Independent short-form field notesLocal review edition · 19 September 2026
Short-Form Research

Policy & rules / Source record

The FTC's COPPA safe harbor list names six approved programs

The FTC's own pages set how a COPPA safe harbor program is approved and what it must do.

Historical context. This record is preserved from the September 16 archive. A new page layout does not mean every original claim was reverified. Event dates describe the subject, not when this site published it.

The test

The Federal Trade Commission maintains a page, COPPA Safe Harbor Program, describing how an industry group can seek Commission approval to run its own self-regulatory program under the Children's Online Privacy Protection Act. The page states the Rule requires the Commission to act on a safe harbor request within 180 days of the filing of the request, after notice and comment, and that Section 312.10 sets the approval criteria and required application materials. As retrieved on 16 September 2026, it lists six approved organizations: the Children's Advertising Review Unit, the Entertainment Software Rating Board, iKeepSafe, kidSAFE, PRIVO and TRUSTe.

What the evidence says

The FTC's separate COPPA compliance FAQ adds detail the safe-harbor page does not: an application must explain the applicant's business model and assessment mechanisms, compare each guideline against the corresponding Rule provision, and state how disciplinary consequences provide effective enforcement. The FAQ says the Commission checks for an effective, mandatory mechanism to assess members, including a comprehensive annual review of each operator, plus effective disciplinary actions. Notably, the FAQ cites this framework to 16 C.F.R. Section 312.11, while the safe-harbor page cites Section 312.10 — a discrepancy plausibly tied to the Rule's April 2025 amendments, which the FAQ's own note flags, though neither page resolves which citation is current.

The sample and the variance

Both are living FTC pages describing an ongoing mechanism, not a snapshot of any company's compliance record. Membership substitutes the safe harbor's own review and discipline for direct FTC enforcement against that member, but neither page says membership exempts a company from COPPA's substantive requirements — only that the safe harbor administers review. Because both pages are subject to revision, a reader checking these facts later should confirm the current approved list and rule citation rather than assume either stayed static.

What to try next

An app operator considering third-party child-privacy certification can use the FTC's list as a starting point for identifying currently approved programs, and can request each program's own guidelines and determination materials, which the FAQ says are published alongside each application. This is an editorial suggestion, not a compliance judgment: which program suits a given business depends on facts the FTC's pages do not evaluate.

  • Which Rule section — 312.10 or 312.11 — currently governs safe harbor approval, and has one FTC page simply not been updated since the 2025 amendments?
  • Does the safe harbor program a given company has joined still appear on the FTC's current approved list?
  • What does that program's own comprehensive annual review actually check, beyond the general standard the FTC's FAQ describes?

The FTC's own pages establish how a safe harbor program is approved and what the Commission expects it to do; they do not establish how rigorously any specific approved program applies that standard in practice.

Sources & limits

  1. COPPA Safe Harbor Program ↗

    Lists the FTC's currently approved safe harbor organizations and states the statutory approval process, citing Section 312.10.

    Source · Source publication date not stated · Archive retrieval: 2026-09-16
  2. Complying with COPPA: Frequently Asked Questions ↗

    States the safe harbor application requirements, the 180-day determination clock, and the comprehensive annual review and disciplinary-action criteria, citing 16 C.F.R. Section 312.11.

    Source · Source publication date not stated · Archive retrieval: 2026-09-16

Original source trail retained. Claims and media need owner review before release.