COPPA 16 CFR 312.5(c)(3), (5), (6) - Assess one-time contact, child-safety and security/legal exceptions
Assess the exact data, purpose, notice and deletion conditions of the one-time, child-safety or security/legal consent pathway
Where this comes from
Provision: 16 CFR 312.5(c)(3), (5), (6) - Assess one-time contact, child-safety and security/legal exceptions
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.5(c)(3), (5), (6), 312.4(c)(4) and 312.2; 90 FR 16918 (22 April 2025), effective 23 June 2025, general compliance date 22 April 2026
Text version: 16 CFR 312.2, 312.4, 312.5, eCFR displayed through 3 September 2026, retrieved 6 September 2026; 2025 final rule, 90 FR 16918
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
- COPPA assessed activity Q_COPPA_CONTACT_EXCEPTION_REVIEW: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Identify the exact 312.5(c)(3), (5) or (6) branch and document every condition; a selected safety or internal-use purpose is not permission.
- For a one-time reply, collect only the child's online contact information for the child's specific request; prohibit recontact, other use and disclosure, then delete promptly after responding.
- For child safety, assess child/parent names and online contact information, safety-only use/disclosure and reasonable efforts to provide the full 312.4(c)(4) notice, including refusal/deletion and the stated-purpose effect of no response.
- For security/legal purposes, assess child name/contact data, the enumerated site-security, liability, judicial-process or law-enforcement/public-safety purpose, other-law limits and no other use; do not infer authority from a request alone.
- Do not impose a blanket no-disclosure rule on every branch; assess the actual permitted purpose and legal constraints, and handle repeated contact and identifier-only operations separately.
Evidence an auditor expects
- Assessment documentDocument review
Complete exception assessment and implemented boundary evidence
Source/version/activity-specific evidence: Identify the exact 312.5(c)(3), (5) or (6) branch and document every condition; a selected safety or internal-use purpose is not permission. For a one-time reply, collect only the child's online contact information for the child's specific request; prohibit recontact, other use and disclosure, then delete promptly after responding. For child safety, assess child/parent names and online contact information, safety-only use/disclosure and reasonable efforts to provide the full 312.4(c)(4) notice, including refusal/deletion and the stated-purpose effect of no response. For security/legal purposes, assess child name/contact data, the enumerated site-security, liability, judicial-process or law-enforcement/public-safety purpose, other-law limits and no other use; do not infer authority from a request alone. Do not impose a blanket no-disclosure rule on every branch; assess the actual permitted purpose and legal constraints, and handle repeated contact and identifier-only operations separately. Test purpose/data boundaries, receipt/refusal and deletion; preserve minimized assessment/control evidence without raw child messages or contact details in general logs. A DRAFT source, selected feature or generated task is not consent or an approved exception.
Questions people ask
- Does COPPA 16 CFR 312.5(c)(3), (5), (6) - Assess one-time contact, child-safety an… apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES; COPPA assessed activity Q_COPPA_CONTACT_EXCEPTION_REVIEW: YES.
- From when does this apply?
- COPPA 16 CFR 312.5(c)(3), (5), (6) - Assess one-time contact, child-safety an… applies from 22 April 2026. Its current status is: in force.
- What evidence does an auditor expect?
- Complete exception assessment and implemented boundary evidence.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.