emailmarketing.net

Minors and Email Marketing — COPPA, the UK Children's Code, and GDPR Article 8

When collecting a child's email address triggers US COPPA (under-13 rule, verifiable parental consent, the FTC six-step plan), the UK Age Appropriate Design Code's 15 standards, GDPR Article 8 age thresholds, and what all of this means for ESP signup forms and age gates.

Reference14 min read

Who it is for Compliance teams, Senders

Applies to senders on any platform

If a signup form could collect an email address from a child, the children's privacy laws apply before a single message is sent. Every one of these regimes treats an email address as personal information about the child, so collecting it is the act that triggers the law.

An ESP and its customers are most likely to meet three frameworks: the US COPPA Rule (under 13), the UK Children's Code (under 18), and the consent ages in GDPR Article 8 (13–16, depending on the member state). General consent practice is covered in Consent Methods, and the marketing laws that apply to adults in CAN-SPAM, CASL and UK PECR.

COPPA (United States): the under-13 rule

The Children's Online Privacy Protection Act (1998) and the Federal Trade Commission's (FTC) COPPA Rule put parents in control of what is collected online from children under 13. The Rule is 16 C.F.R. Part 312. It took effect on April 21, 2000, was amended with effect from July 1, 2013, and was amended again on April 22, 2025, so check the revised Rule for the current text.

The FTC enforces the Rule, as do state attorneys general and sector regulators. Civil penalties run up to $53,088 per violation. They are set on factors that include how egregious the violation was, prior violations, the number of children, the type of information, sharing with third parties, and the size of the company. Some cases settle with no penalty, and others for millions.

COPPA applies if any of these is true:

  1. the site or service is directed to children under 13 and collects personal information from them;
  2. it is directed to children under 13 and lets others collect personal information from them (ad networks, plug-ins: the operator is liable for collection by third parties on its property);
  3. it is a general-audience service with actual knowledge that it is collecting personal information from a child under 13; or
  4. it runs an ad network or plug-in with actual knowledge that it collects personal information directly from users of a service directed to children.

"Online service" has a broad meaning: mobile apps, gaming platforms, plug-ins, ad networks, voice over IP (VoIP), connected toys and other Internet of Things (IoT) devices, and smart speakers. Foreign services directed to US children, or that knowingly collect from them, are covered, and so are US services that collect from foreign children. Nonprofits outside Section 5 of the FTC Act are generally exempt. Congress deliberately stopped at 13, so teenagers are outside COPPA.

"Personal information" includes the email address

The Rule lists: first and last name; a physical address (street and city or town); online contact information, meaning an email address or any identifier that allows direct contact (instant messaging, VoIP or video chat identifiers, mobile numbers); a screen name or user name that works as online contact information; a telephone number; government-issued identifiers (Social Security number, state ID, birth certificate, passport); persistent identifiers (a cookie ID, an IP address, a device serial number or unique device ID); a photo, video or audio file that contains a child's image or voice; geolocation precise enough to identify a street and city or town; biometric identifiers; and any information about the child or parent combined with one of these.

"Collect" includes requesting or prompting a child to submit information even if it is optional, allowing a child to post it publicly, and passive tracking.

When collecting a child's email address triggers COPPA, and when it does not

The points in the FAQ that concern email, in short:

Scenario Outcome under COPPA
A newsletter or other repeated email contact that the child requested Allowed under the multiple-contact exception (§ 312.5(c)(4)). Collect the online contact information of the child and of a parent, and give the parent direct notice and an opportunity to opt out before the ongoing contact starts. Use it for no other purpose, do not disclose it, and do not combine it with other data. If the notice bounces, you have not made "reasonable efforts", and the exception does not apply
A one-time response to a child's specific request (answering a question, "Ask the Author") The one-time contact exception (§ 312.5(c)(3)). Respond once, then delete the address promptly. Do not contact the child again, disclose the address or use it for anything else. If you choose not to respond, you must still delete it immediately
A contest entry The one-time exception works only if you collect only online contact information, contact the child once (to say whether they won), and then delete it. If you expect to contact the child several times, the multiple-contact exception applies (notice to the parent, and an opportunity to opt out). If you collect a mailing address for a prize, you need full notice to the parent and verifiable consent, or you can send the prize through the parent's contact information
A password reminder at registration The multiple-contact exception (notice, and an opt-out for the parent) if you keep the address in a form you can retrieve. No notice is needed if you collect nothing else, the child cannot disclose personal information on the service, and you immediately and permanently hash the address so that it cannot be reconstructed or used to contact the child
Collecting the parent's online contact information to ask for consent Allowed (§ 312.5(c)(1)). If you do not obtain consent within a reasonable time, delete it. A mobile phone number is not "online contact information" and cannot be collected from the child to start the consent process (although an exception in the Rule allows collecting a mobile number used only to text the parent to ask for consent)
E-cards or forward-to-a-friend features on a service directed to children The one-time exception applies only if the system collects the recipient's email address (with first names at most), sends the message immediately, deletes the data immediately, and has no free-text fields. Delayed sending follows the multiple-contact exception (notice to the parent and an opt-out first). If the feature gives any opportunity to reveal other personal information, full verifiable parental consent is needed ("email plus" is not allowed)
Push notifications from an app directed to children The device token is online contact information. The multiple-contact exception can apply (notice to the parent and an opt-out) if the child asked for the notifications and they relate to the app's content
Information collected from parents or other adults about children Not covered: COPPA only covers information collected online from children
A general-audience service receives an email from a user who says he is under 13 The service may reply once under the one-time exception and then delete the email. But the message may give the service actual knowledge about data it collected earlier (for example, an address given at registration), which then requires consent or deletion

