COPPA & Children's Privacy in Mobile Games: A Publisher's Guide
Why COPPA Should Be On Every Game Studio's Radar
If your mobile game reaches the United States and appeals to anyone under 13, the Children's Online Privacy Protection Act (COPPA) almost certainly applies — even if children aren't your primary audience. Enforced by the U.S. Federal Trade Commission, COPPA governs how online services collect and use personal information from children under 13, with penalties reaching tens of millions of dollars in settlements against game and app makers.
For publishers who monetize with ads, COPPA isn't just a legal checkbox — it directly reshapes which ads you can serve and how much they earn.
Are You "Child-Directed" or "Mixed Audience"?
COPPA sorts apps into three buckets, and your obligations follow from which one you're in:
- Child-directed: targets children under 13 as the primary audience. Signals include cartoonish characters, simple gameplay, bright visuals, and marketing aimed at kids. COPPA then applies to all users by default.
- Mixed audience: child-directed in part, but children aren't the primary audience. You may use a neutral age screen and apply COPPA only to users who identify as under 13.
- General audience: not directed to children. COPPA is triggered only if you have actual knowledge you've collected data from a child under 13.
The FTC weighs the totality of these factors — you can't self-declare "general audience" just because it's the easier path. Honest classification is the foundation of everything that follows.
Verifiable Parental Consent
Before collecting personal information from a child under 13, COPPA requires verifiable parental consent (VPC). "Personal information" is broad: it includes persistent identifiers like advertising IDs used for behavioral advertising, geolocation, photos, and voice.
Acceptable VPC methods include a signed form, a small charge to a payment card, or a call with trained staff. Crucially, there is an exception: if you collect a persistent identifier solely to support internal operations — game state, frequency capping, or serving contextual (non-personalized) ads — you generally do not need VPC. That exception is why contextual advertising is the default monetization path for children's content.
The Impact on Ad Targeting & Revenue
For child-directed traffic the rule is simple: no personalized or behavioral advertising. You cannot build profiles, retarget, or use persistent identifiers for ad targeting tied to a child. What remains is contextual advertising — ads chosen from the app's content and general context rather than the individual.
- Contextual eCPMs are typically lower than personalized ones because advertisers can't target precise audiences.
- Recover value through direct deals, family-friendly brand campaigns, and well-placed rewarded video.
- Strong contextual signals — genre, content rating, placement — help advertisers bid confidently without user-level data.
Treating contextual as a deliberate strategy, not a limitation, separates studios that thrive in the kids' space from those that struggle.
Google Families Policy & Designed for Families
If you ship on Google Play and target children, you must follow the Families Policy and may opt into the Designed for Families program. Key requirements:
- Use only Google-certified ad SDKs approved for child-directed traffic.
- Flag child-directed content in AdMob/Ad Manager via tag for child-directed treatment (TFCD) and tag for users under the age of consent (TFUA), which force non-personalized ads.
- Avoid ad formats and content inappropriate for children, and meet content-rating and disclosure standards.
Misconfiguring these signals is one of the most common — and most costly — mistakes, because it can mean serving personalized ads to children without consent.
Interplay with GDPR-K in the EU
COPPA is U.S. law, but children's data is protected globally. Under the EU's GDPR, often called GDPR-K here, the age of digital consent ranges from 13 to 16 depending on the member state. Below that age, consent must come from a parent or guardian. Where COPPA fixes the line at 13, the EU does not — so a one-size-fits-all age gate will fail somewhere. Publishers operating internationally need region-aware age thresholds and the ability to enforce contextual-only ads wherever a user falls under the applicable age of consent.
How FlexyConsent Helps
Managing COPPA, GDPR-K, and Google's Families rules across markets is hard by hand. FlexyConsent — a Google-certified Consent Management Platform supporting IAB TCF 2.3 and Google Consent Mode v2 — centralizes consent and age signals so the right rules fire automatically by region. It can enforce contextual-only ad serving for under-age users, propagate the correct child-directed and under-age tags to your ad stack, and keep a tamper-evident audit trail of every consent decision across regions. This article is general guidance, not legal advice; consult qualified counsel for your situation.
Key Takeaways
- Classify honestly — child-directed, mixed audience, or general audience determines every obligation that follows.
- Collecting personal data (including ad IDs) from under-13 users requires verifiable parental consent; contextual-only ads are the consent-free path.
- Children's traffic means non-personalized ads — plan for contextual eCPMs and recover value through direct, family-friendly deals.
- Use region-aware age gates: COPPA's line is 13, but GDPR-K runs 13–16, and Google's Families Policy adds its own tagging and SDK rules.