COPPA FTC Education Technology Policy (19 May 2022) - School-context data controls
Constrain school-authorized processing to the requested service and preserve the operator's collection, security, retention and consent responsibilities
Where this comes from
Provision: FTC Education Technology Policy (19 May 2022) - School-context data controls
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: FTC Education Technology Policy Statement, 19 May 2022, pp. 2-4; COPPA FAQs N.1-N.5; 16 CFR 312.4-312.8 and 312.10; 90 FR 16918, 16919 (2025)
Text version: FTC COPPA FAQs section N (staff guidance); 19 May 2022 Commission edtech policy; 90 FR 16918, 16919 (22 April 2025) retains guidance and does not codify school authorization; checked 6 September 2026
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
- COPPA assessed activity Q_COPPA_SCHOOL_PATH: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Trace the school-requested purpose through collection, processors, use, sharing and deletion; deny unrelated commercial reuse of school-authorized data.
- Test that advertising, unrelated commercial profiling, sale and speculative future use cannot consume these data; a paid educational service is not excluded merely because it is commercial.
- Verify collection necessity, an assessed retention schedule and reasonable security separately from the school's authorization.
- Exercise the school's review, deletion and prevention controls and keep the operator's responsibility explicit in agreements.
- Preserve a minimized record of purpose and authorization; do not copy child payloads into general audit logs.
Evidence an auditor expects
- Assessment documentDocument review
Source-linked COPPA activity, authority and control assessment
Trace the school-requested purpose through collection, processors, use, sharing and deletion; deny unrelated commercial reuse of school-authorized data. Test that advertising, unrelated commercial profiling, sale and speculative future use cannot consume these data; a paid educational service is not excluded merely because it is commercial. Verify collection necessity, an assessed retention schedule and reasonable security separately from the school's authorization. Exercise the school's review, deletion and prevention controls and keep the operator's responsibility explicit in agreements. Preserve a minimized record of purpose and authorization; do not copy child payloads into general audit logs. Record the exact source version, reviewer, activity and evidence limits. A template or seed is not consent or qualified legal approval.
Questions people ask
- Does COPPA FTC Education Technology Policy (19 May 2022) - School-context data con… apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES; COPPA assessed activity Q_COPPA_SCHOOL_PATH: YES.
- From when does this apply?
- COPPA FTC Education Technology Policy (19 May 2022) - School-context data con… applies from 19 May 2022. Its current status is: in force.
- What evidence does an auditor expect?
- Source-linked COPPA activity, authority and control assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.