⇐ Back to Blog

Running Kids' Games in 2026: The Compliance Stack Nobody Priced Into Their Portal

Published on August 13, 2026

Kids' games are now a compliance product. COPPA's amended rule, app store age signals and new state laws reset what it costs to run a children's game portal. Most operators are still running a 2019 stack against a 2026 rulebook, and the gap is expensive.

The last eighteen months rewrote the rules for anyone who puts a game in front of a player who might be under 13. Not incrementally. The FTC's amended COPPA Rule hit full compliance in April, Apple rebuilt its age rating system, Google Play started handing developers the player's age band, and Texas made age verification at the app store a legal requirement that survived all the way to the Supreme Court. If your kids' catalogue is monetised the same way it was two years ago, you are carrying risk you have not priced.

This is the operational version of that story: what actually changed, what it does to your revenue per player, and the specific ways portal operators are getting it wrong.

⚖️ What the Amended COPPA Rule Actually Requires Now

The FTC finalised the first substantive changes to the COPPA Rule since 2013. The amendments were announced in January 2025, published in the Federal Register on 22 April 2025, took effect 23 June 2025, and carried a full compliance deadline of 22 April 2026. That date has passed. Whatever gap is still in your stack is exposure, not runway.

Four changes matter most if you operate a portal or license a catalogue:

  • Consent is no longer one box. You need separate verifiable parental consent before using a child's data for targeted advertising, and separate consent again before disclosing that data to third parties. The old bundled "I agree" that covered collection and downstream sharing in one click does not survive.
  • Personal information got wider. The definition now expressly includes biometric identifiers — face templates, fingerprints, voiceprints, retina scans — and government-issued identifiers. If a game captures voice input or a photo for an avatar, that is in scope.
  • You cannot keep it forever. Operators must have a written retention policy, keep children's data only as long as reasonably necessary for the purpose it was collected for, and delete it after. Indefinite retention is out.
  • "Mixed audience" is now a defined category. The Rule formally recognises services that target a general audience but attract children, and allows limited collection for the purpose of determining age before consent is triggered. This is the most useful change for portal operators — but it is a narrow carve-out, not a loophole.

Note what did not change: contextual advertising. Ads served against the content of the page rather than a profile of the player remain permissible under the support-for-internal-operations carve-out, without separate consent. That single fact drives most of the economics below.

💸 The Revenue Hit Nobody Wants to Model

Here is the uncomfortable arithmetic. Child-directed inventory can only be sold contextually. Contextual inventory prices below behaviourally targeted inventory, everywhere, always, because the buyer knows less about who they are reaching.

I am not going to give you a multiplier, because there isn't a credible public one. You will find blog posts quoting confident percentage drops and neat RPM comparisons for kids' content versus general content. Trace those numbers and they lead to vendor marketing pages and secondhand summaries, not audited data. Ad tech does not publish clean child-directed versus general-audience eCPM benchmarks, and the honest answer is that the gap varies enormously by geography, format and season.

What you can rely on is the direction and the mechanism, and you should model your own numbers rather than borrow someone else's:

  • Run a real test. Serve a slice of your kids' traffic contextual-only and compare against your blended rate. That measured delta is the only figure worth putting in a business plan.
  • Assume rewarded video holds up better than display. It is a value exchange the player opts into, and its pricing depends less on targeting.
  • Assume your ad mediation stack needs work. Many demand sources will not bid on child-directed inventory at all, which thins the auction before targeting even enters the picture. Fewer bidders is often the bigger effect.

The strategic conclusion follows directly: if a meaningful share of your catalogue is child-directed, advertising alone is a weak primary model. Operators running kids' content profitably tend to lean on subscription, carrier bundles, B2B licensing or sponsorship instead — models where revenue does not depend on knowing who the player is. Our monetization guidance covers how those mixes get built.

📱 The App Stores Now Tell You How Old the Player Is

This is the structural change most licensors have not absorbed. For twenty years, "we didn't know they were children" was a defensible position for a general-audience service. That defence is being dismantled by the platforms themselves.

Apple rebuilt its ratings

In July 2025 Apple overhauled App Store age ratings, adding 13+, 16+ and 18+, removing the old 12+ and 17+, and keeping 4+ and 9+. Every app had to complete an expanded ratings questionnaire — covering in-app controls, capabilities, medical and wellness topics, and violent themes — by 31 January 2026, or lose the ability to ship new submissions and updates. Apple also shipped a Declared Age Range API so apps can receive a player's age band directly.

Google Play is rolling age signals out worldwide

On 29 July 2026, Google announced it was expanding the Play Age Signals API to all developers globally. Parents share a child's age range from Family Link; the app receives a band — 0-12, 13-15, 16-17 or 18+ — rather than a birthdate. It launched in Brazil, extended to Australia and Canada, and is going global. Separately, since 28 January 2026, apps offering real-money gambling or dating have had to use Play's Restrict Declared Minors setting.

Texas made it law, and it stuck

Texas SB 2420, the App Store Accountability Act, was signed in May 2025 and took effect 1 January 2026. It requires app stores to verify age category at account creation — Child under 13, younger teenager 13-15, older teenager 16-17, adult 18+ — obtain parental consent for minors before downloads and in-app purchases, and pass that age and consent information to developers.

The law was challenged immediately. A federal district court blocked it in December 2025; the Fifth Circuit suspended that block in June 2026; and on 6 July 2026 the Supreme Court declined to reinstate it, with no public dissents. It is being enforced while the constitutional appeal continues. Louisiana passed a comparable law and other states have followed.

