Most parents don't realize they have legal rights when it comes to the data companies collect about their children. Federal — and in many cases state — law in the United States grants parents specific, meaningful rights, and understanding them can change how you approach digital privacy for your family. This guide covers the U.S. legal framework in plain language; it's general information to help you understand your options, not a substitute for legal advice about your specific situation.

COPPA: The Children's Online Privacy Protection Act

COPPA is a federal law enforced by the Federal Trade Commission that applies to websites and online services either directed at children under 13 or that have actual knowledge they're collecting data from a child under 13. Under COPPA, covered companies must obtain verifiable parental consent before collecting personal information from a child, and must give parents the ability to review the information collected, request its deletion, and refuse to allow further collection. If a company covered by COPPA is collecting data on your under-13 child without your consent, you have grounds to demand deletion and, if needed, file a complaint with the FTC.

One important limit worth understanding up front: COPPA's core protections apply specifically to children under 13. For teens 13 and older, COPPA doesn't directly apply — which is exactly why the state laws below, and a platform's own privacy policy and terms of service, become more relevant as your child moves through the teen years.

State Laws That Go Further

A growing number of states have passed their own children's and teen online privacy laws that extend protections beyond COPPA's under-13 scope or add requirements on top of it — California's Age-Appropriate Design Code framework is one widely-referenced example, and several other states have since introduced or passed comparable legislation. These laws change fairly often as new sessions pass new bills, so rather than listing specific requirements that could go stale, the practical takeaway is: check your specific state's current children's/teen privacy law before assuming COPPA is the only protection that applies, especially if your teen is 13 or older.

How to Make a Data Deletion Request

Most major platforms and services have a dedicated privacy request portal. For Google products, use myaccount.google.com. For Apple, use privacy.apple.com. For social media and other platforms, check the platform's Help Center under "Privacy" or "Data and Privacy" — nearly every major platform has some version of this by now, often required by law in at least one jurisdiction where they operate. A solid request should include:

  • Your child's name, username, or account identifier as it appears on the platform.
  • A clear description of what you're requesting — full account deletion, specific data categories, or both.
  • A reference to the applicable law where relevant (COPPA for under-13 accounts, or your state's specific statute for teens).
  • Your relationship to the child and a way to verify parental status if the platform asks for it.

Keep a simple record of every request you send and every response you get — date, platform, what you asked for, and what happened. This matters if you ever need to escalate.

When and How to Escalate

If a company covered by COPPA fails to respond within a reasonable time, or refuses a legitimate request without a clear reason, the next steps are the FTC (reportfraud.ftc.gov, which handles COPPA-related complaints) and your state attorney general's consumer protection division, which typically has an online complaint form. Neither of these guarantees a specific outcome or timeline, but both create a formal record and, at scale, contribute to enforcement patterns regulators use to prioritize which companies to investigate.