How Parents Can Push Back on Data Brokers Collecting Kids’ Information
Children’s personal information can end up in marketing databases, app ecosystems, people-search records, and other brokered data flows long before a parent realizes it. That can include names, birthdays, device identifiers, location-related data, school-related details, or information gathered through websites and apps aimed at younger users.
The good news is that parents and guardians are not starting from zero. Federal rules under COPPA give families important rights when a child under 13 is involved, and some state laws add extra tools for data broker removal and consumer privacy requests. These laws do not stop every form of collection, and they do not promise complete privacy. But they do create practical ways to ask questions, revoke consent, and request deletion.
This guide explains the legal basics in plain English and shows how to use them in a practical workflow.
Understanding COPPA Regulations for Minors' Data
COPPA, the Children’s Online Privacy Protection Act, is a U.S. law focused on children under 13. It applies to operators of websites and online services directed to children, and also to operators that have actual knowledge they are collecting personal information from a child under 13.
In practical terms, COPPA matters because it limits what covered services can do before collecting, using, or disclosing a child’s personal information. Federal guidance and the rule text emphasize a core requirement: verifiable parental consent must come first in many situations.
For parents, the most useful COPPA rights are these.
- You should be able to receive notice about the operator’s data practices.
- You can review personal information collected from your child.
- You can ask for deletion of that information.
- You can refuse further collection or use in many cases.
That makes COPPA more than a policy statement. It creates a process you can use when a child-focused app, game, website, or online service has collected data tied to your child.
A simple way to spot a COPPA-related request is to look for a privacy policy section about children, parental rights, or verifiable parental consent. FTC compliance guidance commonly tells businesses to post a COPPA-compliant privacy policy, notify parents directly, and obtain consent before collection. If a service says it is directed to children or has a children’s privacy section, that is often your starting point for a deletion or access request.
It also helps to understand what COPPA does not do. It does not automatically erase a child’s information from every database connected to the internet. It does not cover every teen privacy issue. And it does not guarantee that a third-party data broker never received information in the first place. Still, it gives parents a strong basis to ask a covered operator what was collected, how it was shared, and how to delete it.
Enforcement matters here too. The FTC enforces COPPA, and state attorneys general can also take action. That gives the law more weight than a voluntary promise in a privacy notice. If a company directed to children ignores parental rights, there is a legal framework behind your request.
When you contact a service under COPPA, keep your request narrow and specific. Ask for:
- Confirmation of whether the service collected personal information from your child
- A copy or description of the categories collected
- The names or categories of third parties that received the data, if disclosed in the policy
- Deletion of the child’s personal information
- Revocation of any prior parental consent, if applicable
Save screenshots, emails, and submission confirmations. If you need to follow up later, documentation makes the process easier.
State-Specific Data Broker Laws for Minors' Protection
COPPA is the federal baseline for younger children, but state laws can add another layer, especially when data brokers are involved. This matters because a parent may not be dealing only with the original app or website. Information can move into broker systems that aggregate, categorize, and resell data.
California is especially important to watch. The state has a data broker registration framework, and recent developments under the Delete Act are designed to strengthen deletion and opt-out mechanisms. Public summaries of the law note that registered brokers must disclose certain practices and that California is building a more centralized deletion request process. For families, that means state-level tools may become more usable than chasing dozens of separate companies one by one.
Some state laws also pay special attention to minors’ data or sensitive categories that can include minors’ information. Even when the exact process differs by state, the practical takeaway is the same: state registration and privacy laws can help you identify who is handling data and where to send requests.
Texas is another example worth monitoring. Public legal summaries describe rules requiring parental consent for some data collection involving minors on covered social platforms. The exact scope and legal status of state rules can change, so parents should verify current enforcement details before relying on a specific state process. Still, these laws show a broader trend: states are adding privacy protections for minors that can go beyond COPPA’s under-13 framework.
