COPPAChildren’s Data ProtectionAge Verification Mechanism

US Market Expansion Focus: Key Points for COPPA Compliance [Monthly Gaming Overseas Sharing]

美国出海关注,COPPA合规要点汇总【游戏出海月度分享】

January 15, 2026
28 views

Summary

On April 18, the Kinding Law Firm Overseas Expansion Team hosted a live webinar focusing on U.S. children’s data protection and COPPA compliance for game publishers going overseas. The session provided a comprehensive overview of the regulatory framework, enforcement trends, and operational best practices related to protecting minors in the U.S. gaming market, with a particular focus on age verification, parental consent, data governance, monetization design, and FTC enforcement risks.

On April 18, the Kinding Law Firm Overseas Expansion Team hosted a live stream sharing practical insights on expanding games into the U.S. market. The session primarily covered compliance practices for protecting minors in the U.S., including relevant regulations, COPPA compliance cases related to game oversight, and hands-on experience addressing COPPA compliance requirements. Two attorneys engaged in a dialogue-style discussion, sharing content tailored to specific entities and answering audience questions about U.S. compliance during the live stream. Below is a recap of key points from this practical sharing session.

PART 1

Key Provisions of COPPA

COPPA is a U.S. law specifically designed to protect the privacy rights of children under 13. It requires operators to obtain verifiable parental consent before collecting children's information and imposes strict restrictions on data processing activities. Key provisions related to the protection of minors include:

1. Requiring verifiable consent from the minor themselves or their parents (for children);

2. Prohibition on storing or transferring children's information outside the U.S. without notification;

3. Granting parents the right to delete or correct children's information;

4. Prohibition on targeted advertising to children and minors.

Key Considerations: COPPA applicability issues—how to determine if a product/service targets children as part of its user base?

Criteria for determining whether internet products/services target minors include:

- Age of promotional models, celebrities, or KOLs featured

- Marketing materials associated with the product/service

Additionally, third-party evidence—such as audience composition data and target audience evidence—will be used to assess minor involvement. Detailed evaluation criteria and descriptions are outlined in the table below:

PART 2

Analysis of Typical COPPA Cases

This section focuses on two landmark gaming industry cases led by the FTC involving Fortnite and Genshin Impact. Key takeaways from both cases are summarized below:

Age Verification Mechanism Deficiencies:

Relying solely on user-reported age (e.g., Genshin Impact's “12+ declaration”) is insufficient for liability exemption. Age screening must be conducted in a neutral manner—without default age settings or incentives for visitors to falsify age information. FTC guidelines further require companies to proactively identify children through technical means (e.g., third-party verification tools) or behavioral analysis (e.g., playtime duration, spending patterns).

Obligations for Mixed-Audience Games:

If game design (e.g., cartoon art style) or marketing activities (e.g., collaborations with child KOLs) may attract children, COPPA's highest standards apply even if the target audience is teenagers. The definition of “mixed audience” is refined, adding new factors for assessing mixed-audience products, such as marketing or promotional materials and plans, statements to consumers or third parties, user or third-party reviews, and the age of users on similar websites or services.

Transparent Probability and Pricing:

Dynamically display cumulative spending amounts on gacha interfaces (e.g., “Spent: $50”) and provide a “probability calculator” tool to help players estimate costs.

Anti-Predatory Design:

Implement a cooling-off period mechanism: Require secondary confirmation for single transactions exceeding a specific threshold (e.g., $100), or grant guardians the ability to set weekly spending limits for minors within parental control features.

Age Verification and Parental Consent:

Implement tiered verification: Require self-reported age upon initial login. Trigger parental consent workflows (e.g., credit card verification, video authentication) for suspected child users (e.g., frequent account switching, small-value purchases).

Establish “Child Safety Mode”: Social features and in-app purchase permissions are disabled by default, accessible only after parental unlocking or verification.

Data Minimization and Retention Limits:

Collect only essential information (e.g., not mandating children's birthdays or geolocation) and automatically delete data upon parental request or account closure.

PART 3

COPPA Compliance Practical Dialogue

Children's Data Protection and Privacy Policy Development

The discussion primarily focused on data processing compliance issues, including rights fulfillment responses, user agreements, and privacy policies. Special attention was given to the protection of minors under the age of 13, specifically regarding data collection practices for children under 13 and disclosure requirements within privacy policies. Additionally, the process of parental consent was addressed, including how to collect parental personal information and associated data, as well as how to process and anonymize this data to safeguard user rights. Finally, the session explored drafting user agreements and privacy policies, along with page and interaction design considerations for products or websites.

