this approach.
See
Gregory Schiller (comment 47); Office of the State Attorney—15th Judicial Circuit in and for Palm Beach County, Florida (comment 47); TRUSTe (comment 64), at 4; Maureen Cooney, Chief Privacy Officer, TRUSTe, Remarks from
COPPA's Definition of “Personal Information”
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online at 191-92 (June 2, 2010), available at
http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf.

(i) A photograph, video, or audio file where such file contains a child's image or voice; This proposed change will ensure that parents are given notice and the opportunity to decide whether the posting of images or audio files is an activity in which they wish their children to engage.

e. Geolocation Information (New Paragraph (j))

In recent years, geolocation services have become ubiquitous features of the personal electronics market.
90

Numerous commenters raised with the Commission the issue of the potential risks associated with operators' collection of geolocation information from children. Some commenters urged the Commission to expressly modify the Rule to include geolocation information, given the current pervasiveness of such technologies and their popularity among children.
91

Others maintained that geolocation information is already covered by existing paragraph (b) of the Rule's definition of “personal information,” which includes “a home or other physical address including street name and name of a city or town”
92

90
For example, geolocation-based navigation tools help users reach destinations, find local businesses or events, find friends and engage in social networking, “check in” at certain locations, and link their location to other activities. Many users access geolocation services through mobile devices. However, devices such as laptop and desktop computers, tablets, and in-car navigation and assistance systems also may be used to access such services. Geolocation information may be used once for a single purpose, or it may be stored or combined with other information to produce a history of a user's activities or a detailed profile for advertising or other purposes.
See
ACLU, “Location Based Services: Time For a Privacy Check-In” 1, 3 (Nov. 2010)
available at http://dotrights.org/sites/default/files/lbs-white-paper.pdf.

91

See, e.g.,
EPIC (comment 19), at 8.

92

See
Institute for Public Representation (comment 33), at 26; TRUSTe (comment 64), at 4.
See also
Jules Polonetsky, Director, Future of Privacy Forum; Paul Ohm, Professor, Univ. of Colorado Law School; Sheila A. Millar, Partner, Keller & Heckman LLP; Matt Galligan, Founder and CEO, SimpleGeo; Heidi C. Salow, Of Counsel, DLA Piper, Remarks from
COPPA's Definition of “Personal Information”
Panel at the Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online at 195, 205-07 (June 2, 2010),
available at http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf.

Technologies that collect geolocation information can take a variety of forms and can communicate location with varying levels of precision. Generally speaking, most commonly used location tracking technologies are capable of revealing a person's location at least down to the level of a street name and the name of a city or town.
93

In the Commission's view, any geolocation information that provides precise enough information to identify the name of a street and city or town is covered already under existing paragraph (b) of the definition of “personal information.” However, because geolocation information may be presented in a variety of formats (
e.g.,
coordinates or a map), and in some instances may be more precise than street name and name of city or town, the Commission proposes making geolocation information a stand-alone category within that definition.

93

See
ACLU,
supra
note 90, at 9.

Those commenters who opposed the inclusion of geolocation information within COPPA's definition of “personal information” argued that such information cannot be used to identify a specific individual, but only a device.
94

However, as discussed above, the Commission finds this argument unpersuasive.
95

Physical address, including street name and name of city or town, alone is considered personal information under COPPA. Accordingly, geolocation data that provides information at least equivalent to “physical address” should be covered as personal information.

94

See
DMA (comment 17), at 7-8; MPAA (comment 42), at 6-7; Net Choice (comment 45), at 6.