Persistent identifiers used only for support for internal operations (network communication, authentication, contextual ads, frequency capping, security, compliance, analytics, spam protection, debugging) need no notice or consent. Behavioral advertising and building profiles are explicitly outside that definition.

The FTC's six-step compliance plan

  1. Determine whether COPPA covers you by applying the four triggers above. Whether a service is "directed to children" depends on its subject matter, its visual and audio content, animated characters, activities and incentives aimed at children, the age of models, child celebrities, ads directed at children, and empirical evidence about the audience. A clause in the terms of service that bans under-13s does not stop the service from being directed to children.
  2. Post a privacy policy that complies with COPPA. Put a clear and prominent link on the homepage and at every point where information is collected. List all operators that collect information through the service (name, and address, phone or email; one operator may answer inquiries, but all must be listed). Describe the types of information collected, how they are used, and what is disclosed to third parties. State a data retention policy with a timeframe for deletion (keeping data indefinitely is prohibited, a point the 2025-amendment emphasizes). Describe parents' rights.
  3. Give parents direct notice before collection. The notice must contain the key facts in the notice itself. A link to the privacy policy on its own does not comply, although a link must also be included. The notice says that you collected the parent's contact information to ask for consent, what you want to collect, how it will be used and disclosed, how to consent, and that you will delete the parent's contact information if consent does not arrive within a reasonable time. Any material change requires a new notice and new consent.
  4. Obtain verifiable parental consent before collecting, using or disclosing information. The approved methods are: a signed consent form (by mail, fax or scan); a credit card, debit card or online payment with a notification of the transaction to the account holder; a toll-free call or video conference with trained staff; a check of a government ID against a database (delete the ID after verification); knowledge-based challenge questions; and a photo ID matched by facial recognition to a second photo the parent submits (delete both after matching). If the data is used only internally (no disclosure, nothing made public), "email plus" is enough: consent by return email, followed by a confirming step, such as a follow-up call, fax or letter, or a delayed confirmation message that repeats the notice and explains how to revoke consent. Entering an app store password on its own does not give enough assurance that the parent is the one consenting. Disclosure to third parties needs separate consent, unless it is integral to the service.
  5. Honor parents' ongoing rights. On request, let parents review the child's data, revoke consent or refuse further collection, and delete the data. Verify that you are dealing with the parent (a PIN or password issued when consent was given helps). You may end the child's use of the service after a revocation only if the data is reasonably necessary for taking part.
  6. Secure, retain and delete data properly. Keep a written information security program with safeguards in proportion to the sensitivity of the data and the size of the business. Release data only to parties that can protect it, with written assurances. Keep a written policy on retention and deletion. Collect as little as possible, keep it only as long as reasonably necessary, and then dispose of it securely.

Age gates under COPPA

  • A general-audience service does not have to ask for ages, and may block under-13s entirely. If it screens for age, the screen must be neutral. Let users enter their month and year of birth freely. Do not use drop-down menus that only allow birth years for ages 13+, "I am over 12" checkboxes, or warnings that under-13s cannot take part or should ask a parent (that coaches children to lie). FTC staff recommend a cookie that stops users from going back to enter a different age. A service that asks for age and then fails to screen out children or get consent creates liability (FTC cases: Path, Playdom, Sony BMG, Yelp).
  • A mixed-audience service (directed to children under the factors above, but children are not its primary audience) may screen for age, but may not block under-13s. It must either not collect information from them or get parental consent. It must collect no personal information before the age question. A math problem in place of an age question is not adequate (it is allowed only in addition to one).
  • A service directed to children (where children are the primary audience) may not screen for age at all: every visitor gets the protections of COPPA.
  • Operators may rely on the age that users enter on a neutral screen, even if it is false. Actual knowledge can arise later (for example, from a parent's complaint, or a monitored post that reveals a user's age or school grade), and it then requires consent or deletion.

UK Children's Code (Age Appropriate Design Code)

The Information Commissioner's Office (ICO) issued this statutory code under the Data Protection Act (DPA) 2018. It applies to "information society services likely to be accessed by children", where children means anyone under 18, a much wider group than COPPA's under-13s. "Likely to be accessed" covers services that children use even when they are not the target audience. The code reaches apps, games, search engines, social platforms, marketplaces, streaming services, news and educational sites, and connected toys, as well as companies outside the UK that process the data of UK children. It does not apply to schools, although education technology providers that serve schools can be in scope. The ICO judges compliance with UK GDPR and the DPA 2018 for children's data by conformance with the code, so breaches are enforced with the normal UK GDPR powers.

