COPPA
Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
COPPA Data Security and Retention
An operator may retain personal information collected from a child only for as long as reasonably necessary to fulfil the specific purpose for which it was collected, and must then delete it using reasonable measures to protect against unauthorised access during deletion. The 2025 amendments require a written data retention policy, posted in the online notice, stating the purposes for retention and the retention timeframe, and prohibit indefinite retention.
- Written children's-data retention policy stating purposes and timeframes, published in the online notice
- Evidence of automated or scheduled deletion when the retention purpose is met
- Secure-deletion procedures and confirmation logs
- Indefinite retention of children's data
- No published retention policy after the 2025 amendments
- Retaining data after the collection purpose has been fulfilled
The operator must establish, implement, and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children. The 2025 amendments require a written information security program with safeguards appropriate to the sensitivity of the data and the operator's size and complexity, designation of an employee to coordinate it, periodic risk assessment, and obtaining written assurances from third parties to whom children's data is released that they will maintain its confidentiality, security, and integrity.
- Written children's-data information security program document
- Designation of a coordinating employee and evidence of periodic risk assessments
- Written security assurances from each third party receiving children's personal information
- No written security program after the 2025 amendments
- Releasing children's data to third parties without written security assurances
- No periodic risk assessment or designated program owner
COPPA Enforcement and Accountability
Industry self-regulatory guidelines may be submitted to the FTC for approval as safe harbor programs. Approved programs must provide substantially the same or greater protections than the Rule, include an effective mandatory mechanism for independent assessment of members' compliance, and disciplinary or other consequences for non-compliance. The 2025 amendments increased transparency, requiring approved programs to publicly identify members and report periodically to the Commission.
- Evidence of membership in an FTC-approved safe harbor program (if relied upon)
- Records of the program's independent assessment of the operator's compliance
- Program guidelines mapped to the Rule's requirements
- Claiming safe harbor coverage without active membership or assessment
- Relying on a safe harbor seal while practices diverge from program guidelines
- No record of the program's periodic compliance review of the operator
An operator or other interested party may file a written request for Commission approval of a new method of obtaining verifiable parental consent, or for a determination that a particular activity falls within the support-for-internal-operations exception. The request must describe the proposed method or activity in detail and include supporting analysis and any supporting materials.
- Any submitted requests for FTC approval of new consent methods or internal-operations activities
- Documentation supporting a novel consent mechanism relied upon
- Commission responses or approvals received
- Deploying a novel consent method without confirming it meets the verifiable-consent standard
- No supporting analysis for a claimed internal-operations activity
- Assuming a new mechanism is approved without a Commission determination
A violation of the Rule is treated as an unfair or deceptive act or practice under Section 18(a)(1)(B) of the FTC Act. The FTC enforces the Rule and may seek civil penalties; specified federal agencies enforce against entities within their jurisdiction; and state attorneys general may bring civil actions on behalf of residents.
- Records demonstrating compliance posture (consent rates, notice versions, deletion logs) available for regulator inquiry
- Tracking of FTC and state-AG COPPA enforcement relevant to the operator's sector
- Remediation records for any identified COPPA gaps
- No readiness to evidence compliance if the FTC or a state AG inquires
- Treating COPPA as low risk despite significant civil penalty exposure
- No tracking of enforcement trends to inform controls
COPPA Notice to Parents
It is unlawful for a covered operator to collect personal information from a child in a manner that violates the Rule. Generally an operator must: provide notice of what it collects, how it uses it, and its disclosure practices; obtain verifiable parental consent before collection, use, or disclosure; provide a reasonable means for a parent to review and refuse further use of the child's information; not condition participation on disclosing more information than is reasonably necessary; and establish and maintain reasonable security procedures.
- COPPA compliance program documentation mapping each of the five core obligations to implemented controls
- Cross-references from privacy notice, consent, review, and security procedures
- Management attestation of program coverage
- Implementing some obligations (notice) but not others (review rights, data minimisation)
- No single owner accountable for the COPPA program
- Security obligation treated as out of scope of the privacy program
The operator must provide notice and obtain verifiable parental consent before collecting, using, or disclosing personal information from children. Notice must be clearly and understandably written, complete, and contain no unrelated, confusing, or contradictory materials.
- Current notice text reviewed for clarity, completeness, and absence of contradictory material
- Readability assessment appropriate to a parent audience
- Version history of notice changes
- Dense or legalistic notice unsuitable for parents
- Notice bundled with unrelated marketing or contradictory terms
- Notice not presented before collection
The operator must make reasonable efforts, considering available technology, to ensure a parent receives direct notice of its collection, use, and disclosure practices before collecting personal information, including notice of any material change to practices the parent previously consented to. The direct notice content varies by purpose: obtaining consent, multiple-contact communications, and protecting a child's safety.
