---
title: Pixalate Exposes Widespread COPPA Violations in New Verifiable Parental Consent (VPC) Report Q2 2025
description: "Pixalate Exposes Widespread COPPA Violations in New Report: 99% of U.S.-Registered Apple App and Google Play Store Likely Child-Directed Apps Fail to Obtain Required Verifiable Parental Consent (VPC)"
image: https://www.pixalate.com/hubfs/Q2%202025%20Verifiable%20Parental%20Consent%20(VPC)%20Failures%20under%20COPPA%20in%20Mobile%20Apps.png
---

[![pixalate-full-logo](https://www.pixalate.com/hs-fs/hubfs/Pixalate_Logos/pixalate-full-logo.jpg?width=150&height=60&name=pixalate-full-logo.jpg "pixalate-full-logo")](https://www.pixalate.com)

Search

**Menu**

** **

![](https://www.pixalate.com/hubfs/Blog_Media/Blog%20photos/pixalate-blog-bg.png)

[Mobile Apps](https://www.pixalate.com/blog/topic/mobile-apps) | [Privacy](https://www.pixalate.com/blog/topic/privacy) | [coppa](https://www.pixalate.com/blog/topic/coppa) |

 3 min read

# Pixalate Exposes Widespread COPPA Violations in New Report: 99% of U.S.-Registered Apple App and Google Play Store Likely Child-Directed Apps Fail to Obtain Required Verifiable Parental Consent (VPC)

 Written by [Pixalate](https://www.pixalate.com/blog/author/pixalate)

 Sep 25, 2025 1:00:00 PM

*According to Pixalate's research, Google Ad Exchange is listed in 90% of likely non-compliant apps' ads.txt files (apps enabled for advertising), Meta/Facebook in 58%, and AppLovin in 54%*

LONDON, September 25, 2025 -- Pixalate, the leading global platform for ad fraud protection, privacy, and compliance analytics, today released its [Q2 2025 Verifiable Parental Consent Failures In Mobile Apps Report](https://www.pixalate.com/verifiable-parental-consent-vpc-failures-under-coppa-in-mobile-apps). The report exclusively examines mobile apps on the Apple App Store and Google Play Store that are registered in the U.S. and likely aimed at children under 13 (i.e., Child-Directed) but do not collect Verifiable Parental Consent (VPC), potentially violating the [Children’s Online Privacy Protection Act ](https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa)(COPPA).

This report highlights potential privacy violation risks for app developers under COPPA, specifically concerning the collection, sale, or sharing of children’s personal information through likely Child-Directed apps without obtaining lawful VPC, as assessed by Pixalate. The Federal Trade Commission (FTC)’s  COPPA Rule governs the online collection, use, and disclosure of personal information from children under 13 in the United States (U.S.). It also outlines multiple acceptable methods for obtaining a VPC.

## **Key Findings Raise Concerns About Children’s Data Privacy**

The legal analysis, conducted by Pixalate’s legal and data science teams, examined 1,149 U.S.-registered, likely Child-Directed Google Play and Apple App Store-hosted apps with advertising capabilities:

- **99%** Non-Compliance Rate: 1,136 out of 1,149 manually reviewed Google Play and Apple App Store-hosted apps failed to obtain VPC under the COPPA Rule, as assessed by Pixalate 
    - Apple App Store violations: **866** of 877 examined Apple iOS-hosted apps (99%) lacked lawful VPC mechanisms
    - Google Play Store Violation: **270** out of 272 examined Google Play-hosted apps lacked lawful VPC mechanisms

## Additional Personal Information Sharing Violations Discovered in Likely Child-Directed Apps without VPC Measures:

- **40%** of the apps shared device IDs in the ad bidstream
- **42%** of the apps transmitted IP addresses in the ad bidstream
- **34%** disclose location information in the ad bidstream
- **31%** of the apps transmitted all three types of personal information in the ad bidstrea

## Advertising Supply Chain Implications

**  
**The report identifies major advertising platforms facilitating monetization within these likely non-compliant apps:

- **Google Ad Exchange:** Listed in app-ads.txt files of 1,019 (90%) likely non-compliant apps
- **Meta/Facebook:** Present in 658 (58%) likely non-compliant apps
- **AppLovin: **Associated with 619 (54%) likely non-compliant apps

To learn more about our other recent investigation into COPPA violations, please see the [report](https://www.pixalate.com/verifiable-parental-consent-vpc-failures-under-coppa-in-mobile-apps).

Top 10 U.S.-Registered Apps without VPC - Apple App Store

Top 10 U.S.-Registered Apps without VPC - Google Play Store

“App developers collecting and sharing children’s personal information without obtaining VPC signifies the apparent failure to comply with COPPA’s express compliance obligations,” said Shanzay Javaid, Data Protection & Privacy Counsel at Pixalate. “Despite recent amendments to the COPPA Rule, this systematic non-compliance exposes the entire advertising supply chain, including supply-side platforms and downstream advertising partners, to regulatory risks.”

To compile this research, Pixalate’s legal and data science teams employed automated processing combined with manual reviews by its Trust & Safety Advisory Board to assess nearly 134,000 apps with ads* (i.e., those with open programmatic traffic and ad impressions in the United States) available for download from the Google Play Store and Apple App Store in Q2 2025.

Download Pixalate’s Verifiable Parental Consent Failures In Mobile Apps report.

[![VPC - Verifiable Parental Consent Failures In Mobile Apps](https://no-cache.hubspot.com/cta/default/2364596/c6a9e456-a1c6-4312-9390-23b2bbba5664.png)](https://cta-redirect.hubspot.com/cta/redirect/2364596/c6a9e456-a1c6-4312-9390-23b2bbba5664)

**About Pixalate**

Pixalate is a global platform specializing in privacy compliance, ad fraud prevention, and digital ad supply chain data intelligence. Founded in 2012, Pixalate is trusted by regulators, data researchers, advertisers, publishers, ad tech platforms, and financial analysts across the Connected TV (CTV), mobile app, and website ecosystems. Pixalate is accredited by the MRC for the detection and filtration of Sophisticated Invalid Traffic (SIVT). [pixalate.com](https://www.pixalate.com/)

**Disclaimer**

*The content of this press release, and the COPPA VIOLATION CRISIS: Verifiable Parental Consent Failures In Mobile Apps report (the “Report”), reflect Pixalate's opinions with respect to factors that Pixalate believes may be useful to the digital media industry. Any data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate's opinions are just that, opinions, which means that they are neither facts nor guarantees. It is important to note that the mere fact that an app appears to be directed to children or is deemed likely child-directed (e.g., data subjects under 13 years of age, as defined by COPPA), or appears not to obtain VPC (e.g. as per the COPPA Rule)  does not mean that any such app, or its operator, is failing to comply with COPPA. Further, with respect to apps that appear to be directed to children and have characteristics that, in Pixalate’s opinion, may trigger related privacy obligations and/or risk, such assertions reflect Pixalate’s opinions (i.e., they are neither facts nor guarantees); and, although Pixalate’s methodologies used to render such opinions are derived from automated processing, which at times is coupled with human intervention, no assurances can be – or are – given by Pixalate with respect to the accuracy of any such opinions. Pixalate is sharing this data not to impugn the standing or reputation of any entity, person or app, but, instead, to report findings and trends pertaining to programmatic advertising activity in the time period studied.*

### Search Blog

Search

### Follow Pixalate

<https://twitter.com/pixalateinc> <https://www.linkedin.com/company/pixalate> <https://www.facebook.com/pixalate> [**](https://www.pixalate.com/hubfs/Pixalate%20Wechat.png?utm_campaign=Company%20News&utm_medium=email&_hsenc=p2ANqtz-_ZtCSHiG6VOXsk-H9wZxOKVhNZxU_38xbLSOf7jCI9cht_GS6NejKw3dZ_BY3kYiwF7Hc9ZWlilTmIVK5YSB9-baUW2w&_hsmi=336270631&utm_content=336270631&utm_source=hs_email)

### Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use ](https://www.pixalate.com/terms)and [Privacy Policy.](https://www.pixalate.com/privacypolicy)

Previous Story

[← Pixalate’s Global Q2 2025 Ad SDK Market Share Rankings: IAB OMSDK (95%) Leads Among Google Play Store Apps, AppLovin (87%) No. 1 on Apple App Store Apps](https://www.pixalate.com/blog/pixalate-releases-q2-2025-mobile-sdks-market-share-report)

[** ](https://www.pixalate.com/blog)

Next Story

[Pixalate’s August 2025 Canada Publisher Rankings for Websites, Mobile and CTV Apps: bbc.com, ‘Vita Mahjong’, and ‘Tubi’ Among Top-Ranked for Open Programmatic Ad Traffic Quality →](https://www.pixalate.com/blog/august-2025-canada-publisher-trust-rankings)

## You May Also Like

These Stories on Mobile Apps

[![](https://www.pixalate.com/hubfs/Abandoned%20Mobile%20Apps%20Report%20-%20blog%20cover.png) ](https://www.pixalate.com/blog/pixalate-releases-may-2026-global-abandoned-mobile-apps-report)

[Mobile Apps](https://www.pixalate.com/blog/topic/mobile-apps)

### [Pixalate Releases May 2026 Global Abandoned Mobile Apps Report: “Draw In™” at the top on Apple App Store, “GUNSHIP BATTLE: Helicopter 3D” tops Google Play Store](https://www.pixalate.com/blog/pixalate-releases-may-2026-global-abandoned-mobile-apps-report)

 Jun 24, 2026 9:00:02 AM |

 3 min read

[![](https://www.pixalate.com/hubfs/Blog%20Media/2026%20Covers%20and%20Images/MONTHLY%20MOST%20COMMON%20MOBILE%20AD%20FRAUD%20TYPES%20GOOGLE%20-%20APPLE%20BLOG%20COVER.png) ](https://www.pixalate.com/blog/pixalates-may-2026-most-common-mobile-app-ad-fraud-types)

