← COPPA · Parental consent
312.5 — Verifiable parental consent before collection
Requirement
The operator obtains verifiable parental consent before collecting, using or disclosing personal information from a child, using a method reasonably calculated to ensure the person consenting is the parent — such as a signed form, a payment-card transaction with notice, a call or video conference with trained staff, government ID checked against a database and deleted, knowledge-based questions, facial matching to ID, or text-plus (email plus) where information is only used internally — unless a 312.5(c) exception applies.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| CCPA/CPRA | 1798.120(c)-(d) | Opt-in consent to sell or share minors' information | children consent |
| GDPR | Art.8 | Conditions for a child's consent to online services | consent children |
| NDPA 2023 | s.31 | Processing the data of children and persons lacking capacity | consent children |
| GDPR | Art.6 | Lawful basis for processing | consent |
| GDPR | Art.7 | Conditions for consent | consent |
| GDPR | Art.21 | Right to object, including to direct marketing | consent |
| CCPA/CPRA | 1798.120 | Right to opt out of sale and sharing | consent |
| CCPA/CPRA | 1798.121 | Right to limit use of sensitive personal information | consent |