TwinEthos homeAPI access

Law

COPPA Rule (16 CFR Part 312), as amended 2025

U.S. Federal Trade Commission · United States (federal) (US) · 3 provisions encoded · verified against the official source as of 2026-10-04.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: www.ecfr.gov, www.federalregister.gov.

Trust and provenance 5 official sources · last verified 4 Oct 2026 · not reviewed by a lawyer · 3 of 3 provisions audit-grade · release 2026.10.04.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 3
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.04.3, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 3 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 3.
Audit standard
3 of 3 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.04.3 (4 Oct 2026): 3 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

Keep children's data in AI stores only as long as reasonably necessary, under a written retention policy (COPPA 2025)

16 CFR 312.10 · official text · In force: applies since 22 Apr 2026 · United States (federal) (US)

An operator may retain personal information collected online from a child only as long as reasonably necessary for the specific purposes it was collected for, must then delete it with reasonable measures against unauthorized access, may not retain it indefinitely, and must establish, implement and maintain a written data retention policy stating the purposes, the business need and a deletion timeframe, provided in its online notice (16 CFR 312.10, as amended in 2025; 'delete' in 312.2). For AI features that covers transcripts, voice recordings, images, embeddings and model inputs and outputs kept about a child. Detect child-directed code that stores AI transcripts, recordings or embeddings with no expiry or deletion.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.04.3
Lane
Binding law — in force In force: applies since 22 Apr 2026
Official source
16 CFR 312.10 · captured 4 Oct 2026 · anchor hash (SHA-256) 3567bccaa1ba… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.04.3, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Retention configured in infrastructure (S3 lifecycle, TTL indexes) outside the repository
  • Provider-side retention of prompts and files
  • Expiry may be set by a bucket lifecycle rule, a database TTL index or a scheduled purge outside the file; check infrastructure and jobs before reporting.

Who it applies to

  • Duty falls on: operator
  • Operators of websites or online services directed to children under 13, or with actual knowledge that they collect a child's personal information, that keep children's personal information in AI stores (transcripts, recordings, images, embeddings, training sets), for children in the United States. The amended Rule is in force from 2025-06-23; the written retention policy and the bar on indefinite retention must be complied with by 2026-04-22.
  • Not covered:
    • Nonprofit entities that would otherwise be exempt from coverage under Section 5 of the FTC Act (15 U.S.C. 45) are not operators (16 CFR 312.2, 'Operator')
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Give every store of children's data in an AI feature (transcripts, audio, embeddings, training sets) a retention period from a written policy and delete on schedule.

Writes of children's transcripts, audio, images and embeddings set an expiry (TTL, object lifecycle rule or expires_at) taken from the retention policy; a scheduled job deletes expired records from the database, the vector index, object storage and provider-stored files; the written policy (purposes, business need, deletion timeframe) is in the children's privacy notice.

Where it goes: 1 application source code, 6 API calls and integrations, 2 data models.

What this provision adds:

  • Publish the written retention policy (purposes, business need, deletion timeframe) for children's personal information in the online notice, and delete with reasonable measures against unauthorized access when the purpose ends.

Example (Python + Redis + vector store), before:

transcript = client.audio.transcriptions.create(model='whisper-1', file=audio)
db.child_messages.insert({'child_id': child.id, 'text': transcript.text})
index.upsert([(msg_id, embed(transcript.text), {'child_id': child.id})])

After:

RETENTION = timedelta(days=CHILD_DATA_RETENTION_DAYS)  # from the written retention policy
transcript = client.audio.transcriptions.create(model='whisper-1', file=audio)
db.child_messages.insert({'child_id': child.id, 'text': transcript.text, 'expires_at': now() + RETENTION})
index.upsert([(msg_id, embed(transcript.text), {'child_id': child.id, 'expires_at': (now() + RETENTION).isoformat()})])
# purge_expired_child_data() runs daily over db, index and provider files

Control: Children's personal information copied into AI stores is kept without a retention limit or deletion. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id us-coppa.child-data-retention-limit-in-ai-stores · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.