Binding law — in force
An operator may retain personal information collected online from a child only as long as reasonably necessary for the specific purposes it was collected for, must then delete it with reasonable measures against unauthorized access, may not retain it indefinitely, and must establish, implement and maintain a written data retention policy stating the purposes, the business need and a deletion timeframe, provided in its online notice (16 CFR 312.10, as amended in 2025; 'delete' in 312.2). For AI features that covers transcripts, voice recordings, images, embeddings and model inputs and outputs kept about a child. Detect child-directed code that stores AI transcripts, recordings or embeddings with no expiry or deletion.
us-coppa.child-data-retention-limit-in-ai-stores · 16 CFR 312.10 · official source · jurisdictions: US
The guard to add, and how far to trust this rule
Binding law — in force
From the 2026-04-22 compliance date of the 2025 amendments, an operator must let the parent consent to collection and use of the child's personal information without consenting to its disclosure to third parties, unless the disclosure is integral to the service, and must obtain separate verifiable parental consent to such a disclosure (16 CFR 312.5(a)(2)). In adopting the amendment the Commission stated that disclosures to third parties to train or otherwise develop artificial intelligence technologies are not integral and need that separate consent (90 FR 16918, Part II.D.1.b). Detect child-directed code that exports children's data to a third-party training, fine-tuning or dataset path with no separate parental consent check.
us-coppa.separate-consent-before-child-data-to-third-party-ai-training · 16 CFR 312.5(a)(2) · official source · jurisdictions: US
The guard to add, and how far to trust this rule
Binding law — in force
An operator of a website or online service directed to children, or with actual knowledge that it collects personal information from a child under 13, must obtain verifiable parental consent before any collection, use or disclosure of the child's personal information (16 CFR 312.3(b), 312.5(a)(1)). Personal information includes a photograph, video or audio file containing a child's image or voice, persistent identifiers, and, since the 2025 amendments, biometric identifiers such as voiceprints and faceprints (312.2), so voice assistants, chatbots and image features that send what a child says or shows to a model need that consent first. Two exceptions matter for AI features: an audio file used only to answer the child's request and deleted immediately (312.5(c)(9)), and a persistent identifier used only for internal operations (312.5(c)(7)). Detect child-directed code that sends a child's input to a model with no parental-consent check.
us-coppa.verifiable-parental-consent-before-ai-collection · 16 CFR 312.5(a)(1) · official source · jurisdictions: US
The guard to add, and how far to trust this rule