Children's DataUK GDPR

UK GDPR Children and Age Appropriate Design

Design online services for children using the ICO child first standards.

If a service is likely to be accessed by children, the Children's Code affects defaults, profiling, geolocation, sharing, and transparency.

Author
Sorena AI
Published
Feb 21, 2026
Updated
Feb 21, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Feb 21, 2026
Updated Feb 21, 2026
Overview

The Children's Code changes product settings, feature design, vendor choices, and testing practices for online services likely to be accessed by children.

Section 1

Likely to be accessed analysis

The first decision is whether children are likely to access the service. ICO guidance expects a real assessment of audience, features, marketing, and actual user patterns, not a simple statement that the service is intended for adults.

  • Document audience evidence from analytics, market, and product signals
  • Map the child journey across onboarding, content, messaging, ads, and support
  • Identify third party SDKs and data sharing dependencies that affect children
  • Record the age bands you design for and why
Section 2

Standards that usually require product changes

The standards most often missed in practice are high privacy by default, data minimisation, avoiding detrimental uses, turning geolocation off by default, disabling profiling by default unless there is a compelling reason, and not using nudge techniques that push children toward weaker privacy.

  • Set high privacy defaults for collection and sharing
  • Turn precise geolocation off by default unless strongly justified
  • Avoid profiling or persuasive design that undermines privacy choices
  • Provide child appropriate explanations at the point of use
Section 3

Assurance and evidence

The ICO AADC impact assessment template is a practical way to show how product and privacy teams considered harms, alternatives, and safeguards before launch.

  • Maintain a Children's Code control matrix against the 15 standards
  • Keep AADC impact assessments, design decisions, and testing evidence
  • Log approvals for exceptions and mitigations
  • Include child privacy checks in release governance and incident response
Recommended next step

Use UK GDPR Children and Age Appropriate Design as a cited research workflow

Research Copilot can take UK GDPR Children and Age Appropriate Design from getting cited answers and faster research on this topic to a reusable workflow inside Sorena. Teams working on UK GDPR can keep owners, evidence, and next steps aligned without copying this guide into separate documents.

Primary sources

References and citations

Related guides

Explore more topics

IDTA vs EU SCCs | UK GDPR Transfer Tool Comparison
Compare the UK IDTA, UK Addendum, and EU standard contractual clauses for UK GDPR transfer compliance, contract selection, and transfer risk assessments.
UK GDPR Applicability Test | Territorial Scope and Roles
Assess UK GDPR territorial scope, controller or processor role, special category triggers, and UK transfer exposure with a defensible applicability test.
UK GDPR Breach Notification | 72 Hour ICO Reporting Guide
Operational guide to UK GDPR breach notification, including the 72 hour ICO deadline, processor escalation, breach logging.
UK GDPR Checklist | Practical Compliance Checklist
Practical UK GDPR checklist for accountability, lawful basis, Article 30 records, processor contracts, rights handling, transfers, and breach readiness.
UK GDPR Compliance Program | Operating Model Guide
Build a UK GDPR compliance program with accountability, Article 30 records, DPIAs, controller processor contracts, rights operations, transfer controls.
UK GDPR Data Subject Rights | One Month Response Guide
Operational guide to UK GDPR data subject rights, including access, rectification, erasure, restriction, portability, objection.
UK GDPR Deadlines and Compliance Calendar
Calendar view of UK GDPR milestones, including January 1, 2021 applicability, March 2022 transfer tools, one month rights deadlines.
UK GDPR FAQ | Practical Questions and Answers
Practical UK GDPR FAQ covering scope, lawful basis, rights timing, breach reporting, transfers, children, and enforcement exposure.
UK GDPR Penalties and Fines | Enforcement Exposure Guide
Guide to UK GDPR penalties and fines, including the 17.5 million pounds or 4 percent upper tier, the 8.7 million pounds or 2 percent standard tier.
UK GDPR Requirements | Control Level Requirements Guide
Control level UK GDPR requirements covering principles, lawful basis, transparency, rights, Article 30 records, security, contracts, transfers, and DPIAs.
UK GDPR Transfers, IDTA, and UK Addendum
Detailed UK GDPR international transfers guide covering adequacy, UK IDTA, UK Addendum, transfer risk assessments, vendor governance, and UK bridge reliance.
UK GDPR vs Data Protection Act 2018
Compare the UK GDPR and the Data Protection Act 2018, including what the UK GDPR does directly and where the DPA 2018 supplements, restricts, or extends it.
UK GDPR vs EU GDPR | Practical Comparison
Practical comparison of the UK GDPR and EU GDPR, including scope, transfers, regulators, adequacy, and operational divergence for multinational programmes.
UK vs EU GDPR Differences | Operational Differences List
Operational differences between the UK and EU privacy regimes, including transfer tools, adequacy lists, regulators, notices, and programme governance.