- Templates of each direct-notice variant (consent, multiple-contact, safety)
- Records that direct notice was sent to parents before collection and on material changes
- Evidence of re-notice and re-consent on material practice changes
- Relying only on a posted privacy policy with no direct notice to the parent
- No re-consent when collection or disclosure practices materially change
- Direct notice missing required content elements (third-party identities, deletion of contact info if no consent)
In addition to direct notice, the operator must post a prominent, clearly labelled link to an online notice of its information practices regarding children on the home or landing page and at each area where personal information is collected. The notice must state the name and contact details of all operators, the types of personal information collected and how collected, how the information is used, disclosure practices and third-party recipients, and that the parent can review and refuse further collection and request deletion.
- Published children's privacy notice with all required content elements
- Placement evidence (home/landing page link plus links at each collection point)
- List of all operators and third parties disclosed in the notice
- Single generic privacy policy that omits child-specific disclosures
- Missing the list of all operators collecting through the service
- No link at the point of collection in child-directed areas
COPPA Parental Rights and Participation
Upon proper identification of the parent, the operator must provide a description of the specific types of personal information collected from the child, an opportunity to refuse further use or collection and to direct deletion, and a means to review the personal information collected. The operator must use reasonable procedures to verify the requester is the child's parent before granting access.
- Documented parental access, refusal, and deletion request procedure
- Identity-verification steps for the requesting parent
- Logs of parental review and deletion requests and responses
- No mechanism for parents to review or delete a child's data
- Disclosing a child's data to a requester whose parental status was not verified
- Refusing further collection but continuing to use already-collected data
An operator may not condition a child's participation in a game, the offering of a prize, or another activity on the child disclosing more personal information than is reasonably necessary to participate in that activity.
- Data-minimisation review of each child-facing activity confirming only necessary fields are required
- Mapping of required vs optional data per activity
- Design records showing participation is not gated on excess data
- Mandatory profile fields that exceed what the activity needs
- Requiring registration data unrelated to the activity to claim a prize
- No documented necessity analysis for collected fields
COPPA Scope and Applicability
The Rule implements the Children's Online Privacy Protection Act and governs unfair or deceptive acts in the collection, use, or disclosure of personal information from and about children on the internet. It applies to any operator of a website or online service directed to children, or any operator with actual knowledge that it collects or maintains personal information from a child under 13.
- Documented COPPA applicability assessment identifying whether the service is child-directed or has actual knowledge
- Data map showing whether personal information is collected from users under 13
- Records establishing commercial operation and operator status
- No documented applicability analysis
- Assuming COPPA does not apply without an audience/age assessment
- Treating a mixed-audience service as general-audience without screening
A general-audience operator becomes subject to COPPA when it has actual knowledge that it is collecting or maintaining personal information from a child under 13. Operators must define how age signals, user statements, and reports create actual knowledge and how the service responds once actual knowledge arises.
- Procedure defining what constitutes actual knowledge of a user under 13
- Workflow for handling age admissions, parental notifications, and third-party reports
- Logs of actual-knowledge events and the resulting deletion or consent actions
- No process to act on age information volunteered by users
- Ignoring reports that a known under-13 user is on the service
- Retaining a flagged child's data without obtaining consent or deleting it
Whether a site or service is directed to children is judged on a multi-factor test (subject matter, visual and audio content, use of animated characters or child-oriented activities, age of models, presence of child celebrities, advertising directed to children, and competent empirical evidence of audience). A mixed audience service is child-directed but does not target children as its primary audience and must use a neutral age-screening or determination method before collecting personal information.
- Documented multi-factor child-directed analysis with supporting evidence
- Age-screening or age-gate design demonstrating a neutral mechanism that does not default to an age or encourage falsification
- Audience-composition data used in the determination
- Age gate that defaults to over-13 or nudges users to enter a false age
- No neutral age-screening on a mixed-audience service
- Ignoring child-oriented visual or audio cues in the determination
An operator is any person who operates a commercial website or online service and collects or maintains personal information from or about users, or on whose behalf such information is collected. Information is collected on behalf of an operator where a service provider or agent collects it, or where the operator benefits by allowing a third party to collect directly. Nonprofits exempt from FTC Act Section 5 are excluded.
