COPPA-312-10-SAFE-HARBORMEDIUMProcessGovernanceAssess actual guideline compliance and the service-specific scope of any COPPA safe-harbor reliance
16 CFR §312.11(h) - Operator participation in approved safe harbor programs · Read the full page →
COPPA
FTC rules governing the collection of personal information from children under 13.
24 obligations in this framework — full source text, applicability logic, and engineering tickets inside Landfall.
24 obligation pages · last updated 11 September 2026
COPPA-312-10-SAFE-HARBORMEDIUMProcessGovernanceAssess actual guideline compliance and the service-specific scope of any COPPA safe-harbor reliance
16 CFR §312.11(h) - Operator participation in approved safe harbor programs · Read the full page →
COPPA-312-2-ACTUAL-KNOWLEDGECRITICALProcessAge VerificationAssess and document the operator, child-directed and actual-knowledge basis for this activity's COPPA coverage
16 CFR 312.2 and 312.3 - Operator, child-directed status and actual knowledge · Read the full page →
Featured — source excerpt“Source-based paraphrase: Section 312.3 covers operators of child-directed websites/services and operators with actual knowledge of collecting or maintaining a child's personal information.”
COPPA-312-2-OPERATOR-LIABILITYHIGHProcessGovernanceAssess the host and embedded provider separately; preserve the actual-knowledge condition for the embedded provider's child-directed-service branch
16 CFR 312.2 - Host and embedded-provider responsibility · Read the full page →
Featured — source excerpt“Landfall paraphrase of 16 CFR 312.2: A covered operator is responsible for collection on its behalf, including collection by an agent/service provider or where it benefits by allowing direct...”
COPPA-312-2-PERSISTENT-IDSHIGHProcessProfilingTreat qualifying persistent identifiers as personal information and assess consent, internal-operations limits and the distinct registered-user exception
16 CFR 312.2, 312.5(c)(7)-(8) - Assess persistent identifiers and complete exception conditions · Read the full page →
Featured — source excerpt“Landfall paraphrase of 16 CFR 312.2 and 312.5(c)(7)-(8): Personal information includes a persistent identifier usable to recognize a user over time and across websites or online services,...”
COPPA-312-3-PARENTAL-CONSENTCRITICALProcessConsentDetermine and enforce the consent basis for each covered child-data practice, including material changes and narrowly conditioned exceptions
16 CFR 312.3(b), 312.5(a)-(c) - Parental consent and limited exceptions · Read the full page →
COPPA-312-3-THIRD-PARTY-COLLECTIONCRITICALProcessData CollectionAssess and control collection on a covered host's behalf, including non-advertising SDKs and service providers
16 CFR 312.2, 312.3 and 312.8(c) - Host responsibility for collection on its behalf · Read the full page →
COPPA-312-4A-WEBSITE-NOTICEHIGHProcessTransparencyAssess applicable notice duties and place a prominent, clearly labelled notice link at the required screens and collection points
16 CFR 312.4(a), (d) - Assess and implement online notice placement and clarity · Read the full page →
COPPA-312-4B-DIRECT-NOTICEHIGHProcessTransparencyAssess the direct-notice pathway and deliver its complete contents and material-change notice where required
16 CFR 312.4(b), (c)(1)-(4) - Assess and implement the applicable direct notice · Read the full page →
COPPA-312-4D-NOTICE-CONTENTHIGHProcessTransparencyAssess and complete operator, data-use, disclosure, retention, internal-operations, audio and parental-rights notice content
16 CFR 312.4(d)(1)-(5) - Assess and complete amended online notice content · Read the full page →
COPPA-312-5-DATA-SHARINGCRITICALProcessData SharingAssess third-party disclosure and any integral-service qualification; provide a separate choice and obtain separate verifiable parental consent where required
16 CFR 312.5(a)(2) - Separate choice and consent for third-party disclosure · Read the full page →
COPPA-312-5-INTERNAL-USEMEDIUMProcessData ProcessingAssess the exact data, purpose, notice and deletion conditions of the one-time, child-safety or security/legal consent pathway
16 CFR 312.5(c)(3), (5), (6) - Assess one-time contact, child-safety and security/legal exceptions · Read the full page →
COPPA-312-5-VPC-METHODSCRITICALProcessConsentAssess the actual parental-verification conditions, notice, disclosure limits and prompt ID/image deletion before selecting a consent method
16 CFR 312.5(b)(1)-(3) - Assess and implement verifiable parental consent methods · Read the full page →
COPPA-312-5C2-PUSH-CONTACTHIGHProcessConsentVerify every repeated-response exception condition; repeated messages or push notifications alone do not remove the parental-consent requirement