95

See supra
Part V.A.(6)(c).

f. Date of Birth, Gender, and ZIP Code

Several commenters recommended that the Commission include date of birth, gender, or ZIP code in the definition of “personal information.”
96

The Commission gave careful thought to these recommendations, but is not proposing to include these items within

the definition because the Commission does not believe that any one of these items of information, alone, permits the physical or online contacting of a specific individual. However, the Commission seeks input as to whether the
combination
of date of birth, gender, and ZIP code provides sufficient information to permit the contacting of a specific individual such that this combination of information should be included in the Rule as “personal information.”
97

Moreover, there is a question whether an operator's collection of “ZIP+4” may, in some cases, be the equivalent of a physical address. “ ZIP+4 Code consists of the original 5-digit ZIP Code plus a 4-digit add-on code that identifies a geographic segment within the 5-digit delivery area, such as a city block, office building, individual high-volume receiver of mail, or any other unit that would aid efficient mail sorting and delivery.
98

The Commission seeks input on whether ZIP+4 is the equivalent of a physical address and whether it should be added to the Rule.
99

96

See
EPIC (comment 19), at 8-9; Institute for Public Representation (comment 33), at 33.

97

See infra
Part X. at Question 9(b). Commenter Paul Ohm cites to several studies finding that a significant percentage of individuals can be uniquely identified by the combination of these three pieces of information
. See
Paul Ohm (comment 48), at 3, note 7.

98

See
United States Postal Service, Frequently Asked Questions, ZIP Code Information, http://faq.usps.com/eCustomer/iq/usps/(search “ZIP Code Information”; then follow “ZIP Code Information” hyperlink) (last visited September 12, 2011).

99

See infra
Part X. at Question 9(c).

g. Other Collections of Information

Taking a different view of “personal information,” one commenter argued that the Commission should move away from identifying new particular individual items of personal information, and instead add to the definition “any collection of more than twenty-five distinct categories of information about a user.”
100

This proposed definition is based on the premise that above a certain quantity threshold, the information an operator holds about a particular user becomes sufficiently identifying so as to be “personal.” The Commission recognizes the potential for collections of diverse bits of information to permit the identification of a specific individual; however, the record is not sufficiently developed at this time to support a quantity-based approach to defining personal information. Without greater specificity, a quantity-based approach would not provide operators with sufficient certainty to determine which collections and combinations of information trigger the Rule's requirements and which do not. As a result, this standard would be difficult for operators to implement, as well as for the government to enforce.
101

The Commission believes that setting bright-line categories of personal information, while potentially both over- and under-inclusive, provides greater certainty for operators seeking to follow the Rule.

100

See
Paul Ohm (comment 48), at 2.

101
Professor Ohm acknowledges that “most websites probably do not count their data in this way today, so the regulation will require some websites to expend modest new resources to comply. Moreover, every time a website decides to collect new categories of information from users, it needs to recalculate its count.”
Id.
at 8-9.

(7) Web Site or Online Service Directed to Children

The Commission also considered whether any changes needed to be made to the Rule's definition of “website or online service directed to children.” The current definition is largely a “totality of the circumstances” test that provides sufficient coverage and clarity to enable Web sites to comply with COPPA, and the Commission and its state partners to enforce COPPA.
102

Few commenters addressed the definition. However, one commenter, the Institute for Public Representation, suggested that the Rule be amended so that a Web site
per se
should be deemed “directed to children” if audience demographics show that 20% or more of its visitors are children under age 13.
103

102

See, e.g., United States
v.
Playdom, Inc.,
No. SA CV-11-00724 (C.D.Ca., filed May 11, 2011) (finding defendants' Pony Stars Web site to be “directed to children”);
United States
v.
Industrious Kid, Inc.,
No. CV-08-0639 (N.D. Cal., filed Jan. 28, 2008);
United States
v.
UMG Recordings, Inc.,
No. CV-04-1050 (C.D. Cal., filed Feb. 17, 2004);
United States
v.
Bonzi Software, Inc.,
No. CV-04-1048 (C.D. Cal., filed Feb. 17, 2004).

103

See
Institute for Public Representation (comment 33), at iii (urging the Commission to adopt the same threshold, 20%, used in the Commission's 2007 food marketing Orders to File a Special Report).

