From: Holland & Knight
Article by Steven B. Roosa and Peter Omerod
Steven B. Roosa is a Partner in our New York office.
The Federal Trade Commission (FTC) has recently responded to three applications seeking approval for new methods for obtaining parental consent under the Children’s Online Privacy Protection Rule.
In November, the Commission denied an application seeking approval to use “social-graph verification” to verify a parent’s identity; “social-graph verification” attempts to verify the identity of a parent by relying on a parent’s “friends” on a social network to verify a parent’s identity. Then in December, the Commission unanimously voted to approve using “knowledge-based authentication” to obtain parental consent, which verifies the parent’s identity through asking a series of “challenge questions” that only the parent is capable of answering. The third response, from late February, provides further details on the scope and operation of the approved “knowledge-based authentication” method.
The Updated COPPA Rule
The FTC’s Children’s Online Privacy Protection (COPPA) Rule requires that online sites and services that are directed at children under age 13 must obtain “verifiable parental consent” (VPC) before collecting personal information from a child. While the Rule enumerates several permissible methods for obtaining parental consent, the regulation also allows interested parties to submit new VPC methods to the Commission for approval.
Leave a Reply