The under-13 line is the whole federal trigger
16 CFR 312.2 defines the covered population precisely: “Child means an individual under the age of 13.” That age is statutory, at 15 U.S.C. 6501(1), and the FTC cannot move it by rulemaking. The Commission’s April 22, 2025 final rule (effective June 23, 2025, with a full compliance date of April 22, 2026) expanded the definitions of personal information, added consent methods, and tightened retention and security duties — but it expressly preserved the under-13 threshold.
The practical consequence for a high school recruiting platform is narrow and often misunderstood: COPPA is not a “minors” statute. A 16-year-old is outside it. The exposure is concentrated entirely in the youngest sliver of the audience — and in whether the operator ever learns someone is in that sliver.
Actual knowledge: how a general-audience site becomes covered
The FTC states that the Rule “applies to operators of sites and online services geared toward general audiences when they have ‘actual knowledge’ they are collecting information from children under 13.” The agency goes further on how that knowledge arrives: an operator “who asks for a date of birth on a site’s registration page has actual knowledge as defined by COPPA if a user responds with a year that suggests they’re under 13,” and knowledge may equally arise from age-identifying questions such as “What grade are you in?” or questions about school type. It can also arrive entirely outside the signup form — a parent who emails the operator about their child’s account has just supplied it.
One precision matters here and is routinely lost: knowledge attaches to the answer that indicates under-13 status, not to the act of asking. A grade or graduation-year answer from an actual high school athlete will usually negate under-13 status rather than establish it. The trigger case is concrete rather than theoretical: a 12-year-old seventh grader who completes a grade field has just given the operator actual knowledge, and full COPPA duties attach to that account.
A viewable athlete profile is a “disclosure” — and that removes the cheap consent methods
16 CFR 312.2 defines disclosure to include “[m]aking personal information collected by an operator from a child publicly available in identifiable form by any means, including… a public posting through the internet, or through a personal home page or screen posted on a website.” An athlete profile is squarely that. Release to verified college coaches would also implicate the third-party-release prong.
This is not a labelling exercise. 16 CFR 312.5(b)(2)(viii)–(ix) make the email-plus and (newly added) text-plus consent methods available only to an operator that does not disclose children’s personal information — the Commission’s reasoning being that email and text carry a higher risk of a child impersonating a parent. A platform that publishes minor profiles therefore cannot use either one.
What is left
The methods still available under 16 CFR 312.5(b)(2)(i)–(vii) are all high-assurance:
- a print-and-send signed consent form;
- a credit card, debit card, or other online payment transaction that provides notification of each discrete transaction;
- a toll-free telephone call to trained personnel;
- a video conference with trained personnel;
- a government-issued ID checked against a database, with prompt deletion of the ID;
- knowledge-based authentication using dynamic multiple-choice questions;
- a photo ID matched to a second photo using facial recognition.
Two footnotes. Knowledge-based authentication and the facial-match method were codified directly into the Rule in 2025 and no longer require separate case-by-case Commission approval — the FTC’s FAQ still carries legacy language suggesting otherwise, so cite the regulation rather than the FAQ on method availability. And the list is not closed: 16 CFR 312.12 allows petitions for new methods.
“The parent made the account” is not verifiable parental consent
This is the single most common design assumption we have seen, and it does not hold. The FTC is explicit: “The mere entry of an app store account number or password, for example, without other indicia of reliability (e.g., knowledge-based authentication questions or verification of government identification), does not provide sufficient assurance that the person entering the account or password information is the parent, and not the child.” Structurally, “someone asserted they are the parent and made an account” simply is not among the methods enumerated at 16 CFR 312.5(b)(2).
The correct statement is narrow, and we keep it narrow deliberately: an account credential is insufficient standing alone. It can form part of a compliant flow when coupled with other indicia of reliability and accurate direct notice. A broader claim — that a parent-fills-the-form model can never escape the Rule where the child’s data is published — was proposed during our research and did not survive verification, so we do not assert it.
Photos, video, and audio are themselves personal information
The FTC treats “photos, videos, and audio recordings that contain a child’s image or voice” as personal information, and requires a covered operator to either prescreen and delete such media from children’s submissions, or give parents notice and obtain consent before permitting the upload. Embedded geolocation metadata is separately covered: the operator “must also delete any other personal information, for example, geolocation metadata, contained in the photos prior to posting them.”
For a highlight-reel product this is the operative clause, not a footnote. One caveat from our verification: prescreen-and-delete only works if the deletion is genuinely immediate — mere retention is itself collection under the amended Rule.
What the 2025 amendments added
Two changes bear directly on age-verification and ID-collection design.
First, the amended 16 CFR 312.2 adds biometric identifiers that can be used for automated recognition — fingerprints, voiceprints, gait patterns, facial templates — and expands identifiers to include state ID card, birth certificate, and passport numbers. The narrowing detail matters: the biometric category covers derived templates and faceprints, not raw images; the Commission struck broader “data derived from… facial data” language as overbroad. So this bites a recruiting platform only if it applies face recognition, auto-tagging, or automated player identification to uploaded media. Raw photos and video were already covered under the older clause.
