See how Syrenis helps simplify compliance, build trust, and gain greater control over customer data. Book a Demo

Blog Article

Back to Education Means Back to Data Collection

Posted: September 21, 2026

Education is one of the most concentrated data collection events in a family’s year, and 2026 is the first school season under a rewritten federal rulebook. For any organization touching student or parent data, consent management for minors has moved from a specialist concern to a core requirement.

The Federal Trade Commission’s amended Children’s Online Privacy Protection Rule (COPPA) reached its compliance deadline on April 22, 2026, the first major overhaul since 2013. 

Operators must now obtain separate verifiable parental consent before disclosing a child’s personal information to third parties for targeted advertising, or for any other purpose that is not “integral” to the service.

A single bundled “I agree” no longer covers both collection and sharing. The direct notice to parents must also name the categories of third-party recipients and tell parents they can consent to collection without consenting to disclosure.

Consent management is the practice of capturing what a person agreed to, at what granularity, and making sure every downstream system honors it. Under the amended rule, that granularity is legally mandatory for any service reaching children under 13.

Edtech vendors often rely on the school to provide consent in place of parents. But the FTC permits this only where the data is used for the school’s educational purpose and nothing else, which excludes advertising, profiling, and product development unrelated to the contract.

The distinction means that each school contract establishes a boundary concerning the use of data. A vendor has crossed this boundary if its marketing stack treats a student account in the same way as any other customer record, even if no one meant to.

COPPA’s protections end at 13, and state law picks up from there. 

In March 2026, California’s privacy regulator CalPrivacy fined a high school sports ticketing platform $1.1 million for using third-party tracking on its sites and apps and sharing the data with advertising and analytics partners.

That was the agency’s first enforcement action involving students, but the facts are familiar: A consent banner that forced users to click “agree,” and no working path to say “no.” Any platform where a 14-year-old can buy a ticket, join a club, or log a grade faces the same standard.

The state picture is getting more varied. In Syrenis’s recent 2026 Privacy Playbook webinar, Jodi Daniels of Red Clover Advisors pointed out that the new children’s laws are aimed at the teen market and that the age bands differ by state, with some running to 16, some to 17, and some to 18. 

B2B companies frequently discover through a data inventory that they process children’s data on behalf of their clients, and that those clients are starting to write additional obligations into contracts.

Retention is Now an Enforcement Priority

On June 5, 2026, the FTC finalized its order against an edtech vendor whose 2021 breach exposed personal information on more than 10 million students, including medical and special education records. 

The final order requires the company to delete data it no longer needs, publish a data retention schedule, and refrain from collecting information that is not reasonably necessary.

The amended COPPA Rule makes the same point in general terms: Children’s data may be kept only as long as reasonably necessary for the purpose it was collected for, and never indefinitely. A student who leaves a district in June should not still be a live marketing record in September.

Streaming and Gaming Count as Back-to-School Platforms

Children’s data collection extends well beyond the classroom. In December 2025, a federal court approved an order requiring a major entertainment company to pay $10 million over allegations that it allowed personal data to be collected from children watching its kid-directed videos on a major video-sharing platform without parental consent.

In October 2025, a $530,000 CCPA settlement with a TV streaming service required the company to let parents create a child profile that defaults to no sale or sharing of personal information and no cross-context behavioral advertising. 

Regulators are treating household-level, parent-directed preference management as a baseline feature.

What This Asks of a Preference Management Program

Three capabilities enable organizations to meet these new, stricter child privacy rules:

  • Age-aware consent flows: Different journeys for under-13, 13 to 15, and adult users, with parental consent recorded separately from the child’s account. 
  • Purpose-level granularity, so that consent for the educational service and consent for third-party disclosure are distinct records with distinct downstream effects. 
  • Retention logic tied to the relationship, so that the end of a school year or a contract triggers deletion rather than a note in a spreadsheet.

The Stakes of the New Term

COPPA civil penalties can exceed $53,000 per violation, and state regulators have shown they will act on student data even where the amounts are smaller. The exposure compounds because a single platform can hold tens of thousands of minors’ records, each a potential violation.

The market for consent and preference management is consolidating around platforms that can hold a parent’s choices, a child’s profile, and a school’s authorization in one record and enforce all three. The obligation, however, belongs to every organization that collects a student’s data, whatever tools it runs.

Before the term gets busy, pull one student record and trace what would happen if the parent withdrew consent for third-party sharing today. The answer will tell you whether your program is ready for the year ahead.

For more on children’s and sensitive data obligations in 2026, watch the full Privacy Playbook webinar