The Children’s Online Privacy Protection Act (COPPA), which regulates how online services collect and use information from children under 13, is one of the United States’ only cross-sectoral privacy laws. It’s a federal law that has existed for over 20 years, but laws are only as good as their enforcement. As the number of mobile apps designed for children surged in the mid-2010s and toddlers began toting around iPads like a favorite stuffed animal, Serge Egelman wondered whether all those apps were actually following the law.
Rather than reading lengthy and ambiguous privacy policies, Egelman—starting at UC Berkeley and later growing out a team at ICSI—focused on assessing how apps actually behave. With funding from the National Science Foundation, Department of Homeland Security, and National Security Agency, Egelman and colleagues developed a custom version of a smartphone operating system that allowed them to monitor information exchanged between apps and mobile devices. Analyzing some 6,000 kid-oriented mobile apps, the researchers discovered a majority exhibited behaviors that could run afoul of COPPA, including location-tracking and targeted ads.
Their findings, documented in a paper recognized with the Caspar Bowden Award for Outstanding Research in Privacy Enhancing Technologies, exposed critical gaps in COPPA enforcement and drew attention from developers, app marketplaces, and regulators. Immediately after publication, Google and Apple implemented new rules for children’s apps distributed through their marketplaces and the Federal Trade Commission opened a process to revisit regulations surrounding COPPA. Several regulators and plaintiffs’ attorneys filed federal lawsuits against app developers and third-party data recipients, all either citing the paper or using Egelman’s data.
In 2019, the researchers used their technology as the basis for AppCensus, a startup that builds tools for use by enterprise customers, governments, litigators, and consumer-advocacy groups to check mobile app compliance with a range of relevant privacy and security regulations. Egelman says COPPA noncompliance rates are now drastically reduced, though keeping on top of mobile privacy violations requires continued vigilance and tools to empower both app developers and those responsible for enforcing the rules. In one follow-on project, the team uncovered numerous privacy vulnerabilities in Android apps, earning them bug bounties from Google, a USENIX Distinguished Paper Award and recognition from multiple international data protection authorities.
What made ICSI a good place to pursue these projects?

“The main thing is having the freedom to do the work. Once you get the grant money to pursue a project, you can just focus on doing the project. ICSI is free of a lot of the bureaucracy you encounter on a university campus, for example.
ICSI also incubated our startup, AppCensus, and is our only external shareholder beyond the four founders. Since we had customers from day one, that allowed us to grow the company without pursuing more funding or having to sacrifice our values in doing so.”
Serge Egelman
Senior Research Scientist and Group Lead for Usable Privacy and Security, ICSI
This story was published in January 2026 as part of a retrospective series highlighting ICSI’s accomplishments and impacts over the years. To learn about our ongoing work, explore our Core Research Themes.