The current definition of “website or online service directed to children” already notes that the Commission will consider competent and reliable empirical evidence of audience composition as part of a totality of circumstances analysis. The Commission's experience with online audience demographic data in both its studies of food marketing to children and marketing violent entertainment to children shows that such data is neither available for all Web sites and online services, nor is it sufficiently reliable, to adopt it as a
per se
legal standard.
104

Accordingly, the Commission declines to adopt a standard akin to the 20% standard proposed by the Institute for Public Representation.

104
In the context of the Commission's food marketing studies, food marketers were required to identify and report Web site expenditures targeted to children based on a number of criteria, one of which was whether audience demographic data indicated that 20% or more of visitors to a Web site were children ages 2-11.
See
Fed. Trade Comm'n, Order to File Special Report, B-3, note 14 (July 31, 2007)
available at http://www.ftc.gov/os/6b_orders/foodmktg6b/070731boskovichfarmssixb.pdf.
There, the 20% threshold was not used as a basis to impose legal liability for a Rule violation.

However, the Commission proposes minor modifications to the definition, as follows. First, as part of the totality of the circumstances analysis, the Commission proposes modifying the term “audio content” to include musical content. In addition, the Commission proposes adding the presence of child celebrities, and celebrities who appeal to children, within the non-exclusive set of indicia it will use to determine whether a Web site or online service is directed to children. In the Commission's experience, both music and the presence of celebrities are strong indicators of a Web site or online service's appeal to children. Finally, the Commission proposes reordering the language of the definition so that the terms “animated characters” and “child-oriented activities and incentives” are addressed alongside the other indicia of child-directed content.

Therefore, the proposed definition of “Web site or online service directed to children” reads:

Website or online service directed to children
means a commercial Web site or online service, or portion thereof, that is targeted to children. Provided, however, that a commercial Web site or online service, or a portion thereof, shall not be deemed directed to children solely because it refers or links to a commercial website or online service directed to children by using information location tools, including a directory, index, reference, pointer, or hypertext link. In determining whether a commercial Web site or online service, or a portion thereof, is targeted to children, the Commission will consider its subject matter, visual content, use of animated characters or child-oriented activities and incentives, music or other audio content, age of models, presence of child celebrities or celebrities who appeal to children, language or other characteristics of the website or online service, as well as whether advertising promoting or appearing on the Web site or online service is directed to children. The Commission will also consider competent and reliable empirical evidence regarding audience composition, and evidence regarding the intended audience.

B. Notice (16 CFR 312.4)

The linchpins of the COPPA Rule are its parental notice and consent requirements. Providing parents with clear and complete notice of operators' information practices is the necessary first step in obtaining informed consent

from parents. COPPA requires that parents be notified in two ways: on the operator's Web site or online service (the “online notice,” which typically takes the form of a privacy policy), and in a notice delivered directly to a parent whose child seeks to register on the site or service (the “direct notice”). The current Rule requires that operators provide extensive information about their children's privacy practices in their online notice. While the Rule states that the direct notice must contain the information an operator includes in its online notice as well as certain additional information, in the past, the Commission has indicated that operators may truncate the information in the direct notice by providing a hyperlink to their online privacy policy.
105

105

See
1999 Statement of Basis and Purpose, 64 FR 59888, 59897.

Outside the COPPA context, in recent years, the Commission has begun to urge industry to provide consumers with notice and choice about information practices at the point consumers enter personal data or before accepting a product or service.
106

The analogous point of entry under COPPA would be the direct notice, which has the potential to provide parents with the best opportunity to consider an operator's information practices and to determine whether to permit children's engagement with such operator's Web site or online service. Therefore, the Commission proposes to revise the notice requirements to reinforce COPPA's goal of providing complete and clear information in the direct notice, and to rely less heavily on the online notice or privacy policy as a means of providing parents with information about operators' information practices.
107

106

See
Protecting Consumer Privacy in an Era of Rapid Change,
supra
note 23, at 57-59.

