Skip to main content

Children’s Internet Protection Act

The Children’s Internet Protection Act establishes internet-safety requirements for schools and libraries receiving certain discounts through the federal E-Rate program. Its central requirements involve an internet-safety policy, technology protection measures, and a public process for adopting the policy.

CIPA at a Glance

Congress enacted CIPA in 2000. The Federal Communications Commission adopted implementing rules in 2001 and later updated them to include education for students about appropriate online behavior, social networking, chat rooms, and cyberbullying awareness and response.

Who must comply?

CIPA applies to schools and libraries seeking E-Rate discounts for Category One internet access and Category Two services, including eligible internal connections, managed internal broadband services, and basic maintenance of internal connections. Applicants receiving discounts only for telecommunications services are generally not subject to CIPA.

Requirement 1

Internet-safety policy

Adopt and enforce a policy addressing the internet-safety topics specified by CIPA.

Requirement 2

Technology protection

Use a technology measure that blocks or filters access to specified visual depictions.

Requirement 3

Public process

Provide reasonable public notice and hold at least one hearing or meeting before adopting the policy.


Required blocking or filtering

The technology protection measure must block or filter internet access to visual depictions that fall within the following categories:

Obscenity

Visual depictions meeting the applicable federal legal definition of obscenity.

Child pornography

Visual depictions meeting the applicable federal definition of child pornography.

Harmful to minors

An additional category that applies when computers with internet access are used by minors.

CIPA focuses on visual depictions

CIPA’s federal filtering requirement is tied to the statutory categories of visual material. A school or library may adopt broader local filtering rules, but those additional choices should not automatically be described as federal CIPA requirements.

What the policy must address

  • Access by minors to inappropriate material on the internet and World Wide Web.
  • The safety and security of minors using email, chat rooms, and other forms of direct electronic communication.
  • Unauthorized access—including “hacking”—and other unlawful online activities by minors.
  • Unauthorized disclosure, use, and dissemination of personal information concerning minors.
  • Measures designed to restrict minors’ access to material harmful to them.

Local school boards, educational agencies, libraries, or other responsible authorities determine what additional matter is inappropriate for minors in their communities.

Additional requirements for schools

A school’s internet-safety policy must include monitoring the online activities of minors. Schools must also educate minors about appropriate online behavior, including interactions on social-networking websites and in chat rooms, as well as cyberbullying awareness and response.

Public notice and adoption

Before adopting the required internet-safety policy and technology protection measure, the responsible school or library authority must provide reasonable public notice and hold at least one public hearing or meeting addressing the proposal. Private schools provide notice to their appropriate constituent group.

Once an entity has satisfied CIPA’s public notice and hearing requirement for a compliant policy, CIPA generally does not require another hearing each time the policy is amended. State law, local rules, or the policy itself may impose additional meeting requirements.

Common CIPA Questions

Must every adult’s internet access remain filtered?

An administrator, supervisor, or other authorized person may disable the technology protection measure during use by an adult to permit bona fide research or another lawful purpose. Local procedures should define who is authorized and how requests are handled.

Does monitoring mean tracking everyone’s browsing history?

No specific federal method of monitoring is prescribed, and CIPA does not require schools or libraries to maintain individually identifiable records of every website visited. Schools should define an appropriate monitoring approach while also considering privacy, security, records-retention rules, and local policy.

Does CIPA apply to every school and library?

No. Its requirements are tied to receiving specified E-Rate discounts. Schools and libraries outside that scope may still be subject to state laws, local policies, acceptable-use rules, and other internet-safety obligations.

Does a filtering product by itself establish compliance?

No. Filtering is only one part of CIPA. Covered entities also need an enforceable internet-safety policy, the required public notice and meeting, appropriate certifications, and—in schools—monitoring and student education.

A Practical CIPA Compliance Checklist

  • Confirm whether the requested E-Rate services trigger CIPA.
  • Maintain a current internet-safety policy containing every required topic.
  • Document public notice, the hearing or meeting, and formal policy adoption.
  • Confirm that filtering operates on covered computers with internet access.
  • Establish procedures for authorized disabling during adult use.
  • Document how the school monitors minors’ online activities.
  • Provide and document instruction on appropriate online behavior and cyberbullying.
  • Complete the applicable annual E-Rate CIPA certification.
  • Retain policies, meeting records, filtering evidence, and certifications for the required period.

Good Compliance Is More Than a Filter

An effective CIPA program combines technology, policy, instruction, supervision, documentation, and community participation. Filtering can reduce exposure to harmful visual content, but students also need the skills to behave safely and responsibly in digital environments.

This overview is provided for general educational purposes and is not legal advice. Schools and libraries should review current FCC and USAC requirements, state and local law, and their specific E-Rate participation when evaluating compliance.