- GOV.UK explanatory memorandum source confirming the Age Appropriate Design Code was laid before Parliament as a statutory code under UK data protection law.
"the Secretary of State to lay the Code before Parliament"
If children are likely to access an online service, assess their best interests and developmental needs, complete the required risk work, and build the Children's Code standards into the service.
Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.
Structured answer sets in this page tree.
Cited legal and guidance references.
Apply the Age Appropriate Design Code when an information society service is likely to be accessed by anyone under 18 in the UK, even if children are not the target audience. Decide likely access, age ranges and risk first; then complete the DPIA and build the 15 standards into the service. The separate age-13 rule matters only when consent is the Article 6 basis for the service.
The UK ICO Age Appropriate Design Code applies to online services likely to be accessed by children and sets 15 flexible standards. Its core requirements are to put the best interests of the child first, use high-privacy settings by default, collect and retain only the minimum personal data, not disclose children's data unless there is a compelling reason to do so, taking account of the child's best interests, switch off geolocation by default, and avoid nudge techniques that pressure children to weaken privacy settings or provide unnecessary data.
Scope does not end because terms say the service is for adults. Assess likely child access from the nature and content of the service, marketing, audience evidence, user research, comparable services, and controls that genuinely prevent child access. Record the age ranges and developmental needs the design must support.
Since 5 February 2026, Article 25 expressly requires a controller providing likely to be accessed by children to consider how children can best be protected and supported, their lower awareness of data risks and rights, and their different needs at different ages and developmental stages.
The controller owns the likely-access assessment and compliance. Product and design own the child journey and defaults; privacy or legal reviews lawful basis, notices, rights, and DPIA; engineering implements age assurance, minimisation, geolocation, profiling, and parental-control states; safety and research teams supply age and risk evidence; procurement controls processors and sharing.
Evidence should show the scope assessment, age ranges, child-rights and best-interests analysis, lawful basis, age-assurance proportionality, DPIA, design decisions, child testing, notices, default settings, data and sharing maps, geolocation and profiling controls, parental-control indicators, monitoring, and remediation.
The Children's Code is a statutory code that explains how data protection law applies; it is not a certification and does not replace UK GDPR, the Data Protection Act 2018, PECR, consumer law, or online-safety duties. Preventive or counselling services are excluded from the Article 25 definition of , but their other data-protection duties still require separate analysis.
Age assurance must be proportionate to the risk and should not collect more data than necessary. A service that cannot establish age with sufficient certainty may need to apply the Code's protections to all users rather than assume everyone is an adult.
Run the work in sequence: decide likely child access; identify age ranges and risks; choose a proportionate age-assurance approach; complete the DPIA; design each relevant Code standard; test with appropriate users and specialists; approve exceptions; and monitor the live service.
Reassess after changes to content, audience, recommendation systems, monetisation, sharing, geolocation, defaults, connected devices, age assurance, or evidence that children use the service differently from the original assessment.
Record likely child access, age ranges, best interests, age assurance, DPIA, standard-by-standard controls, exceptions, testing and monitoring.
Create likely-access, age, risk, default, profiling, location, sharing, test and monitoring questions.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"the Secretary of State to lay the Code before Parliament"
"Transfers of personal data to countries outside of the European Economic Area"
"The code is a set of 15 flexible standards"
"This framework will help you assess your own compliance"