Published: June 19, 2026

Our bulletin Cyber Threat Watch has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.

Featured Cyber News — Children’s Data: Overlooked Risk for Small Businesses

Recent amendments to the Children’s Online Privacy Protection Act (COPPA) Rule are increasing attention on how businesses collect and handle children’s personal information. According to a recent discussion published by the International Association of Privacy Professionals (IAPP), businesses that fall within the scope of the amended COPPA Rule must comply by April 22, 2026, as it introduces additional requirements related to obtaining parental consent and handling children’s information. The amended COPPA Rule applies across the United States and is not limited to specific states.

At first glance, many small businesses may assume these requirements apply only to social media platforms, gaming apps, and websites specifically designed for children. However, businesses that don’t specifically target children may still encounter situations where their information is collected through business websites—the concern may not be intentional collection, but whether businesses have assessed how this information could enter their systems in the first place.

How Children’s Data Can Be Collected Unintentionally

Typically, children’s information may be collected in settings such as childcare and daycare providers, swim schools, tutoring services, youth programs, healthcare clinics, and other businesses that interact with children. However, many small businesses rely on digital tools to support customer engagement and business operations without fully recognizing what information is being collected or how it is being used. As a result, children’s information can sometimes be collected through normal business activities without businesses specifically intending to do so. Examples include the following:

  • Website analytics tools collecting visitor information and browsing activity
  • Online forms and mobile apps requesting personal information
  • Third-party social media advertising and tracking tools integrated into websites

External services or plug-ins collecting information behind the scenes

What Your Business Needs to Know

Under COPPA, businesses that specifically target children under 13 must obtain parental consent before collecting or sharing children’s personal information. The law can also apply once businesses gain actual knowledge that they are collecting personal information from children under 13, even if their services are intended for a general audience. In practical terms, this may occur if information is submitted with personal details via forms or other interactions that indicate a user is under 13.

For small businesses, the concern may not be intentionally collecting children’s information, but simply not recognizing where it could happen. Businesses may assume their services are intended for adults, while information from younger users could still be collected through websites, registrations, or online interactions. Therefore, understanding data collection practices can help businesses identify potential collection risks earlier.

Practical Steps to Reduce Risk

Small businesses can take the following practical steps to reduce potential privacy and compliance risks.

  1. Review Digital Services: Mobile apps, website forms, customer portals, and other online services should be reviewed to understand what information is being collected from users.
  2. Evaluate Third-Party Tools: Website analytics tools, advertising tools, and other third-party services should be evaluated to understand what information they collect.
  3. Verify Vendor Practices: Vendors handling your customer information are responsible for maintaining appropriate privacy and security practices.
  4. Identify External Services and Plug-ins: External services or website plug-ins may collect information behind the scenes. Examine what information is being gathered.
  5. Update Privacy Notices: Privacy notices on the website, mobile app, and other online services should accurately describe how information is collected and used.
  6. Establish Internal Procedures: Staff need to know how to respond if information from children is identified.
  7. Collect Only Necessary Information: Data collection should be limited to only information needed for business purposes.

Conclusion

Many businesses may not intentionally collect children’s information but can overlook how it is collected through various digital channels. As attention to children’s privacy continues to increase, understanding data collection practices can help businesses identify risks earlier and apply appropriate safeguards.

The NCSS encourages businesses to adopt comprehensive security practices and stay informed about evolving requirements. We recommend you consider becoming an NCSS member to access a wide range of our services. For more information, visit our Small Business page.

About the NCSS

The National Cybersecurity Society (NCSS) is committed to improving the online safety and security of the small business community through education, awareness, and advocacy. As a 501(3)(c) organization, the NCSS uses funds from charitable donations and grants to develop educational materials, webinars, weekly cyber tips, videos, and how-to-guides. The organization’s goal is to enable and empower small and medium businesses to obtain cybersecurity services, assist them in understanding their cyber risk, and advise on the type of protection needed. We want to continue to grow our community and encourage you to tell other small businesses we are here to help.

The NCSS is committed to respecting the use of images in our communication efforts. Accordingly, unless otherwise specifically noted, the graphics in our bulletin are sourced under license from Adobe Stock. The header and footer images were designed and purchased through a contract with Eyedea Advertising & Design Studio.