User Privacy Protection and Compliance Requirements

The design of the user consent mechanism was discussed, with a recommendation to adopt a simple checkbox approach while ensuring a seamless user experience. On the backend, it is necessary to log the user's consent time, ID, IP address, and other relevant information. During product usage, multiple contact channels must be provided, such as email and online forms. Upon receiving user requests, identity verification must be conducted, such as email binding, sending verification codes, or providing game IDs. For minor users, guardian identity must be confirmed using government IDs, driver's licenses, etc. Response cycles should be processed within 45 days from receipt of complete request materials. Regarding data deletion, certain data must be retained for internal analysis and evidence preservation, including registration information, email addresses, phone numbers, and device identifiers.

User Age Verification Solutions and Regulatory Analysis

Based on COPPA regulations and related practices, mainstream verification methods include signed consent forms, paper or electronic payments, credit card or online payment systems, microtransactions, voice calls, and video conferencing. It is emphasized that the verification process should not collect additional personal information from adults to avoid increasing data compliance obligations. Additionally, some vendors utilize third-party service providers for age verification to manage their mandatory data compliance responsibilities.

Game User Authentication and Control Practices

First, the game registration page requires users to provide a clear date of birth to prevent the use of real names and mitigate malicious incidents such as cyberbullying. Second, parental control features allow guardians to link their email addresses to accounts, enabling oversight of minors' in-game spending and social interactions. Finally, for age verification, the game employs an age selector wheel to require players to provide an accurate birthdate. Dynamic verification codes are sent to ensure parents or guardians retain control over the actions of their supervised users.

Compliance Outlook: Content Compliance and User Age Verification in Social Products

Social products face challenges in content compliance governance related to underage users accessing potentially problematic content, such as implicitly sexual material. The current industry standard practice in social platforms is to require users to proactively input their age information to verify if they are at least 18 years old. Users under 18 can register by submitting identity verification documents. Additionally, facial recognition technology commonly used in social products can identify minors and suspend their accounts. Real-name authentication is another prevalent verification method. Compared to mainland China, overseas markets have relatively lower age verification requirements, favoring more encouraging or neutral verification approaches. With the advancement of AI technology, more companies may offer age recognition services in the future, providing additional support for social products.

Deceptive Design and Dark Patterns in Game Design

Deceptive design encompasses misleading cases and confusion tactics that induce players into non-resource or impulse purchases. Dark patterns refer to unfair and deceptive commercial practices as defined by Section 5 of the FTC Act, such as false in-game countdown timers for limited-time offers or limited-quantity item purchases. Additionally, in game advertising, using real-person KOLs to promote gameplay interfaces while the actual player experience significantly differs from promotional materials may constitute consumer fraud.

Social Features and Compliance Requirements for Minor Protection

It is recommended that high-risk social features be disabled by default for minor users, requiring explicit opt-in authorization. Concurrently, parents should retain the right to review communication activities involving minor users.

Compliance Analysis of Prize Drawings

When conducting online or offline prize drawings, compliance with consumer protection laws is mandatory. Activity rules must be transparent, and false advertising (such as implying purchases increase winning odds) must be avoided. Second, prioritize child protection by implementing compliance measures for minor users to prevent access to mechanics like loot box-style prize draws. For offline sweepstakes specifically, note that U.S. states have varying regulations—such as registration requirements in Florida and New York, and monetary thresholds in Rhode Island. Therefore, primarily conduct sweepstakes through online channels (e.g., social media shares) to reduce compliance costs.

中文原文

4月18日,诺诚游戏出海团队进行了游戏出海美国实务分享直播,主要内容涉及出海美国的未成年保护合规实务,包括法规相关内容、游戏监管相关的COPPA合规案例以及与围绕COPPA合规要求的相关实操经验。两位律师以对谈形式,围绕特定主体进行了内容分享,并在直播过程中回答观众关于出海美国合规问题的留言。以下是对本次实务分享的全程要点回顾。

PART 1

COPPA重点法条分享

COPPA是美国专门针对13岁以下儿童的隐私权益保护法律,要求运营商在收集儿童信息前获得可验证的父母同意,并严格限制数据处理行为。与未成年人保护相关的重点法条包括:

1.要求获得青少年本人或父母(针对儿童)的可验证同意;

2.禁止未经通知将儿童信息存储或传输至美国境外;

3.赋予父母删除或更正儿童信息的权利;

4.禁止针对儿童和青少年的定向广告。

重点关注问题:COPPA法案适用问题,如何判断产品/服务将儿童纳入目标用户群体?

