ANALYSIS (no court or agency has ruled)
There is a federal law about collecting personal information from children online. It is called the Children’s Online Privacy Protection Act, it is enforced by the Federal Trade Commission, and Bricks & Minifigs knows it by name: the company wrote a section headed “Age Verification & COPPA Compliance” into the rules of one of its sweepstakes. It did not write one for the rewards club that records a child’s birthday, for the birthday parties it books for five-year-olds, or into the privacy policy on its store websites, which tells the reader the site is “not intended for children under 13.” A company that plans, in its own operations manual, for “a lot of children in our stores” is telling the law the children are not there. This post reads the documents against each other. Whether they add up to a violation is a question the Commission decides, and it has not been asked here.
Why this belongs on this site. The rest of this reporting reads the company’s own records against each other: its disclosure documents, the operations manual it published, the storefronts it runs. Children’s data is the one class of customer information a specific federal rule protects, with penalties counted by the child. So it is worth setting down, side by side, what the company says about children when it is selling to them and what it says about children when it is describing how it handles their data.
CONFIRMED (the giveaway’s own rules)
Start with the document that settles what the company knows. The official rules of the Bricks & Minifigs MegaCon Orlando 2026 giveaway carry a section of their own, headed “Age Verification & COPPA Compliance,” which reads: “This Sweepstakes is intended for adults aged 18 and older. Sponsor does not knowingly collect or store personal information from individuals under the age of 13. If Sponsor discovers that an entry has been submitted by an individual under the age of 18, or if a parent or guardian informs Sponsor that a minor has submitted personal information, that entry will be immediately deleted and disqualified from the Sweepstakes.” That is a children’s-privacy notice, written on purpose, naming the statute, for a one-time contest. It establishes three things at once: the company knows COPPA exists, the company knows how to write an age gate, and the company decided where to put one. It put it on the giveaway. It is not on the rewards enrollment, not on the party booking, and not in the store privacy policy.
CONFIRMED (BAM’s manual and store pages)
Who the customer is is not in dispute, because the company has already said. Its operations manual stocks the store bathroom with diapers and a step stool because, in the manual’s words, “we will have a lot of children in our stores,” and the customer chapter names the child “the conduit to the parents” the store buys from. The storefronts match the manual. A Bricks & Minifigs birthday party is booked online through the store’s own shop, a deposit charged up front, for children the party pages put at “ages 5+.” The rewards program, free to join, is one the company invites a customer to “share…with the whole family,” and it records a birthday: the store pages promise a reward “on your birthday.” Subject matter, the toy every child associates with the word; child-oriented activities, the party and the build bar and the minifigure a child assembles to take home; incentives aimed at families and birthdays. These are the exact features the FTC’s rule tells the Commission to weigh.
CONFIRMED (the privacy policies)
The privacy policy on the store websites says the reverse of the manual. The Anaheim store policy, last updated in 2019, and the Salt Lake store policy, last updated in 2021, use the same words: the website “is not intended for children under 13 years of age,” “no one under age 13 may provide any personal information to or on the Website,” and “we do not knowingly collect personal information from children under 13.” The Grand Rapids store policy, updated five days before this post, on July 25, 2026, carries the same disclaimer in the newer form that the services “are not intended to be used by children.” The company’s own corporate privacy policy, last touched on May 28, 2019, does not mention children at all; the only child in it is a warning that some sets contain “small parts that are NOT suitable for…children under 3 years of age.” A store that plans for a lot of children tells the reader, in the one document that governs their data, that the children are not its audience.
ANALYSIS (the legal read)
The Children’s Online Privacy Protection Act makes it unlawful to collect personal information online from a child under 13 without first giving parents notice and getting “verifiable parental consent.” It reaches an operator two ways: a service “directed to children,” or any operator with “actual knowledge” that it is collecting a child’s information. No parental-consent step was found on the rewards enrollment, on the party booking, or anywhere on the store sites a child’s information is entered. The disclaimer does not close that gap; it may widen it. The word doing the work in “we do not knowingly collect” is “knowingly,” and knowledge is exactly what a party booking that names a child of a stated age, or a rewards account built around a birthday, supplies. The Federal Trade Commission has treated a birthdate entered at sign-up as exactly that kind of knowledge: in 2023 it required Microsoft to pay $20 million over charges that the Xbox sign-up collected children’s personal information, including their age, before a parent was ever asked. Whether the sites are “directed to children” is the harder question, decided on a list of factors, the subject matter, the child-oriented activities and incentives, the audience, that a company’s own disclaimer does not settle. The penalties are counted per child, up to $53,088 each in 2025; in that year the FTC obtained a $10 million penalty from a company that mislabeled child-directed content and let a child’s data be collected for advertising. This site does not assert that Bricks & Minifigs has crossed that line. It sets the documents down and lets the reader see how short the distance is.
The fair counterpoint. Nothing here is a finding that Bricks & Minifigs has violated COPPA or any privacy law, no court or agency has made that finding, and this site does not claim it has happened. Selling to families is lawful, a great many retailers do it, and a birthday field on a rewards program is ordinary. The “not intended for children under 13” line is a standard clause that ships inside countless Shopify privacy policies, and its presence is a template default rather than, by itself, an admission of anything. Whether these particular sites are “directed to children,” or are a mixed audience whose paying customers are mostly adult buyers and collectors, is a fact-specific question the Commission decides on the factors its rule lists, and it is the contestable part of this picture; the actual-knowledge route does not depend on it, but it, too, would have to be proven case by case. That the company wrote a careful COPPA section for one sweepstakes shows it can and does write children’s-privacy language when it turns to the question; it is not proof of what it did or did not do elsewhere, and a company may conclude in good faith that a given surface does not trigger the rule. Every document above is reproduced as written, on public pages the company controls and that are linked so a reader can check them. Nothing here is a finding of law, and every person and company named is presumed to have acted lawfully.
Sources. The Age Verification & COPPA Compliance section is quoted verbatim from the official rules of the Bricks & Minifigs MegaCon Orlando 2026 giveaway. The children’s clauses are quoted from the store privacy policies at Anaheim (updated June 19, 2019), Salt Lake (updated May 21, 2021), and Grand Rapids (updated July 25, 2026), each served over Shopify; the policy with no children’s provision is the corporate policy (updated May 28, 2019). The party terms are from the store party pages and the rewards terms from the store rewards pages. The manual’s “a lot of children in our stores” and “conduit to the parents” are quoted from the Bricks & Minifigs operations manual, reproduced and reported in the July 28 post and at The disclosure. On the law, the FTC’s children’s-privacy guidance and the COPPA Rule, 16 C.F.R. Part 312, including the “directed to children” factors and the definitions of “actual knowledge” and “verifiable parental consent”; the 2025 penalty is the FTC action announced here.
The BAM Map is independent reporting on matters of public concern. Nothing here is a finding of any person’s guilt; the criminal charges referenced are unadjudicated and every defendant is presumed innocent. Sources are linked so readers can check the record. · Home · Map · The law · Bodycam