- Inventory of first-party and third-party / service-provider data collection on the service
- Contracts allocating operator responsibilities with plug-ins, SDKs, and ad networks
- Determination of for-profit / nonprofit status
- Failing to treat embedded third-party SDKs or ad networks as triggering operator obligations
- No mapping of who collects persistent identifiers on the service
- Assuming nonprofit status without confirming the FTC Act Section 5 exemption
Personal information includes name, physical address, online contact information, screen or user name used as contact information, telephone number, government-issued identifier, persistent identifier that can recognise a user over time and across services, photo/video/audio containing a child's image or voice, geolocation sufficient to identify a street and town, and biometric identifiers. The 2025 amendments added government identifiers and biometric identifiers explicitly.
- Data inventory mapping each COPPA personal-information category collected from children
- Identification of persistent identifiers (cookies, IP, device IDs) and biometric data flows
- Records of geolocation precision and photo/video/audio handling
- Treating persistent identifiers as non-personal information
- Omitting biometric or government identifiers from the inventory after the 2025 amendments
- Not recognising audio voice recordings as personal information
Persistent identifiers collected solely to support the internal operations of the service (such as maintaining or analysing functioning, performing network communications, authenticating users, serving contextual ads, protecting security or integrity, legal compliance, or fulfilling a one-time request) may be used without verifiable parental consent, provided the information is not used or disclosed to contact a specific individual, including through behavioural advertising, or for any other purpose.
- Documented list of persistent-identifier uses relied on as support for internal operations
- Controls preventing reuse of those identifiers for behavioural advertising or profiling
- Technical evidence that identifiers are not used to contact or build profiles of children
- Using the internal-operations exception as cover for targeted advertising
- No technical separation between internal-operations and advertising uses of identifiers
- Undocumented scope of the exception relied upon
COPPA Verifiable Parental Consent
Where an operator collects personal information from students in the educational context, a school may authorise the collection in lieu of parental consent, provided the information is used only for a school-authorised educational purpose and not for any commercial purpose. The 2025 amendments codified the conditions, including school notice, limits on use and disclosure, and deletion when no longer needed for the educational purpose.
- Written agreement with the school documenting the authorised educational purpose
- Controls preventing commercial use of student data collected under school authorisation
- Deletion schedule tied to the educational purpose
- Using school-authorised student data for advertising or product development
- No written record of the school's authorisation
- Retaining student data beyond the educational purpose
An operator must obtain verifiable parental consent before any collection, use, or disclosure of personal information from a child, and must give the parent the option to consent to collection and use without consenting to disclosure to third parties (except where integral to the service). Under the 2025 amendments, separate verifiable parental consent is required before disclosing personal information to third parties, including for targeted advertising.
- Consent records linking each child's data collection to a verifiable parental consent event
- Separate consent capture for third-party disclosure / targeted advertising
- Mechanism allowing consent to collection without consent to disclosure
- Bundling collection consent with third-party disclosure consent
- No retained, auditable record of the parental consent obtained
- Collecting before consent is obtained
The operator must use a method reasonably calculated, in light of available technology, to ensure the person providing consent is the child's parent. A sliding scale applies: internal-use-only collection may use email-plus, while disclosure requires more reliable methods. Approved methods include a signed consent form, a monetary transaction with notification, a toll-free telephone or video-conference call to trained personnel, checking a government-issued identification, knowledge-based authentication, and facial recognition matched to a verified photo identification (added 2025).
- Documentation of the consent method(s) used and why they are reasonable for the data practices
- Evidence of the sliding-scale logic (internal use vs disclosure)
- Vendor assessments for KBA, government-ID, or facial-match providers and deletion of verification data after use
- Using email-plus where data is disclosed to third parties
- Retaining government-ID images or biometric verification data longer than necessary
- No documented basis for the chosen consent method
Limited exceptions permit collection before consent: collecting a parent's or child's online contact information solely to obtain consent or provide notice; responding once directly to a child's specific one-time request; multiple-contact communications after notice (email-plus); protecting a child's safety; protecting the security or integrity of the service, taking precautions against liability, responding to judicial process, or complying with law; and collecting a persistent identifier solely to support internal operations.
- Mapping of each pre-consent collection activity to a specific Section 312.5(c) exception
- Evidence that information collected under an exception is used only for the stated purpose and then deleted
- Notice provided to parents where required by the multiple-contact and safety exceptions
- Stretching the one-time-response exception into ongoing contact
- Using exception-collected contact information for marketing
- No deletion of online contact information after the exception purpose is met
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the COPPA framework page.