Skip to content

Evidence request lists

COPPA

Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

COPPA Data Security and Retention

COPPA-312.10
Data Retention and Deletion (Written Retention Policy)

An operator may retain personal information collected from a child only for as long as reasonably necessary to fulfil the specific purpose for which it was collected, and must then delete it using reasonable measures to protect against unauthorised access during deletion. The 2025 amendments require a written data retention policy, posted in the online notice, stating the purposes for retention and the retention timeframe, and prohibit indefinite retention.

Artefacts an auditor will ask for
  • Written children's-data retention policy stating purposes and timeframes, published in the online notice
  • Evidence of automated or scheduled deletion when the retention purpose is met
  • Secure-deletion procedures and confirmation logs
Where this commonly fails
  • Indefinite retention of children's data
  • No published retention policy after the 2025 amendments
  • Retaining data after the collection purpose has been fulfilled
COPPA-312.8
Confidentiality, Security, and Integrity (Written Information Security Program)

The operator must establish, implement, and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children. The 2025 amendments require a written information security program with safeguards appropriate to the sensitivity of the data and the operator's size and complexity, designation of an employee to coordinate it, periodic risk assessment, and obtaining written assurances from third parties to whom children's data is released that they will maintain its confidentiality, security, and integrity.

Artefacts an auditor will ask for
  • Written children's-data information security program document
  • Designation of a coordinating employee and evidence of periodic risk assessments
  • Written security assurances from each third party receiving children's personal information
Where this commonly fails
  • No written security program after the 2025 amendments
  • Releasing children's data to third parties without written security assurances
  • No periodic risk assessment or designated program owner

COPPA Enforcement and Accountability

COPPA-312.11
FTC-Approved Safe Harbor Programs

Industry self-regulatory guidelines may be submitted to the FTC for approval as safe harbor programs. Approved programs must provide substantially the same or greater protections than the Rule, include an effective mandatory mechanism for independent assessment of members' compliance, and disciplinary or other consequences for non-compliance. The 2025 amendments increased transparency, requiring approved programs to publicly identify members and report periodically to the Commission.

Artefacts an auditor will ask for
  • Evidence of membership in an FTC-approved safe harbor program (if relied upon)
  • Records of the program's independent assessment of the operator's compliance
  • Program guidelines mapped to the Rule's requirements
Where this commonly fails
  • Claiming safe harbor coverage without active membership or assessment
  • Relying on a safe harbor seal while practices diverge from program guidelines
  • No record of the program's periodic compliance review of the operator
COPPA-312.12
Voluntary Commission Approval Processes

An operator or other interested party may file a written request for Commission approval of a new method of obtaining verifiable parental consent, or for a determination that a particular activity falls within the support-for-internal-operations exception. The request must describe the proposed method or activity in detail and include supporting analysis and any supporting materials.

Artefacts an auditor will ask for
  • Any submitted requests for FTC approval of new consent methods or internal-operations activities
  • Documentation supporting a novel consent mechanism relied upon
  • Commission responses or approvals received
Where this commonly fails
  • Deploying a novel consent method without confirming it meets the verifiable-consent standard
  • No supporting analysis for a claimed internal-operations activity
  • Assuming a new mechanism is approved without a Commission determination
COPPA-312.9
Enforcement as an Unfair or Deceptive Practice

A violation of the Rule is treated as an unfair or deceptive act or practice under Section 18(a)(1)(B) of the FTC Act. The FTC enforces the Rule and may seek civil penalties; specified federal agencies enforce against entities within their jurisdiction; and state attorneys general may bring civil actions on behalf of residents.

Artefacts an auditor will ask for
  • Records demonstrating compliance posture (consent rates, notice versions, deletion logs) available for regulator inquiry
  • Tracking of FTC and state-AG COPPA enforcement relevant to the operator's sector
  • Remediation records for any identified COPPA gaps
Where this commonly fails
  • No readiness to evidence compliance if the FTC or a state AG inquires
  • Treating COPPA as low risk despite significant civil penalty exposure
  • No tracking of enforcement trends to inform controls

COPPA Notice to Parents

COPPA-312.3
General Requirements: Five Core Obligations

It is unlawful for a covered operator to collect personal information from a child in a manner that violates the Rule. Generally an operator must: provide notice of what it collects, how it uses it, and its disclosure practices; obtain verifiable parental consent before collection, use, or disclosure; provide a reasonable means for a parent to review and refuse further use of the child's information; not condition participation on disclosing more information than is reasonably necessary; and establish and maintain reasonable security procedures.

