Back to Frameworks

ESRB Privacy Certified

United States (ESRB / FTC)
v2023
5 domains
20 controls

ESRB Privacy Certified (EPC) is one of the FTC-approved Children's Online Privacy Protection Act (COPPA) Safe Harbor programs (16 CFR Part 312, Section 312.11), operated by the Entertainment Software Rating Board since 1999. Members enter a contractual agreement with ESRB, submit each product/service for review, and undergo ESRB's comprehensive privacy assessment process plus at least two ongoing compliance reports per year and spot audits. EPC offers two seals: the ESRB Privacy Certified Seal (general audience) and the ESRB Privacy Certified Kids Seal (child-directed products). The full normative Member Guidelines and Kids Seal Requirements are FTC-approved but delivered to members under contractual membership; the program's structure and obligations - anchored in COPPA's notice, parental consent, data minimisation, retention/deletion, security and parental access requirements - are publicly documented on esrb.org.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

ESRB Privacy Certified - Child-Specific Controls

4 controls
Controls in the ESRB Privacy Certified - Child-Specific Controls domain of ESRB Privacy Certified4 controls
CodeTitle
ESRB-PC-17Behavioural advertising and targeted-advertising controls
ESRB-PC-18Age screening and mixed-audience determination
ESRB-PC-19Geolocation and persistent identifiers
ESRB-PC-20User-generated content, photos, video, audio and moderation

ESRB Privacy Certified - Data Practices and Rights

5 controls
Controls in the ESRB Privacy Certified - Data Practices and Rights domain of ESRB Privacy Certified5 controls
CodeTitle
ESRB-PC-10Data minimisation for child personal information
ESRB-PC-11Internal Operations Exception scope
ESRB-PC-12Parental access, review and deletion rights
ESRB-PC-13Data retention and secure deletion
ESRB-PC-14Third-party and SDK due diligence

ESRB Privacy Certified - Notice and Parental Consent

4 controls
Controls in the ESRB Privacy Certified - Notice and Parental Consent domain of ESRB Privacy Certified4 controls
CodeTitle
ESRB-PC-06Online Privacy Notice (privacy policy)
ESRB-PC-07Direct Notice to parents
ESRB-PC-08Verifiable Parental Consent (VPC)
ESRB-PC-09Material change notification

ESRB Privacy Certified - Program Eligibility and Operation

5 controls
Controls in the ESRB Privacy Certified - Program Eligibility and Operation domain of ESRB Privacy Certified5 controls
CodeTitle
ESRB-PC-01COPPA Safe Harbor program eligibility and Seal selection
ESRB-PC-02Initial certification assessment and ESRB review
ESRB-PC-03Ongoing compliance reports, spot audits and annual recertification
ESRB-PC-04Use of the certification Seal
ESRB-PC-05Complaint handling and dispute resolution mechanism

ESRB Privacy Certified - Security and Operational Safeguards

2 controls
Controls in the ESRB Privacy Certified - Security and Operational Safeguards domain of ESRB Privacy Certified2 controls
CodeTitle
ESRB-PC-15Confidentiality, security and integrity of child PI
ESRB-PC-16Incident handling and ESRB notification

Maps to 3 other frameworks

20 total controls
COPPA
11 source controls mapped|11 target controls covered
55%
GDPR
3 source controls mapped|3 target controls covered
15%
UK Age Appropriate Design Code (Children's Code)
3 source controls mapped|2 target controls covered
15%

Frequently Asked Questions

What is ESRB Privacy Certified?

ESRB Privacy Certified is a compliance framework from United States (ESRB / FTC) with 5 domains and 20 controls. ESRB Privacy Certified (EPC) is one of the FTC-approved Children's Online Privacy Protection Act (COPPA) Safe Harbor programs (16 CFR Part 312, Section 312.11), operated by the Entertainment Software Rating Board since 1999. Members enter a contractual agreement with ESRB, submit each product/service for review, and undergo ESRB's comprehensive privacy assessment process plus at least two ongoing compliance reports per year and spot audits. EPC offers two seals: the ESRB Privacy Certified Seal (general audience) and the ESRB Privacy Certified Kids Seal (child-directed products). The full normative Member Guidelines and Kids Seal Requirements are FTC-approved but delivered to members under contractual membership; the program's structure and obligations - anchored in COPPA's notice, parental consent, data minimisation, retention/deletion, security and parental access requirements - are publicly documented on esrb.org. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ESRB Privacy Certified have?

ESRB Privacy Certified has 20 controls organised across 5 domains. The largest domains are ESRB Privacy Certified - Data Practices and Rights (5 controls), ESRB Privacy Certified - Program Eligibility and Operation (5 controls), ESRB Privacy Certified - Child-Specific Controls (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ESRB Privacy Certified map to?

ESRB Privacy Certified maps to 3 other compliance frameworks. The top mapping partners are COPPA (55% coverage), GDPR (15% coverage), UK Age Appropriate Design Code (Children's Code) (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ESRB Privacy Certified compliance?

Start your ESRB Privacy Certified compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ESRB Privacy Certified requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required