Verify any claim · lenz.io
Claim analyzed
Legal“In the United States, a developer can legally show contextual (non-behavioral) ads in a mobile game directed to children aged 6–15 without obtaining verifiable parental consent, provided no personal data is collected or disclosed to third parties for advertising purposes.”
Submitted by Steady Koala 16cb
The conclusion
Open in workbench →The core claim is substantially accurate. Under COPPA, a child-directed mobile game may serve purely contextual ads to under-13 users without verifiable parental consent when personal information is not collected, used, or disclosed for behavioral advertising. The main caveat is that COPPA covers only children under 13; for ages 13–15, the result is generally the same, but for a different legal reason, and other laws or platform rules may still apply.
Caveats
- COPPA's parental-consent framework applies only to children under 13; ages 13–15 are outside COPPA, so the legal basis is different.
- This is not a blanket exemption: if an ad SDK collects persistent identifiers such as IP addresses or device IDs beyond internal operations, COPPA obligations can change.
- Even without parental consent, operators may still need COPPA-compliant privacy disclosures and must check state privacy laws and app-store requirements.
Get notified if new evidence updates this analysis
Create a free account to track this claim.
Sources
Sources used in the analysis
The Final Rule adds that operators must obtain separate verifiable parental consent before disclosing children’s personal information to third parties, unless the disclosure is integral to the nature of the online service. The Final Rule also requires operators relying on the internal-operations exception to disclose the specific internal operations for which persistent identifiers are used. The rule continues to allow persistent identifiers to be collected for internal operations, including contextual advertising, without separate parental consent, so long as the use fits the exception and the identifiers are not used or disclosed for impermissible purposes.
Section 312.2 defines "support for the internal operations of the website or online service" to include activities such as "serving contextual advertising on the website or online service" and frequency capping. This is a listed exception in the COPPA Rule's definitions, meaning contextual advertising can fall within internal operations without parental consent if the operator otherwise complies with COPPA's limits.
The Rule provides a narrow exception for a site or service that may be directed to children under the criteria set forth in FAQ D.1 above, but that does not target children as its primary audience. "Support for internal operations" does, however, include the collection or use of persistent identifiers in connection with serving contextual advertising on the child-directed site.
COPPA applies to operators of commercial websites and online services (including mobile apps) directed to children under 13 that collect, use, or disclose personal information from children, and operators of general audience websites or online services with actual knowledge that they are collecting, using, or disclosing personal information from children under 13.[7] Personal information under COPPA includes “a persistent identifier that can be used to recognize a user over time and across different websites or online services.”[7] COPPA imposes requirements only where such personal information is collected, used, or disclosed; contextual advertising that does not involve collection of personal information generally falls outside these requirements.[7]
"Parental consent is not required under the following circumstances: ... 2. When a website or app collects personal information for internal use to improve the website or app, so long as the information is not disclosed to third parties ... COPPA prohibits websites and apps from collecting personal information from children for the purpose of marketing or advertising. In addition, it prohibits websites and apps from targeting children with personalized ads based on their personal information." "Websites and apps cannot collect personal information from children for the purpose of marketing or advertising products or services to them. They also cannot target children with personalized ads based on their personal information. If a website or app serves ads to children, they must ensure that the ads are appropriate for children and do not collect personal information."
Children’s Online Privacy Protection Act of 1998 (COPPA), 15 U.S.C. § 6501 et seq., addresses the collection, use, and disclosure of personal information about children collected from children through websites or other online services.[8] Parental Consent – Obtaining, through reasonable efforts and with limited exceptions, verifiable parental consent prior to the collection, use, or disclosure of personal information from children.[8] COPPA does not regulate purely contextual advertising where no personal information is collected from the child and no persistent identifiers are used to track the child over time or across services.[8]
The FTC's new Rule would require parental consent before children's data can be shared with third parties for targeted advertising purposes. First, the Rule update does not modify COPPA’s treatment of contextual advertising. The rule continues to distinguish contextual advertising from targeted advertising, and contextual advertising remains outside the new parental-consent requirement when it fits the internal-operations exception.
The Children’s Online Privacy Protection Act (“COPPA”) specifically aims to protect the privacy of children under the age of 13 by requesting parental consent for the collection or use of any personal information of the users.[3] The main requirements of the Act that a website operator must comply with include: Acquisition of a verifiable parental consent prior to collection of personal information from a child under the age of 13.[3] COPPA applies to commercial websites and online services that are directed at children; it does not apply to services directed at teenagers 13 and older, and it only applies where personal information is collected, used, or disclosed.[3]
COPPA requires app developers and website operators to provide notice about their data collection practices and to **obtain verifiable parental consent before collecting personal information online from children—including persistent identifiers used to target advertising to them.** In the HyperBeard case, the FTC alleged the company "unlawfully collected their personal information to direct **targeted advertising** to them" without obtaining verifiable parental consent. The complaint distinguishes targeted behavioral advertising based on activity over time from other forms of advertising; it is the collection and use of personal information for targeted ads that triggered COPPA violations.[4]
Operators may continue to rely on the support for internal operations exception to collect persistent identifiers for contextual advertising. The Final Rule requires separate parental consent for disclosures of personal information that are not integral to the nature of the online service, such as targeted advertising.