Second, “online contact information” now includes a parent’s mobile number used solely to send texts in connection with obtaining consent, supporting the new text-plus method at 16 CFR 312.5(b)(2)(ix). As noted above, that method is available only to non-disclosing operators — so a platform that publishes minor profiles cannot use it.
Mixed audience, and the neutral age screen
The 2025 amendments codified “mixed audience website or online service” at 16 CFR 312.2: a service directed to children but not targeting them as its primary audience, which does not collect personal information from any visitor — other than for the limited purposes set out in 312.5(c) — before collecting age information or otherwise determining whether the visitor is a child. Any collection of age information “must be done in a neutral manner that does not default to a set age or encourage visitors to falsify age information.”
FTC guidance translates that into concrete design: ask “How old are you?” with a free-entry field, not “Are you over 12?” as a checkbox, and do not advertise that users 13 and over get extra features. Two qualifications travel with it. The 312.5(c) carve-out permits limited pre-screen collection — for example, to obtain parental consent, or persistent identifiers used only for internal operations. And mixed-audience status does not remove a service’s “directed to children” classification; it only permits the operator to apply COPPA duties selectively to visitors identified as under 13.
For a genuinely general-audience site, by contrast, the FTC states that the Rule “doesn’t require operators of sites or services directed to general audiences to investigate the ages of its users,” which makes age gating an elective tradeoff. That safe harbor disappears if the service is classified mixed audience.
Which classification a recruiting site falls into is unsettled
We will not tell you the answer, because no source we verified provides one. Classification runs on the totality-of-circumstances test in 16 CFR 312.2, and a stated “13+” policy does not by itself resolve it. Given sport-based subject matter that also appeals to middle schoolers, mixed-audience classification is plausible, and treating it as the conservative default pending advice of counsel is the defensible posture. That is a design judgment, not a legal conclusion.
The February 2026 FTC age-verification policy statement
On February 25, 2026 the Commission issued an “Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology” (2–0 vote) permitting general- and mixed-audience operators to collect personal information solely to determine a user’s age without first obtaining verifiable parental consent, conditioned on six practices: use the data only to determine age; do not retain it longer than necessary and delete it promptly; disclose it only to third parties capable of maintaining confidentiality, security, and integrity, secured by written assurances; give clear notice to parents and children; apply reasonable security safeguards; and take reasonable steps to confirm the method is likely to produce reasonably accurate age results.
Three limits are load-bearing and we state them with the statement itself: it “does not create any substantive rights or entitlements” and is not binding law; it is temporary, lasting only until the FTC finalizes age-verification rule amendments or withdraws it; and it applies only to general- and mixed-audience operators — the FTC says child-directed sites should not collect age information at all but should assume their audience is under 13. This is prosecutorial discretion, not a safe harbor.
A sourcing note in the interest of the same honesty: ftc.gov returned automated-fetch blocks during our verification, and the issuance date was confirmed through independent law-firm analyses rather than by loading the FTC page directly. A competing claim dating the statement February 13 was refuted. We record this item at lower confidence than the rest of this page.
COPPA 2.0 has not been enacted
COPPA 2.0 would raise the covered age to under 17 (Senate version) or create a 14 / 14–17 two-tier structure (House version). It passed the Senate unanimously on March 6, 2026 but had not been reconciled or enacted as of mid-2026. Enactment would move the entire analysis from the under-13 line to essentially the whole user base of a high school recruiting platform — which is a reason to watch it, not a reason to describe it as law.
What is still unsettled
- Classification. Whether a youth recruiting site is general audience, mixed audience, or child-directed under the 16 CFR 312.2 totality test. This determines whether neutral age screening is mandatory and whether the February 2026 forbearance is even available.
- The COPPA/FERPA boundary. The FTC declined to finalize its proposed ed-tech and school-authorization amendments, deferring to a possible Department of Education FERPA rulemaking that has not been finalized. There is therefore no COPPA-side school-consent safe harbor. The Commission’s longstanding informal FAQ guidance permitting schools to act as the parent’s agent in limited school-purpose ed-tech contexts was not codified — but also not abolished. In any event a commercial recruiting platform does not operate under school authorization and would need verifiable parental consent directly for any under-13 user. See FERPA, transcripts, and third-party recruiting platforms.
Related
- Can a 16-year-old agree to Terms of Service? — the separate, non-COPPA reason the parent should hold the account.
- Florida HB 3 and Texas SCOPE: do they apply to a recruiting site? — state law reaches well past the under-13 line.
- What a youth athlete platform should collect — and what it shouldn’t.
Before you rely on this
This page describes publicly available law and agency guidance as we read it on the verification date shown above. It is not legal advice, and it is not a compliance certification. Several of the items below sit on interlocutory postures that can flip without notice. Confirm anything you act on with your own counsel, and with your state high school athletic association where eligibility is involved.