107
The proposed changes to the direct notice provision, discussed in Part V.B.(2)
infra,
would reverse the Commission's guidance that operators may truncate the information in the direct notice by providing a hyperlink to their online privacy policy.
See
note 105 and accompanying text.

(1) Notice on the Web site or Online Service (Revised Paragraph (b))

The Commission proposes to streamline § 312.4(b),
108

regarding the placement and content of the notice of information practices that operators must provide on their Web sites or in their online services. The language regarding the required placement of this online notice has been shortened and clarified, thereby making the provision more instructive to operators. The revised language more succinctly requires that the online notice be clearly labeled and prominently located, and be posted on an operator's home page or home screen and at each location where the operator collects personal information from children.
109

108
No changes are proposed to § 312.4(a) (“general principles of notice”).

109
The Commission poses a question whether the Rule should be modified to require operators to post a link to their online notice in any location where their mobile applications can be purchased or otherwise downloaded.
See infra
Part X. at Question 14.

With respect to the content of the online notice, the Commission proposes several improvements to the Rule's current list of requirements. First, the Commission proposes requiring operators to provide contact information, including, at a minimum, the operator's name, physical address, telephone number, and e-mail address. In contrast to the current Rule, this proposal would apply to
all
operators of a Web site or online service, rather than permitting the designation of a single operator as the contact point. Given the possibility of a child interacting with multiple operators on a single Web site or online service (
e.g.,
in the case of a mobile application that grants permission to an advertising network to collect user information from within the application), the Commission believes that the identification of each operator will aid parents in finding the appropriate party to whom to direct any inquiry.

Second, the Commission proposes eliminating the Rule's current lengthy—yet potentially under-inclusive—recitation of an operator's information collection, use, and disclosure practices in favor of a simple statement of: (1) What information the operator collects from children, including whether the Web site or online service enables a child to make personal information publicly available, (2) how the operator uses such information, and (3) the operator's disclosure practices for such information.
110

In the Commission's experience, privacy policies are often long and difficult to understand, and may no longer be the most effective way to communicate salient information to consumers, including parents.
111

By streamlining the Rule's online notice requirements by reverting to the language of the COPPA statute, the Commission hopes to encourage operators to provide clear, concise descriptions of their information practices, which may have the added benefit of being easier to read on smaller screens (
e.g.,
those on Internet-enabled mobile devices).

110
This language mirrors the statutory requirements for the online notice.
See
15 U.S.C. 6503(b)(1)(A)(i).

111

See
Protecting Consumer Privacy in an Era of Rapid Change,
supra
note 23, at 7.

The Commission also proposes eliminating the requirement, articulated in § 312.4(b)(2)(v), that an operator's privacy policy state that the operator may not condition a child's participation in an activity on the child's disclosing more personal information than is reasonably necessary to participate in such activity. In the Commission's experience, this blanket statement, often parroted verbatim in operators' privacy policies, detracts from the key information of operators' actual information practices, and yields little value to a parent trying to determine whether to permit a child's participation. In proposing to delete this requirement in the privacy notice, however, the Commission does not propose deleting § 312.7 of the Rule, which still prohibits operators from conditioning a child's participation in a game, the offering of a prize, or another activity on the child's disclosing more personal information than is reasonably necessary to participate in such activity.
112

112

See
16 CFR 312.7.

Therefore, the Commission proposes to revise paragraph (b) of § 312.4 so that it states:

(b)
Notice on the Web site or online service.
Pursuant to § 312.3(a), each operator of a Web site or online service directed to children must post a prominent and clearly labeled link to an online notice of its information practices with regard to children on the home or landing page or screen of its Web site or online service,
and,
at each area of the Web site or online service where personal information is collected from children. The link must be in close proximity to the requests for information in each such area. An operator of a general audience Web site or online service that has a separate children's area or site must post a link to a notice of its information practices with regard to children on the home or landing page or screen of the children's area. To be complete, the online notice of the Web site or online service's information practices must state the following:

