COPPA Compliance: Running Sweepstakes That Include Minors
COPPA restricts how you collect personal information from children under 13. This guide covers when the law applies to sweepstakes, what it requires, verifiable parental consent, practical approaches, penalties, and common mistakes.
The Children's Online Privacy Protection Act (COPPA) is one of the most consequential — and most misunderstood — laws affecting promotional sweepstakes. It restricts the collection of personal information from children under 13 online, and the penalties for violation are substantial: the FTC has imposed fines exceeding $500 million in recent COPPA enforcement actions.
COPPA compliance is not optional and the FTC is not bluffing. Epic Games paid $275 million. TikTok paid $5.7 million. The FTC will come after smaller companies too.
For most sweepstakes sponsors, the safest path is to set a minimum entry age of 18 and enforce it. But "safest" does not mean the question goes away. Brands that market to families, produce children's products, or run promotions on platforms with mixed-age audiences need to understand when COPPA applies, what it requires, and why the compliance burden is high enough that most sponsors choose to avoid it entirely.
This guide covers the law, the requirements, and the practical decisions sponsors face.
This article is for informational purposes only and does not constitute legal advice. Consult with a qualified attorney for guidance specific to your promotion.
What COPPA Requires
COPPA is a federal law enacted in 1998 and last updated by the FTC in 2013 (with proposed updates under review). It applies to operators of websites, apps, and online services that are directed at children under 13, or that have actual knowledge that they are collecting personal information from children under 13.
The core rule is simple: you cannot collect personal information from a child under 13 without first obtaining verifiable parental consent.
"Verifiable" is the operative word. COPPA does not accept a checkbox, a "click here if your parent says it's okay" button, or a simple email confirmation. The FTC requires methods that provide a reasonable level of assurance that the person giving consent is actually the child's parent or guardian.
What Counts as Personal Information
COPPA's definition of "personal information" is broad. It covers the obvious categories — name, physical address, email address, phone number, Social Security number — but also persistent identifiers like cookies, device IDs, and IP addresses when used to recognize a user over time or across different services. Photos, videos, and audio files containing a child's image or voice qualify. So does geolocation data sufficient to identify a street name and city, and any information combined with any of the above.
The persistent identifier category is the one that catches sponsors off guard. Even if your entry form does not ask for a child's name, if your platform uses cookies or device fingerprinting to track users (which most fraud prevention systems do), you are collecting personal information under COPPA.
When COPPA Applies to Sweepstakes
COPPA applies to your sweepstakes in three scenarios:
1. Your Promotion Is Open to Children Under 13
If your official rules set the minimum age below 13 — or set no minimum age at all — COPPA applies to any entries from children under 13. This is the most straightforward trigger.
2. Your Promotion Is on a Site or Platform Directed at Children
If you run a sweepstakes on a website, app, or platform that is "directed to children" as the FTC defines it, COPPA applies regardless of who actually enters. The FTC considers factors including the subject matter of the site, visual content, use of animated characters, language, advertising directed at children, and whether the audience includes a significant proportion of children.
A cereal brand running a sweepstakes on its website featuring cartoon characters and kid-oriented games is operating a site "directed to children." A luxury car brand running a sweepstakes on its corporate website is not.
3. You Have Actual Knowledge That Children Under 13 Are Participating
If a participant indicates they are under 13 — by entering a date of birth, for example — and you proceed to collect their personal information, you have actual knowledge that triggers COPPA. This is true even if your promotion targets adults.
This scenario creates a specific obligation: if your age gate reveals that a user is under 13, you must stop collecting data immediately. Do not collect their information and then discard it. Do not store the information temporarily. Stop the collection process at the point where you learn the user's age.
The Simplest Solution: Set the Minimum Age at 18
The overwhelming majority of sweepstakes sponsors avoid COPPA by setting the minimum entry age at 18 (or 13, for promotions that do not involve minors under 13). This is the recommendation for any sponsor who does not have a specific business reason to include children under 13.
Age-Gating Requirements
An age gate must be implemented at the point of entry — before any personal information is collected.
The gate should ask for a full date of birth, not a yes/no question. "Are you 18 or older?" is trivially easy to circumvent. A date-of-birth field provides more friction, though it is still not foolproof. If the entered date of birth indicates the user is under the minimum age, the form must not proceed to collect personal information — do not show the entry form, and do not offer to save their information for later.
A common mistake: displaying "You must be 18 to enter" before asking for the date of birth. That tells the underage user exactly what date to enter on their next attempt. Ask for the date of birth first, then display the message if they do not meet the threshold. And set a persistent block — use a cookie or session marker to prevent the same user from immediately re-entering with a different date of birth. The FTC has stated that age gates should not allow users to simply go back and try again.
