COPPA and Under-13 Messaging: When It Applies to a School Platform
COPPA is invoked constantly in edtech procurement and understood rarely. It is a rule about operators collecting personal information online from children under 13, and a great deal of what a district communications platform does falls outside it entirely — while a small and specific part of what some platforms do falls squarely inside. Knowing which is which saves a lot of misdirected questionnaire time.
| Scenario | Who provides the data | COPPA analysis | What to ask the vendor |
|---|---|---|---|
| District pushes a roster of student names to the platform | The district | Not collection from a child; other frameworks govern | FERPA terms and the state statute, not COPPA |
| Guardian creates an account with their own details | An adult | Outside the rule | Nothing COPPA-specific |
| Under-13 student logs in and sends a message | The child | Squarely inside | What is collected, retained, and on whose consent |
| Under-13 student's device identifier is logged on a family app | The child, passively | Persistent identifiers count | Analytics SDKs, advertising identifiers, crash reporters |
| Student replies to a school SMS from a family phone | Ambiguous | Depends on the surface and what is retained | Whether inbound content is stored and for how long |
| Photo of a child uploaded by a teacher | An adult | Not collection from the child, but sensitive | Storage, sharing scope and deletion |
| Third-party advertising or analytics in a child-facing app | The child, via the third party | The operator is responsible for it | The full list of SDKs in any family or student app |
Column three is an orientation for scoping a procurement conversation, not a legal determination. The COPPA Rule has been amended and the FTC publishes current guidance and business compliance material; confirm the current requirements with counsel before relying on any of this.
The school consent route, and its conditions
The Federal Trade Commission's long-standing guidance has been that a school may provide consent on behalf of parents for an operator's collection of personal information from students, in the educational context, where the information is collected solely for the use and benefit of the school and for no other commercial purpose. That route is what makes most school edtech workable at all.
The conditions are what matter, and they are conditions on the vendor's conduct rather than on the district's paperwork:
- Solely for the school's use and benefit. Product improvement, benchmarking against other districts, and model training are the three places this quietly breaks. Read the use-limitation clause.
- No commercial purpose. No advertising, no selling, no family-facing upsell built on data collected from children.
- The school must have enough information to make the decision. That means the vendor tells the district what is collected, how it is used, and what the retention and deletion positions are — before, not after.
- Parents retain rights. A parent can ask to review what has been collected about their child and to have it deleted, routed through the school.
The FTC has amended the COPPA Rule and publishes updated business guidance; the direction of travel has been toward tighter limits on retention and on third-party disclosure. Confirm current requirements rather than relying on guidance summaries, including this one.
What to actually ask a communications vendor
Four questions resolve nearly all of it.
- “Does a student under 13 ever hold an account or a login on your platform?” If no, most of COPPA does not engage and the conversation moves to FERPA and your state statute. If yes, everything below matters.
- “List every third-party SDK, analytics tool and crash reporter in any app a child could use.” This is the question that finds real problems. Operators are responsible for what their embedded third parties collect, and advertising identifiers in a children's app are the classic finding.
- “What inbound content from students is retained, and for how long?” A reply from a student's phone is content, and content is retained by default in most systems.
- “Is there any advertising, recommendation or monetisation surface anywhere in the product?” Not “do you advertise to children” — any surface at all, including a free family tier with a paid upgrade.
Our answers: Kastr has no advertising, no recommendation system and no monetisation surface anywhere, and clause 9.4 makes that permanent rather than current. There is no push-notification infrastructure and no device-token registration, because we send SMS, email and voice only. We have no photo or video sharing and no attachment upload path at all, which removes an entire category of child-image handling risk by simply not having the feature. Students exist in the identity model as people with student roles, and the retention class for a student record is derived from that role at creation.
Where COPPA gets confused with things it is not
COPPA is not FERPA. Different statute, different regulator, different subject. FERPA is about education records held by the district. COPPA is about an operator collecting information online from a child. A vendor answering a FERPA question with a COPPA statement, or vice versa, has not understood the question.
COPPA is not a state student privacy statute. The SOPIPA-family statutes reach vendor conduct regardless of the child's age and regardless of who supplied the data. In most communications procurements those state statutes do more work than COPPA does.
“COPPA compliant” on a marketing page means very little on its own. The rule's requirements depend on what the operator collects and from whom. A platform that collects nothing from children is trivially compliant and should say so in those words rather than displaying a badge.
The under-13 question that actually bites in communications. It is not the student account. It is the family device. A parent-facing app installed on a shared household tablet, used by a nine-year-old, with an analytics SDK collecting persistent identifiers, is the scenario that has produced real enforcement interest in adjacent categories. If a vendor offers a family app, ask for the SDK list in writing. If they hesitate, that is the finding.
This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.
Questions people actually ask
Does COPPA apply to a school parent communication app?
Often not directly, because the data is supplied by the district and the accounts are held by adults. It engages where a child under 13 uses the service themselves, or where a child-facing surface collects persistent identifiers through embedded third parties. Scope the question by asking whether a child ever holds a login.
Can a school give consent on behalf of parents under COPPA?
FTC guidance has long supported a school consent route in the educational context, where information is collected solely for the use and benefit of the school and for no other commercial purpose. The conditions attach to the vendor's conduct, so read the use-limitation clause carefully and confirm current requirements with counsel.
What is the difference between COPPA and FERPA?
FERPA governs education records held by a district and the disclosure of information from them. COPPA governs operators collecting personal information online from children under 13. They overlap in edtech but answer different questions, and a vendor conflating them is a signal about the quality of the rest of their answers.
What should we ask about third-party SDKs in a family app?
Ask for the complete list, in writing, including analytics, crash reporting and any advertising identifiers, and ask what each collects. An operator is responsible for what embedded third parties do on a child-facing surface, and this is where the real findings are.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.