COPPA 16 CFR 312.3(b), 312.5(a)-(c) - Parental consent and limited exceptions
Determine and enforce the consent basis for each covered child-data practice, including material changes and narrowly conditioned exceptions
Where this comes from
Provision: 16 CFR 312.3(b), 312.5(a)-(c) - Parental consent and limited exceptions
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.2 (Obtaining verifiable consent), 312.3(b), 312.4 and 312.5(a)-(c); 90 FR 16918 (22 April 2025), effective 23 June 2025, general compliance date 22 April 2026. The underlying consent duty predates the amendment.
Text version: 2025 final rule, 90 FR 16918, 16977-16981, retrieved 6 September 2026; 312.3 current eCFR displayed through 3 September. Fresh live 312.5 access was unavailable. FTC 25 February 2026 age-verification enforcement policy is a separate guidance review, not a rule amendment.
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Resolve the consent basis for each collection, use and disclosure, including startup SDK traffic and material changes; block non-exempt processing until the parent receives notice and gives appropriately verified authorization.
- Assess 312.5(a)(2)'s separate disclosure choice/consent and integral-service qualification; age entry, a parent email, a policy link or silence is not general consent.
- For any 312.5(c) claim, document the exact branch and every data, purpose, use/disclosure, notice and deletion condition; enable only the established limited activity, never an automatic exception from a checkbox.
- Preserve the limited (c)(1) name/contact consent-seeking pathway and delete after a reasonable time from collection without consent; do not block all pre-consent contact or reset this clock by sending a later notice.
- Test missing, denied, revoked, scope-limited and materially changed consent, and verify browser/mobile/server paths respect the assessed basis. Consent does not override unrelated security, rights, purpose or retention duties.
Evidence an auditor expects
- Policy documentDocument review
Consent-basis and exception-boundary assessment
[ ] Resolve the consent basis for each collection, use and disclosure, including startup SDK traffic and material changes; block non-exempt processing until the parent receives notice and gives appropriately verified authorization. [ ] Assess 312.5(a)(2)'s separate disclosure choice/consent and integral-service qualification; age entry, a parent email, a policy link or silence is not general consent. [ ] For any 312.5(c) claim, document the exact branch and every data, purpose, use/disclosure, notice and deletion condition; enable only the established limited activity, never an automatic exception from a checkbox. [ ] Preserve the limited (c)(1) name/contact consent-seeking pathway and delete after a reasonable time from collection without consent; do not block all pre-consent contact or reset this clock by sending a later notice. [ ] Test missing, denied, revoked, scope-limited and materially changed consent, and verify browser/mobile/server paths respect the assessed basis. Consent does not override unrelated security, rights, purpose or retention duties. [ ] Preserve minimized method/scope/notice-version and test evidence without raw identity documents or child payloads. Treat school guidance and the 25 February 2026 FTC age-verification policy as separate current-source reviews, not codified exceptions or automatic permission. Evidence supports review; it is not consent, exception approval or legal certification.
Questions people ask
- Does COPPA 16 CFR 312.3(b), 312.5(a)-(c) - Parental consent and limited exceptions apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES.
- From when does this apply?
- COPPA 16 CFR 312.3(b), 312.5(a)-(c) - Parental consent and limited exceptions applies from 21 April 2000. Its current status is: in force.
- What evidence does an auditor expect?
- Consent-basis and exception-boundary assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.