COPPA
Children's Online Privacy Protection Act
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Access
| Code | Title |
|---|---|
| 16 CFR s312.6(a) | Parental Right to Review |
| 16 CFR s312.6(b) | Identity Verification for Parental Access |
| 16 CFR s312.6(c) | Right to Refuse Further Collection and Deletion |
COPPA: Accountability & Compliance
Demonstration of compliance and accountability (COPPA)
| Code | Title |
|---|---|
| COPPA-25 | Compliance monitoring and auditing |
| COPPA-26 | Training and awareness programs |
| COPPA-27 | Regulatory reporting and cooperation |
| COPPA-28 | Complaints handling and resolution |
| COPPA-29 | Enforcement and penalties awareness |
COPPA: Data Collection & Consent
Requirements for lawful collection and consent management (COPPA)
| Code | Title |
|---|---|
| COPPA-01 | Notice and transparency requirements |
| COPPA-02 | Consent management and withdrawal |
| COPPA-03 | Lawful basis for processing |
| COPPA-04 | Purpose limitation and specification |
| COPPA-05 | Data minimization requirements |
COPPA: Data Governance
Organizational governance of personal data processing (COPPA)
| Code | Title |
|---|---|
| COPPA-19 | Data protection officer designation |
| COPPA-20 | Records of processing activities |
| COPPA-21 | Data protection impact assessments |
| COPPA-22 | Privacy by design and default |
| COPPA-23 | Data processing agreements |
| COPPA-24 | Cross-border transfer safeguards |
COPPA: Data Security
Technical and organizational security measures (COPPA)
| Code | Title |
|---|---|
| COPPA-13 | Encryption of personal data |
| COPPA-14 | Pseudonymization techniques |
| COPPA-15 | Access control for personal data |
| COPPA-16 | Data breach notification requirements |
| COPPA-17 | Security incident response procedures |
| COPPA-18 | Regular security testing and assessment |
COPPA: Data Subject Rights
Individual rights regarding their personal data (COPPA)
| Code | Title |
|---|---|
| COPPA-06 | Right of access to personal data |
| COPPA-07 | Right to rectification of inaccurate data |
| COPPA-08 | Right to erasure and deletion |
| COPPA-09 | Right to data portability |
| COPPA-10 | Right to restrict processing |
| COPPA-11 | Right to object to processing |
| COPPA-12 | Automated decision-making protections |
Data Minimisation
| Code | Title |
|---|---|
| 16 CFR s312.7 | Prohibition Against Conditioning Participation |
Enforcement
| Code | Title |
|---|---|
| 15 U.S.C. s6502(c) / 16 CFR Part 312 | Enforcement, Penalties, and State Attorneys General |
Notice
| Code | Title |
|---|---|
| 16 CFR s312.4(a) | Clear and Understandable Notice |
| 16 CFR s312.4(b) | Material Change Re Notice and Re Consent |
| 16 CFR s312.4(c) | Direct Notice to Parents |
| 16 CFR s312.4(d) | Online Notice (Privacy Policy Content) |
| 16 CFR s312.4(d)(2) | Third Party Operator Disclosure |
Program Governance
| Code | Title |
|---|---|
| 16 CFR s312.3 | General Requirements (Five Core Obligations) |
Retention
| Code | Title |
|---|---|
| 16 CFR s312.10 | Data Retention and Deletion |
Safe Harbor
| Code | Title |
|---|---|
| 16 CFR s312.11 | Safe Harbor Programs |
Scope
| Code | Title |
|---|---|
| 16 CFR Part 312 (Mixed Audience) | Mixed Audience Sites and Age Screening |
| 16 CFR s312.2 (Actual Knowledge) | Actual Knowledge Standard for General Audience Sites |
| 16 CFR s312.2 (Definitions: Operator) | Operator Scope Determination |
| 16 CFR s312.2 (Directed to Children) | Child Directed Determination (Multi Factor Test) |
| 16 CFR s312.2 (Personal Information) | Personal Information Categories Inventory |
| 16 CFR s312.2 (Support for Internal Operations) | Support for Internal Operations Definition |
| FTC COPPA FAQs (Audio Voice) | Voice Recordings as Personal Information |
Security
| Code | Title |
|---|---|
| 16 CFR s312.8 | Confidentiality, Security, and Integrity |
Verifiable Parental Consent
| Code | Title |
|---|---|
| 16 CFR s312.5 (Schools) | School Consent in Lieu of Parental Consent (Limited) |
| 16 CFR s312.5(a) | Verifiable Parental Consent Requirement |
| 16 CFR s312.5(a)(2) | Consent for Disclosure to Third Parties |
| 16 CFR s312.5(b) | Approved Methods of Verifiable Parental Consent |
| 16 CFR s312.5(b)(1) | Sliding Scale Verification (Internal vs Disclosure Use) |
| 16 CFR s312.5(b)(2)(vii) | Knowledge Based Authentication (KBA) |
| 16 CFR s312.5(b)(2)(viii) | Facial Recognition Consent Method |
| 16 CFR s312.5(c) (Email Plus) | Email Plus for Internal Use Only Collection |
| 16 CFR s312.5(c) (Exceptions) | Exceptions to Prior Parental Consent |
| 16 CFR s312.5(c)(4) | Persistent Identifier Internal Operations Exception |
Your Compliance Coverage
If you comply with COPPA, you already cover:
UK Data Protection Act 2018
28%
17 controls mapped
Compare →Argentina PDPA
23%
14 controls mapped
Compare →Switzerland FADP
23%
14 controls mapped
Compare →+ 607 more: APPI (23%), Colorado Privacy Act (23%)
See all 610 mapped frameworks ↓Maps to 610 other frameworks
Frequently Asked Questions
What is COPPA?
COPPA is a compliance framework from United States with 15 domains and 60 controls. Children's Online Privacy Protection Act It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does COPPA have?
COPPA has 60 controls organised across 15 domains. The largest domains are Verifiable Parental Consent (10 controls), COPPA: Data Subject Rights (7 controls), Scope (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does COPPA map to?
COPPA maps to 610 other compliance frameworks. The top mapping partners are UK Data Protection Act 2018 (28% coverage), Argentina PDPA (23% coverage), Switzerland FADP (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with COPPA compliance?
Start your COPPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about COPPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 60 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required