(1) Each operator's contact information, which at a minimum, must include the operator's name, physical address, telephone number, and e-mail address;

(2) A description of what information each operator collects from children, including whether the Web site or online service enables a child to make personal information publicly available; how such operator uses such information, and; the operator's disclosure practices for such information; and,

(3) That the parent can review and have deleted the child's personal information, and refuse to permit further collection or use of

the child's information, and state the procedures for doing so.
113

113
No change is proposed to the Rule's requirement that operators disclose that a parent may review and have deleted a child's personal information and refuse to permit further collection or use of that child's information. Although one commenter observed that parents seldom exercise these rights,
see
WiredSafety.org (comment 68), at 28, the Commission believes that requiring operators to provide such rights to parents remains an important element of the Rule. In the context of its broader inquiry into how to best protect privacy in today's marketplace, Commission staff is exploring methods of ensuring consumer access to data as a means of increasing the transparency of companies' data practices.
See
Protecting Consumer Privacy in an Era of Rapid Change,
supra
note 23, at 72-76.

(2) Direct Notice to a Parent (Revised Paragraph (c))

As described above, the Commission proposes refining the Rule requirements for the direct notice to ensure that this notice works as an effective “just-in-time” message to parents about an operator's information practices. Specifically, the Commission proposes to reorganize and standardize the direct notice requirement to set forth the precise items of information that must be disclosed in each type of direct notice required under the Rule. These specific notice requirements correspond to the requirements for obtaining parental consent under § 312.5 of the Rule. The proposed reorganization is intended to make it easier for operators to determine what information they must include in the direct notice to parents, based upon operators' particular information collection practices.

The proposed revised language of § 312.4(c) specifies, for each different form of direct notice required by the Rule, the precise information that operators must provide to parents regarding: The items of personal information the operator already has obtained from the child (the parent's online contact information either alone or together with the child's online contact information); the purpose of the notification; action that the parent must or may take; and, what use, if any, the operator will make of the personal information collected. The proposed revised provision also makes clear that each form of direct notice must provide a hyperlink to the operator's online notice of information practices. The Commission believes the proposed revisions will help ensure that parents receive key information up front, while directing them online to view any additional information contained in the operator's online notice.

The Commission also proposes adding a new paragraph, § 312.4(c)(2), setting out the requirements for a direct notice when an operator chooses to collect a parent's online contact information from the child in order to provide parental notice about a child's participation in a Web site or online service that does not otherwise collect, use, or disclose children's personal information. This new form of parental notice corresponds to a newly proposed exception to the parental consent requirement for the collection of a parent's online contact information when done to inform the parent of a child's participation in a Web site or online service that does not otherwise collect personal information from the child.
114

114

See infra
Part V.C.(4).

Therefore, the Commission proposes to revise paragraph (c) of § 312.4 so that it reads:

(c)
Direct notice to a parent.
An operator must make reasonable efforts, taking into account available technology, to ensure that a parent of a child receives direct notice of the operator's practices with regard to the collection, use, or disclosure of the child's personal information, including notice of any material change in the collection, use, or disclosure practices to which the parent has previously consented.

(1)
Content of the direct notice to the parent required under §
312.5(c)(1) (Notice to Obtain Parent's Affirmative Consent to the Collection, Use, or Disclosure of a Child's Personal Information).
This direct notice shall set forth:

(i) That the operator has collected the parent's online contact information from the child in order to obtain the parent's consent;

(ii) That the parent's consent is required for the child's participation in the Web site or online service, and that the operator will not collect, use, or disclose any personal information from the child if the parent does not provide such consent;

(iii) The additional items of personal information the operator intends to collect from the child, if any, and the potential opportunities for the disclosure of personal information, if any, should the parent consent to the child's participation in the Web site or online service;

(iv) A hyperlink to the operator's online notice of its information practices required under § 312.4(b);

(v) The means by which the parent can provide verifiable consent to the collection, use, and disclosure of the information; and,

(vi) That if the parent does not provide consent within a reasonable time from the date the direct notice was sent, the operator will delete the parent's online contact information from its records.

