COPPA 16 CFR 312.2 - Host and embedded-provider responsibility
Assess the host and embedded provider separately; preserve the actual-knowledge condition for the embedded provider's child-directed-service branch
Where this comes from
Provision: 16 CFR 312.2 - Host and embedded-provider responsibility
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.2 (operator; website or online service directed to children, paragraph (2)); 312.3; FTC COPPA FAQs A.2 and E
Text version: 16 CFR 312.2, eCFR as of 3 September 2026, including 2025 amendments
Checked against the source: 6 September 2026
Who it applies to
Covered operator and activity — all of these:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
Host collection or embedded provider with actual knowledge — any one of these:
- What is your role in this collection of children's information? is Host whose activity includes third-party collection or Both roles in the assessed activity
Embedded-provider child-directed-service branch — all of these:
- COPPA assessed activity Q_COPPA_THIRD_PARTY_ROLE: EMBEDDED_PROVIDER
- COPPA assessed activity Q_COPPA_CHILD_SITE_KNOWLEDGE: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Identify the actual collection and each actor's assessed COPPA role and activity; separate host/on-behalf collection from embedded-provider collection.
- Document the host's benefit or on-behalf collection and the embedded provider's actual knowledge of direct collection from a child-directed service.
- Do not infer actual knowledge, universal joint liability or an exemption from integration alone; an unknown knowledge assessment stays unresolved.
- Check each actor's notices, consent and permitted processing independently; contracts cannot eliminate legally imposed responsibility.
- Preserve minimized source-linked facts and responsibilities without copying children's payloads into general logs.
Evidence an auditor expects
- Assessment documentDocument review
Source-linked COPPA activity, authority and control assessment
Identify the actual collection and each actor's assessed COPPA role and activity; separate host/on-behalf collection from embedded-provider collection. Document the host's benefit or on-behalf collection and the embedded provider's actual knowledge of direct collection from a child-directed service. Do not infer actual knowledge, universal joint liability or an exemption from integration alone; an unknown knowledge assessment stays unresolved. Check each actor's notices, consent and permitted processing independently; contracts cannot eliminate legally imposed responsibility. Preserve minimized source-linked facts and responsibilities without copying children's payloads into general logs. Record the exact source version, reviewer, activity and evidence limits. A template or seed is not consent or qualified legal approval.
Questions people ask
- Does COPPA 16 CFR 312.2 - Host and embedded-provider responsibility apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES; and at least one of: What is your role in this collection of children's information? is Host whose activity includes third-party collection or Both roles in the assessed activity; and COPPA assessed activity Q_COPPA_THIRD_PARTY_ROLE: EMBEDDED_PROVIDER; COPPA assessed activity Q_COPPA_CHILD_SITE_KNOWLEDGE: YES.
- From when does this apply?
- COPPA 16 CFR 312.2 - Host and embedded-provider responsibility applies from 1 July 2013. Its current status is: in force.
- What evidence does an auditor expect?
- Source-linked COPPA activity, authority and control assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.