Complex answer: How you determine if the person is under 13 and how you get the parents permission can be done a lot of different ways. Some of the most popular is doing a test charge against a credit card number, assuming kids won't have those.
I thought that there were 2 options with COPPA compliance: Allow <13s to register and have an email sent to their parents IF they select that they are under 13 OR disallow under 13s through a terms of service "Do not register if you are under 13" type clause. Is that not compliant?
Absolutely categorically not.
A ToS clause alone has been tested and found not compliant.
For a while, when the ToS clause was tested and failed, the panic reaction acid test was asking for a valid CC.
Over the past decade best practice has relaxed to a gating page asking for confirmation of over age, or, for the more cautious, asking for the user to explicitly provide their birth year (not birthday).
You only have to take action to get parent's permission if:
a) Your site or app is very specifically targeting children (LEGO or Disney for example)
b) You have asked for some information from the user that positively identifies them as a child - birthdate is the main one
Path were fined because they asked for birthdate during the signup process and then allowed registration even if the user was under 13.
It is unlawful for an operator of a website or
*online service directed to children*, or any operator
that has *actual knowledge that it is collecting
personal information from a child*, to collect personal
information from a child in a manner that violates the
regulations prescribed under subsection (b) of this section.
So either:* service directed to children (LEGO, Disney etc) * actual knowledge that it is collecting information from a child (birthdate, age etc)
My understanding was from internal legal guidance at a previous company I consulted for but I haven't worked on COPPA projects for a few years so I don't know if there have been any major cases.
In any event Path specifically asked for birthdates and then allowed children to carry on and use the service with no changes which is a violation that should have been spotted by anyone with some understanding of COPPA.
Then you can CFAA those little twerps.