(2)
Content of the direct notice to the parent allowed under § 312.5(c)(2) (Notice to Parent of a Child's Online Activities Not Involving the Collection, Use or Disclosure of Personal Information).
This direct notice shall set forth:

(i) That the operator has collected the parent's online contact information from the child in order to provide notice to the parent of a child's participation in a Web site or online service that does not otherwise collect, use, or disclose children's personal information; and,

(ii) That the parent's online contact information will not be used or disclosed for any other purpose;

(iii) That the parent may refuse to permit the operator to allow the child to participate in the Web site or online service and may require the deletion of the parent's online contact information, and how the parent can do so; and,

(iv) A hyperlink to the operator's online notice of its information practices required under § 312.4(b).

(3)
Content of the direct notice to the parent required under § 312.5(c)(4) (Notice to a Parent of Operator's Intent to Communicate with the Child Multiple Times).
This direct notice shall set forth:

(i) That the operator has collected the child's online contact information from the child in order to provide multiple online communications to the child;

(ii) That the operator has collected the parent's online contact information from the child in order to notify the parent that the child has registered to receive multiple online communications from the operator;

(iii) That the online contact information collected from the child will not be used for any other purpose, disclosed, or combined with any other information collected from the child;

(iv) That the parent may refuse to permit further contact with the child and require the deletion of the parent's and child's online contact information, and how the parent can do so;

(v) That if the parent fails to respond to this direct notice, the operator may use the online contact information collected from the child for the purpose stated in the direct notice; and,

(vi) A hyperlink to the operator's online notice of its information practices required under § 312.4(b).

(4)
Content of the direct notice to the parent required under § 312.5(c)(5) (Notice to a Parent In Order to Protect a Child's Safety).
This direct notice shall set forth:

(i) That the operator has collected the child's name and the online contact information of the child and the parent in order to protect the safety of a child;

(ii) That the information will not be used or disclosed for any purpose unrelated to the child's safety;

(iii) That the parent may refuse to permit the use, and require the deletion, of the information collected, and how the parent can do so;

(iv) That if the parent fails to respond to this direct notice, the operator may use the information for the purpose stated in the direct notice; and,

(v) A hyperlink to the operator's online notice of its information practices required under § 312.4(b).

C. Parental Consent (16 CFR 312.5)

A central element of COPPA is its requirement that operators seeking to collect, use, or disclose personal

information from children first obtain verifiable parental consent.
115

“Verifiable parental consent” is defined in the statute as “any reasonable effort (taking into consideration available technology), including a request for authorization for future collection, use, and disclosure, described in the notice.”
116

In paragraph (b)(1), the Rule provides that operators:

115
Paragraph (a) of § 312.5 reads:

(1) An operator is required to obtain verifiable parental consent before any collection, use, and/or disclosure of personal information from children, including consent to any material change in the collection, use, and/or disclosure practices to which the parent has previously consented.

(2) An operator must give the parent the option to consent to the collection and use of the child's personal information without consenting to disclosure of his or her personal information to third parties.

116
15 U.S.C. 6501(9).

must make reasonable efforts to obtain verifiable parental consent, taking into consideration available technology. Any method to obtain verifiable parental consent must be reasonably calculated in light of available technology to ensure that the person providing consent is the child's parent.

The Rule then sets forth a non-exclusive list of methods that meet the standard of verifiable parental consent.
117

Specifically, paragraph (b)(2) states:

117

See
16 CFR 312.5(b).

