Security, retention and deletion
The express security requirement — including the written information security program required by the 2025 amendments — and the data retention and deletion requirements.
§ 312.8 Confidentiality, security, and integrity of personal information collected from children.
Verbatim from eCFR (current text as at 2026-09-01).
(a) The operator must establish and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children.
(b) At a minimum, the operator must establish, implement, and maintain a written information security program that contains safeguards that are appropriate to the sensitivity of the personal information collected from children and the operator's size, complexity, and nature and scope of activities. To satisfy this requirement, the operator must:
(2) Identify and, at least annually, perform additional assessments to identify internal and external risks to the confidentiality, security, and integrity of personal information collected from children and the sufficiency of any safeguards in place to control such risks;
(3) Design, implement, and maintain safeguards to control risks identified through the risk assessments required under paragraph (b)(2) of this section. Each safeguard must be based on the volume and sensitivity of the children's personal information that is at risk, and the likelihood that the risk could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information;
(4) Regularly test and monitor the effectiveness of the safeguards in place to control risks identified through the risk assessments required under paragraph (b)(2) of this section; and
(5) At least annually, evaluate and modify the information security program to address identified risks, results of required testing and monitoring, new or more efficient technological or operational methods to control for identified risks, or any other circumstances that an operator knows or has reason to know may have a material impact on its information security program or any safeguards in place to protect personal information collected from children.
(c) Before allowing other operators, service providers, or third parties to collect or maintain personal information from children on the operator's behalf, or before releasing children's personal information to such entities, the operator must take reasonable steps to determine that such entities are capable of maintaining the confidentiality, security, and integrity of the information and must obtain written assurances that such entities will employ reasonable measures to maintain the confidentiality, security, and integrity of the information.
§ 312.10 Data retention and deletion requirements.
Verbatim from eCFR (current text as at 2026-09-01).
An operator of a website or online service shall retain personal information collected online from a child for only as long as is reasonably necessary to fulfill the specific purpose(s) for which the information was collected. When such information is no longer reasonably necessary for the purposes for which it was collected, the operator must delete the information using reasonable measures to protect against unauthorized access to, or use of, the information in connection with its deletion. Personal information collected online from a child may not be retained indefinitely. At a minimum, the operator must establish, implement, and maintain a written data retention policy that sets forth the purposes for which children's personal information is collected, the business need for retaining such information, and a timeframe for deletion of such information. The operator must provide its written data retention policy addressing personal information collected from children in the notice on the website or online service provided in accordance with § 312.4(d).
Sources
- eCFR — 16 CFR Part 312 (COPPA Rule), current text
- 15 U.S.C. §§6501–6506 (COPPA statute)
- FTC — COPPA guidance
Meta
All regulation text above is reproduced verbatim from the eCFR (current amended text), extracted mechanically from the official API. Paragraph designations ((a), (1), (i)) are part of the official text. Paragraphs carry derived attribute anchors mirroring the eCFR's own fragment scheme ({#p-312-8-b-2} here corresponds to #p-312.8(b)(2) on the linked section pages); where a section restarts its label sequence (definition lists), only the first occurrence is anchored.