COPPA 16 CFR 312.2/312.3
Assess COPPA duties across covered connected-device, companion-app and cloud data flows
Where this comes from
Provision: 16 CFR 312.2/312.3; FTC guidance - Connected-device online data flows
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.2, 312.3, 312.4-312.8 and 312.10; FTC Six-Step Compliance Plan (May 2026), https://www.ftc.gov/business-guidance/resources/childrens-online-privacy-protection-rule-six-step-compliance-plan-your-business
Text version: 16 CFR 312.2/312.3, eCFR displayed through 3 September 2026, checked 6 September; FTC Six-Step Compliance Plan (May 2026) identifies connected toys/IoT as online services. 2013 final rule (78 FR 3972, effective 1 July 2013) establishes the geolocation definition. Current duties must be read with the amended consent, security and retention provisions.
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
- COPPA assessed activity Q_COPPA_CONNECTED_DEVICE_FLOW: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Establish the covered activity and each device, companion-app, cloud and on-behalf actor; include general-audience devices with actual knowledge and do not equate every manufacturer with the same operator role.
- Inventory collected identifiers, images/voice files, transcripts, geolocation and recognition-capable biometrics across setup, telemetry, support and recipients; raw voice is not automatically a biometric identifier.
- Establish notice, consent or every condition of a narrow 312.5(c) exception before non-exempt flows. A device purchase, OS permission or child setup answer is not parental consent.
- Assess the written security program, prior recipient capability/written assurances, transport/storage, pairing, credentials and firmware/update risks. Select and test appropriate safeguards without presenting one cipher/protocol as prescribed by COPPA.
- Honor parental review/refusal/deletion across actual stores and recipients, and apply purpose/business-need retention under 312.10; immediate response-linked deletion is specific to the narrow child-audio exception, not every device flow.
Evidence an auditor expects
- Assessment documentDocument review
Connected-device data-flow and duty assessment
[ ] Establish the covered activity and each device, companion-app, cloud and on-behalf actor; include general-audience devices with actual knowledge and do not equate every manufacturer with the same operator role. [ ] Inventory collected identifiers, images/voice files, transcripts, geolocation and recognition-capable biometrics across setup, telemetry, support and recipients; raw voice is not automatically a biometric identifier. [ ] Establish notice, consent or every condition of a narrow 312.5(c) exception before non-exempt flows. A device purchase, OS permission or child setup answer is not parental consent. [ ] Assess the written security program, prior recipient capability/written assurances, transport/storage, pairing, credentials and firmware/update risks. Select and test appropriate safeguards without presenting one cipher/protocol as prescribed by COPPA. [ ] Honor parental review/refusal/deletion across actual stores and recipients, and apply purpose/business-need retention under 312.10; immediate response-linked deletion is specific to the narrow child-audio exception, not every device flow. [ ] Test guests, initial setup, refusal/revocation, reconnects/offline buffers, firmware changes and vendor processing with synthetic data; keep minimized assessment and test evidence without raw child payloads. This evidence supports review; it is not legal approval, parental consent or an automatic exception.
Questions people ask
- Does COPPA 16 CFR 312.2/312.3 apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES; COPPA assessed activity Q_COPPA_CONNECTED_DEVICE_FLOW: YES.
- From when does this apply?
- COPPA 16 CFR 312.2/312.3 applies from 22 April 2026. Its current status is: in force.
- What evidence does an auditor expect?
- Connected-device data-flow and duty assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.