16 CFR 312.5(c)(4) and 312.4(c)(3) - Repeated response exception · Read the full page →
COPPA-312-5C4-SCHOOL-AUTHHIGHProcessConsentAssess the limited FTC school-authorization guidance before relying on it; school use alone does not authorize collection or other commercial reuse
FTC COPPA FAQs N.1-N.3 - Assess school authorization · Read the full page →
COPPA-312-6-PARENT-REVIEW-DELETECRITICALProcessUser RightsAssess and implement parental review, refusal and deletion rights with proportionate verification and qualified service restrictions
16 CFR 312.6(a)-(c) - Parental review, refusal and deletion rights · Read the full page →
COPPA-312-7-NO-CONDITIONINGCRITICALProhibitionData CollectionDo not require more personal information than reasonably necessary for a child's participation, including guest activities
16 CFR 312.7 - No conditioning participation on excessive personal information · Read the full page →
COPPA-312-8-DATA-SECURITYCRITICALRequirementData ProcessingMaintain a written, risk-based children's information security program, annual assessments and updates, regular safeguard testing, and prior written recipient assurances
16 CFR 312.8(a)-(c) - Written information security program and recipient safeguards · Read the full page →
COPPA-312-9-DATA-RETENTIONHIGHRequirementData RetentionImplement and publish a written children's-data retention policy with specific purposes, business need and deletion timeframes; delete securely when no longer reasonably necessary
16 CFR 312.10 - Written retention policy, purpose limits and secure deletion · Read the full page →
COPPA-312-CONNECTED-TOYSCRITICALProcessData CollectionAssess COPPA duties across covered connected-device, companion-app and cloud data flows
16 CFR 312.2/312.3; FTC guidance - Connected-device online data flows · Read the full page →
COPPA-312-EDTECH-PROVISIONSHIGHProcessConsentConstrain school-authorized processing to the requested service and preserve the operator's collection, security, retention and consent responsibilities
FTC Education Technology Policy (19 May 2022) - School-context data controls · Read the full page →
COPPA-312-FTC-ENFORCEMENTCRITICALProcessGovernanceRecord COPPA enforcement authority and dated penalty context without inventing liability or recordkeeping requirements
15 U.S.C. §§6504-6505; 16 CFR §1.98 - Enforcement authority and dated penalty context · Read the full page →
COPPA-312-GEOLOCATIONHIGHProcessData CollectionAssess actual geolocation precision, collection timing and linked information before relying on a COPPA consent or exception basis
16 CFR 312.2 - Personal information, geolocation and combined identifiers · Read the full page →
COPPA-312-MIXED-AUDIENCEHIGHProcessAge VerificationAssess mixed-audience eligibility and enforce neutral age determination before non-exempt collection from any visitor
16 CFR 312.2 - Mixed audience definition and directed-to-children paragraph (3) · Read the full page →
COPPA-312-STREAMING-AUDIOHIGHProcessData CollectionAssess child-voice audio collection, consent and every condition of the specific-request audio exception, including immediate deletion and online notice
16 CFR 312.2, 312.5(c)(9), 312.4(d)(4) - Assess child audio and the narrow request-response exception · Read the full page →
Landfall turns each of the 24 Children's Online Privacy Protection Act obligations into traceable engineering tickets — with full source text, applicability logic, and a citation chain your auditors can follow.
Critical Boundaries
Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.
This product does not provide legal advice and does not create an attorney-client relationship.
Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.
We do not quantify, calculate, or certify your compliance risk level.
No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.
This is a planning and mapping tool, not a runtime enforcement system.
Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.
Using this tool does not mean you are compliant with any regulation.
No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.
Our interpretations are not binding and may differ from regulatory guidance.
Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.
This tool does not shield you from enforcement actions or liability.
Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.
AI features assist analysis but do not make compliance decisions for you.
AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.
We do not cover all regulations, all obligations, or all jurisdictions.
Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.
What This Tool IS: