Artifact GuideUKChildren's Code

UK GDPR Children's Code

The Children's Code applies to information society services likely to be accessed by children. It sets 15 standards for designing and operating those services under UK data protection law.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

The is the ICO's statutory Age Appropriate Design Code for information-society services likely to be accessed by children. Its 15 standards guide how UK GDPR applies in this context; they are not a separate product certification. Scope turns on likely child access, not only whether the service says it is for adults.

Section 1

What should teams decide about Children's Code under the UK GDPR?

Assess whether children are likely to access the service using audience data, content, design, marketing, comparable services, user research, and the effectiveness of any access restrictions. If they are, document the child's best interests, age assurance proportionality, default privacy, minimisation, geolocation, profiling, nudges, parental controls, transparency, and DPIA decisions.

The UK age of consent for an information-society service is 13 where consent is the Article 6 basis, but age 13 is not a general scope cutoff for the Code or for children's UK GDPR protections.

  • Scope and best interests: record likely child access, relevant age ranges, evidence, the child's best interests, and the controller responsible.
  • Risk and age: complete a DPIA and use a risk-based, proportionate method to establish age or apply child protections to all users.
  • Information and defaults: provide concise age-appropriate information, set high privacy by default, minimise collection and retention, and uphold published terms and policies.
  • Data use: do not use children's data in ways shown to harm wellbeing, and do not usually disclose it unless there is a compelling reason linked to the child's best interests.
  • Features: switch geolocation off by default with an obvious active signal; switch profiling off by default unless the Code's conditions support it; signal parental monitoring; avoid nudges that weaken privacy; secure connected toys and devices; and provide accessible tools for rights and complaints.
Section 2

Who should own Children's Code, and what evidence should prove the decision?

The controller owns the Code assessment. Product, design, engineering, privacy, safety, research, and procurement should divide the implementation work by the decisions they control. A named senior owner should approve the scope conclusion, DPIA, defaults, exceptions, and remediation.

Evidence should show likely-access research, age ranges, best-interests analysis, lawful basis, age-assurance design, DPIA, notices, default-state tests, data minimisation and retention, sharing decisions, geolocation and profiling states, parental-control signals, nudge review, connected-device security, user-rights tools, monitoring, and changes.

  • Senior owner: approve the scope decision, best-interests analysis, DPIA, high-privacy defaults, compelling-reason exceptions and remediation.
  • Product, design and research: retain child-age assumptions, journey maps, notices, default states, nudge review, user evidence and release acceptance.
  • Engineering and security: retain age-assurance, minimisation, retention, sharing, geolocation, profiling, parental-control, connected-device and rights-tool tests.
  • Privacy, legal and procurement: record lawful basis, Article 8 consent logic where relevant, Article 25 duties, processor instructions, data sharing and transfer routes.
  • Monitoring owner: track child access, complaints, rights requests, profiling and location events, default changes, exceptions, incidents and corrective work.
Section 3

Which edge cases should teams check before relying on a Children's Code decision?

An adult-only label does not settle scope when children are likely to access the service. Conversely, not every offline product or non-commercial activity is an information society service. Record why the service qualifies and whether territorial scope reaches a non-UK provider processing UK children's data.

The Code explains compliance and must be taken into account by the ICO and courts where relevant, but it is not a separate certification or an automatic finding of breach. Other duties under UK GDPR, the Data Protection Act 2018, PECR, consumer law, and online-safety law may apply in parallel.

  • Likely child access can exist even where the service is aimed at adults; assess content, design, marketing, audience data, comparable services and the effectiveness of restrictions.
  • Age 13 is the Article 8 threshold for a child's own consent to an information society service, not the Code's upper or lower age boundary.
  • High privacy is the default unless a compelling reason linked to the child's best interests supports another setting; record the reason, scope and review.
  • Age assurance should be proportionate to the risk and data-minimising; if age cannot be established with enough certainty, apply the standards to all users.
  • The ICO and courts must take the Code into account where relevant, but it is neither certification nor a substitute for applying the binding UK GDPR provisions.
Section 4

How should teams operationalize Children's Code with proportionate controls?

Use a standard-by-standard control record. For each of the 15 standards, record applicability, the product behaviour, owner, evidence, exception or compelling reason, approver, test result, and monitoring signal. Link the record to the DPIA and live release.

Reopen the assessment when the audience, design, recommendation or advertising logic, data fields, sharing, geolocation, profiling, parental controls, connected device, age assurance, or child-use evidence changes.

  • Scope record: service, UK connection, likely-access evidence, child age ranges, access restrictions, uncertainty, owner and approval.
  • DPIA record: best interests, data and sharing flows, age assurance, defaults, geolocation, profiling, nudges, parental controls, connected devices, rights and mitigations.
  • Standards record: for each of the 15 standards, state applicability, live behaviour, owner, evidence, exception or compelling reason, approver and test result.
  • Release record: verify notices, default settings, child controls, monitoring signals and unresolved actions against the live version.
  • Change record: reopen the assessment for audience, content, data, monetisation, recommendation, vendor, location, profiling, parental-control, connected-device or age-assurance changes.
Primary sources

References and citations

ico.org.uk
Referenced sections
  • ICO processor template supporting the page's recommendation to retain Article 30 records where required.
"Headings highlighted green are required areas of documentation under Article 30 of the GDPR"
legislation.gov.uk
Referenced sections
  • Binding source for the age-13 consent rule and children's higher-protection matters in services likely to be accessed by children.
ico.org.uk
Referenced sections
  • ICO source for data-sharing controls that may be relevant when Children's Code decisions involve partners or onward sharing.
ico.org.uk
Referenced sections
  • ICO guidance confirming the Children's Code applies to information society services likely to be accessed by children, including non-UK companies where the UK GDPR territorial-scope conditions are met.
ico.org.uk
Referenced sections
  • ICO statutory code source for Children's Code scope, design standards, DPIA, transparency, and child-user protection under UK data protection law.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.