COPPA 16 CFR 312.2, 312.3 and 312.8(c) - Host responsibility for collection on its behalf
Assess and control collection on a covered host's behalf, including non-advertising SDKs and service providers
Where this comes from
Provision: 16 CFR 312.2, 312.3 and 312.8(c) - Host responsibility for collection on its behalf
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.2 (Operator, Collects or collection, Disclose or disclosure, Third party), 312.3, 312.4(d)(1)-(2), 312.5 and 312.8(c); 90 FR 16918 (22 April 2025), effective 23 June 2025, general compliance date 22 April 2026.
Text version: 2025 final rule, 90 FR 16918, 16977-16981, retrieved 6 September 2026; amended 312.8(c) general compliance 22 April 2026. Earlier host responsibility existed before these written-assurance amendments.
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
- What is your role in this collection of children's information? is Host whose activity includes third-party collection or Both roles in the assessed activity
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Establish this activity's covered-host role and inventory agents, service providers and other entities collecting/maintaining child information on its behalf, including SDK and server-side flows with advertising disabled.
- Assess 312.2's agency/service-provider or host-benefit basis, actual personal information and passive tracking; vendor labels and contracts alone do not decide legal roles.
- Apply host notice, consent or the complete exact exception, purpose, parental-rights, security and retention duties to each flow; distinguish 312.2 disclosure/third-party definitions and 312.5(a)(2) separate choice.
- Before allowing 312.8(c) collection/maintenance/release, take reasonable steps to determine recipient security capability and obtain written assurances of reasonable security measures; a generic consent warranty or child-directed-site email is not a substitute.
- Do not miscite 312.3(c), which concerns parental review, as a universal SDK-notification rule. Assess the embedded provider's distinct actual-knowledge coverage separately.
Evidence an auditor expects
- Policy documentDocument review
Host collection and recipient safeguard assessment
[ ] Establish this activity's covered-host role and inventory agents, service providers and other entities collecting/maintaining child information on its behalf, including SDK and server-side flows with advertising disabled. [ ] Assess 312.2's agency/service-provider or host-benefit basis, actual personal information and passive tracking; vendor labels and contracts alone do not decide legal roles. [ ] Apply host notice, consent or the complete exact exception, purpose, parental-rights, security and retention duties to each flow; distinguish 312.2 disclosure/third-party definitions and 312.5(a)(2) separate choice. [ ] Before allowing 312.8(c) collection/maintenance/release, take reasonable steps to determine recipient security capability and obtain written assurances of reasonable security measures; a generic consent warranty or child-directed-site email is not a substitute. [ ] Do not miscite 312.3(c), which concerns parental review, as a universal SDK-notification rule. Assess the embedded provider's distinct actual-knowledge coverage separately. [ ] Prevent unsupported flows and test real client/server traffic before/after consent, refusal and vendor changes. CSP is not proof for mobile SDKs or server calls; retain minimized inventory, assurance and test evidence without child payloads. Evidence supports review; it is not consent, exception approval or legal certification.
Questions people ask
- Does COPPA 16 CFR 312.2, 312.3 and 312.8(c) - Host responsibility for collection o… apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES; What is your role in this collection of children's information? is Host whose activity includes third-party collection or Both roles in the assessed activity.
- From when does this apply?
- COPPA 16 CFR 312.2, 312.3 and 312.8(c) - Host responsibility for collection o… applies from 22 April 2026. Its current status is: in force.
- What evidence does an auditor expect?
- Host collection and recipient safeguard assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.