[Ad Fraud](https://www.pixalate.com/blog/topic/ad-fraud)

### [Pixalate Releases May 2026 Most Common Mobile App Ad Fraud Types: ‘High Risk Device ID’ Most Common Type Across Google Play Store (32%); ‘High Risk IP’ Most Common on Apple App Store (48%)](https://www.pixalate.com/blog/pixalates-may-2026-most-common-mobile-app-ad-fraud-types)

 Jun 9, 2026 9:00:00 AM |

 2 min read

[![](https://www.pixalate.com/hubfs/Blog%20Media/2026%20Covers%20and%20Images/MONTHLY%20TOP%20MOBILE%20AD%20FRAUD%20TYPES%20GOOGLE%20-%20APPLE%20BLOG%20COVER.jpg) ](https://www.pixalate.com/blog/pixalates-april-2026-most-common-mobile-app-ad-fraud-types)

[Ad Fraud](https://www.pixalate.com/blog/topic/ad-fraud)

### [Pixalate Releases April 2026 Most Common Mobile App Ad Fraud Types: ‘High Risk Device ID’ Most Common Type Across Google Play Store (28%); ‘High Risk IP’ Most Common on Apple App Store (23%)](https://www.pixalate.com/blog/pixalates-april-2026-most-common-mobile-app-ad-fraud-types)

 May 18, 2026 9:00:00 AM |

 2 min read

**

### Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use ](https://www.pixalate.com/terms)and [Privacy Policy.](https://www.pixalate.com/privacypolicy)

![pixalate-logo-red-small](https://www.pixalate.com/hs-fs/hubfs/2018NewTemplate/pixalate-logo-red-small.png?width=208&name=pixalate-logo-red-small.png "pixalate-logo-red-small")

**

 By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy)

Products

[Analytics](https://www.pixalate.com/products/analytics) [Blocking](https://www.pixalate.com/products/blocking) [Media Rating Terminal](https://www.pixalate.com/products/mrt) [Publisher Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex) [Seller Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex) [IoT Device Rankings](https://www.pixalate.com/rankings/?group=app&reportId=iotDeviceReach)

Resources

[Blog](https://blog.pixalate.com/) [Press](https://www.pixalate.com/press) [Careers](https://www.pixalate.com/jobs) [Team](https://info.pixalate.com/pixalate-leadership-team)

Contact

Email

[** sales@pixalate.com ](mailto:sales@pixalate.com)

[** privacy@pixalate.com ](mailto:privacy@pixalate.com)

US:

[** +1 888 749 2528 ](tel:+1%20888%20749%202528)

EU:

[** +44 (0)800 011 2050 ](tel:+44%20(0)800%20011%202050)

Slack:

[Join ATSAPI Slack Channel ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

Offices

Global Offices

US

1775 Greensboro Station Place, Suite 425, McLean, VA 22102

UK

20 North Audley Street   
London, W1K 6WE, United Kingdom

EU

10 Earlsfort Terrace   
Dublin 2, D02 T380, Ireland

Singapore

10 Anson Road, #22-02 International Plaza, Singapore 079903

[![facebook](https://www.pixalate.com/hubfs/footer/icons/facebook.png) ](https://www.facebook.com/pixalate) [![x](https://www.pixalate.com/hubfs/footer/icons/twitter-x.png) ](https://twitter.com/pixalateinc) [![linkedin](https://www.pixalate.com/hubfs/footer/icons/linkedin.png) ](https://www.linkedin.com/company/pixalate) ![wechat](https://www.pixalate.com/hubfs/footer/icons/wechat.png) [![slack](https://www.pixalate.com/hubfs/footer/icons/slack.png) ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

[Terms of Use](https://www.pixalate.com/terms) [Privacy Policy](https://www.pixalate.com/privacypolicy) [GDPR Compliance](https://www.pixalate.com/gdpr) Disclaimer

Copyright © 2025 Pixalate

[Back to top **](https://www.pixalate.com/blog/pixalate-exposes-widespread-coppa-violations-in-new-verifiable-parental-consent-vpc-report-q2-2025#)

# Disclaimer

 Disclaimer: The content of this page reflects Pixalate’s opinions with respect to the factors that Pixalate believes can be useful to the digital media industry. Any proprietary data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate’s opinions are just that - opinion, not facts or guarantees.

 Per the MRC, “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes. Also per the MRC, “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”

**

**

*By clicking Download and entering your email address, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and have read and acknowledge our [Privacy Policy](https://www.pixalate.com/hubfs/2024-08-20_Pixalate_Privacy_Policy.pdf).

*Copyright © 2025 Pixalate** *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

*

×

## Subscribe to the Pixalate Blog

The first step in ad fraud prevention.

Loading...

 By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy).

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Contact Us12

Loading...

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Download GSTI

Loading...

Schedule your demo today

Please complete all fields

Loading...

By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy).

*

* *

*

*