FTC Cracks Down on COPPA: Disney and Apitor Settle

Kids’ privacy on the internet has always been a serious topic. But lately, the FTC has been treating it like a “no running by the pool” signexcept the pool is data, and the running is targeted advertising, location tracking, and “oops, our vendor did that.”

Two enforcement actionsone involving Disney’s kid-directed videos on YouTube, the other involving a robot toy maker’s appshow what the FTC is emphasizing right now: COPPA compliance isn’t just about what you collect. It’s also about what gets collected because of you, including through platforms and third-party software.

This article breaks down what happened in the Disney and Apitor settlements, why these cases matter to anyone who builds, markets, or monetizes kid-friendly content, and what “reasonable steps” actually look like when you’re trying to keep children’s data out of the wrong hands (and out of the FTC’s crosshairs).

What COPPA Is (and Why the FTC Keeps a Close Eye on It)

COPPAthe Children’s Online Privacy Protection Act and the FTC’s implementing COPPA Ruleputs parents in control when online services collect personal information from kids under 13. In practical terms, if you operate a website, app, game, connected toy, or even monetized content that’s directed to children (or you have actual knowledge you’re collecting from kids), you generally must:

  • Provide clear notice of what you collect and why.
  • Give parents direct notice (not the “we buried it in the footer” variety).
  • Get verifiable parental consent before collecting, using, or disclosing kids’ personal information (with limited exceptions).
  • Let parents review and delete data.
  • Keep kids’ data secure and retain it only as long as necessary.

“Personal information” under COPPA isn’t limited to a child’s name or email. It can include things like persistent identifiers used to recognize a user over time (think cookies and device IDs), and precise geolocation data. That’s why kid-directed services can’t treat “analytics” or “ad tech” as harmless background noiseit may be the main event.

The Disney Settlement: When “Made for Kids” Isn’t Just a Checkbox

The FTC’s core allegation

According to the FTC and DOJ, Disney settled allegations that it enabled the unlawful collection of children’s personal data by failing to properly label some kid-directed videos uploaded to YouTube as “Made for Kids” (MFK). When videos that should be designated MFK are mislabeled, YouTube may collect personal data from viewers under 13 and use it for targeted advertisingwithout providing notice to parents or obtaining verifiable parental consent.

The point wasn’t “Disney built YouTube.” The point was: if you publish kid-directed content in a way that allows children’s data to be collected for ad targeting, COPPA can still come knocking on your door.

What Disney agreed to do

The final order requires Disney to pay a $10 million civil penalty and to comply with the COPPA Rule going forward. Importantly, Disney must also establish and implement a program to review whether videos posted to YouTube should be designated MFKunless YouTube implements age assurance technology that can reliably determine user age (or stops allowing creators to label videos as MFK).

That last part is a flashing neon sign: the FTC is thinking about the future of kids’ privacy in a world where “age assurance” and “age estimation” tools may shift how platforms manage child-directed experiences. Even if your business is not building those tools, you may be expected to adapt to them.

Why this case is bigger than Disney

Disney has the kind of brand recognition that makes regulators pay attention. But the legal lesson isn’t “famous companies get fined.” It’s this:

  • Platforms don’t magically absorb your COPPA obligations. If your kid-directed content causes personal information to be collected on your behalf (including through ad tech), you can be treated as an operator under COPPA.
  • Operational settings matter. A default configuration, a channel-level setting, or an internal workflow that “usually works” can become a compliance failure if it routinely misclassifies child-directed content.
  • Monetization choices change the risk profile. Targeted ads + kids = the regulatory equivalent of storing fireworks next to a barbecue grill.

In other words: COPPA compliance is not a policy. It’s a process. And the FTC is showing it expects that process to be deliberate, repeatable, and documented.

The Apitor Settlement: The “Our SDK Did It” Defense Didn’t Fly

What the FTC alleged

Apitor Technology, a robot toy maker, settled FTC allegations that its app allowed a third party to collect children’s precise geolocation information without parental notice or consent. The FTC’s press release describes a scenario many developers will recognize (and immediately dread): the app integrated a third-party software development kit (SDK) that collected location data and transmitted it to the SDK provider’s serverswithout parents being properly informed and without verifiable parental consent.

The FTC highlighted that Android users were required to enable location sharing to use the app and connect the toy, and that the app began collecting and sharing precise location data after downloadbefore a meaningful COPPA-compliant consent flow happened.

The settlement terms in plain English

Under the proposed order (later filed in federal court), Apitor faced a $500,000 civil penalty that was suspended based on inability to pay, with a condition: the company must pay the full amount if it is found to have misrepresented its financial condition. Apitor also must delete personal information collected in violation of COPPA unless it notifies parents and obtains consent, and it must ensure that any third-party software it uses complies with COPPA.

This is one of the most important takeaways from Apitor: the FTC is telling app developers and connected-device companies that vendor risk is your risk. If an SDK collects children’s data in your product, regulators may treat it as collection “on your behalf.”

