A working group at the Institute of Electrical and Electronics Engineers (IEEE) is developing a new framework for verifying parental consent online, according to a report from Biometric Update. The effort reflects a broader shift happening across the tech and regulatory world: the rules that have governed children's data online for roughly three decades, largely built around the Children's Online Privacy Protection Act (COPPA), are being reconsidered for a very different internet than the one they were written for.

Why COPPA Needs a Modern Parental Consent Standard

COPPA was written to require companies to obtain verifiable parental consent before collecting personal data from children. But the law predates smartphones, social media, app stores, and the sprawling ecosystem of platforms that now ask users, of all ages, to prove who they are and how old they are. Enforcement has often relied on simple checkbox consent or self-reported birthdates, methods that offer little real assurance that a parent, rather than a child, is on the other end of the transaction.

That gap has become more visible as governments push new age assurance laws that go beyond COPPA's original scope. Age verification mandates are now spreading across states and countries, often with little coordination on what counts as adequate proof of age or consent. As we've covered in our look at the global patchwork of age verification privacy risks, the absence of a shared technical standard has left companies building their own inconsistent systems, some of which collect more personal data than the law requires just to prove compliance.

An industry standard for parental consent could help close that gap by giving companies, regulators, and platforms a common reference point for what "verified" consent actually looks like, rather than leaving each jurisdiction and each company to define it independently.

What the IEEE Working Group Is Trying to Build

According to the reporting, the working group's goal is to create a framework specifically focused on verifying that a parent or guardian has genuinely authorized a child's use of an online service, distinct from the broader question of verifying a user's own age. This is a meaningful distinction. Age verification asks "how old is this person?" Parental consent verification asks a different question: "does this account belong to a minor whose parent has actually agreed to the terms?"

Building a standard around that second question is harder in some ways, because it requires establishing a verified relationship between two people, not just confirming a single person's age. It also means the standard has to account for varying levels of assurance. A lightweight email confirmation offers weaker proof than a government-ID-linked verification, and different services may need different levels depending on the sensitivity of the data being collected.

Privacy Implications of Verifying Parental Consent

Any system built to verify who someone is, or who they are related to, inevitably raises privacy questions. A parental consent framework that relies on stronger identity proofing, such as document uploads or biometric checks, could mean parents are asked to hand over more personal data than a simple checkbox ever required. That tradeoff, more assurance in exchange for more data collection, is the central tension running through nearly every age assurance debate right now.

It echoes concerns raised in New York, where the SAFE for Kids Act sets measurable accuracy requirements for age-check technology, forcing companies to demonstrate their systems actually work rather than just claim compliance. A well-designed IEEE standard could push the industry toward similar accountability for parental consent tools, specifying not just that consent is collected, but how reliably and how minimally.

The stakes of getting this wrong are real. Australia's experience with its under-16 social media restrictions showed that enforcement gaps can undercut the intent of a law entirely, with account numbers dropping even as verification checks remained largely untested. A parental consent standard that is too weak risks the same outcome: rules on paper that don't hold up in practice. One that is too invasive risks turning child protection efforts into a new source of family data exposure.

What This Means For You

If you're a parent, expect to see more services asking you to verify your identity, not just your child's, before granting account access. This may involve document checks, credit card verification, or other identity-proofing steps that go beyond the current "click to confirm you're an adult" model. Understanding why a service is asking, and what data it retains afterward, will become more important as these systems roll out.

If you're simply a user of platforms affected by age assurance rules, it's worth paying attention to how much personal information any verification step actually requires. A parental consent standard, done well, should reduce unnecessary data collection by giving companies a clear, minimal bar to meet, rather than encouraging them to over-collect out of legal caution.

Key Takeaways

The IEEE's work on a parental consent standard is still in development, and its final form will determine whether it improves privacy protections or simply formalizes new data collection. As COPPA-era rules give way to more rigorous age assurance regimes, families and platforms alike will benefit from clear, consistent standards rather than a patchwork of competing compliance approaches. Readers should watch for how any resulting standard balances verification strength against data minimization, and should feel empowered to ask platforms directly what parental consent data they collect and how long they keep it.