The 15 standards (those relevant to email and marketing are in bold):

# Standard Requirement in one line
1 Best interests of the child The primary consideration in design and development
2 DPIAs Assess and reduce risks to children, by age and stage of development, in a data protection impact assessment
3 Age appropriate application Establish users' ages with a certainty in proportion to the risk of the data processing, or apply the code's standards to all users
4 Transparency Concise, prominent privacy information suited to the child's age, with "bite-sized" explanations at the moment they are needed
5 Detrimental use of data No uses shown to harm wellbeing, or that breach industry codes, regulatory provisions or government advice
6 Policies and community standards Actually uphold your published terms, age restrictions and policies
7 Default settings "High privacy" by default, unless there is a compelling reason based on the child's best interests
8 Data minimisation Collect and keep only the minimum needed for the elements the child actively uses, with a separate choice for each element
9 Data sharing No disclosure of children's data without a compelling reason based on the child's best interests
10 Geolocation Off by default, with an obvious sign when it is on. Visibility to others switches back to off at the end of each session
11 Parental controls Information suited to the child's age, and an obvious sign to the child when they are being monitored
12 Profiling Off by default, and only with measures that protect the child from harmful effects
13 Nudge techniques No nudging children into providing unnecessary data or weakening their privacy protections
14 Connected toys and devices Include effective tools for conformance
15 Online tools Prominent tools for children to exercise their rights and report concerns

For email marketing, standards 3, 7, 8, 12, and 13 have the most effect. A signup flow "likely to be accessed" by under-18s cannot pre-tick marketing options, nudge minors toward opting in, profile them for targeting by default, or collect an email address beyond what the requested feature needs. If the service will not assess users' ages, it must apply those defaults for children to everyone.

GDPR Article 8: consent ages for information society services

Article 8 applies where an information society service is offered directly to a child and relies on consent (Art. 6(1)(a)), which is the lawful basis that email marketing normally uses. The child's own consent is valid only from age 16. Below that age, "processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child."

Member states may lower the threshold by law, but not below 13, so the age of digital consent ranges from 13 to 16 across the EU. The UK set 13 in the Data Protection Act 2018, which is why the ICO's marketing guidance treats 13 as the minimum age for a minor's own consent. The controller must make "reasonable efforts to verify" that consent was given or authorised by the holder of parental responsibility, "taking into consideration available technology."

What this means for a signup form that serves Europe: below the national age that applies, a child's own opt-in is not valid consent. At or above that age, a plain opt-in works, but the rules on the quality of consent in PECR and ePrivacy still apply.

What this means for ESP policy

Taken together, the three regimes have these consequences for an ESP's own platform rules and for its customers' forms:

  • Age gates on signup forms. Hosted forms for general audiences that want to exclude minors should use a neutral date-of-birth field. Never use a picker that only offers ages 13+ or 16+, never use an "I am over N" checkbox, and add no discouraging text. Store the answer (in a cookie) so that users cannot go back and try again. Blocking respondents under the age limit is lawful for general-audience properties under every regime. The risk is asking for age and then ignoring the answer, which turns ignorance into actual knowledge.
  • Customers whose audience is children are a separate risk class. They need the COPPA process (direct notice, verifiable parental consent, and an opt-out for parents under the multiple-contact exception for newsletters), which a standard flow of subscribing and confirming does not provide. An ESP should either support consent collected through the parent (the parent's address collected with the child's, a notice sent to the parent, and the opt-out honored before ongoing sends) or prohibit lists directed to children in its acceptable use policy (AUP).
  • Consent records must show whose consent it is. For minors, the proof-of-consent record needs the parent's identity or contact details and the verification method used. A timestamped opt-in from the child's own address proves nothing under any of these regimes.
  • Deletion is part of the lifecycle. COPPA's one-time exceptions and the parent's right to revoke consent, the Children's Code standards on data minimisation and retention, and erasure under GDPR all mean that children's addresses need prompt deletion that you can prove, not just suppression.
  • Watch for actual knowledge. Support tickets, replies and complaints that reveal a subscriber is a child give the sender actual knowledge (and arguably the ESP that processes data on the sender's behalf). The compliant responses are parental consent or deletion. Continuing to send mail is the violation.
  • Marketing law still applies as well. Nothing above replaces CAN-SPAM, CASL or PECR. A children's newsletter with parental consent still needs truthful headers, identification of the sender and a working unsubscribe.

These summaries follow guidance published by the regulators (the FTC's guidance as of its May 2026 revision of the six-step plan and the April 22, 2025 amendment to the COPPA Rule, and the text of the ICO code as published). They are not legal advice.