互联网产品和服务是否面向未成年人的考量维度,包括选用的推广模特、名人或KOL的年龄,以及产品服务关联的推广素材等因素。

同时,第三方证据,如受众组成证据和目标受众证据,也将用以判断产品是否涉及未成年人。各类评估维度及描述内容,详见下表:

PART 2

COPPA典型案例解析
本部分重点分析了关于《堡垒之夜》和《原神》两款产品,由FTC主导的游戏领域典型案例。针对两个案件,总结重点内容如下:

  • 年龄验证机制缺陷:

仅依赖用户自填年龄(如《原神》的“12+声明”)不足以免责。而在年龄验证设计方面,年龄筛选需以中立方式进行,不得默认设定年龄或鼓励访问者伪造年龄信息。同样根据FTC的相关指南,要求企业通过技术手段(如第三方验证工具)或行为分析(如游戏时长、消费模式)主动识别儿童。

  • 混合受众游戏的义务:

若游戏设计(如卡通画风)、营销活动(如与儿童KOL合作)可能吸引儿童,即使目标为青少年,仍需按COPPA最高标准处理。“混合受众”的定义细化,在对于混合受众产品的判断新增了考虑因素,如营销或宣传材料及计划、对消费者或第三方的陈述、用户或第三方的评论,以及类似网站或服务中用户的年龄等。

  • 透明化概率与定价:

在抽卡界面动态显示累计消费金额(如“已花费:$50”),并提供“概率计算器”工具帮助玩家预估成本。

  • 反诱导消费设计:

设置冷静期机制:单次消费超过特定金额(如$100)需二次确认,或在家长控制功能中,为监护人提供未成年人周消费限额的设置权限。

  • 年龄验证与家长同意:

采用分层验证机制:首次登录时要求自填年龄,对疑似儿童用户(如频繁切换账号、小额消费)触发家长同意流程(如信用卡验证、视频认证)。

建立“儿童安全模式”:默认关闭社交功能与内购权限,仅家长解锁或验证后方可开放。

  • 数据最小化与留存限制:

仅收集必要信息(如不强制要求儿童提供生日、地理位置),并在家长要求或账户注销后自动删除。

PART 3

COPPA合规实务对谈

儿童数据保护与隐私政策制定

主要讨论了关于数据处理合规性的问题,包括行权响应、用户协议和隐私政策等内容。特别关注了未保未成年人保护,对于13岁以下儿童的数据收集行为和隐私政策中的披露要求。同时,提到了家长同意的过程,如何收集家长个人信息和关联数据,以及如何处理和匿名化这些数据以保护用户权利。最后,讨论了用户协议和隐私政策的拟定,以及如何在产品或网页上进行页面或交互设计。

用户隐私保护与合规要求

讨论了用户同意机制的设计,建议采用简单的勾选框,同时保证用户体验。在后端,需要记录用户的同意时间、ID和IP地址等信息。在产品使用过程中,需要提供多渠道的联系方式,如邮箱、在线表单等。在收到用户请求后,需要进行身份确认,如绑定邮箱、发送验证码、提供游戏ID等。对于未成年人用户,需要确认监护人身份,如政府ID、驾驶证等。在响应周期上,建议从收到完整请求材料起算的45天内进行处理。在数据删除方面,需要保留部分数据用于内部分析和留存证据,如注册信息、邮箱、电话号码和设备标识等。

用户年龄验证方案及法律法规解析

根据COPPA法规及相关实操,主流验证方案包括如签署同意书、纸质或电子支付、信用卡或在线支付系统、小额支付、语音电话、视频会议等。同时,强调了验证过程中不应额外收集成年人的个人信息,避免数据合规义务上升。此外,部分厂商也通过第三方服务商进行年龄验证的方式,来控制自身在数据合规层面的强制性义务。

游戏用户身份验证与控制实践

首先,游戏注册页面要求用户填写明确的出生日期,以避免使用真实姓名,防止网络霸凌等恶性事件。其次,家长控制功能通过提供监护人邮箱与账号关联,对未成年人用户的消费行为和社交行为进行控制。最后,年龄验证方面,游戏会通过年龄滚轮的方式,要求玩家提供准确的出生日期,并通过发送动态验证码等方式,确保家长或监护人对受监护用户的行为有控制权限。

合规展望:社交产品内容合规与用户年龄验证

社交产品在内容合规治理层面面临未成年人用户进入可能遇到的问题,如隐晦色情内容。目前普遍的社交领域做法是要求用户主动输入年龄信息,评估是否已满18岁。未满18岁的用户,可以通过提交身份验证材料进行注册。此外,社交产品中常用的人脸识别技术可以识别未成年人,并对其账号进行封禁。实名认证也是常见的验证方式。与大陆地区相比,海外市场对年龄验证的要求相对较低,更倾向于鼓励式或中立性的验证方案。随着AI技术的发展,未来可能会有更多企业提供年龄识别服务,为社交产品提供更多支持。

游戏设计中的诱导性设计与暗黑模式

诱导性设计包括误导性的案件、混淆去诱导玩家做非资源或冲动型消费等。暗黑模式则是指以FTC法案第5条所规定的不公平、欺骗性的商业行为,如游戏内虚假的倒计时限购、限量道具购买等。此外,在游戏广告层面,如使用真人KOL进行游戏试玩界面宣传,但实际玩家体验与宣传素材存在明显差异时,亦存在消费者欺诈的可能性。

社交功能与未成年人保护的合规要求

建议对于未成年人用户,默认关闭高风险社交功能,通过选择加入的方式获得授权。同时,家长可以对未成年用户的通信情况有确认权。

抽奖活动合规性分析

如开展线上线下抽奖活动,应满足消费者保护法相关要求,要求活动规则透明,避免虚假宣传(如暗示购买可提高中奖概率等)。其次,关注儿童保护,建议对未成年人用户采取合规措施,避免他们接触类似抽奖战利品箱的玩法。特别针对线下抽奖活动,美国各州对于抽奖活动存在不同规定,如佛罗里达州和纽约州的登记要求,以及罗德岛州的金额要求。因此建议主要将抽奖活动设置在线上渠道,例如通过社交媒体转发等方式参加,以降低合规成本。

分享文章

相关文章

General

Game Licensing (ISBN Approval): Can Cultural Enforcement Be Exercised Across Regions?

游戏版号,文化执法也能异地?

This article analyzes the legality and rationality of cross-regional administrative enforcement in game licensing cases in China. It argues that, under the current legal framework, enforcement should follow the principle of territorial jurisdiction, as the place of illegal conduct is typically tied to the location of the game company. Cross-regional enforcement may lead to jurisdictional conflicts, increased compliance burdens, and risks of profit-driven enforcement, thereby undermining the business environment and procedural fairness.

5 views
General

Twitch bans streamers from “promoting or sponsoring” CS:GO skin gambling

Twitch禁止主播“推广或赞助”CSGO皮肤赌博

Twitch has updated its community guidelines to further restrict gambling-related content, explicitly banning the promotion and sponsorship of skin gambling websites, particularly those مرتبط with Counter-Strike: Global Offensive. Since 2022, Twitch has prohibited the promotion of gambling sites that are not licensed in jurisdictions with consumer protections, naming platforms such as Stake, Rollbit, and Roobet. The latest update expands these restrictions to include CS:GO skin gambling sites and their free social versions, while also banning links, promo codes, and visual displays of such content. Twitch stated that the move responds to renewed interest in CS:GO skin gambling.

3 views
General

U.S. Market Expansion: New Age Verification Method Under COPPA

美国出海:COPPA下新的年龄验证方法

To facilitate compliance with the Children’s Online Privacy Protection Act (COPPA), the Entertainment Software Rating Board (ESRB), together with other U.S. institutions, has proposed a new mechanism for obtaining verifiable parental consent (VPC). The proposal relies on privacy-protective facial age estimation technology, developed with technical support from Yoti and SuperAwesome. The U.S. Federal Trade Commission (FTC) is currently soliciting public comments on whether this method falls within existing COPPA-approved verification methods, whether it satisfies the statutory requirements for parental consent, and whether it introduces privacy risks, including those related to biometric information. The proposal signals a potentially significant development in age verification compliance for online platforms and gaming services operating in the United States.

4 views