"The COPPA Rule should permit responsible data practices without verifiable parental consent. Privacy for America supports responsible data practices without obtaining verifiable parental consent (VPC) that allow companies to collect, use, and share children’s data in ways that enhance online experiences and support important business operations while still protecting children from harms." "Contextual advertising, frequency capping, measurement, and fraud prevention can be accomplished without building behavioral profiles of children or engaging in targeted advertising based on tracking children across websites and apps."
"COPPA is a U.S. law designed to protect the digital privacy of kids under 13. It prohibits the collection of personal information, including technical data like full IP addresses, precise location data, and browser cookie data without obtaining verifiable parental consent." "To comply, companies must stick to contextual advertising, use compliant kidtech, or obtain parental consent before collecting any personal data." "Contextual Advertising Is Still the Only Expressly Approved Form of Advertising to Youth Audiences – The Rule continues to allow operator-driven personalization and contextual advertising under the 'support for internal operations' exemption, with no new restrictions introduced."
The existing COPPA Rule permits businesses to use persistent identifiers for internal operations without parental consent. The FTC asks whether certain types of personalization and contextual advertising remain appropriately categorized as internal operations, underscoring that contextual advertising is currently treated differently from behavioral or targeted advertising.
COPPA restricts you to contextual advertising with partners that do not collect any personal information from children. COPPA does not prohibit advertising to children, but it states that you may not collect any personal information (which includes cookies and other persistent identifiers) from children under 13 years of age without verifiable parental consent.
The Children’s Online Privacy Protection Act of 1998 (COPPA) is a United States federal law.[5] The act … applies to the online collection of personal information by persons or entities under U.S. jurisdiction about children under 13 years of age.[5] COPPA requires operators to “obtain verifiable parental consent, with limited exceptions, prior to any collection, use, and/or disclosure of personal information from persons under age 13”; contextual advertising that does not collect such personal information is generally viewed as outside that requirement.[5]
Under COPPA, **collecting personal information from children is illegal without verifiable parental consent.** The article explains that “all behavioral and targeted advertising to children is out” and that “for this reason, all advertising in a children's gaming app will need to be strictly **contextual**, unless you have a gated adult section for advertising to parents.” It notes that “unless your game is a zero-data application, you will need to request verifiable consent from a parent before collecting any information at all from a child, even if it's just an IP address,” emphasizing that contextual ads are permitted when the app operates as a **zero‑data environment** or otherwise does not collect personal information for advertising.[1]
"The aforementioned exception is a narrowly defined carve-out of the COPPA Rule added in 2013 that allows companies to collect personal information from a child without parental consent if the data is used to support the internal operations of a site or service. Authenticating users, protecting security, ensuring regulatory compliance, personalizing site content, frequency capping and serving contextual advertising are all examples of activities that would qualify." "Because contextual advertising doesn’t rely on cookies or other personal identifiers, it’s the monetization method of choice for many child-directed websites and services with 'actual knowledge' that they’re collecting personal information from a child, like YouTube. The FTC did not change the support for internal operations exception, which expressly allows operators to collect persistent identifiers, such as IP addresses, as necessary to serve contextual advertising on their websites or online services."
The Children’s Online Privacy Protection Act (COPPA) was updated in 2013 to make it illegal for commercial websites to collect identifying information about kids under the age of 13 without verifiable parental consent.[6] COPPA focuses on data that can identify a child, such as names, contact information, and persistent identifiers used to recognize users over time and across online services.[6] If an online service presents advertising based solely on the context of the content being viewed and does not collect identifying information or track children over time, this type of contextual advertising is generally considered outside the scope of COPPA’s consent requirements.[6]
COPPA says that **you can't collect children's data without permission from their parents or guardians** and provides guidance on what you can and can't do with their data once you have it. The article gives Gameloft as an example of a kids’ app that "doesn't collect any identifying information" and whose privacy policy says it "will not collect geolocation information from apps where a child is under the age of consent and will **only display contextual advertising (not behavioral).**" It reiterates: "You are **not allowed** to collect the data of any child under 13 (COPPA) without first getting verified permission from their parent or guardian," implying that contextual ads that do not involve data collection are an allowed practice.[2]
"Owners of websites directed towards children are required to provide notice on the website of what information is collected from children, how the operator uses such information, and the operator's disclosure practices for such information." "In addition, Congress requires website owners to obtain verifiable parental consent before any collection, use, or disclosure of personal information from children, subject to limited exceptions."