Use this quick comparison to understand how the two layers differ.
| Legal layer | Main focus | Who it helps most | Practical use for parents |
|---|---|---|---|
| COPPA | Collection from children under 13 by covered online services | Parents of younger children | Request notice, access, consent records, and deletion |
| State data broker laws | Registration, disclosure, deletion, or opt-out duties for brokers | Families trying to limit downstream sharing | Find brokers, use state-listed rights, submit deletion requests |
| State minors’ privacy laws | Additional rules for teens or covered platforms | Parents of older minors, depending on state | Check whether parental consent or extra opt-out rights apply |
A practical habit is to check whether your state has:
- A data broker registry
- A consumer privacy law with deletion rights
- Special rules for minors or social platforms
- A state attorney general complaint process
If your child’s information appears to have spread beyond the original service, state data broker laws may be the most useful path for data broker removal. They will not cover every broker in every state, but they can help you identify registered entities and use a formal deletion route instead of relying only on customer support forms.
Practical Opt-Out Processes for Minors' Data
The most effective approach is usually a layered one. Start with the service that collected the information, then move outward to brokers and state-level request channels.
Here is a practical sequence parents can follow.
- Identify where the collection likely started.
Look at apps, games, school-adjacent services, social platforms, contest forms, and family account signups. Review the service’s privacy policy for a children’s privacy section, parental rights language, or a contact method for privacy requests.
- Submit a COPPA-based access or deletion request when the child is under 13.
Ask whether the company collected your child’s personal information, what categories were collected, and how to delete it. If the service requires identity verification or proof of parental authority, follow that process carefully.
- Review the policy for sharing disclosures.
Many privacy policies describe whether data is shared with service providers, advertising partners, analytics vendors, or other third parties. This will not always name every broker, but it can help you map where to send follow-up requests.
- Check state broker registries or privacy agency resources.
If your state provides a registry or broker list, search for companies connected to people-search, marketing, audience data, location data, or consumer profiling. If California tools apply to you, watch for the state’s centralized deletion mechanisms as they become available.
- Send direct deletion or opt-out requests to brokers.
Use the broker’s privacy request form if available. If the request concerns a minor, say so clearly and ask what documentation they require to verify parental authority. Keep copies of everything you submit.
- Follow up and track responses.
Some companies reply quickly. Others may ask for more information or route you through a general privacy portal. A simple tracking sheet can help you avoid duplicate work.
Use this checklist as you go.
- Save the child-related account names, usernames, and email addresses involved
- Take screenshots of privacy policy language and request forms
- Record the date each request was submitted
- Note any ticket number or confirmation email
- Track whether the company confirmed deletion, partial deletion, or only an opt-out
- Calendar a follow-up if no response arrives within the company’s stated timeframe
A few practical cautions can save time.
| Mistake | Why it causes problems | Better approach |
|---|---|---|
| Sending vague requests | The company may not know which account or child record you mean | Include identifiers tied to the account, but share only what is necessary |
| Assuming one request reaches every partner | Many brokers and platforms run separate systems | Treat each company or registry process as its own request path |
| Expecting permanent internet-wide deletion | The law does not promise that outcome | Focus on deletion from the covered service or broker and reduce future collection |
| Ignoring account settings | Collection may continue after a deletion request | Review privacy settings, ad settings, and permissions after the request |
It also helps to reduce future exposure. That includes limiting unnecessary profile fields, turning off location access when not needed, using separate family email addresses for child-related signups, and reviewing whether a service really needs a child’s real birthday or full name.
This is also where broader account security habits support privacy. A password manager basics approach can help families use unique passwords for child-related accounts, and a two factor authentication guide can help secure parent accounts that control permissions and deletion requests. Those steps do not replace legal opt-outs, but they reduce the chance that someone else changes settings or reopens data-sharing pathways.
If you are also thinking about identity theft protection, remember that prevention for minors often starts with reducing unnecessary data collection. In some cases, families may also consider a credit freeze guide for a child, where state law and credit bureau procedures allow it. That is a separate process from how to remove personal information online, but both can be part of a broader family privacy plan.
Conclusion
Parents and guardians cannot control every path a child’s information may take online, but they do have more leverage than many people realize. COPPA gives families a practical way to question, review, and delete data collected from children under 13 by covered services. State data broker laws can add another route for finding brokers and submitting opt-out or deletion requests.
The most realistic approach is a layered one.
- Start with the original service
- Use COPPA rights where they apply
- Check state broker registries and privacy laws
- Submit direct deletion requests to brokers
- Review settings regularly to limit new collection
That combination will not guarantee complete prevention of data collection, and it should not be framed as permanent data removal from the internet. But it can meaningfully reduce exposure and give families a repeatable process for protecting minors’ personal information over time.