Date: Jun 22, 2017
The Federal Trade Commission (FTC) has updated its guidance on complying with Children's Online Privacy Protection Rule (COPPA Rule) "to reflect developments in the marketplace."
The revised plan also discusses two new methods for obtaining parental consent: knowledge-based authentication questions and facial recognition. These techniques may offer additional flexibility for businesses seeking to make providing consent easier for parents.
Makers of connected children's products know that their IoT devices are subject to the COPPA Rule; this isn't news. However, the FTC's updated guidance document offers a good opportunity to consider some practical ways to approach COPPA compliance. First, since technology firms and traditional product manufacturers often partner together to bring connected products to market, it is important to contractually establish which party is primarily responsible for COPPA compliance as the "operator." Second, COPPA compliance requirements relate to the product's capabilities and how it is used. Understanding what, how, and when data is collected, and how it is used - in other words, mapping the data flows - is essential, as it determines whether, and how, parental consent must be obtained. Third, that same data mapping exercise is crucial to establishing the appropriate set of security measures for the collected data.
The FTC's updated guidance sketches out COPPA basics, including the exceptions and different scenarios for different types of verifiable parental consent. This serves to reaffirm that while there are overarching principles of privacy and security, there is no one-size-fits-all approach to COPPA compliance for connected children's products any more than there is for websites or apps. That, in and of itself, is a helpful reminder.