The U.S. Federal Trade Commission (FTC) issued a policy statement clarifying it will not pursue COPPA enforcement against websites and online services that collect, use, or share personal data solely to perform age verification, addressing industry concerns that age-checking could itself trigger COPPA liability. The FTC said the exemption applies only when providers give clear notice to parents/children, limit use of the data to confirming age, avoid retaining the information after verification, and share it only with third parties they are confident will maintain confidentiality; the agency also emphasized the need to employ reasonable security safeguards and take reasonable steps to ensure age-verification methods and vendors provide reasonably accurate results.
The FTC said it plans to review the COPPA Rule to further address age verification, following earlier agency remarks framing age verification as an important child-protection tool. Separately, Discord announced it is postponing and modifying a planned global age-verification policy after user backlash, delaying rollout to the second half of 2026 and adding options beyond government ID or video selfies (e.g., credit card verification), along with commitments to vendor transparency and a forthcoming technical explanation of its “age determination systems”; this reflects broader regulatory pressure for platforms to verify user ages but is distinct from the FTC’s COPPA enforcement posture.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Alongside the policy statement, the FTC said it plans to review the COPPA Rule to further address age verification issues.
The FTC issued a policy statement saying it will not bring COPPA enforcement actions against websites and online services that collect, use, and share personal data solely for age verification if specified conditions are met. Those conditions include limiting use to verification, deleting the data afterward, providing clear notice, restricting third-party disclosures, using reasonable security safeguards, and taking reasonable steps to ensure accuracy.
Roughly a month before the policy statement, FTC officials described age verification as an important child-protection technology and indicated the agency would issue guidance to reassure companies about COPPA compliance.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.