COPPA 16 CFR 312.8(a)-(c) - Written information security program and recipient safeguards
Maintain a written, risk-based children's information security program, annual assessments and updates, regular safeguard testing, and prior written recipient assurances
Where this comes from
Provision: 16 CFR 312.8(a)-(c) - Written information security program and recipient safeguards
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.8(a)-(c); 90 FR 16918 (22 April 2025), amended rule effective 23 June 2025, general compliance date 22 April 2026
Text version: 16 CFR Part 312, 2025 amended Rule (90 FR 16918); eCFR as of 3 September 2026; retrieved 6 September 2026
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Establish, implement and maintain a written program proportionate to children's information sensitivity and the operator's size, complexity and activities; designate employee coordinators.
- Identify internal/external risks and safeguards' sufficiency, reassess at least annually, and implement controls based on information volume, sensitivity and likelihood of compromise.
- Regularly test and monitor safeguard effectiveness; at least annually evaluate and modify the program for risks, results, methods and other material circumstances.
- Before on-behalf collection/maintenance or release, reasonably assess recipient capability and obtain written assurances of reasonable protection measures.
- Preserve minimized, attributable program, assessment, test and recipient evidence; justify chosen technologies without claiming that this provision mandates an algorithm or independent audit.
Evidence an auditor expects
- Policy documentDocument review
Written security program and implemented controls
Reviewed evidence for the assessed activity and applicable source version: Establish, implement and maintain a written program proportionate to children's information sensitivity and the operator's size, complexity and activities; designate employee coordinators. Identify internal/external risks and safeguards' sufficiency, reassess at least annually, and implement controls based on information volume, sensitivity and likelihood of compromise. Regularly test and monitor safeguard effectiveness; at least annually evaluate and modify the program for risks, results, methods and other material circumstances. Before on-behalf collection/maintenance or release, reasonably assess recipient capability and obtain written assurances of reasonable protection measures. Preserve minimized, attributable program, assessment, test and recipient evidence; justify chosen technologies without claiming that this provision mandates an algorithm or independent audit. A generated task, policy document alone or DRAFT source does not establish implemented compliance.
Questions people ask
- Does COPPA 16 CFR 312.8(a)-(c) - Written information security program and recipien… apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES.
- From when does this apply?
- COPPA 16 CFR 312.8(a)-(c) - Written information security program and recipien… applies from 22 April 2026. Its current status is: in force.
- What evidence does an auditor expect?
- Written security program and implemented controls.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.