Skip to main content
All lessons
Lesson 24Privacy & Footprint pathway

Digital Consent & Privacy Rights

You agreed to something — know what

Highlighted wordsare glossary terms — tap one for a plain-language definition.

Consent online is supposed to mean a real choice: you know what is being collected, why, and you can say no or change your mind. In practice it's buried in settings and 40-page policies. This lesson covers the rights you actually have — including the strong, specific protections children get under COPPA — and the handful of controls worth using today. [1, 2, 3]

Children get stronger rights: COPPA

The Children's Online Privacy Protection Rule applies to sites, apps, and services directed to children under 13 — and to general services that know they have under-13 users. Before collecting a child's , the operator must post a clear privacy notice and get verifiable parental consent. Personal information here is broad: name, address, email, phone, photos, voice recordings, geolocation, and persistent identifiers used for across apps. Operators must also keep the data only as long as needed, protect it, and not condition a child's participation in a game on handing over more than is reasonably necessary. [2, 4]

  • Under 13 means parental consent is required before collection — not after.
  • Photos, voice recordings, and tracking identifiers all count as a child's personal information.
  • A game may not demand more personal information than it genuinely needs to let a child play.
  • "Directed to children" covers the content and audience, not just what the terms of service claim.

The rights parents can use

COPPA gives parents standing rights, not just a one-time yes or no. At any point a parent can ask to review what personal information a service has collected about their child, refuse to let it be collected any further, and require it to be deleted — and a service can't retaliate by cutting off features that don't depend on that data. Consent for collection does not automatically mean consent to disclose the data to third parties; parents can allow the first and refuse the second. To use these rights, look for the contact details the privacy notice is required to publish. [2, 4]

  • Ask to see what's been collected — the operator must provide a way to review it.
  • You can revoke consent and require deletion at any time.
  • You can permit internal use while refusing third-party sharing.
  • Every covered service must publish contact details for privacy requests — use them in writing and keep a copy.

Exercising your own privacy controls

Don't wait for a policy to protect you. The FTC's practical advice is to limit what you hand over in the first place: give the minimum on sign-up forms, turn off the permissions an app doesn't need to do its job, opt out of ad personalization and cross-app tracking on your phone, and delete accounts and apps you no longer use so their data stops accumulating. Many states now also give you the right to request access to, correction of, or deletion of your data, and to opt out of its sale. And if a service broke its own privacy promise, you can report it to the FTC at ReportFraud.ftc.gov. [1, 3]

  • Fill in only the required fields; skip optional birthdays, phone numbers, and addresses.
  • Turn off location, contacts, microphone, and cross-app tracking for anything that doesn't need them.
  • Use the privacy dashboard in your account settings to download or delete your history.
  • Delete dormant accounts and apps — unused data is still breachable data.
  • Report a broken privacy promise at ReportFraud.ftc.gov.

Brought to you by NorthBridge

Unfamiliar term? Open the Digital Safety Glossary