ESRB Privacy Certified
The Entertainment Software Rating Board (ESRB) Privacy Certified program is an FTC-approved COPPA Safe Harbor program that enables participating companies to demonstrate compliance with children's online privacy protection requirements. The program independently reviews and certifies websites, apps, and online services directed to children under 13 to ensure adherence to strict privacy standards in accordance with COPPA.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Accountability and Compliance
| Code | Title |
|---|---|
| AC-1 | Policy and Procedures |
| AC-2 | Account Management |
| AC-3 | Access Enforcement |
| AC-4 | Information Flow Enforcement |
Advertising
| Code | Title |
|---|---|
| ESRB-PC-09 | Behavioural Advertising Controls |
Age Gating
| Code | Title |
|---|---|
| ESRB-PC-14 | Age Screening Mechanism |
Branding
| Code | Title |
|---|---|
| ESRB-PC-20 | Use of Certification Seal |
Complaints
| Code | Title |
|---|---|
| ESRB-PC-08 | Complaint Mechanism |
Consent
| Code | Title |
|---|---|
| ESRB-PC-04 | Verifiable Parental Consent |
Consent and Choice
| Code | Title |
|---|---|
| CC-1 | Verifiable Parental Consent (COPPA) |
| CC-2 | Opt-In and Opt-Out Mechanisms |
| CC-3 | Purpose Limitation |
| CC-4 | Right to Access and Deletion |
Data Minimization and Retention
| Code | Title |
|---|---|
| DM-1 | Data Minimization Principle |
| DM-2 | Data Retention Policies |
| DM-3 | Data Deletion Procedures |
Data Security
Data protection, encryption, and information handling
| Code | Title |
|---|---|
| CPG-3.A | Log Collection |
| CPG-3.B | Secure Log Storage |
| CPG-3.C | Strong and Agile Encryption |
| DS-1 | Security Safeguards |
| DS-2 | Ensure Inventory of Software Components in Code |
| DS-3 | Breach Response Procedures |
| HUN-10 | Security Obligations |
| HUN-11 | Data Transfer Registry |
Disclosure
| Code | Title |
|---|---|
| ESRB-PC-02 | Privacy Policy Disclosures |
Eligibility
| Code | Title |
|---|---|
| ESRB-PC-01 | COPPA Safe Harbor Eligibility |
Geolocation
| Code | Title |
|---|---|
| ESRB-PC-16 | Geolocation Controls |
Incident
| Code | Title |
|---|---|
| ESRB-PC-19 | Incident Notification |
Marketing
| Code | Title |
|---|---|
| ESRB-PC-18 | Marketing Communications to Children |
Media
| Code | Title |
|---|---|
| ESRB-PC-17 | Photo, Video and Audio Controls |
Minimisation
| Code | Title |
|---|---|
| ESRB-PC-05 | Data Minimisation for Children |
Moderation
| Code | Title |
|---|---|
| ESRB-PC-13 | User Generated Content Moderation |
Notice
| Code | Title |
|---|---|
| ESRB-PC-03 | Direct Notice to Parents |
Operator
| Code | Title |
|---|---|
| ESRB-PC-15 | Internal Operator Lists |
Recertification
| Code | Title |
|---|---|
| ESRB-PC-07 | Annual Recertification |
Retention
| Code | Title |
|---|---|
| ESRB-PC-11 | Data Retention and Deletion |
Rights
| Code | Title |
|---|---|
| ESRB-PC-06 | Parental Access and Deletion Rights |
Security
| Code | Title |
|---|---|
| ESRB-PC-12 | Security Safeguards |
Supply Chain
| Code | Title |
|---|---|
| ESRB-PC-10 | Third Party and SDK Due Diligence |
Transparency and Notice
| Code | Title |
|---|---|
| SPP-6 | Privacy Policy Changes |
| SPP-7 | Privacy Education Resources |
| TN-1 | Privacy Policy Disclosure |
| TN-2 | Direct Notice to Parents |
| TN-3 | Material Change Notification |
| TN-4 | Data Practice Descriptions |
Your Compliance Coverage
If you comply with ESRB Privacy Certified, you already cover:
COPPA
24%
11 controls mapped
Compare →UK Data Protection Act 2018
24%
11 controls mapped
Compare →Saudi Arabia PDPL
20%
9 controls mapped
Compare →+ 504 more: New Hampshire Privacy Act (20%), Privacy Act 1988 (Australia) (20%)
See all 507 mapped frameworks ↓Maps to 507 other frameworks
Frequently Asked Questions
What is ESRB Privacy Certified?
ESRB Privacy Certified is a compliance framework from United States (ESRB / FTC) with 25 domains and 45 controls. The Entertainment Software Rating Board (ESRB) Privacy Certified program is an FTC-approved COPPA Safe Harbor program that enables participating companies to demonstrate compliance with children's online privacy protection requirements. The program independently reviews and certifies websites, apps, and online services directed to children under 13 to ensure adherence to strict privacy standards in accordance with COPPA. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ESRB Privacy Certified have?
ESRB Privacy Certified has 45 controls organised across 25 domains. The largest domains are Data Security (8 controls), Transparency and Notice (6 controls), Accountability and Compliance (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ESRB Privacy Certified map to?
ESRB Privacy Certified maps to 507 other compliance frameworks. The top mapping partners are COPPA (24% coverage), UK Data Protection Act 2018 (24% coverage), Saudi Arabia PDPL (20% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ESRB Privacy Certified compliance?
Start your ESRB Privacy Certified compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ESRB Privacy Certified requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required