Artifact GuideUKChildren and Age Appropriate Design

UK GDPR Children and Age Appropriate Design

If children are likely to access an online service, assess their best interests and developmental needs, complete the required risk work, and build the Children's Code standards into the service.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

Apply the Age Appropriate Design Code when an information society service is likely to be accessed by anyone under 18 in the UK, even if children are not the target audience. Decide likely access, age ranges and risk first; then complete the DPIA and build the 15 standards into the service. The separate age-13 rule matters only when consent is the Article 6 basis for the service.

Section 1

What should teams decide about Children and Age Appropriate Design under the UK GDPR?

The UK ICO Age Appropriate Design Code applies to online services likely to be accessed by children and sets 15 flexible standards. Its core requirements are to put the best interests of the child first, use high-privacy settings by default, collect and retain only the minimum personal data, not disclose children's data unless there is a compelling reason to do so, taking account of the child's best interests, switch off geolocation by default, and avoid nudge techniques that pressure children to weaken privacy settings or provide unnecessary data.

Scope does not end because terms say the service is for adults. Assess likely child access from the nature and content of the service, marketing, audience evidence, user research, comparable services, and controls that genuinely prevent child access. Record the age ranges and developmental needs the design must support.

Since 5 February 2026, Article 25 expressly requires a controller providing likely to be accessed by children to consider how children can best be protected and supported, their lower awareness of data risks and rights, and their different needs at different ages and developmental stages.

  • Document the likely-access assessment, child age ranges, evidence, assumptions, owner, reviewer, and reassessment triggers.
  • Complete a DPIA that covers the child's best interests, age assurance, data flows, defaults, sharing, geolocation, profiling, nudges, connected devices, and mitigations.
  • Use age-appropriate notices and prompts, high-privacy defaults, data minimisation, visible geolocation indicators, and proportionate age assurance.
  • Do not treat age 13 as the Code's scope boundary. It is the UK threshold for a child's own consent to an information society service when consent is the Article 6 basis.
  • Test the live child journey and record exceptions, compelling reasons for lower-privacy defaults, approvals, monitoring, and remediation.
Section 2

Who should own Children and Age Appropriate Design, and what evidence should prove the decision?

The controller owns the likely-access assessment and compliance. Product and design own the child journey and defaults; privacy or legal reviews lawful basis, notices, rights, and DPIA; engineering implements age assurance, minimisation, geolocation, profiling, and parental-control states; safety and research teams supply age and risk evidence; procurement controls processors and sharing.

Evidence should show the scope assessment, age ranges, child-rights and best-interests analysis, lawful basis, age-assurance proportionality, DPIA, design decisions, child testing, notices, default settings, data and sharing maps, geolocation and profiling controls, parental-control indicators, monitoring, and remediation.

  • Senior owner: approve the likely-access conclusion, best-interests analysis, age ranges, DPIA, defaults, exceptions and remediation.
  • Product and design: retain child-journey maps, age-appropriate notices, default-state specifications, nudge review, user testing and release evidence.
  • Engineering and security: retain age-assurance logic, collection and retention settings, sharing, geolocation, profiling, parental-control indicators, access controls and connected-device tests.
  • Privacy or legal: record lawful basis, any consent and parental-authorisation path, Article 25 analysis, rights design, processor terms and parallel PECR or transfer duties.
  • Monitoring owner: track child-use evidence, complaints, rights requests, default changes, profiling outcomes, location access, exceptions, incidents and corrective work.
Section 3

Which edge cases should teams check before relying on a Children and Age Appropriate Design decision?

The Children's Code is a statutory code that explains how data protection law applies; it is not a certification and does not replace UK GDPR, the Data Protection Act 2018, PECR, consumer law, or online-safety duties. Preventive or counselling services are excluded from the Article 25 definition of , but their other data-protection duties still require separate analysis.

Age assurance must be proportionate to the risk and should not collect more data than necessary. A service that cannot establish age with sufficient certainty may need to apply the Code's protections to all users rather than assume everyone is an adult.

  • Likely access is broader than a declared target audience; evidence of actual child use or features attractive to children can outweigh an adult-only label.
  • Age 13 controls when a child may give their own consent to an information society service under Article 8; it does not define a child for the Code or remove protections for teenagers.
  • A lower-privacy default needs a documented compelling reason tied to the child's best interests, not a commercial preference or the user's failure to change a setting.
  • Parental controls do not displace the child's privacy interests; the service should give the child an obvious signal when a parent or guardian monitors activity or location.
  • Preventive or counselling services are excluded from the Article 25 definition used for the new higher-protection matters, but UK GDPR may still apply to their processing.
Section 4

How should teams operationalize Children and Age Appropriate Design with proportionate controls?

Run the work in sequence: decide likely child access; identify age ranges and risks; choose a proportionate age-assurance approach; complete the DPIA; design each relevant Code standard; test with appropriate users and specialists; approve exceptions; and monitor the live service.

Reassess after changes to content, audience, recommendation systems, monetisation, sharing, geolocation, defaults, connected devices, age assurance, or evidence that children use the service differently from the original assessment.

  • Scope: identify the service, UK connection, likely child access, age ranges, evidence, uncertainty and any effective access restriction.
  • Risk: map the child's best interests, data flows, sharing, profiling, geolocation, nudges, parental controls and connected features in the DPIA.
  • Design: apply each relevant Code standard to defaults, notices, controls and user journeys, recording every compelling-reason exception and approver.
  • Test: check the live service with appropriate research and specialist input, including default states and what children can understand or change.
  • Monitor: reopen the assessment when audience evidence, content, monetisation, recommendation logic, data, sharing, location, profiling, age assurance, parental controls or connected features change.
Primary sources

References and citations

gov.uk
Referenced sections
  • GOV.UK explanatory memorandum source confirming the Age Appropriate Design Code was laid before Parliament as a statutory code under UK data protection law.
"the Secretary of State to lay the Code before Parliament"
legislation.gov.uk
Referenced sections
  • Binding source for children's higher-protection matters and the exclusion of preventive or counselling services from the Article 25 information-society-service definition.
legislation.gov.uk
Referenced sections
  • Binding source for the age-13 consent rule and the children's higher-protection matters for information society services likely to be accessed by children.
edpb.europa.eu
Referenced sections
  • EU transfer guidance supplied as comparative background only; it does not establish the current UK transfer route.
"Transfers of personal data to countries outside of the European Economic Area"
ico.org.uk
Referenced sections
  • ICO statutory code source for online services likely to be accessed by children, including best-interests, DPIA, default-setting, and data-minimisation expectations.
"The code is a set of 15 flexible standards"
ico.org.uk
Referenced sections
  • ICO audit framework source for turning children-data decisions into accountable evidence, testing, and audit records.
"This framework will help you assess your own compliance"
ico.org.uk
Referenced sections
  • ICO guidance on the risk-based security measures that apply to children's personal data and the services processing it.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.