1. I do want to have a competition on my child-directed website. Could I utilize the Rule’s “one-time contact” exclusion to prior parental consent?
Yes, in the event that you precisely design your contest. You could make use of the “one time contact” exception then only contact such children once when the contest ends to notify them if they have won or lost if you collect children’s online contact information, and only this information, to enter them in the contest, and. At that time, you need to delete the contact that is online you have got collected.
If, but, you expect to make contact with the children multiple time, you need to make use of the exception that is“multiple-contact” that you can also needs to gather a parent’s online email address and supply parents with direct notice of the information methods and a chance to decide down. Either way, the Rule forbids you against utilizing the children’s online contact information for almost any other function, and needs one to make sure the safety associated with the information, that will be especially important in the event that competition operates for almost any amount of time.
Should you want to collect any information from children online beyond online contact information regarding the contest entries – such as gathering a winner’s home target to mail a reward – you have to first offer moms and dads with direct notice and get verifiable parental permission, while you would for any other forms of private information collection beyond online contact information. You may ask the child to provide his parent’s online contact information and use that identifier to notify the parent if the child wins the contest if you do need to obtain a mailing address and wish to stay within the one-time exception. In your reward notification message towards the parent, you could ask the moms and dad to give a true home mailing target to deliver the award, or invite the moms and dad to call a cell phone number to produce the mailing information.
2. We have a website that is child-directed comes with an “Ask the Author” corner where young ones can e-mail concerns to highlighted writers. Do i must offer notice and get parental consent?
In the event that you just respond to the child’s question and then delete the child’s email (and don’t otherwise keep or keep the child’s information that is personal in virtually any type), then you belong to the Rule’s “one-time contact” exception and don’t need certainly to get parental consent.
3. We provide e-cards therefore the ability for young ones to forward components of interest for their buddies on my child-directed application. Could I benefit from one of several Rule’s exceptions to consent that is parental should I notify moms and dads and get consent with this activity?
The solution hinges on the method that you design your e-card or system that is forward-to-a-friend. Any system supplying any chance to expose information that is personal compared to the recipient’s email requires you to obtain verifiable consent through the sender’s moms and dad (not email plus), and will not fall within certainly one of COPPA’s restricted exceptions. Which means that then you must notify the
sender’s parent and obtain verifiable parental consent before collecting any personal information from the child if your e-card/forward-to-a-friend system permits personal information to be disclosed either in the “from” or “subject” lines, or in the body of the message.
To be able to make use of COPPA’s contact that is“one-time” for the e-cards, your on line type may just gather the recipient’s email (and, if desired, the sender or recipient’s first name); may very well not gather every other information that is personal either through the transmitter or perhaps the receiver, including persistent identifiers that monitor an individual with time and across sites. Moreover, to be able to satisfy this one-time contact exclusion, your e-card system should never permit the sender to enter her complete name, her e-mail address, or the recipient’s name that is full. Nor may you permit the transmitter to easily type messages in a choice of the line that is subject in any text areas of this e-card.
Finally, you ought to deliver the e-card straight away and automatically delete the recipient’s email right after giving. If you opt to wthhold the recipient’s email until some part of the near future (age.g., before the e-card is exposed because of the receiver, or perhaps you let the transmitter to point a night out together as time goes on if the e-card must be delivered), then this collection parallels the conditions for the Rule’s “multiple contact exception” for acquiring verifiable parental permission. In this scenario, you need to collect the sender’s parent’s e-mail target and supply notice and a chance to decide down to the sender’s parent prior to the e-card is delivered. See 1999 Statement of Basis and Purpose, 64 Fed. Reg. 59888, 59902 n. 222.
4. I wish to gather current email address, but hardly any other information that is personally identifying inside my website’s registration procedure. We plan to make use of the email limited to the objective of providing password reminders to users who sign up to my site. Do I first need to provide notice and get parental permission before gathering a child’s current email address?
Then you must provide notice to parents and the opportunity to opt out under the Rule’s multiple-contact exception if you plan to retain the child’s email address in retrievable form after the initial collection, to be used, for example, to email children reminders of their passwords. See 16 C.F.R. § 312.5(c)(4).
But, you might gather a child’s email to be used to authenticate the child for purposes of producing a password reminder without very first delivering parental notice and providing a moms and dad the chance to opt away in the event that you meet listed here conditions: (1) you don’t gather any private information through the son or daughter apart from the child’s email; (2) the child cannot reveal any private information on the internet site; and (3) you immediately and completely affect the email (e.g., through “hashing”) so that it can just only be used being a password reminder and should not be reconstructed into its original type or utilized to contact the kid. You need to explain this procedure in an obvious and manner that is conspicuous both during the point of collection plus in your site’s online privacy, which means your users and their moms and dads are informed regarding how the e-mail details is supposed to be used. This may avoid confusion by site site visitors among others whom may otherwise assume that the web site is improperly collecting and email that is retaining with no type of parental notice.
