Map what data each tool collects, who receives it, and what happens when the session ends. Include usernames, photos, voices, project files, messages, device information, and account recovery details where relevant.
In the United States, COPPA covers certain online services collecting personal information from children under thirteen. The FTC flags its April 2025 amendment and directs readers to the revised rule for current requirements. Check the actual camp and provider roles; do not assume a school exception or one parent checkbox solves every duty.1
Canadian and other privacy requirements must also be reviewed for the organization and services used.2 A foreign software provider does not remove your need to understand the arrangement.
Give parents plain notice about required tools and optional public sharing. Do not bundle publicity into necessary participation without careful review and a meaningful alternative where appropriate.
Use internal participant IDs where possible. Keep the link to real identities protected. Avoid full names in public filenames, project titles, or class galleries.
Set a retention and deletion process. Keep legally required business and care records for the appropriate period, but do not leave children's projects and accounts online indefinitely because nobody owns cleanup.
Your task: Draw a data map from registration to final project delivery and deletion.
Sources for this page
- Federal Trade Commission, Complying with COPPA: Frequently Asked Questions. U.S. children’s online privacy. The page flags the April 2025 rule amendment; use the linked revised rule for current requirements. ↩
- Office of the Privacy Commissioner of Canada, Privacy for businesses. Find the privacy rules and guidance relevant to the organization and its data use. ↩