Age-gating is not a guarantee of COPPA compliance — a determined 12-year-old can enter a false date of birth. But a properly implemented age gate with the design considerations above demonstrates good faith effort to restrict underage participation, which matters if the FTC ever investigates.
If You Must Include Minors
Sometimes a brand has a legitimate business reason to run promotions that include younger participants. Family brands, children's entertainment companies, and educational organizations may need to engage minors in their campaigns.
Ages 13 to 17
Participants aged 13 to 17 are generally not covered by COPPA (which applies only to children under 13). However, including minors aged 13 to 17 does create other obligations:
- State contract laws may require parental consent for a minor to enter into the agreement represented by the official rules.
- Prize acceptance may require a parent or guardian's signature.
- Some states have additional restrictions on promotions directed at minors.
For the 13-to-17 age range, the standard approach is to require a parent or guardian co-sign the entry or the winner verification documents.
Under 13: Full COPPA Compliance
If your promotion must be open to children under 13, COPPA applies in full. This means verifiable parental consent before collecting any personal information.
Verifiable Parental Consent Methods
The FTC has approved several methods for obtaining verifiable parental consent. Each involves significant friction and cost, which is the primary reason most sponsors avoid promotions that include children under 13.
Signed Consent Form
The parent prints, signs, and returns a consent form by mail, fax, or scanned email attachment. This is the most traditional method and provides a clear paper trail, but the turnaround time is measured in days, not minutes.
Credit Card Verification
Charge a small amount to the parent's credit card (which is refunded) as verification that a real adult is providing consent. The theory is that children do not have credit cards. This method is faster than a signed form but raises its own data security concerns.
Government ID Verification
The parent submits a copy of their government-issued ID, which is verified and then deleted. This provides strong verification but involves collecting sensitive documents and creates privacy risks.
Video Call Verification
A live video call with the parent to verify their identity and obtain consent. Effective but difficult to scale for promotions with large numbers of underage entrants.
Knowledge-Based Authentication
Challenge questions based on information in the parent's credit history (similar to the questions lenders use for identity verification). This can be automated but requires integration with a credit bureau or knowledge-based authentication provider.
The Friction Problem
Every approved consent method adds significant friction to the entry process. A child who wants to enter a sweepstakes must first get their parent to complete a consent process that may take days. For promotions where ease of entry is critical to participation volume, this friction can reduce entries from the under-13 segment to near zero.
This is why the entry method selection decision is so important for promotions targeting families — the entry mechanism must account for the consent workflow.
What COPPA Requires Beyond Consent
Verifiable parental consent is the headline requirement, but COPPA imposes additional obligations:
Direct Notice to Parents
Before collecting information from a child, you must provide the parent with a clear, complete notice describing:
- What information you collect from children
- How you use it
- Your disclosure practices (who you share it with)
- The parent's right to review the child's information
- The parent's right to have the information deleted
- The parent's right to refuse further collection
Data Minimization
You may not collect more personal information from a child than is reasonably necessary for the activity. For a sweepstakes entry, this means name and email (or whatever minimal information is needed to administer the entry) — not phone number, address, school name, or other information that is not essential to the promotion.
Data Security
You must maintain reasonable security procedures to protect the confidentiality, security, and integrity of children's personal information. This includes both technical safeguards (encryption, access controls) and organizational measures (limiting employee access, training staff).
Data Retention and Deletion
You must retain children's personal information only as long as necessary for the purpose for which it was collected, and you must delete it when it is no longer needed. Parents also have the right to request deletion at any time.
Platform-Specific Considerations
Running sweepstakes on social media platforms introduces platform-specific COPPA concerns.
YouTube
YouTube's "Made for Kids" designation, implemented after Google's $170 million COPPA settlement, restricts data collection on content directed at children. Sweepstakes conducted through YouTube comments or linked from "Made for Kids" content are subject to these restrictions.
Instagram and TikTok
Both platforms have minimum age requirements (13 for Instagram, 13 for TikTok in the US). However, underage users routinely create accounts with false ages. A sweepstakes promoted on these platforms may attract participants under 13 even if the platform's terms nominally exclude them.
TikTok paid $5.7 million to settle FTC COPPA charges in 2019 for collecting personal information from children under 13 on its predecessor app Musical.ly.
App Stores
If your sweepstakes is accessible through a mobile app listed in the "Kids" or "Family" category of the Apple App Store or Google Play Store, COPPA applies with near-certainty. Both app stores have their own policies regarding children's data collection that layer on top of COPPA.
Penalties and Enforcement
The FTC enforces COPPA aggressively. Penalties are calculated per violation — each instance of collecting personal information from a child without verifiable parental consent is a separate violation.
