Children's Online Privacy Protection Rule (“COPPA”)
- Document
- 1 July 2013
- Event
- 1 July 2013
- Retrieved
- 16 September 2026
The play
Long before connected toy was a marketing term, the Children's Online Privacy Protection Act of 1998 set rules for any website or online service that collects personal information from children under 13. The FTC's rule implementing that law, known as the COPPA Rule, is a regulatory text rather than a toy, but it decides which data practices in a smart teddy bear or a companion robot are lawful. On 17 January 2013 the FTC published a final rule amending that text, with the changes taking effect on 1 July 2013.
What the evidence says
The Federal Register document states plainly that the amended Rule would become effective on 1 July 2013, and it explains what changed: the amendment expanded personal information to include geolocation information and persistent identifiers that can be used to recognize a user over time and across different websites or online services, and it gave photographs, videos, and audio files their own place in the definition, reflecting what the Commission called their inherently personal nature, rather than counting them only when combined with other identifying details. The FTC's own legal library page for the rule lists this 2013 action among a series of Federal Register notices stretching from 1999 to the present, underscoring that the amendment sits inside a rule the FTC has revisited repeatedly rather than a single fixed statute. The 2013 amendment changed that implementing rule; it did not rewrite the underlying 1998 statute.
Age fit and safety
The rule's protections apply to any operator, toy-related or not, that has actual knowledge it is collecting personal information from a child under 13; it does not set a play-based age range the way a toy safety standard does. What it does establish, directly relevant to a connected toy, is that a voice recording or a photo containing a child's likeness, and a persistent identifier such as a device ID, are now expressly covered, whether or not that data is combined with a name or address.
What to look for
This is an editorial translation of the rule's language, not new guidance: a connected toy that stores a voice clip, a device identifier, or a location fix is handling exactly the categories of information the 2013 amendment added, whether the manufacturer's own materials call it personal information or not. A privacy policy that mentions only names and addresses, and stays silent on identifiers, recordings, and location, is describing an older, narrower version of what the rule now covers.
- Does the toy's privacy policy mention voice, photo, or video data specifically, not just names or emails?
- Does it say whether the toy assigns a persistent device identifier, and what that identifier is used for?
- Does it mention geolocation at all, even to say the toy does not collect it?
A rule change from 2013 is easy to treat as ancient history next to a toy released this year, but it is the same expanded definition that determines what a modern connected toy's privacy policy is legally required to disclose.
Sources & reading trail
FTC's own rule index confirming the 1998 statute, the rule's 1999 promulgation, and the 17 January 2013 Federal Register notice amending it.
Source published: Not established · Retrieved: 16 September 2026
States the amendment's 1 July 2013 effective date and that it expanded personal information to include geolocation, persistent identifiers, and photos, videos, and audio files.
Source published: 17 January 2013 · Retrieved: 16 September 2026
Standards, recall notices, studies and records establish the entry; the what-to-look-for reading is Toy Almanac editorial analysis. This retrospective draft does not imply the site published on the event date.