Artifact GuideUKChildren's Code

UK GDPR Children's Code

The statutory Age Appropriate Design Code applies to relevant online services likely to be accessed by children under 18 in the UK, even when children are not the target audience.

Assess likely access, complete a child-focused DPIA, put the child's best interests first, and apply the 15 standards in a proportionate way.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The Children's Code explains how UK data-protection law applies to relevant information society services . It covers services such as apps, games, websites, social media, streaming, online marketplaces, connected toys, and other connected services when the legal scope test is met. The code is not a separate ban on child access, but the ICO must take it into account when assessing compliance.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

Does the Children's Code apply to our service?

Check whether the service is an : a service normally provided for remuneration, at a distance, by electronic means, at the individual request of a recipient. Most for-profit online services meet that definition. Then assess whether the service is under 18 in the UK, not merely whether the product is marketed to them.

Use evidence about the nature and presentation of the service, appeal to children, actual audience, comparable services, marketing, user research, and the effectiveness of access restrictions. If the service is unsuitable for children and reliable controls prevent their access, document that conclusion. If evidence later shows a substantive child audience, revisit the assessment and either conform to the code or improve the restriction.

The statutory scope excludes a general broadcast that is not provided at an individual's request and a preventive or counselling service, such as an online health screening or counselling service, offered specifically to children. An on-demand element of a broader broadcast and a general health, fitness, or well-being service can still be covered. The code came into force on 2 September 2020, and its 12-month transition ended on 2 September 2021, so an in-scope service should conform now.

  • Map UK child users, age ranges, personal data, profiling, sharing, geolocation, default settings, nudges, and parental features.
  • Document the evidence for likely access and review it after product, audience, marketing, or access-control changes.
  • Apply the code's territorial rules carefully. It covers processing in the context of a UK establishment and can cover a provider outside the UK that offers services to, or monitors, people in the UK. Since the end of the EU exit implementation period, this includes a provider with no UK establishment but an establishment elsewhere in the EEA.
  • Keep the Article 8 consent rule distinct from the code's under-18 design scope. For an relying on consent, a UK child can give their own consent from age 13; below 13, the holder of parental responsibility must give or authorise it. Another lawful basis may fit the processing, but the code can still apply to users up to age 18.
Citations
Question 2

What do the 15 standards require teams to address?

Treat the child's as a primary consideration and complete a DPIA that assesses differing ages, capacities, and risks. Apply the code in a risk-based and proportionate way, but do not use proportionality to remove the substance of a standard.

The 15 standards cover: ; DPIAs; age-appropriate application; transparency; detrimental use of data; policies and community standards; high-privacy default settings; data minimisation; data sharing; geolocation; parental controls; profiling; nudge techniques; connected toys and devices; and online tools that let children exercise rights or report concerns.

  • Use high-privacy defaults unless a compelling reason, tied to the child's , supports another setting.
  • Collect and retain only the minimum personal data needed for each active element of the service.
  • Keep geolocation off by default and make location tracking obvious while active.
  • Do not use nudges that encourage children to provide unnecessary data or weaken privacy controls.
  • Explain data use in concise, prominent, age-appropriate language and provide child-accessible privacy tools.
Citations
ICO - Age appropriate design code

The statutory code and its 15 standards, including best interests, DPIA, defaults, minimisation, sharing, geolocation, profiling, nudges, and tools.

Question 3

What evidence should product teams keep?

Keep the scope and age-range assessment, child-focused DPIA, design decisions against all 15 standards, user research, notices, settings, age-assurance reasoning, testing, parental-control behaviour, profiling logic, sharing map, geolocation controls, retention, and rights routes. Evidence should match the released product on each supported platform.

Review after new features, material interface changes, new profiling or sharing, changed age-assurance methods, a shift in the child audience, complaints, incidents, or evidence that a control does not work as intended.

Citations
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding duty requiring the Commissioner to prepare the age-appropriate-design code for relevant services likely to be accessed by children.
ico.org.uk
Referenced sections
  • The statutory code and its 15 standards, including best interests, DPIA, defaults, minimisation, sharing, geolocation, profiling, nudges, and tools.
ico.org.uk
Referenced sections
  • Confirms that the transition phase ended on 2 September 2021 and explains the ICO's clarified position on adult-only services.
ico.org.uk
Referenced sections
  • ICO assessment resource for recording the service, child users, data uses, standards, risks, and mitigations.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.