COPPA 16 CFR 312.2 - Personal information, geolocation and combined identifiers
Assess actual geolocation precision, collection timing and linked information before relying on a COPPA consent or exception basis
Where this comes from
Provision: 16 CFR 312.2 - Personal information, geolocation and combined identifiers
Instrument: Children's Online Privacy Protection Act (COPPA)
Citation: 16 CFR 312.2 (Collects or collection; Personal information, paragraphs (9) and (11)), 312.3-312.5; 78 FR 3972 (17 January 2013), effective 1 July 2013, https://www.ftc.gov/system/files/2012-31341.pdf
Text version: 16 CFR 312.2/312.3, eCFR displayed through 3 September 2026, checked 6 September; FTC Six-Step Compliance Plan (May 2026) identifies connected toys/IoT as online services. 2013 final rule (78 FR 3972, effective 1 July 2013) establishes the geolocation definition. Current duties must be read with the amended consent, security and retention provisions.
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES
- COPPA assessed activity Q_COPPA_GEOLOCATION_FLOW: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Inventory actual location collection and inference from GPS, networks, SDKs, submissions and server processing; assess every recipient and linked identifier rather than assuming IP-derived data is always coarse.
- Determine whether information identifies street name and city/town under 312.2(9), and separately assess personal information combined with listed identifiers under 312.2(11); coarse location alone and combined child information are different cases.
- Resolve notice, consent and every condition of any claimed 312.5(c) exception before non-exempt collection; a location permission or app-store disclosure is not parental consent.
- Test what is received before truncation, rounding or deletion. Server-side precision reduction after receiving precise coordinates cannot undo earlier collection; assess the earliest collection point and what leaves the device.
- Test background/SDK traffic, denied permissions, failures, logs/caches and derived or combined location. Assess disclosure choice and purpose limits separately; a coarse label or fixed decimal count is not proof.
Evidence an auditor expects
- Assessment documentDocument review
Geolocation precision, timing and linked-data assessment
[ ] Inventory actual location collection and inference from GPS, networks, SDKs, submissions and server processing; assess every recipient and linked identifier rather than assuming IP-derived data is always coarse. [ ] Determine whether information identifies street name and city/town under 312.2(9), and separately assess personal information combined with listed identifiers under 312.2(11); coarse location alone and combined child information are different cases. [ ] Resolve notice, consent and every condition of any claimed 312.5(c) exception before non-exempt collection; a location permission or app-store disclosure is not parental consent. [ ] Test what is received before truncation, rounding or deletion. Server-side precision reduction after receiving precise coordinates cannot undo earlier collection; assess the earliest collection point and what leaves the device. [ ] Test background/SDK traffic, denied permissions, failures, logs/caches and derived or combined location. Assess disclosure choice and purpose limits separately; a coarse label or fixed decimal count is not proof. [ ] Preserve minimized flow, precision and consent-or-exception evidence using synthetic points; avoid raw child-location histories merely for proof and label minimization choices separately from statutory requirements. This evidence supports review; it is not legal approval, parental consent or an automatic exception.
Questions people ask
- Does COPPA 16 CFR 312.2 - Personal information, geolocation and combined identifiers apply to my service?
- It applies when COPPA assessed activity Q_COPPA_COVERED_ACTIVITY: YES; COPPA assessed activity Q_COPPA_GEOLOCATION_FLOW: YES.
- From when does this apply?
- COPPA 16 CFR 312.2 - Personal information, geolocation and combined identifiers applies from 1 July 2013. Its current status is: in force.
- What evidence does an auditor expect?
- Geolocation precision, timing and linked-data assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.