- UK government publication context for the statutory Age Appropriate Design Code laid before Parliament.
"the Secretary of State to lay the Code before Parliament"
The Children's Code applies to information society services likely to be accessed by children. It sets 15 standards for designing and operating those services under UK data protection law.
Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.
Structured answer sets in this page tree.
Cited legal and guidance references.
The is the ICO's statutory Age Appropriate Design Code for information-society services likely to be accessed by children. Its 15 standards guide how UK GDPR applies in this context; they are not a separate product certification. Scope turns on likely child access, not only whether the service says it is for adults.
Assess whether children are likely to access the service using audience data, content, design, marketing, comparable services, user research, and the effectiveness of any access restrictions. If they are, document the child's best interests, age assurance proportionality, default privacy, minimisation, geolocation, profiling, nudges, parental controls, transparency, and DPIA decisions.
The UK age of consent for an information-society service is 13 where consent is the Article 6 basis, but age 13 is not a general scope cutoff for the Code or for children's UK GDPR protections.
The controller owns the Code assessment. Product, design, engineering, privacy, safety, research, and procurement should divide the implementation work by the decisions they control. A named senior owner should approve the scope conclusion, DPIA, defaults, exceptions, and remediation.
Evidence should show likely-access research, age ranges, best-interests analysis, lawful basis, age-assurance design, DPIA, notices, default-state tests, data minimisation and retention, sharing decisions, geolocation and profiling states, parental-control signals, nudge review, connected-device security, user-rights tools, monitoring, and changes.
An adult-only label does not settle scope when children are likely to access the service. Conversely, not every offline product or non-commercial activity is an information society service. Record why the service qualifies and whether territorial scope reaches a non-UK provider processing UK children's data.
The Code explains compliance and must be taken into account by the ICO and courts where relevant, but it is not a separate certification or an automatic finding of breach. Other duties under UK GDPR, the Data Protection Act 2018, PECR, consumer law, and online-safety law may apply in parallel.
Use a standard-by-standard control record. For each of the 15 standards, record applicability, the product behaviour, owner, evidence, exception or compelling reason, approver, test result, and monitoring signal. Link the record to the DPIA and live release.
Reopen the assessment when the audience, design, recommendation or advertising logic, data fields, sharing, geolocation, profiling, parental controls, connected device, age assurance, or child-use evidence changes.
Record likely access, age ranges, the DPIA, each of the 15 standards, live evidence, exceptions, approvals, tests and change triggers.
Create likely-access, DPIA and standard-by-standard evidence questions with owners and reviewers.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"the Secretary of State to lay the Code before Parliament"
"Headings highlighted green are required areas of documentation under Article 30 of the GDPR"