Highlighted wordsare glossary terms — tap one for a plain-language definition.
Consent online is supposed to mean a real choice: you know what is being collected, why, and you can say no or change your mind. In practice it's buried in settings and 40-page policies. This lesson covers the rights you actually have — including the strong, specific protections children get under COPPA — and the handful of controls worth using today. [1, 2, 3]
What consent is supposed to mean
Real consent is informed, specific, and revocable. A company should tell you what it collects, what it does with it, and who it shares it with — and honor your choice when you turn something off. That's why the FTC treats a privacy promise as enforceable: if a service says it doesn't sell your data or share your location and then does, that's a deceptive practice, not a technicality. A pre-checked box, a "we may share with partners" catch-all, or a setting you can't find is not meaningful consent, and you're allowed to treat it with suspicion. [1, 3]
- Skim a privacy policy for three things: what's collected, who it's shared with, and how to delete it.
- Treat "we may share with trusted partners" as "this may go to data brokers and advertisers."
- Consent you gave once can usually be withdrawn — look for a privacy or permissions page in the account settings.
- Free apps are often paid for with your data; ask what the business model is.
Children get stronger rights: COPPA
The Children's Online Privacy Protection Rule applies to sites, apps, and services directed to children under 13 — and to general services that know they have under-13 users. Before collecting a child's Personal informationWhat it means: Information that identifies or can be connected to a person.Example: Your full name together with your birthdate and home address.What to do: Share only the minimum a form actually requires.Important: Small details combined are enough for identity theft.What does this mean?, the operator must post a clear privacy notice and get verifiable parental consent. Personal information here is broad: name, address, email, phone, photos, voice recordings, geolocation, and persistent identifiers used for TrackingWhat it means: Collecting information about a person's online behavior across websites, apps, or devices.Example: Ads for a product following you from site to site.What to do: Turn on your browser's tracking protection and limit ad tracking on your phone.Important: The same profiles are also used to make scams feel personal and believable.What does this mean? across apps. Operators must also keep the data only as long as needed, protect it, and not condition a child's participation in a game on handing over more than is reasonably necessary. [2, 4]
- Under 13 means parental consent is required before collection — not after.
- Photos, voice recordings, and tracking identifiers all count as a child's personal information.
- A game may not demand more personal information than it genuinely needs to let a child play.
- "Directed to children" covers the content and audience, not just what the terms of service claim.
The rights parents can use
COPPA gives parents standing rights, not just a one-time yes or no. At any point a parent can ask to review what personal information a service has collected about their child, refuse to let it be collected any further, and require it to be deleted — and a service can't retaliate by cutting off features that don't depend on that data. Consent for collection does not automatically mean consent to disclose the data to third parties; parents can allow the first and refuse the second. To use these rights, look for the contact details the privacy notice is required to publish. [2, 4]
- Ask to see what's been collected — the operator must provide a way to review it.
- You can revoke consent and require deletion at any time.
- You can permit internal use while refusing third-party sharing.
- Every covered service must publish contact details for privacy requests — use them in writing and keep a copy.
Exercising your own privacy controls
Don't wait for a policy to protect you. The FTC's practical advice is to limit what you hand over in the first place: give the minimum on sign-up forms, turn off the permissions an app doesn't need to do its job, opt out of ad personalization and cross-app tracking on your phone, and delete accounts and apps you no longer use so their data stops accumulating. Many states now also give you the right to request access to, correction of, or deletion of your data, and to opt out of its sale. And if a service broke its own privacy promise, you can report it to the FTC at ReportFraud.ftc.gov. [1, 3]
- Fill in only the required fields; skip optional birthdays, phone numbers, and addresses.
- Turn off location, contacts, microphone, and cross-app tracking for anything that doesn't need them.
- Use the privacy dashboard in your account settings to download or delete your history.
- Delete dormant accounts and apps — unused data is still breachable data.
- Report a broken privacy promise at ReportFraud.ftc.gov.
Why Hygi. recommends this — the guidance above follows these published sources:
FTC
How To Protect Your Privacy Online(opens in a new tab)Practical consumer steps: share less, tighten app permissions, limit tracking, and delete unused accounts.
FTC
Children's Privacy (COPPA business guidance)(opens in a new tab)Who COPPA covers, verifiable parental consent, and parents' rights to review, refuse, and delete.
FTC
Protecting Your Child's Privacy Online(opens in a new tab)What parents can ask for and how to act on a child's privacy online.
FTC
Complying with COPPA: Frequently Asked Questions(opens in a new tab)Definition of a child's personal information, including photos, voice, geolocation and persistent identifiers.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary