Kids Online Safety Act (KOSA)
KOSA Parental Tools

Kids Online Safety Act (KOSA) KOSA-Parental-Tools-Section5-Notification-Control-Account-Privacy-Time-Spending-Limits-Minor-Account-Identification: KOSA Parental Tools + Section 5 + Notification + Control + Account Privacy + Time + Spending Limits + Minor Account Identification + Parental Override + Confirmation + Linked Accounts + Reasonable Tools

Section 5 of KOSA mandates that covered platforms provide parental tools enabling parents and guardians to support minor users. (1) Section 5(a) Required Parental Tools: (a) Account Privacy Controls - parent ability to view and modify minor account privacy settings; (b) Time Management Controls - parent ability to set time limits + bedtime restrictions + view usage; (c) Spending Limits - parent ability to set or block in-app purchases + monitor spending; (d) Notification Settings - parent notification of minor account activities + content reports + safety alerts; (e) Account Privacy Override - parent ability to enable/disable certain features; (f) Linked Accounts Mechanism - secure linking of parent and minor accounts; (g) Education and Awareness Resources - parental guides + safety tips + reporting instructions. (2) Section 5(b) Minor Account Identification: (a) Platform must clearly identify minor accounts; (b) Distinct minor experience + UI flag; (c) Account aging up procedure (e.g. 13->17->18 transitions); (d) Existing user re-identification for known minors; (e) Privacy-preserving identification methods. (3) Section 5(c) Linkage Process: (a) Verification mechanism - email + phone + government ID + payment method + family group; (b) Secure parental verification - similar to COPPA verifiable parental consent; (c) Multiple linked parent accounts permitted; (d) Linkage revocation procedure (parent or aged-up minor); (e) Privacy protection during linkage. (4) Section 5(d) Parental Dashboard: (a) Centralised parent view of minor accounts; (b) Multi-child management; (c) Cross-platform integration considerations; (d) Privacy-preserving design; (e) Mobile + desktop access; (f) Accessibility for parents with disabilities. (5) Section 5(e) Notification Specifics: (a) Real-time safety alerts (e.g. content reports + restricted contact attempts + unusual activity); (b) Periodic activity reports - usage summary + engagement metrics + content patterns; (c) Account change notifications; (d) Customizable notification preferences; (e) Push + email + SMS options. (6) Section 5(f) Privacy Considerations: (a) Minor privacy interests balanced with parental oversight rights; (b) NO surveillance of private communications without minor awareness; (c) Notification to minor of parental dashboard access; (d) Right of minor to private communication in certain contexts; (e) Older minor (16-17) progressive autonomy. (7) Section 5(g) Reasonable Tools Standard: (a) Tools must be reasonably available; (b) NOT impose burdensome requirements on parents; (c) Multi-language support; (d) Accessibility compliance per ADA; (e) Customer service for parent inquiries; (f) Tutorials + walkthroughs. (8) Section 5(h) Family + Multi-Caregiver Considerations: (a) Multiple parental relationships - biological + adoptive + step + guardian + foster; (b) Legal custody coordination; (c) Joint custody scenarios; (d) Separation + divorce considerations; (e) Grandparents + extended family options; (f) Court-ordered restrictions. (9) Section 5(i) Section 9 Kids Online Safety Council Guidance: (a) Best Practices for parental tools; (b) Multi-stakeholder input including parents + minors + experts; (c) Updates to reflect evolving practices; (d) Industry self-regulation alignment. (10) Industry Implementation Examples: (a) Apple Family Sharing + Screen Time; (b) Google Family Link; (c) Meta Family Center + Parent Supervision Tools; (d) TikTok Family Pairing; (e) Snapchat Family Center; (f) Discord Family Center; (g) Roblox Parental Controls; (h) Xbox Family Settings. (11) Industry Challenges: (a) Cross-platform parent dashboard integration; (b) Verification of parental relationship; (c) Privacy of minor vs parent oversight; (d) Older minor agency considerations; (e) International family + custody coordination; (f) Court orders + restrictions integration. (12) Enforcement of Section 5: (a) FTC Section 5 enforcement; (b) State AG enforcement; (c) Civil penalty up to USD 43,792 per violation; (d) NO Private Right of Action. Coordinates with COPPA verifiable parental consent + UK Age Appropriate Design Code Standard 11 + California AB 2273 + EU DSA Article 28 + Apple Family Sharing + Google Family Link + Meta Family Center + TikTok Family Pairing + Snapchat Family Center + Discord Family Center + Roblox + Xbox Family Settings + Family Educational Rights and Privacy Act + ADA + Section 9 Kids Online Safety Council. KOSA Parental Tools + Section 5 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 104 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AL-DPA-12 International Data Transfers
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.