Read those three developments together and the consequence is obvious. Platforms are now pushing verified age signals to developers. Receiving a signal that says 0-12 gives you actual knowledge that you are dealing with a child, and actual knowledge is the exact trigger that pulls a general-audience service into COPPA. The industry spent two decades building plausible deniability about player age. The plumbing that destroys it is shipping globally this year.

🌍 The UK and EU Layer Is Not Optional Either

If you serve European traffic — and any open HTML5 games portal does, whether or not you targeted it — two more regimes apply.

  • UK Online Safety Act. Age assurance duties became enforceable on 25 July 2025, with Ofcom requiring "highly effective age assurance" for certain content and children's risk assessments from services likely to be accessed by children. Penalties run to £18 million or 10% of global turnover, whichever is higher, plus business disruption orders. Ofcom has said plainly that online gaming is a fundamental form of children's entertainment, which tells you where it is looking.
  • ICO Children's Code. Applies to any service likely to be accessed by children in the UK. High privacy by default, profiling and geolocation off, minimal data collection, no manipulative design patterns, age-appropriate privacy information. "Likely to be accessed" is a much lower bar than "targeted at."
  • EU DSA minors guidelines. The European Commission published guidelines on the protection of minors online on 14 July 2025. They address age assurance, discourage manipulative design such as countdown timers and pressure-to-purchase prompts, and take a hard line on gambling-like mechanics including loot boxes.

The common thread across all three is design, not just data. A game that is technically privacy-compliant but leans on urgency timers and randomised paid rewards is still a regulatory problem in Europe.

🔨 What Enforcement Costs When It Lands

In January 2025 the FTC settled with Cognosphere, the publisher behind Genshin Impact, for $20 million. The complaint covered COPPA violations — marketing to children and collecting their data without parental consent — alongside deceptive disclosure of loot box odds and costs. The settlement bars selling loot boxes to under-16s without parental consent and forced an age-verification rebuild.

Two things about that case are worth internalising. First, the privacy claim and the monetization-design claim arrived together, because regulators increasingly treat them as one problem. Second, the operational remedies — rebuild age verification, gate purchases, change disclosure — cost more to retrofit under a consent decree than they would have cost to build correctly.

🚫 How Portal Operators Get This Wrong

Patterns worth naming, because they repeat:

  • Treating "mixed audience" as a get-out. A general-audience portal with a cartoon and kids section, cartoon art direction and playground search traffic is not going to convince anyone it was surprised by child visitors. The carve-out is for age determination, not for avoiding the question.
  • Age gates that are decoration. A dropdown asking for birth year, with no neutral presentation and no persistence, tells a regulator you knew the issue existed and chose theatre. If you gate, gate neutrally and remember the answer.
  • Assuming the licensor carries the compliance risk. They don't. A licence grants you rights to publish content. Data collected through your portal, your analytics, your ad stack and your accounts is your responsibility as the operator. Check what SDKs ship inside licensed builds — that is a due diligence question to ask before signing, not after an audit.
  • Running one ad configuration across the whole catalogue. If kids' titles and general titles share a mediation setup with behavioural targeting on, the kids' titles are non-compliant. Child-directed traffic needs its own tagging and its own demand path.
  • "We're not a US company." COPPA reaches services directed to US children regardless of where the operator sits, and the DSA applies to platforms available in the EU regardless of establishment. Geography of incorporation is not a defence.
  • Ignoring the platform signal because you only do web. Age assurance expectations are converging across web and app. The store APIs are simply where verified signals appeared first.

📋 A Working Checklist Before You Ship Kids' Titles

  1. Classify every title in the catalogue: child-directed, mixed audience, or general. Write down the reasoning. That record is the first thing anyone will ask for.
  2. Inventory what each build actually collects, including third-party SDKs bundled inside licensed games.
  3. Split your ad stack. Tag child-directed traffic and route it to contextual-only demand.
  4. Implement separate consent flows — one for targeted advertising, one for third-party disclosure. Not one checkbox.
  5. Write and publish a retention policy with actual timeframes, and build the deletion job that enforces it.
  6. Handle every state the platform age APIs can return: verified adult, supervised minor, pending approval, denied, self-declared, no signal.
  7. Complete a children's risk assessment if you have UK traffic.
  8. Audit monetization design against the EU guidance — countdown pressure, randomised paid rewards, dark patterns.
  9. Re-run all of the above whenever you add a market or a demand partner.

🧭 Where This Leaves the Business Case

Kids' games remain one of the most durable categories in casual gaming. Demand is steady, seasonality is predictable, and brand partners keep commissioning them. What changed is that the category now has a compliance cost of goods, and that cost is real enough to belong in the model next to hosting and licensing.

The operators who will do well here are the ones who treat that as a moat rather than a tax. Building the classification, the consent flows and the split ad stack once is a fixed cost. Competitors who skipped it are running a business with an undated liability in it, and their advantage on margin evaporates the first time a regulator or a demand partner asks a question they cannot answer.

If you are licensing content into a kids-facing product, make compliance part of the due diligence conversation before the commercial one. Ask what each build collects, what SDKs are embedded, what the licensor will change on request, and what documentation comes with it. Forestry Games has licensed HTML5 and Android titles since 2017, including work on branded IP where approval and content-suitability review are part of the delivery process — and the catalogue and licence terms are worth reviewing with these questions in hand. Start with the kids and cartoon category and the white-label portal options, and bring the checklist above to the first call.