Methods to obtain verifiable parental consent that satisfy the requirements of this paragraph include: Providing a consent form to be signed by the parent and returned to the operator by postal mail or facsimile; requiring a parent to use a credit card in connection with a transaction; having a parent call a toll-free telephone number staffed by trained personnel; using a digital certificate that uses public key technology; and using e-mail accompanied by a PIN or password obtained through one of the verification methods listed in this paragraph.
118

118
Paragraph (b)(2) continues:

Provided that:
Until the Commission otherwise determines, methods to obtain verifiable parental consent for uses of information other than the “disclosures” defined by § 312.2 may also include use of e-mail coupled with additional steps to provide assurances that the person providing the consent is the parent. Such additional steps include: Sending a confirmatory e-mail to the parent following receipt of consent; or obtaining a postal address or telephone number from the parent and confirming the parent's consent by letter or telephone call. Operators who use such methods must provide notice that the parent can revoke any consent given in response to the earlier e-mail.

A discussion of paragraph (b)(2) follows in Part V.C.(2).

The Rule's enumerated consent mechanisms were discussed in-depth at the Commission's June 2, 2010 COPPA roundtable and also were addressed by a number of commenters.
119

While several persons acknowledged that no one method provides complete certainty that the operator has reached and obtained consent from a parent, they generally agreed that the listed methods continue to have utility for operators and should be retained.
120

A great number of commenters also urged the Commission to expand the list of acceptable mechanisms to incorporate newer technologies.
121

After careful consideration, the Commission proposes several significant changes to the mechanisms of verifiable parental consent set forth in paragraph (b) of § 312.5, including: Adding several newly recognized mechanisms for parental consent; eliminating the sliding scale approach to parental consent; and, adding two new processes for evaluation and pre-clearance of parental consent mechanisms.

119

See
Federal Trade Commission's Roundtable: Protecting Kids' Privacy Online at 195, 208-71 (June 2, 2010),
available at http://www.ftc.gov/bcp/workshops/coppa/COPPARuleReview_Transcript.pdf.

120

See
DMA (comment 17), at 10, 12; Microsoft (comment 39), at 7; Toy Industry Association, Inc. (comment 63), at 3; WiredSafety.org. (comment 68), at 18.

121

See, e.g.,
Boku (comment 5); DMA (comment 17), at 11-12; EchoSign, Inc. (comment 18); Entertainment Software Association (comment 20), at 7-9; Facebook (comment 22), at 2; Janine Hiller (comment 27), at 447-50; Mary Kay Hoal (comment 30); Microsoft (comment 39), at 4; MPAA (comment 42), at 12; RelyID (comment 53), at 3; TRUSTe (comment 64), at 3; Harry Valetk (comment 66), at 6; WiredSafety.org (comment 68), at 53; Susan Wittlief (comment 69).

(1) Mechanisms for Verifiable Parental Consent (Paragraph (b)(2))

A number of commenters made suggestions for strengthening, modernizing, and simplifying the Rule's mechanisms for parental consent. For example, commenters asked the Commission to recognize additional methods of obtaining parental consent, such as by sending a text message to the parent's mobile phone number,
122

offering online payment services other than credit cards,
123

offering parental controls in gaming consoles,
124

offering a centralized parents' opt-in list,
125

and permitting electronic signatures.
126

Upon consideration of each proposal in light of the existing record, the Commission determines that the record is sufficient to justify certain proposed mechanisms, but insufficient to adopt others.

122

See
BOKU (comment 5); Entertainment Software Association (comment 20), at 11-12; TRUSTe (comment 64), at 3; Harry A. Valetk (comment 66), at 6-7.
See
discussion
supra
Part IV, regarding COPPA's application to mobile communications via SMS messaging.

123

See
WiredSafety.org (comment 68), at 24 (noting that operators are considering employing online financial accounts such as iTunes for parental consent).

124

See
Entertainment Software Association (comment 20), at 9-10; Microsoft (comment 39), at 7.

125

See
Entertainment Software Association (comment 20), at 12; Janine Hiller (comment at 27), at 31.

