COPPA and children’s privacy
Websites for children need particular care. COPPA protects children under 13 in the United States, and choosing an analytics tool is only one part of an operator’s responsibilities.
When COPPA applies
COPPA covers operators of child-directed websites and online services that collect personal information, as well as other operators with actual knowledge that they collect it from children under 13. The FTC amended the rule in 2025; review its current guidance rather than relying on an older compliance summary. FTC COPPA guidance.
Analytics and internal operations
Persistent identifiers, including IP addresses, can be personal information under COPPA. A limited exception permits collection of a persistent identifier, without other personal information, solely to support internal operations. Its conditions restrict uses such as contacting a person, behavioural advertising, and building a profile. It is not a general exemption for analytics providers. FTC explanation of the internal-operations exception.
Assess your Fathom implementation
Fathom’s visitor analytics does not use tracking cookies. Its collection process still handles request information, and detected bots are handled separately from ordinary pageviews. Review the data journey and DPA for processing and retention details.
Before adding analytics to a child-directed service, establish which information your pages and events send, whether an exception applies, and what notices, consent, security, and retention measures your service needs. Avoid personal details in URLs, event names, and integrations.
Contact us for processing details to support that assessment. This guide does not certify a particular child-directed deployment or replace your review of the current COPPA requirements.
These guides explain privacy requirements and how they relate to Fathom. They are general information, not legal advice. Your obligations depend on your website, its visitors, and how you use analytics. Contact us for information about your setup.