Artefacts an auditor will ask for
  • COPPA compliance program documentation mapping each of the five core obligations to implemented controls
  • Cross-references from privacy notice, consent, review, and security procedures
  • Management attestation of program coverage
Where this commonly fails
  • Implementing some obligations (notice) but not others (review rights, data minimisation)
  • No single owner accountable for the COPPA program
  • Security obligation treated as out of scope of the privacy program
COPPA-312.4a
Notice: Clear, Complete, and Understandable

The operator must provide notice and obtain verifiable parental consent before collecting, using, or disclosing personal information from children. Notice must be clearly and understandably written, complete, and contain no unrelated, confusing, or contradictory materials.

Artefacts an auditor will ask for
  • Current notice text reviewed for clarity, completeness, and absence of contradictory material
  • Readability assessment appropriate to a parent audience
  • Version history of notice changes
Where this commonly fails
  • Dense or legalistic notice unsuitable for parents
  • Notice bundled with unrelated marketing or contradictory terms
  • Notice not presented before collection
COPPA-312.4c
Direct Notice to the Parent

The operator must make reasonable efforts, considering available technology, to ensure a parent receives direct notice of its collection, use, and disclosure practices before collecting personal information, including notice of any material change to practices the parent previously consented to. The direct notice content varies by purpose: obtaining consent, multiple-contact communications, and protecting a child's safety.

Artefacts an auditor will ask for
  • Templates of each direct-notice variant (consent, multiple-contact, safety)
  • Records that direct notice was sent to parents before collection and on material changes
  • Evidence of re-notice and re-consent on material practice changes
Where this commonly fails
  • Relying only on a posted privacy policy with no direct notice to the parent
  • No re-consent when collection or disclosure practices materially change
  • Direct notice missing required content elements (third-party identities, deletion of contact info if no consent)
COPPA-312.4d
Online Notice of Information Practices (Privacy Policy)

In addition to direct notice, the operator must post a prominent, clearly labelled link to an online notice of its information practices regarding children on the home or landing page and at each area where personal information is collected. The notice must state the name and contact details of all operators, the types of personal information collected and how collected, how the information is used, disclosure practices and third-party recipients, and that the parent can review and refuse further collection and request deletion.

Artefacts an auditor will ask for
  • Published children's privacy notice with all required content elements
  • Placement evidence (home/landing page link plus links at each collection point)
  • List of all operators and third parties disclosed in the notice
Where this commonly fails
  • Single generic privacy policy that omits child-specific disclosures
  • Missing the list of all operators collecting through the service
  • No link at the point of collection in child-directed areas

COPPA Parental Rights and Participation

COPPA-312.6
Right of Parent to Review and Delete Information

Upon proper identification of the parent, the operator must provide a description of the specific types of personal information collected from the child, an opportunity to refuse further use or collection and to direct deletion, and a means to review the personal information collected. The operator must use reasonable procedures to verify the requester is the child's parent before granting access.

Artefacts an auditor will ask for
  • Documented parental access, refusal, and deletion request procedure
  • Identity-verification steps for the requesting parent
  • Logs of parental review and deletion requests and responses
Where this commonly fails
  • No mechanism for parents to review or delete a child's data
  • Disclosing a child's data to a requester whose parental status was not verified
  • Refusing further collection but continuing to use already-collected data
COPPA-312.7
Prohibition Against Conditioning Participation

An operator may not condition a child's participation in a game, the offering of a prize, or another activity on the child disclosing more personal information than is reasonably necessary to participate in that activity.