Why the FTC Is Turning the Volume Up on COPPA Enforcement

These cases fit a broader pattern: the FTC has been signaling that children’s privacy is a priority, and that enforcement will focus on modern data flowsadvertising ecosystems, analytics, embedded SDKs, and cross-border data transfers.

Several themes jump out:

1) “Kid-directed” isn’t just for kids’ apps

COPPA can apply even when you’re on a general-audience platform, especially if your content is directed to children and personal information is collected for commercial purposes. A kids’ cartoon uploaded to a mainstream platform can trigger COPPA obligations just as surely as a standalone kids’ game.

2) Persistent identifiers and geolocation are “personal information” in practice

Businesses sometimes treat cookies, device IDs, and location data as “technical telemetry.” Under COPPA, those data types can be regulated personal informationparticularly when used for advertising or tracking.

3) “We didn’t mean to” is not a compliance strategy

Neither Disney nor Apitor needed a villain twirling a mustache in a server room. COPPA enforcement often centers on design choices, defaults, labeling workflows, and third-party integrations. The FTC is effectively saying: if your product or content predictably results in unlawful data collection, you can’t hide behind intent.

What These Settlements Teach Businesses (Even If You’re Not Disney)

If you create kid-directed content, build apps that appeal to children, sell connected toys, or run ad-supported experiences where children are a foreseeable audience, you should treat these cases as a checklist of what regulators will examine.

Lesson A: Labeling and audience designation must be a system, not a hope

If you publish content on platforms that offer kid-designation tools (like “Made for Kids”), build a formal workflow:

  • Pre-publish review: A clear internal rule for what counts as child-directed content.
  • Two-person checks: Not because your team is incompetentbecause humans are busy and “upload day” is chaos.
  • Documented exceptions: If something is borderline, record why you chose a designation and what factors you used.
  • Periodic audits: Sample a batch of uploads monthly/quarterly to confirm classification consistency.

Think of it like food labeling. If you can’t reliably label the allergens, you don’t get to be surprised when the regulators show up.

Lesson B: SDKs and vendors are not “plug-and-play” in kid contexts

If your app is even arguably kid-directed (or mixed audience with a significant under-13 user base), you need a third-party software intake process that asks:

  • What data does this SDK collect (identifiers, location, microphone, contacts, ad IDs)?
  • When does it start collectingon install, on first launch, after login, after consent?
  • Where does it send the data (and for what purposes)?
  • Can we disable certain data collection features or run it in “kid-safe” mode?
  • Do we have contractual assurances about COPPA compliance and data use limits?

In kid contexts, “free analytics” can be the most expensive line item you never budgeted for.

Lesson C: Don’t collect first and ask later

A common COPPA failure pattern is starting data collection before consent is obtained, then trying to “fix it” downstream. The FTC’s posture suggests that if personal information is collected before verifiable parental consent, you may already be in violationespecially for geolocation and ad-targeting identifiers.

A Practical COPPA Compliance Playbook (Without the Legalese Hangover)

Here’s a practical, engineering-friendly approach that aligns with what the FTC has been emphasizing in guidance and enforcement:

1) Classify your experience honestly

Decide whether your site/service/content is:

  • Directed to children (then treat users as children by default), or
  • Mixed audience (limited ability to age-screen if done correctly), or
  • General audience (but watch for “actual knowledge” triggers).

2) Map every data flow

Create a data inventory that includes first-party collection and third-party collection (ad tech, analytics, crash reporting, push notification services, embedded maps, social logins). For each data element, document: what it is, why it’s collected, where it goes, retention, and deletion triggers.

3) Build consent gating into the product, not the privacy policy

For kid-directed experiences, design so that personal information collection is blocked until appropriate parental consent is obtained (unless a narrow exception applies). This can involve:

  • Disabling ad IDs and targeted ad signals
  • Restricting analytics to aggregated or internal-operations use (where appropriate)
  • Turning off precise location by default
  • Using “privacy by default” configurations for SDKs

4) Create a deletion and parent-access workflow that actually works

If a parent requests deletion, your systems should be able to find and delete the child’s dataacross your databases and across vendor systems where feasible. If you can’t do that, you’re essentially collecting data you can’t responsibly manage.

5) Train the humans who press “publish” and “ship”

Many COPPA problems come from marketing and content workflows, not malicious coding. Train teams on:

  • How to recognize child-directed content
  • How ad settings work on platforms
  • Why “just one little tracking pixel” isn’t little in a kids’ context

What Parents (and Regular Humans) Should Take Away

These cases aren’t only business headlines. They also matter for families because they reinforce a simple concept: kids’ data should not be collected for targeted advertising or shared through opaque tech stacks without parents’ knowledge and control.

