← Crosswalk explorer

COPPA Google Play Families

6 canonical controls in Keel’s library satisfy clauses of both COPPA and Google Play Families. Implement each once, attach the evidence once, and it counts toward each standard. The overlap is the work you don’t repeat.

6 shared controls COPPA · 16 CFR Part 312 (2025 amendments): 21 in library Google Play Families · Families Policies, retrieved 2026-08-13: 9 in library
Start free with COPPA + Google Play Families See all pairs

Controls that satisfy both

Canonical control COPPA clauses Google Play Families clauses
Children’s online privacy programme
A documented assessment of whether the service is directed to children under 13 or has a mixed audience, which operators collect through it, and the notice, consent, parental-rights, minimisation, security and retention duties that follow. Where the app ships through an app store, the same assessment carries that store’s audience determination — note Amazon treats under 16 as a child in the EU, Australia and Japan, so the age band recorded must be the widest one that applies.
312.3 families/console/target-audience, families/requirements/legal-compliance
Children’s privacy notice (direct & online)
Direct notices to parents for each circumstance that triggers one, and a prominent online children’s privacy notice carrying the operator details, collection, use, disclosure and retention information the rule requires. The same notice work satisfies the app stores’ requirements to publish a privacy policy and to disclose everything collected from children, including through SDKs.
312.4(a), 312.4(b), 312.4(c)(1), 312.4(c)(2), 312.4(c)(3), 312.4(c)(4), 312.4(d) families/requirements/data-disclosure
Minimised collection in children’s activities
Games, prize offerings and other activities aimed at children are reviewed so participation is never conditioned on disclosing more personal information than the activity reasonably needs, and the technical identifiers and location signals the app stores prohibit in children’s apps are neither collected nor transmitted.
312.7 families/requirements/child-only-identifiers, families/requirements/ad-id-permission, families/requirements/mixed-identifiers, families/requirements/phone-number, families/requirements/child-only-location, families/requirements/bluetooth-cdm
Children’s advertising & monetisation controls
Ads and monetisation reaching children or users of unknown age come only from sources the store permits, carry no interest-based targeting or remarketing, present age-appropriate creative, and follow the store’s format rules on ad walls, closeability, launch interstitials, multiple placements and virtual currency. Note the stores differ sharply here: Amazon bars its own advertising and affiliate programmes outright and parental consent does not lift that, while Google permits certified SDKs and Apple permits contextual advertising only from vendors with published kids policies including human creative review.
312.5(c)(7) families/ads/certified-sdk-only, families/ads/no-interest-based-or-remarketing, families/ads/child-appropriate-content, families/ads/legal-and-industry-standards, families/ads-format/no-deceptive-or-inadvertent-clicks, families/ads-format/no-ad-walls, families/ads-format/closeable-after-5-seconds, families/ads-format/no-launch-interstitial, families/ads-format/no-multiple-placements, families/ads-format/distinguishable-from-content, families/ads-format/no-manipulative-tactics, families/ads-format/no-forced-click-through, families/ads-format/virtual-currency-distinction
Third-party SDK & API governance for children’s apps
Every third-party SDK and API in a child-directed app is inventoried with what it collects and transmits, checked against terms that permit child-directed use, and either confirmed suitable for children or gated so it collects nothing from them. This is one inventory that answers Apple’s analytics limits, Google’s approved-SDK rules, Amazon’s child-suitability test and COPPA’s diligence duty at once.
312.8(c) families/requirements/child-only-sdk, families/requirements/mixed-sdk, families/requirements/mixed-sdk-gating
Neutral age screening for mixed audiences
A mixed-audience app establishes a user’s age band with a neutral screen that does not steer or reward a user into misstating their age, treats an unknown age as a child, and uses the result to gate data collection, third-party SDKs and advertising. One implementation is the evidence for the identifier, SDK and ad-serving rules that all depend on knowing which users are children.
312.5(c)(8) families/ads-sdk/mixed-age-screening

Clause identifiers (COPPA and Google Play Families) are referenced factually for mapping. Keel is not affiliated with or endorsed by the bodies that publish these standards. Control descriptions are Keel’s own; a framework’s full authored control count is on its framework page.

Why this is one project, not two

On a crosswalk-native model, Google Play Families mostly lights up controls you already built for COPPA. You’re not re-uploading the same screenshot for a second audit. You apply the framework and see the genuine delta worth working. That’s the whole idea behind collect once, comply everywhere.