Artefacts an auditor will ask for
  • Data-minimisation review of each child-facing activity confirming only necessary fields are required
  • Mapping of required vs optional data per activity
  • Design records showing participation is not gated on excess data
Where this commonly fails
  • Mandatory profile fields that exceed what the activity needs
  • Requiring registration data unrelated to the activity to claim a prize
  • No documented necessity analysis for collected fields

COPPA Scope and Applicability

COPPA-312.1
Scope and Coverage of the COPPA Rule

The Rule implements the Children's Online Privacy Protection Act and governs unfair or deceptive acts in the collection, use, or disclosure of personal information from and about children on the internet. It applies to any operator of a website or online service directed to children, or any operator with actual knowledge that it collects or maintains personal information from a child under 13.

Artefacts an auditor will ask for
  • Documented COPPA applicability assessment identifying whether the service is child-directed or has actual knowledge
  • Data map showing whether personal information is collected from users under 13
  • Records establishing commercial operation and operator status
Where this commonly fails
  • No documented applicability analysis
  • Assuming COPPA does not apply without an audience/age assessment
  • Treating a mixed-audience service as general-audience without screening
COPPA-312.2-AK
Actual Knowledge Standard for General Audience Services

A general-audience operator becomes subject to COPPA when it has actual knowledge that it is collecting or maintaining personal information from a child under 13. Operators must define how age signals, user statements, and reports create actual knowledge and how the service responds once actual knowledge arises.

Artefacts an auditor will ask for
  • Procedure defining what constitutes actual knowledge of a user under 13
  • Workflow for handling age admissions, parental notifications, and third-party reports
  • Logs of actual-knowledge events and the resulting deletion or consent actions
Where this commonly fails
  • No process to act on age information volunteered by users
  • Ignoring reports that a known under-13 user is on the service
  • Retaining a flagged child's data without obtaining consent or deleting it
COPPA-312.2-DTC
Child-Directed and Mixed Audience Determination

Whether a site or service is directed to children is judged on a multi-factor test (subject matter, visual and audio content, use of animated characters or child-oriented activities, age of models, presence of child celebrities, advertising directed to children, and competent empirical evidence of audience). A mixed audience service is child-directed but does not target children as its primary audience and must use a neutral age-screening or determination method before collecting personal information.

Artefacts an auditor will ask for
  • Documented multi-factor child-directed analysis with supporting evidence
  • Age-screening or age-gate design demonstrating a neutral mechanism that does not default to an age or encourage falsification
  • Audience-composition data used in the determination
Where this commonly fails
  • Age gate that defaults to over-13 or nudges users to enter a false age
  • No neutral age-screening on a mixed-audience service
  • Ignoring child-oriented visual or audio cues in the determination
COPPA-312.2-OP
Operator Determination and Covered Entities

An operator is any person who operates a commercial website or online service and collects or maintains personal information from or about users, or on whose behalf such information is collected. Information is collected on behalf of an operator where a service provider or agent collects it, or where the operator benefits by allowing a third party to collect directly. Nonprofits exempt from FTC Act Section 5 are excluded.

Artefacts an auditor will ask for
  • Inventory of first-party and third-party / service-provider data collection on the service
  • Contracts allocating operator responsibilities with plug-ins, SDKs, and ad networks
  • Determination of for-profit / nonprofit status
Where this commonly fails
  • Failing to treat embedded third-party SDKs or ad networks as triggering operator obligations
  • No mapping of who collects persistent identifiers on the service
  • Assuming nonprofit status without confirming the FTC Act Section 5 exemption
COPPA-312.2-PI
Personal Information Scope and Inventory

Personal information includes name, physical address, online contact information, screen or user name used as contact information, telephone number, government-issued identifier, persistent identifier that can recognise a user over time and across services, photo/video/audio containing a child's image or voice, geolocation sufficient to identify a street and town, and biometric identifiers. The 2025 amendments added government identifiers and biometric identifiers explicitly.

Artefacts an auditor will ask for
  • Data inventory mapping each COPPA personal-information category collected from children
  • Identification of persistent identifiers (cookies, IP, device IDs) and biometric data flows
  • Records of geolocation precision and photo/video/audio handling
Where this commonly fails
  • Treating persistent identifiers as non-personal information
  • Omitting biometric or government identifiers from the inventory after the 2025 amendments
  • Not recognising audio voice recordings as personal information
COPPA-312.2-SIO
Support for Internal Operations Exception Definition

Persistent identifiers collected solely to support the internal operations of the service (such as maintaining or analysing functioning, performing network communications, authenticating users, serving contextual ads, protecting security or integrity, legal compliance, or fulfilling a one-time request) may be used without verifiable parental consent, provided the information is not used or disclosed to contact a specific individual, including through behavioural advertising, or for any other purpose.