Under COPPA, children’s personal information is defined as including any information provided by them, their parents or a third party, whether directly or by tracking their actions or participation in activities.[2] Personal information includes persistent online identifiers, such as a profile, cookie, IP address, device serial number or other identifier to recognize a user over time and across different online locations, websites or services.[2] COPPA applies to U.S. and international operators of commercial websites and online services that target children in the U.S. and collect personal information from them; if no personal information is collected, COPPA’s verifiable parental consent obligation generally does not apply, although other laws or app-store policies may.[2]
Many apps violate COPPA by collecting personal information from children without giving notice to parents and obtaining verifiable parental consent, as required by COPPA. The complaint describes how Google and others allowed "child-directed" apps to collect persistent identifiers and other data for **behavioral advertising** without obtaining parental consent. It relies on COPPA’s distinction between allowed uses of persistent identifiers for internal operations (such as contextual ads) and prohibited uses for profiling or targeted ads absent consent.[3]
Some online operators and marketing practices that were not covered before may now be considered within the bounds of FTC's COPPA enforcement. Once triggered, the rule obligates covered operators to acquire the verifiable permission of parents before collecting, using, or disclosing personal information from children. Certain internal-operations activities remain carved out, but third-party ad networks that actually collect personal information from child-directed services can trigger notice and consent obligations.
"It's a federal law that states if your child is under 13, apps and websites cannot collect their personal information without your permission. This includes names, addresses, phone numbers, email addresses, and other identifying information." "COPPA applies to websites and online services directed to children under 13 years of age and to operators that have actual knowledge that they are collecting personal information from children under 13."
Ninety-five percent of commonly downloaded apps marketed to or played by children 5 and under contain at least one type of advertising, according to a new study led by University of Michigan C.S. Mott Children’s Hospital. The study documents that these ads include many formats (banner, pop‑up, in‑app purchases, etc.), but notes that current U.S. law focuses on **data collection and targeted advertising**, not the mere presence of contextual ads. The findings show that widespread advertising in children’s apps is occurring within the existing COPPA framework, under which contextual ads that do not involve personal data collection are generally treated differently from behavioral ads.[6]
This discussion among game developers explains: "You cannot collect personal information for users under age 13 in the US without parental consent. (Ad networks often collect personal data)." Participants note that there are "a ton of rules and restrictions regarding players under the age of 13… also how you show ads, monetize, game content," and that many developers choose not to aim games at under‑13 users to avoid COPPA obligations. The comments implicitly distinguish **ads that require data collection by networks** from possible non‑tracking or contextual approaches that avoid collecting personal information.[9]
Under COPPA, the term "child" is defined as an individual under the age of 13. Services directed to users 13–15 are not covered by COPPA unless they also handle data of children under 13. COPPA requirements, including verifiable parental consent, are triggered only when there is collection, use, or disclosure of personal information from children; if an operator does not collect personal information at all, COPPA’s consent obligations generally do not apply.
A consumer warning aimed at parents notes that "Some ads that are showing up on installed kids games/apps are very inappropriate for most kids" and advises parents to read reviews and use parental controls. It treats ads within kid‑friendly apps as common and focuses on content appropriateness and in‑app purchases, rather than asserting that **all** advertising in child‑directed apps is legally prohibited. The practical advice reflects that contextual ads in children’s mobile games are widely deployed under current law, with legal concern centered on data collection and targeting.[10]
A local news‑style post amplifying FTC guidance warns about "video game ads that encourage kids to spend money" and notes that "some ads that are showing up on installed kids games/apps are very inappropriate for most kids." It refers readers to FTC resources on kids’ apps and advertising, which distinguish between **targeted ads based on data collection** and other forms of advertising. The piece reflects the regulatory focus on deceptive or unfair practices and data‑driven targeting, not a categorical ban on contextual ads absent personal data collection.[8]
What do you think of the claim?
Your challenge will appear immediately.
Challenge submitted!
For developers
This same pipeline is available via API.
Verify your AI's output programmatically.
/extract pulls claims from text ·
/verify returns sourced verdicts ·
/ask answers follow-up questions.
Continue your research
Verify a related claim next.
Debate
Two AI advocates debated this claim using the research gathered.
