User Research With Children and Teens: COPPA, Parental Consent, and Assent
Researching under-13s triggers COPPA verifiable parental consent - including a separate consent before any child data trains AI. Here is the compliance path, the parent-mediated pattern most teams should use instead, and how to design sessions that actually work with young participants.
The short answer
If you collect personal information from children under 13, COPPA requires verifiable parental consent before collection — not after, and not as a checkbox the child clicks. For 13–17 year olds COPPA does not apply, but a growing number of state privacy laws impose their own duties around minors, and ethical obligations apply at every age.
For most product teams, the right answer is not "build a COPPA-compliant child research pipeline." It is:
Research the parent. Bring the child in deliberately, rarely, and with proper consent in place.
Parents are usually the buyer, the payer, the installer, and the person who churns. In family products, the purchasing decision very often lives entirely with the adult — so a great deal of the insight you need is available without touching child data at all.
Not legal advice. COPPA enforcement is active and the Rule was recently amended; confirm your specific approach with counsel before collecting from minors.
What COPPA covers
COPPA applies to operators of websites and online services directed to children under 13, and to any operator with actual knowledge that it is collecting personal information from an under-13 user. "Personal information" is broad: name, email, phone, persistent identifiers, photos, video, and audio recordings of a child's voice.
That last item matters for research. A recorded voice interview with a 10-year-old is squarely personal information.
The Rule was amended recently. The FTC published final amendments in the Federal Register on 22 April 2025, effective 23 June 2025, with a full compliance deadline of 22 April 2026 — so the amended requirements are now fully operative. The changes most relevant to research teams:
- A separate verifiable parental consent is required before disclosing a child's personal information to third parties for targeted advertising or for training or developing AI technologies. Read that twice if you run research through any AI platform. Consent to participate in a study is not consent to use that child's data for model training.
- Retention is explicitly limited. Operators may keep a child's personal information only as long as reasonably necessary for the specific purpose it was collected for, and may not retain it indefinitely. A written, published retention policy is expected.
- Consent methods were expanded, including knowledge-based authentication, photo-identification matching by phone or web, and using a mobile telephone number for text-message consent.
There are eight approved methods for obtaining verifiable parental consent under the amended Rule. All of them are meaningfully more work than an email checkbox — and that friction is the point.
Consent vs assent: two different things
This distinction is the mark of a team that knows what it is doing.
- Parental consent (permission) is the legal instrument. A parent or guardian authorizes the child's participation.
- Assent is the child's own affirmative agreement, in language they actually understand.
You need both. A parent cannot consent away a child's unwillingness. If an 8-year-old goes quiet, gets restless, or says they would rather stop, the session ends — regardless of what the consent form says or whether the incentive has been paid.
Practical assent script, at the child's reading level: "We're trying to make this app better for kids your age. I'll ask some questions about what you liked and what was confusing. There are no right answers, and you can skip anything or stop whenever you want. Is that okay with you?"
The parent-mediated pattern (start here)
For the large majority of consumer, edtech, and family-product research, this sequence answers the business question without collecting child data:
- Interview the parent about the purchase and the friction. Why they chose it, what nearly stopped them, what would make them cancel. This is standard adult research with standard consent.
- Have the parent report observed child behavior. What the child actually does, where they get stuck, what they abandon. Parents are imperfect but useful proxies for behavior, and excellent sources on their own decision-making.
- Use product analytics for behavior rather than asking children to self-report it.
- Only then, if a specific question genuinely requires the child's own voice — comprehension, delight, confusion at a particular step — run a small, properly consented child session, ideally moderated and observed.
Steps 1–3 answer most roadmap questions. Teams skip to step 4 far too quickly, and it is both the most expensive and the most legally loaded option.
If you do research directly with children
Get verifiable parental consent using an approved method, before any collection. Not a click-through, not an email to an address the child typed in.
Collect as little as possible. Prefer text over voice — a voice recording is biometric-adjacent and a stronger category of data. See interview recording consent laws for why voice raises the stakes. Skip anything you do not need: no full names, no schools, no photos.
Go through the school when relevant — and expect two gatekeepers. School districts approve separately, and student education records fall under FERPA. School approval is not a substitute for parental consent, nor the reverse.
Expect IRB involvement in regulated or published work. Federally regulated research with children falls under additional protections (Subpart D of the Common Rule). See IRB approval for user research.
Design for the age, not for adults:
| Age | Session design |
|---|---|
| Under 6 | Observation with caregiver present; almost no verbal interviewing |
| 6–9 | 15 minutes maximum, concrete tasks, show-me rather than tell-me, caregiver nearby |
| 10–12 | 20–25 minutes, concrete language, avoid hypotheticals entirely |
| 13–17 | Closer to adult sessions, but expect strong social-desirability effects |
Two persistent methodological problems with young participants. Acquiescence — children are primed by school and home to give adults the answer they seem to want, so avoid leading questions and yes/no framings where a "yes" is the agreeable answer. Hypotheticals do not work — "would you use a feature that..." produces noise. Ask about what happened yesterday, and watch them do the task.
For teenagers, social desirability is the dominant risk. A 15-year-old will underreport anything embarrassing to an adult moderator, which is exactly where an AI interviewer earns its keep: participants disclose more candidly to a non-judging interviewer, a pattern documented across sensitive-topic research. See social desirability bias.