The maximum civil penalty per violation was adjusted to $50,120 as of 2024, and these amounts are periodically increased.
Recent enforcement actions demonstrate the scale:
- Epic Games (Fortnite) — $275 million in 2022 for COPPA violations related to default privacy settings for children
- Google/YouTube — $170 million in 2019 for collecting personal information from children watching YouTube videos
- TikTok (Musical.ly) — $5.7 million in 2019 for collecting personal information from users under 13
These are not theoretical risks. The FTC actively monitors and investigates online services that interact with children. If you think your promotion is too small to attract attention, consider that the FTC pursued Musical.ly (a startup at the time) before TikTok even acquired it. Size does not buy you immunity.
COPPA and State Laws
Some states impose additional requirements beyond COPPA for the collection of children's data.
California's CCPA/CPRA includes specific provisions for minors. Businesses cannot sell the personal information of consumers they know to be under 16 without affirmative authorization (from the parent for children under 13, from the minor themselves for ages 13-15).
Several states have enacted or proposed "children's privacy" or "age-appropriate design" legislation that imposes obligations beyond COPPA, including data protection impact assessments for services likely to be accessed by children and restrictions on features that encourage excessive use.
The Kids Online Safety Act (KOSA), if enacted at the federal level, would impose additional requirements on platforms regarding content and features accessible to minors. While KOSA is not specifically about sweepstakes, it would affect the platforms on which sweepstakes are promoted.
Common Mistakes
Assuming an Age Gate Is Sufficient
An age gate is a necessary first step, but it is not COPPA compliance. If a child bypasses the age gate (which is trivial for an older child), and you then collect their data, you may still be in violation if you had reason to know children use your platform.
Collecting Device Identifiers Without Considering COPPA
Cookies, device fingerprints, and IP addresses are personal information under COPPA when used to identify or track a user. If your sweepstakes platform collects these identifiers from children — even for fraud prevention — you need parental consent.
Failing to Recognize a "Mixed Audience" Site
A brand that sells products to both adults and children (breakfast cereals, family entertainment, sporting goods) may operate a "mixed audience" website that attracts children even though it is not exclusively directed at them. The FTC has stated that mixed-audience sites must apply COPPA protections when they have actual knowledge that a specific user is under 13.
Running Promotions on Child-Focused Platforms Without COPPA Compliance
Promoting a sweepstakes through YouTube content aimed at children, kid-focused influencers, or family-oriented social media accounts creates COPPA exposure even if the entry form itself is on the sponsor's website.
Using Persistent Identifiers for Tracking Without Consent
Many fraud prevention and analytics tools use persistent identifiers (cookies, device fingerprints) that constitute personal information under COPPA. If children may be using your platform, these tools must either be disabled for underage users or covered by verifiable parental consent.
How Comprizant Handles COPPA
Comprizant's platform provides the tools sponsors need to manage age-related compliance for sweepstakes.
Configurable age gating. Sponsors set the minimum entry age per campaign. The age gate is implemented at the entry form level, before any personal information is collected. If a user indicates they are below the minimum age, data collection stops.
Persistent block. Underage users who fail the age gate receive a session-level block that prevents re-entry with a different date of birth.
No threshold reveal. The age gate requests a full date of birth without revealing the minimum age requirement, reducing the likelihood of repeated attempts with false information.
Compliant entry forms. Entry forms built through Comprizant follow data minimization principles — collecting only the information necessary for the promotion — and include the required compliance disclosures and privacy notices.
Key Takeaways
-
COPPA restricts collection of personal information from children under 13. It applies to sites and services directed at children, and to any operator with actual knowledge that a user is under 13.
-
The simplest approach is to set the minimum age at 18. This avoids COPPA entirely and is the correct choice for most sweepstakes sponsors.
-
If you must include children under 13, verifiable parental consent is required. Every approved method involves significant friction and cost. There are no shortcuts.
-
"Personal information" under COPPA is broad. It includes cookies, device fingerprints, and IP addresses — not just names and emails.
-
Age gates must be designed carefully. Ask for a full date of birth, do not reveal the threshold, set a persistent block, and stop all data collection if the user is underage.
-
Penalties are severe and enforcement is active. The FTC has imposed fines of $170 million and $275 million in recent COPPA cases.
-
Platform matters. Running promotions on YouTube, TikTok, or app stores with children's categories introduces platform-specific COPPA considerations.
-
State laws add additional requirements. California, in particular, extends privacy protections to minors aged 13-15 and restricts data sales involving minors under 16.
Comprizant provides configurable age gating, data minimization, and compliance disclosures for every sweepstakes entry form. Start your free account and run promotions that meet COPPA requirements out of the box.