Does COPPA Apply to the Apps and Parent Portals a Home Daycare Uses?
Someone in a home daycare Facebook group posts a screenshot of a news article about a children's app getting fined for a privacy violation, with the caption "wait, is OUR stuff COPPA compliant??" Forty comments pile on, nobody actually answers the question, and now you're sitting there looking at the attendance app on your phone — the one with every enrolled child's name, birthdate, and allergy list in it — wondering if you, personally, have been quietly out of compliance with a federal law this whole time.
You haven't been typing "COPPA" into Google out of idle curiosity. You're asking because you genuinely don't know whether a law written about children's privacy online applies to a woman running a 6-kid home daycare who uses an app to track who's paid and who hasn't. Here's the honest, non-alarmist answer: almost certainly, this is not your compliance burden to carry — but there's a real nuance underneath that, and "almost certainly not" isn't the same as "definitely not, stop thinking about it."
What COPPA actually regulates
The Children's Online Privacy Protection Act is a federal law enforced by the FTC, and it's more specific than its name suggests. It doesn't regulate "any business that has children's information somewhere in its records." It regulates operators of commercial websites and online services directed to children under 13, or operators who have actual knowledge they're collecting personal information from children under 13 — full stop on who the "operator" is. The FTC's own compliance guidance is built around that definition: a covered operator is the company running the website, app, or online service, not every person or business whose information happens to flow through it. (Source: FTC, "Complying with COPPA: Frequently Asked Questions")
The part that matters most for your situation is buried in how the FTC describes what counts as regulated activity in the first place: COPPA governs personal information collected online from children — including information a child provides about themselves, their parents, friends, or other people. The emphasis is on the child being the one interacting with the service and providing the data. (Source: FTC COPPA FAQ)
Why that distinction covers your situation
Walk through what actually happens when you add a child to an attendance app, a billing tool, or a parent-portal platform: you, an adult running a business, open the app and type in a child's name, birthdate, allergy, and a parent's phone number. The child never opens the app. The child never sees a screen, taps a button, or submits a form. You are the one collecting and entering the information — the same way you'd fill out a paper enrollment form by hand.
That's meaningfully different from the scenario COPPA is built around: a child-directed game, a kids' learning app, or a service that lets a child create their own account and type in their own name and age. In the framework the FTC uses, an adult professional inputting a client's child's information into a business tool she uses isn't the same thing as a website collecting data directly from a child user. The software company behind the tool is the one positioned as the potential "operator" under COPPA — not you.
Where the genuine hedge comes in
Here's the part worth taking seriously instead of skating past: COPPA's operator analysis turns heavily on what the service itself is and does — whether it's directed at children, whether it knowingly collects from under-13 users, how it's marketed, who it's built for. That's a legal question about the software company's product, not about how any individual customer happens to use it. The FTC's published guidance doesn't walk through the specific scenario of "a professional entering a client's child's data on the client's behalf" as its own labeled category with a clean yes/no answer. The reasoning above — that COPPA targets collection from children, not records about children entered by someone else — is well-supported by how the FTC defines coverage, but it isn't a verdict the FTC has spelled out for this exact situation in so many words. That's a real gap, not a technicality, and it's why "mostly not your problem" is the honest phrasing here rather than "never your problem."
Two things follow from that honest hedge, and they're the two that actually matter in practice:
- Never let a child directly interact with an app or portal to enter their own information. If a scenario ever came up where an enrolled child was the one typing into a device — even something as low-stakes as a tablet game embedded in a "learning" feature of a daycare app — that changes the analysis, because now the child is the one providing data to the service. Keep data entry an adult-only task, full stop.
- Ask your software vendor directly about their own COPPA posture, especially if the product has any feature a child could ever touch, or if it markets itself as usable by kids in any way. A vendor who's thought about this will have a clear, confident answer. One who looks confused by the question is itself useful information.
What this article isn't about
A few related questions come up in the same breath as COPPA, and they deserve their own space rather than a rushed paragraph here. If you're trying to lock down the basics of keeping family data secure on your own devices — passwords, device locks, two-factor authentication — that's covered in full in our cybersecurity basics guide. If you're wondering what actually happens after a real breach, including the specific danger a child's Social Security number creates, that's its own article on child identity theft after a daycare data breach. And if you're weighing whether to buy a dedicated insurance product that covers breach-response costs, that's a distinct purchase decision covered in our cyber liability insurance guide — COPPA compliance and cyber insurance are two separate questions that happen to live in the same worried corner of your brain.
It's also worth thinking about this alongside the other places family data leaves your house in digital form — what you post publicly needs its own photo and video consent policy, and if you run a security camera that uploads footage to an app, that account deserves the same scrutiny covered in our guide to home daycare security camera legality.
A short, honest checklist
- Confirm that only you (or another adult staff member, if you have one) ever enters children's information into any app — never a child
- If your billing, attendance, or parent-portal app has any feature a child could access directly (games, logins, chat), ask the vendor specifically whether that feature is designed with COPPA in mind
- Email or ask your software vendor's support team one direct question: "Is your service COPPA compliant, and does that depend on how I use it?" — keep the written answer
- Treat this as separate from your general data-security habits, which matter regardless of what any law requires
This is general information about how COPPA is structured, not a legal opinion about your specific software or situation — if a particular app's marketing or features genuinely make you unsure, a few minutes with a lawyer who handles privacy law, or a direct question to the vendor's support team, is worth more than guessing.
Where DaycareFlow fits
DaycareFlow is built around exactly the data-entry pattern described above: you, the provider, create each child's profile yourself — name, birthdate, allergies, medical notes, parents' contact information, billing rate. A linked parent can view their own child's profile through a read-only share code, but there's no feature anywhere in the product that asks an enrolled child to open the app, create an account, or type in anything at all. That's not a COPPA compliance claim — it's just an honest description of how the product works, which happens to land squarely on the "adult enters the data" side of the distinction this whole article is about.
Free during early access, with no card fees and no per-child pricing. Start free →
Frequently asked questions
Is a home daycare provider legally required to be COPPA compliant?
Generally, no — COPPA regulates operators of websites and online services that collect information directly from children, and a provider typing a child's information into a business app herself isn't the same as a service collecting data from a child user. The software company behind the app is the one positioned as a potential "operator" if its service is covered. This is general information, not a legal determination for your specific situation.
Who is actually responsible for COPPA compliance — me or the software company?
If any party has compliance obligations here, it's the company that built and operates the website, app, or online service — not the business or individual using it to enter someone else's information. The FTC's framework centers on who is collecting data and whether they're doing so directly from a child, which points at the software provider, not a daycare using the tool as an adult.
What should I ask my daycare software vendor about COPPA?
Ask directly whether their service is COPPA compliant and whether that depends on how you use it — specifically, whether any feature allows a child to interact with the app directly rather than an adult entering information on their behalf. A vendor with a clear, confident answer has thought about this; a vague one is worth following up on.
Does it matter if a child sees the screen while I'm entering their information?
What matters under COPPA's framework is who is providing the information to the service, not who's in the room. A child glancing at a screen while you type isn't the child collecting or submitting data. The meaningful line is a child directly interacting with the app or portal to enter their own information — that's the scenario to actively avoid.
Is this the same as general cybersecurity for my daycare's data?
No, and it's worth keeping separate. COPPA is a specific legal framework about who collects information from children online. General data security — locking your devices, using unique passwords, enabling two-factor authentication — matters regardless of COPPA and is covered in our cybersecurity basics guide.
Ready to try it?
Run your daycare with calm.
DaycareFlow is free to start. No credit card, no commitment. Set up in 5 minutes.
Get started free