Teens, and the laws that are not COPPA
COPPA stops at 13, but obligations do not. Most of the 20 US state comprehensive privacy laws now treat certain minor data as sensitive, requiring opt-in consent, and several restrict targeted advertising and data sales involving minors up to 16 or 18. Under GDPR Article 8, the digital age of consent is 16, though member states may lower it to as low as 13 — so the threshold genuinely varies by country. If you research teens across the EU, check per-country.
How to run this on Koji
Be clear-eyed about what the platform is for: Koji is built for business and consumer research with adults, and the parent-mediated pattern above is the intended path. Use it to interview parents, teachers, administrators, and teens at scale — and treat direct under-13 collection as a specialist exercise requiring verifiable parental consent machinery you have deliberately put in place, plus a review of platform terms with your legal team.
Where it fits well:
- Parent and caregiver research at volume. AI voice interviews let you run 50 parent conversations in the time a moderator would run six, which is what makes the parent-mediated pattern practical rather than aspirational.
- Teacher and administrator research for edtech — see AI research for edtech and student satisfaction surveys.
- Text mode for younger or sensitive participants, avoiding audio collection entirely. Voice vs text interviews covers the tradeoff.
- Structured questions keep sessions short and age-appropriate. The six types —
open_ended,scale,single_choice,multiple_choice,ranking,yes_no— let you ask a 12-year-old to pick or rank rather than compose a paragraph, with AI follow-up probing only where an open answer adds something. Capping follow-ups keeps a session inside a young participant's attention span. See the structured questions guide. - Minimal data by design. Scope studies to avoid identifiers, and set a retention limit that satisfies COPPA's "not indefinitely" requirement — see research data retention and deletion and anonymizing customer interview data.
On AI training specifically: the amended COPPA Rule requires separate verifiable parental consent before a child's personal information is disclosed for training or developing AI technologies. Before running any study involving minors, confirm in writing how your platform and its sub-processors handle research data with respect to model training, and document the answer — see enterprise security for AI research platforms.
Common mistakes
- Treating a child's click as consent. COPPA requires verifiable parental consent through an approved method.
- Getting parental consent and skipping the child's assent. Ethically insufficient, and it produces bad data from an unwilling participant.
- Assuming study consent covers AI training. The amended Rule requires a separate consent for that disclosure.
- Recording voice when text would do. Audio of a child's voice is personal information with a higher risk profile.
- Assuming school permission covers parental consent. Two separate gatekeepers, plus FERPA.
- Asking children hypothetical questions. Ask about yesterday; observe the task.
- Keeping child data indefinitely. The amended Rule prohibits it and expects a published retention policy.
- Going straight to child sessions when parent interviews and analytics would have answered the question.
Related Resources
- Structured Questions Guide — short, age-appropriate instruments with controlled probing
- Interview Recording Consent Laws — why voice raises the stakes with minors
- IRB Approval for User Research — when vulnerable-population protections apply
- Research Data Retention and Deletion — meeting the "not indefinitely" requirement
- AI Research for EdTech — teacher, administrator, and institutional research
- Social Desirability Bias — the dominant risk with teen participants
- Trauma-Informed User Research — for sensitive topics with young participants
- Research Consent Form Templates — consent language to adapt
Related Articles
AI-Powered User Research for EdTech: Learners, Educators, and Administrators
How EdTech companies can run parallel research streams with learners, educators, and administrators using AI-moderated interviews — without scheduling headaches or research team scale limitations.
FERPA-Compliant User Research: Interviewing Students, Parents, and Educators
How FERPA, PPRA, and state student-privacy laws apply to edtech user research — when the school official exception covers you, when PPRA consent kicks in, and how to run compliant student interviews.
Interview Recording Consent Laws: One-Party, All-Party, and Biometric Rules (2026)
Federal law allows one-party consent recording, but roughly a dozen US states require all-party consent - and biometric laws like Illinois BIPA add a separate written-consent duty for voiceprints. Here is how research teams stay on the safe side of both.
Do You Need IRB Approval for User Research? A 2026 Decision Guide
Most commercial UX and product research does not require IRB approval - but four specific situations flip the answer to yes. Here is the actual regulatory test, the exempt categories, and how to prepare a submission that clears review fast.
Research Consent Form Templates: GDPR-Compliant Forms for Every Study
Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.
Research Data Retention and Deletion: How Long Should You Keep Interview Data?
There is no universal legal number - which is exactly why having no retention schedule is itself the compliance failure. A tiered, per-artifact schedule for recordings, transcripts, quotes, and reports, plus how to handle deletion requests without losing your insights.
Social Desirability Bias: What It Is and How to Eliminate It in Research
Social desirability bias makes people tell you what sounds good instead of what is true. Learn what causes it, why it quietly wrecks product decisions, and the seven evidence-based ways to reduce it — including why AI-moderated interviews get more honest answers.
Structured Questions in AI Interviews
Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.
How to Measure Student Satisfaction and Improve Institutional Outcomes
A comprehensive guide to designing student satisfaction surveys that capture meaningful feedback across academic, social, and administrative dimensions to drive institutional improvement.
Trauma-Informed User Research: How to Interview on Sensitive Topics Safely and Ethically
A practical guide to trauma-informed UX research grounded in SAMHSA's six principles. Covers screener design, dynamic consent, person-first language, in-session grounding, debrief and resource handoff, and researcher self-care — plus how AI-moderated interviewing operationalizes safety at scale.