COPPA 16 CFR 312.10 - Written retention policy, purpose limits and secure deletion
Implement and publish a written children's-data retention policy with specific purposes, business need and deletion timeframes; delete securely when no longer reasonably necessary
Where this comes from
Provision: 16 CFR 312.10 - Written retention policy, purpose limits and secure deletion
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.10 and 312.4(d)(2); 90 FR 16918 (22 April 2025), amended rule effective 23 June 2025, general compliance date 22 April 2026
Text version: 16 CFR Part 312, 2025 amended Rule (90 FR 16918); eCFR as of 3 September 2026; retrieved 6 September 2026
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Establish, implement and maintain a written policy stating specific collection purposes, the business need for retention and a deletion timeframe.
- Provide that written policy in the online children's privacy notice required by 312.4(d).
- Delete when reasonable necessity ends, prohibit indefinite retention and use reasonable protective measures during deletion; a configured maximum does not justify unnecessary retention.
- Trace and test deletion across primary systems, logs, caches, backups and recipients; document actual residual/restore constraints without making unsupported deletion claims.
- Keep minimized completion evidence without retaining the deleted payload in logs; handle parental rights under 312.6 separately and do not invent an immediate statutory deadline.
Evidence an auditor expects
- Policy documentDocument review
Written retention policy, published notice and deletion execution
Reviewed evidence for the assessed activity and applicable source version: Establish, implement and maintain a written policy stating specific collection purposes, the business need for retention and a deletion timeframe. Provide that written policy in the online children's privacy notice required by 312.4(d). Delete when reasonable necessity ends, prohibit indefinite retention and use reasonable protective measures during deletion; a configured maximum does not justify unnecessary retention. Trace and test deletion across primary systems, logs, caches, backups and recipients; document actual residual/restore constraints without making unsupported deletion claims. Keep minimized completion evidence without retaining the deleted payload in logs; handle parental rights under 312.6 separately and do not invent an immediate statutory deadline. A generated task, policy document alone or DRAFT source does not establish implemented compliance.
Questions people ask
- Does COPPA 16 CFR 312.10 - Written retention policy, purpose limits and secure del… apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES.
- From when does this apply?
- COPPA 16 CFR 312.10 - Written retention policy, purpose limits and secure del… applies from 22 April 2026. Its current status is: in force.
- What evidence does an auditor expect?
- Written retention policy, published notice and deletion execution.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.