If you’re a parent, practical steps include:

  • Check device-level location permissions for children’s apps.
  • Be cautious with connected toys that require companion apps.
  • Use platform settings that limit ad personalization where available.
  • When in doubt, choose experiences that do not rely on ad-driven monetization for kids.

What’s Next: COPPA’s “Old” Law, New Problems, and Emerging Tech

COPPA has been around for decades, but the data economy around kids has evolved at warp speed. Today’s compliance challenges include:

  • Age assurance technologies: The Disney order’s reference to age assurance suggests regulators are anticipating broader adoption of tools that determine age or age rangeraising new questions about accuracy, privacy, and bias.
  • Connected devices and toys: Companion apps can quietly become data collection hubs.
  • Global vendor stacks: A single SDK can route data internationally, complicating oversight and risk assessment.
  • Advertising infrastructure: Even “basic” ad delivery can involve persistent identifiers unless explicitly controlled.

For businesses, the winning approach is not “do the minimum.” It’s “build kid-safe defaults that are hard to break.” The FTC’s recent actions suggest it will reward proactive, documented complianceand penalize “we thought the platform handled it” thinking.

Real-World Experiences: What COPPA Compliance Actually Feels Like (500+ Words)

Let’s talk about the part nobody puts in the glossy compliance deck: the lived experience of trying to make COPPA work in real products and real content pipelines. These are common patterns teams report when they take kids’ privacy seriouslyoften after a near-miss, an internal audit, or a panicked email that begins, “Hey… why is our kids’ app requesting precise location?”

Experience #1: The “labeling gap” that shows up at 11:58 PM

Content teams usually have a rhythm: ideate, produce, edit, upload, promote. The compliance part can feel like a speed bumpuntil someone realizes the speed bump is actually a cliff. A typical moment: a channel manager schedules a batch upload of animated shorts, assumes the channel’s default setting is enough, and hits publish. Days later, someone notices ads behaving oddly or sees a platform warning about child-directed designation. Suddenly, every upload needs to be reviewed retroactively, and the team is scrambling to figure out which videos should have been marked “Made for Kids.”

The fix that works in practice is boringbut effective: a standardized pre-publish checklist, a second set of eyes for child-directed content, and a simple internal rubric (“Does it feature child-oriented characters? Is the story designed for under-13 viewers? Are the visuals and themes kid-centric?”). Teams that do this consistently report fewer late-night fire drills and fewer “we thought it was covered” misunderstandings.

Experience #2: The SDK surprise (a.k.a. “Why is this library talking to the internet?”)

Engineering teams often inherit SDKs the way you inherit a mystery box from your attic: “We’re pretty sure this helps with notifications… maybe analytics… could be both.” In kid-focused apps, that uncertainty is dangerous. A common discovery during a privacy review is that an SDK begins transmitting device identifiers, IP addresses, or location-related signals immediately on app launchlong before any consent flow appears. Nobody intended it; it’s just how the SDK is designed.

Teams that mature their approach start doing “SDK intake” like they do security reviews: they document what the SDK collects, test it under different settings, disable anything non-essential, and require vendors to provide kid-safe configurations. They also treat “precise location” as a high-risk feature that must be justified with a clear product need, not a vague “it improves the experience” statement.

Experience #3: The parental consent flow that looks great… until you try to use it

Consent experiences can become performative: a beautiful UI, a lot of words, and a button that says “Continue.” But COPPA compliance is less about aesthetics and more about mechanics. Real-world pain points include parents not receiving consent emails, consent tokens not syncing across devices, or data being collected “temporarily” before consent is verified (which can become a legal problem, not a technical footnote).

The teams that succeed treat consent like a gate in the architecture: if consent is not verified, the app should operate in a restricted mode that avoids collecting personal information. That design mindset“no consent, no collection”reduces the chance of accidental violations and makes audits far less terrifying.

Experience #4: The culture shiftmarketing and product finally speak the same language

One of the most underrated parts of COPPA compliance is internal alignment. Marketing wants growth. Product wants engagement. Compliance wants safety. The best organizations stop treating these as competing goals and start treating kids’ privacy as a product quality metriclike uptime or crash rate. When that happens, people stop asking “Do we have to do this?” and start asking “How do we do this without compromising the experience?”

And yes, it’s still messy. But it’s the kind of messy that keeps kids saferand keeps your company out of the headline that starts with, “Regulators allege…”

Conclusion

The Disney and Apitor settlements show a COPPA reality check: child privacy compliance is not limited to “kids’ websites” and it’s not solved by a privacy policy. The FTC is focusing on the real mechanics of modern data collectionplatform settings, ad monetization, SDK behavior, and location permissions. If children are a likely audience, your systems must prevent unlawful collection by design, including through third parties and platforms you rely on.

If there’s one takeaway that fits on a sticky note: In COPPA land, partial compliance is basically noncomplianceespecially when data starts flowing before consent.


This site uses cookies to offer you a better browsing experience. By browsing this website, you agree to our use of cookies.