Artefacts an auditor will ask for
  • Documented list of persistent-identifier uses relied on as support for internal operations
  • Controls preventing reuse of those identifiers for behavioural advertising or profiling
  • Technical evidence that identifiers are not used to contact or build profiles of children
Where this commonly fails
  • Using the internal-operations exception as cover for targeted advertising
  • No technical separation between internal-operations and advertising uses of identifiers
  • Undocumented scope of the exception relied upon

COPPA Verifiable Parental Consent

COPPA-312.5-SCH
School Authorization in Lieu of Parental Consent

Where an operator collects personal information from students in the educational context, a school may authorise the collection in lieu of parental consent, provided the information is used only for a school-authorised educational purpose and not for any commercial purpose. The 2025 amendments codified the conditions, including school notice, limits on use and disclosure, and deletion when no longer needed for the educational purpose.

Artefacts an auditor will ask for
  • Written agreement with the school documenting the authorised educational purpose
  • Controls preventing commercial use of student data collected under school authorisation
  • Deletion schedule tied to the educational purpose
Where this commonly fails
  • Using school-authorised student data for advertising or product development
  • No written record of the school's authorisation
  • Retaining student data beyond the educational purpose
COPPA-312.5a
Verifiable Parental Consent Requirement

An operator must obtain verifiable parental consent before any collection, use, or disclosure of personal information from a child, and must give the parent the option to consent to collection and use without consenting to disclosure to third parties (except where integral to the service). Under the 2025 amendments, separate verifiable parental consent is required before disclosing personal information to third parties, including for targeted advertising.

Artefacts an auditor will ask for
  • Consent records linking each child's data collection to a verifiable parental consent event
  • Separate consent capture for third-party disclosure / targeted advertising
  • Mechanism allowing consent to collection without consent to disclosure
Where this commonly fails
  • Bundling collection consent with third-party disclosure consent
  • No retained, auditable record of the parental consent obtained
  • Collecting before consent is obtained
COPPA-312.5b
Approved Methods of Verifiable Parental Consent

The operator must use a method reasonably calculated, in light of available technology, to ensure the person providing consent is the child's parent. A sliding scale applies: internal-use-only collection may use email-plus, while disclosure requires more reliable methods. Approved methods include a signed consent form, a monetary transaction with notification, a toll-free telephone or video-conference call to trained personnel, checking a government-issued identification, knowledge-based authentication, and facial recognition matched to a verified photo identification (added 2025).

Artefacts an auditor will ask for
  • Documentation of the consent method(s) used and why they are reasonable for the data practices
  • Evidence of the sliding-scale logic (internal use vs disclosure)
  • Vendor assessments for KBA, government-ID, or facial-match providers and deletion of verification data after use
Where this commonly fails
  • Using email-plus where data is disclosed to third parties
  • Retaining government-ID images or biometric verification data longer than necessary
  • No documented basis for the chosen consent method
COPPA-312.5c
Exceptions to Prior Parental Consent

Limited exceptions permit collection before consent: collecting a parent's or child's online contact information solely to obtain consent or provide notice; responding once directly to a child's specific one-time request; multiple-contact communications after notice (email-plus); protecting a child's safety; protecting the security or integrity of the service, taking precautions against liability, responding to judicial process, or complying with law; and collecting a persistent identifier solely to support internal operations.

Artefacts an auditor will ask for
  • Mapping of each pre-consent collection activity to a specific Section 312.5(c) exception
  • Evidence that information collected under an exception is used only for the stated purpose and then deleted
  • Notice provided to parents where required by the multiple-contact and safety exceptions
Where this commonly fails
  • Stretching the one-time-response exception into ongoing contact
  • Using exception-collected contact information for marketing
  • No deletion of online contact information after the exception purpose is met
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the COPPA framework page.