COPPA 16 CFR 312.6(a)-(c) - Parental review, refusal and deletion rights
Assess and implement parental review, refusal and deletion rights with proportionate verification and qualified service restrictions
Where this comes from
Provision: 16 CFR 312.6(a)-(c) - Parental review, refusal and deletion rights
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 15 U.S.C. 6502(b)(1)(B); 16 CFR 312.2 (Delete), 312.6(a)-(c) and 312.7; 90 FR 16918, 16981 (22 April 2025); original rule 64 FR 59888 (3 November 1999), effective 21 April 2000. These parental rights predate the 2025 republication.
Text version: 2025 final rule, 90 FR 16918; 16 CFR 312.6 republished at 16981, retrieved 6 September 2026. Live eCFR 312.6 access was unavailable; no assertion of a freshly accessed current consolidation.
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Map the child's collected information and the separate 312.6(a) rights: describe specific types/categories, refuse further use or future online collection and direct deletion, and review any personal information collected from that child.
- Provide a usable review-access method that establishes the requester is a parent of that child, considering available technology without undue burden; test impostor denial and legitimate requests without requiring an existing account.
- Do not invent a mandatory portal, government-ID/VPC method or a fixed statutory response deadline. Distinguish the category-description right from access to the child's actual data.
- Test refusal of further use and future collection and actual deletion across affected systems/providers, including logs, caches and backups, against 312.2's no-retrievable-form/normal-course-of-business standard.
- Assess any service termination under 312.6(c) against the parent's refusal/deletion direction and 312.7's reasonably-necessary participation limit. Treat paragraph (b)'s disclosure protection as conditional on good faith and reasonable procedures.
Evidence an auditor expects
- Policy documentDocument review
Parental-rights process and privacy-preserving control assessment
[ ] Map the child's collected information and the separate 312.6(a) rights: describe specific types/categories, refuse further use or future online collection and direct deletion, and review any personal information collected from that child. [ ] Provide a usable review-access method that establishes the requester is a parent of that child, considering available technology without undue burden; test impostor denial and legitimate requests without requiring an existing account. [ ] Do not invent a mandatory portal, government-ID/VPC method or a fixed statutory response deadline. Distinguish the category-description right from access to the child's actual data. [ ] Test refusal of further use and future collection and actual deletion across affected systems/providers, including logs, caches and backups, against 312.2's no-retrievable-form/normal-course-of-business standard. [ ] Assess any service termination under 312.6(c) against the parent's refusal/deletion direction and 312.7's reasonably-necessary participation limit. Treat paragraph (b)'s disclosure protection as conditional on good faith and reasonable procedures. [ ] Retain minimized request, decision and control-test evidence without copying child records or retaining verification documents merely as proof; unresolved handling and legal-scope questions require review. Evidence supports a source-based review; it is not legal approval or proof from raw child data.
Questions people ask
- Does COPPA 16 CFR 312.6(a)-(c) - Parental review, refusal and deletion rights apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES.
- From when does this apply?
- COPPA 16 CFR 312.6(a)-(c) - Parental review, refusal and deletion rights applies from 21 April 2000. Its current status is: in force.
- What evidence does an auditor expect?
- Parental-rights process and privacy-preserving control assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.