126

See
DMA (comment 17), at 12; EchoSign (comment 18); Entertainment Software Association (comment 20), at 10; Toy Industry Association (comment 63), at 11.

First, the Commission notes that the collection of a parent's mobile phone number to effectuate consent via an SMS text message would require a statutory change, as the COPPA statute currently permits only the collection of a parent's “online contact” information for such purposes, and a phone number does not fall within the statute's definition of “online contact information,”
i.e.,
“an e-mail address or another substantially similar identifier that permits direct contact with a person online.”
127

There are advantages to using SMS texting as a method of contacting the parent and obtaining consent—among them that parents typically do not have multiple mobile phone numbers, and generally have their mobile phones with them at all times. Some commenters opined that this method was as reliable as use of a credit card or fax;
128

others compared the use of SMS text messaging to the “e-mail plus” method permitted under the Rule's sliding scale approach to parental consent.
129

The Commission believes the more apt analogy is to the e-mail plus method in that the operator sends a notice to the parent via the parent's mobile phone number and requests opt-in consent by a return message in some form. In this way, the use of SMS text messaging for parental consent would suffer from the same inadequacies as does e-mail plus, which, as described below, the Commission proposes to eliminate. Just as with an e-mail address, there is no way to verify that the phone number provided by a child is that of the parent rather than that of the child. For these reasons, the Commission declines to add use of SMS text messaging to the enumerated list of parental consent mechanisms.

127
15 U.S.C. 6502(12).

128

See, e.g.,
Entertainment Software Association (comment 20), at 11-12.

129

See
Boku (comment 5).

With respect to expanding the Rule to permit the use of online payment services for verifying consent in lieu of a credit card, the Commission finds that the record is insufficient to warrant adding online payment services as a consent mechanism. The Commission notes that no commenters provided any

analysis of how online payment services might meet the requirements of § 312.5(b)(1); however, one commenter cautioned the Commission against embracing such technologies at this time, noting that alternative payment systems may not be as well-regulated as the credit card industry and thereby may provide even less assurance of parental consent than use of a credit card.
130

The Commission also is mindful of the potential for children's easy access to and use of alternative forms of payments (such as gift cards, debit cards, and online accounts), and would expect to see a fuller discussion of the risks presented in any future application to the Commission for recognition of these consent methods.

130

See
EPIC (comment 19), at 5. (“Alternative methods may not be as heavily regulated as more traditional systems. As a result, the use of alternative methods in gaining parental consent or payment remain inadvisable, although that may change as such methods come under stronger regulation.”).

Several commenters asked the Commission to consider whether, and in what circumstances, parental control features in game consoles could be used to verify consent under COPPA.
131

Parental control settings often permit parents to limit or block functions such as Internet access, information sharing, chat, and interactive game play, and require parental approval before a child adds friends.
132

Parental control features appear to offer parents a great deal of control over a child's gaming experience, and, as commenters acknowledged, can serve as a
complement
to COPPA's parental consent requirements.
133

As acknowledged in the comments, at present, such systems are not designed to comply with COPPA's standards for verifiable parental consent,
134

and the record currently is insufficient for the Commission to determine whether a hypothetical parental consent mechanism would meet COPPA's verifiable parental consent standard. The Commission encourages continued exploration of the concept of using parental controls in gaming consoles (and, presumably, on a host of handheld devices) to notify parents and obtain their prior verifiable consent.

131

See
Entertainment Software Association (comment 20), at 4; Microsoft (comment 39), at 7.

132

See
Entertainment Software Association (comment 20), at 4-6.

133

Id.
at 6.

134

See id.
at 9 (“Therefore, it makes sense to consider how these tools could be harnessed for the related task of acquiring verifiable parental consent under the COPPA Rule”); Microsoft (comment 39), at 7 (describing how a hypothetical parental controls method might be structured in the future to notify a parent and obtain parental consent).

Several commenters also asked the Commission to accept electronic signatures as a form of verifi

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2011-24314. Public record. Not legal advice.