Argument for
Source 1 (FTC), Source 2 (eCFR), Source 3 (FTC), Source 4 (Hyperproof), Source 6 (NCUA), Source 7 (IITF), Source 10 (Venable), Source 12 (SuperAwesome), Source 14 (IAB), Source 15 (Wikipedia), Source 16 (TermsFeed), Source 17 (AdExchanger), Source 18 (University of Alabama), Source 19 (PrivacyPolicies.com), Source 21 (TrustArc), and Source 27 (LLM Background Knowledge) establish that COPPA permits contextual advertising as an internal-operations exception when no personal information is collected or disclosed to third parties, directly confirming the claim for ages 6–12; for ages 13–15, Source 27 further shows COPPA does not apply at all, rendering consent unnecessary. This uniform treatment across high-authority primary regulatory sources and consistent secondary analyses demonstrates the claim is accurate as a matter of law.
The Proponent's argument commits a logical fallacy by conflating a lack of COPPA coverage for teenagers with a positive legal authorization under COPPA's specific "internal operations" exception. Because COPPA's statutory definition of a child is strictly limited to those under 13 as detailed in Source 8 (Electronic Privacy Information Center) and Source 12 (SuperAwesome), it is legally incoherent to claim a developer can utilize a COPPA-specific consent exception for children aged 13 to 15.
Argument against
The claim is false because the Children's Online Privacy Protection Act (COPPA) only applies to children under the age of 13, as established in Source 8 (Electronic Privacy Information Center) and Source 12 (SuperAwesome). By extending the age range to children aged 6–15, the claim incorrectly applies COPPA's specific regulatory framework and parental consent exceptions to teenagers who fall entirely outside the law's statutory definition of a child.
The Opponent's argument relies exclusively on Source 8 (EPIC) and Source 12 (SuperAwesome) to assert non-applicability above age 12 while ignoring Source 27, which establishes that COPPA does not apply to users 13–15 and thus imposes no consent obligation, leaving the claim intact for that cohort. The Opponent further overlooks the internal-operations exception for contextual advertising without personal-data collection or third-party disclosure, as uniformly confirmed for ages 6–12 by Sources 1 (FTC), 2 (eCFR), and 3 (FTC), committing a fallacy of incomplete scope that fails to negate the claim's accuracy across the full stated range.
Panel Review
3 specialized AI experts evaluated the evidence and arguments.
Reviewer 1 — The Logic Examiner
Sources 1–3 and 2 (FTC rule summary, FTC FAQs, and the eCFR text) support the inference that for child-directed services to under-13 users, serving contextual ads can be done without verifiable parental consent when any persistent identifiers are used only for “support for internal operations” and are not used/disclosed for impermissible advertising purposes, and sources 6, 18, and 21 further reinforce that purely contextual ads with no personal information collection generally do not trigger COPPA consent. However, the claim's 6–15 scope is not logically supported because COPPA's consent framework (and its internal-operations exception) is about under-13 children (sources 8, 12, 27), so extending the statement as a single legal rule for ages 13–15 is an overextension even if consent may be unnecessary for other reasons outside COPPA.
Reviewer 2 — The Source Auditor
High-authority sources 1 (FTC), 2 (eCFR), and 3 (FTC) explicitly confirm that contextual advertising qualifies for the internal-operations exception under COPPA when no personal information is collected or disclosed to third parties, allowing such ads without verifiable parental consent for children under 13. For ages 13–15, COPPA does not apply at all per sources 8 (EPIC) and 27, so consent is likewise unnecessary, making the full claim accurate.
Reviewer 3 — The Precision Analyst
The claim states that a developer can legally show contextual (non-behavioral) ads in a mobile game directed to children aged 6–15 without verifiable parental consent, provided no personal data is collected or disclosed to third parties. The precision issue here is the age range: COPPA applies only to children under 13, as confirmed by Sources 8, 12, 15, 24, and 27. For ages 6–12, the claim is well-supported — Sources 1, 2, 3, 6, 7, 10, 12, 17, and others uniformly confirm that contextual advertising falls under the 'support for internal operations' exception and does not require parental consent when no personal information is collected. However, extending the claim to ages 13–15 introduces a precision problem: COPPA simply does not apply to that age group, so framing the legal permissibility for 13–15 year-olds as flowing from COPPA's consent exception is legally incoherent — the absence of COPPA coverage is not the same as a COPPA-based exception. The claim's wording implies a unified legal basis (COPPA's consent framework) applies across ages 6–15, when in reality the legal basis differs materially between the under-13 and 13–15 cohorts. Additionally, for the 13–15 cohort, other laws (state privacy laws, app store policies) may impose restrictions not addressed by the claim. The claim is mostly true in substance — contextual ads without personal data collection are legally permissible for both age groups — but the precision of attributing this to a single COPPA-based framework across ages 6–15 is flawed, as COPPA's specific consent exception only applies to under-13s.