Skip to content

COPPA

Children's Online Privacy Protection Act

FTC rules governing the collection of personal information from children under 13.

24 obligations in this framework — full source text, applicability logic, and engineering tickets inside Landfall.

24 obligation pages · last updated 11 September 2026

COPPA-312-2-OPERATOR-LIABILITYHIGHProcessGovernance

Assess the host and embedded provider separately; preserve the actual-knowledge condition for the embedded provider's child-directed-service branch

16 CFR 312.2 - Host and embedded-provider responsibility · Read the full page →

Featured — source excerptLandfall paraphrase of 16 CFR 312.2: A covered operator is responsible for collection on its behalf, including collection by an agent/service provider or where it benefits by allowing direct...
COPPA-312-2-PERSISTENT-IDSHIGHProcessProfiling

Treat qualifying persistent identifiers as personal information and assess consent, internal-operations limits and the distinct registered-user exception

16 CFR 312.2, 312.5(c)(7)-(8) - Assess persistent identifiers and complete exception conditions · Read the full page →

Featured — source excerptLandfall paraphrase of 16 CFR 312.2 and 312.5(c)(7)-(8): Personal information includes a persistent identifier usable to recognize a user over time and across websites or online services,...

See how these become your engineering backlog

Landfall turns each of the 24 Children's Online Privacy Protection Act obligations into traceable engineering tickets — with full source text, applicability logic, and a citation chain your auditors can follow.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations