RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 160 retrospective records ↗
Love With Machines

The archive / Privacy & data

Privacy & data / From the archive · 17 January 2013 event · prepared 16 September 2026

The 2013 COPPA update reached plug-ins and persistent IDs

The FTC's 2013 rule amendments extended children's privacy protections to persistent identifiers and third-party plug-ins.

federalregister.govprimary record

Children's Online Privacy Protection Rule (Final Rule Amendments)

Document
17 January 2013
Event
17 January 2013
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The design

The Federal Trade Commission issued final amendments to the Children's Online Privacy Protection Rule, published in the Federal Register on 17 January 2013, with an effective date the notice itself sets as 1 July 2013. The rule implements the Children's Online Privacy Protection Act, and the 2013 amendments followed two rounds of public comment, a 2011 proposed rule and a 2012 supplemental proposal, before the Commission adopted a final rule. This predates the FTC's 2025 COPPA update already covered on this site by more than a decade and forms the baseline that update built upon.

What the evidence says

The rule's own preamble states what changed: the definition of “personal information” was expanded to include geolocation information and “persistent identifiers that can be used to recognize a user over time and across different Web sites or online services,” bringing advertising identifiers and device IDs within COPPA's scope for the first time. A separate change extended liability for a child-directed site's own plug-ins and advertising networks, making the site's operator strictly liable for personal information those integrated services collect, and making the plug-in or network itself liable once it has actual knowledge it is collecting data through a child-directed service. The Commission's own summary lists five changed definitions and new provisions on data retention and deletion.

What it asks of people

The rule places its obligations on “operators,” not on children or parents directly: an operator of a child-directed site or app must obtain verifiable parental consent before collecting a persistent identifier used for anything beyond the rule's defined “internal operations,” and must give parents a clear, “just-in-time” notice of what is collected. For a companion or virtual-pet app aimed at or attractive to children, this 2013 baseline determines whether any tracking identifier the app or its ad partners use requires parental consent, independent of whatever the 2025 update later added.

Privacy and safeguards

The amendments added a new retention-and-deletion requirement: an operator may keep a child's personal information only as long as reasonably necessary for the purpose it was collected, then must delete it using reasonable measures. The rule also strengthened the Commission's oversight of self-regulatory safe harbor programs, the industry bodies that certify COPPA compliance. As the FTC's own rulemaking history page confirms, this 2013 action is listed separately from, and years before, the FTC's later 2025 amendments.

  • Does a given companion app's use of persistent identifiers fall within the 2013 rule's “internal operations” exception, or does it require consent?
  • Has a plug-in or ad network embedded in a child-directed app acknowledged “actual knowledge” of collecting data from children, the standard this rule set?
  • What specifically changed between this 2013 baseline and the FTC's 2025 COPPA update already on this site?

The 2013 amendments are the regulatory floor beneath every later COPPA action this site has covered, and the rule's own text, not a paraphrase, defines “persistent identifier” and “internal operations” for any company measuring its compliance today.

Sources & reading trail

Children's Online Privacy Protection Rule (Final Rule Amendments) ↗

Federal Register document giving the rule's publication date, 1 July 2013 effective date, and full statement of basis and purpose for the definitional changes.

Source published: 17 January 2013 · Retrieved: 16 September 2026

Children's Online Privacy Protection Rule (COPPA) rulemaking history ↗

FTC's own rulemaking history page (via Wayback Machine) listing the 2013 amendments and later 2025 amendments as separate, dated rulemakings.

Source published: Not established · Retrieved: 16 September 2026

Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.