Age appropriate design: a code of practice for online services
United Kingdom
RAI-GB-NA-UKAADC-2020The UK Children's Code sets 15 standards for online services to protect children's data and privacy, emphasizing data protection by design.
Summary
Read full text ↗Plain English
Overview
The UK Age-Appropriate Design Code, often referred to as the Children's Code, is a statutory code of practice issued by the Information Commissioner's Office (ICO) in the United Kingdom. It sets out 15 standards that online services likely to be accessed by children must meet to protect children's data and privacy. The Code was developed under the mandate of the Data Protection Act 2018 and is designed to be consistent with the UK General Data Protection Regulation (UK GDPR), ensuring that children's personal information is handled in a way that respects their rights and best interests. Its primary goal is to make the digital world safer, fairer, and more respectful for young people by embedding data protection by design principles into online services.
The Code applies broadly to 'information society services' (ISS) that are likely to be accessed by children under 18, encompassing a wide range of online platforms such as apps, online games, websites, social media sites, and connected toys. It moves beyond traditional data protection compliance by requiring services to consider the 'best interests of the child' as a primary consideration in their design and operation. This includes mandates for high privacy settings by default, data minimization, and transparent communication tailored to the age of the child. The Code came into force on September 2, 2020, with a one-year transition period before full enforcement began in September 2021, providing businesses time to adapt their services.
Definitions
The UK Age-Appropriate Design Code defines several key terms to establish its scope and requirements. An 'Information Society Service' (ISS) is central to its applicability, referring to any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services. This broad definition ensures that a wide array of online platforms, including social media, online games, streaming services, educational apps, and connected devices, fall within the Code's remit if they are likely to be accessed by children. The Code clarifies that 'children' refers to individuals under the age of 18, aligning with the UN Convention on the Rights of the Child and the UK's legal framework for minors.
Another critical concept is the 'best interests of the child,' which the Code mandates as a primary consideration for any service provider. This principle requires organisations to proactively assess and prioritise the physical, mental, and developmental well-being of children when designing and operating their services, often even over commercial interests. 'High privacy by default' is also a foundational definition, meaning that the strictest privacy settings should be automatically applied to children's accounts unless there is a compelling reason, taking into account the child's best interests, to do otherwise. This includes defaults that restrict data sharing, geolocation tracking, and behavioural profiling. The Code also implicitly defines 'age-appropriate design' as the practice of tailoring privacy information, user interfaces, and default settings to suit the developmental capabilities and understanding of different age groups of children.
Governance and Institutional Framework
The Age-Appropriate Design Code is governed and enforced by the Information Commissioner's Office (ICO), the UK's independent authority set up to uphold information rights in the public interest. The ICO was specifically tasked by the Data Protection Act 2018 to develop this statutory code of practice under Section 123. As a statutory code, its provisions can be used as evidence in legal proceedings, and courts are obliged to consider its guidance where applicable, giving it significant legal weight. The ICO provides extensive guidance, resources, and tools, including a self-assessment risk toolkit, to help organisations understand and comply with the Code's 15 standards.
The ICO's role extends beyond guidance to active enforcement. Non-compliance with the Children's Code can lead to investigations, enforcement actions, and significant fines, as it operates under the broader framework of the Data Protection Act 2018 and the UK GDPR. The Commissioner, Elizabeth Denham CBE, emphasised that companies are expected to conform to the standards to demonstrate their commitment to acting in the best interests of the child, warning that those who fail to make the required changes risk regulatory action and being outpaced by compliant organisations. The ICO has also engaged in independent evaluations to assess the Code's effectiveness and companies' understanding of its requirements, reflecting a commitment to ongoing oversight and adaptation.
Key Focus Areas
The Children's Code is built around 15 flexible standards, with three overarching key focus areas: the best interests of the child, data protection by design, and transparency. The principle of the 'best interests of the child' is paramount, requiring online services to prioritise children's physical and mental health and well-being in all aspects of their design and operation. This involves considering how services might expose children to commercial or sexual exploitation, or how data processing could negatively impact their development. This focus necessitates a shift in design philosophy, moving beyond mere compliance to a child-first mindset in creating digital experiences.
Data protection by design is another core tenet, meaning that privacy and data protection measures must be built into the very architecture of online services from the outset, rather than being an afterthought. This includes requirements for 'high privacy by default,' ensuring that children's data is collected and processed with the strictest privacy settings unless there is a compelling, child-centric reason otherwise. It also mandates data minimisation, meaning only the strictly necessary personal data should be collected and retained from children, and it should not be shared with third parties without justification. Finally, transparency is crucial, with services required to provide clear, concise, and age-appropriate privacy information and tools that enable children to understand and exercise their data rights. This often involves tailoring explanations for different age groups, using simple language, visual aids, and interactive elements to ensure comprehension.
Implementation Framework
The implementation framework for the UK Age-Appropriate Design Code is centered on a proactive, risk-based approach, primarily driven by Data Protection Impact Assessments (DPIAs). Online service providers are mandated to conduct a DPIA to identify and mitigate risks to the rights and freedoms of children who are likely to access their service, arising from their data processing activities. This assessment should serve as a roadmap for compliance, documenting how the service balances the varying interests of children across different age groups and how the 'best interests of the child' principle is upheld. The ICO provides guidance and templates for conducting these DPIAs, emphasising their importance as living documents that should be updated as services evolve.
Beyond DPIAs, the Code outlines 15 specific standards that form the practical implementation framework. These standards cover areas such as default settings (requiring 'high privacy' by default), data minimisation, data sharing restrictions, geolocation and profiling limitations, parental controls, and robust age assurance mechanisms. Services must also provide clear and accessible terms, policies, and community standards, and offer prominent and accessible tools for children to exercise their data rights. The Code encourages a multi-departmental effort for compliance, involving design, development, marketing, data security, and legal teams, often led by a Data Protection Officer. This comprehensive approach ensures that child protection is integrated across all facets of service provision.
Monitoring and Evaluation
The Information Commissioner's Office (ICO) is responsible for monitoring compliance with the Age-Appropriate Design Code and has undertaken various initiatives to evaluate its effectiveness. The ICO has commissioned a series of independent evaluations to assess how target companies understand and implement the Children's Code, as well as the efficacy of its support programs, which include online resources and a self-assessment risk tool. This ongoing evaluation process helps the ICO gauge the Code's impact on industry practices and identify areas where further guidance or enforcement may be necessary. The goal is to ensure that the Code genuinely leads to improved data protection and safety outcomes for children online.
Furthermore, the ICO's monitoring activities are supported by its broader enforcement powers under the Data Protection Act 2018. This allows the ICO to conduct investigations into services suspected of non-compliance, issue enforcement notices, and impose fines where breaches are found. The regulatory body also tracks industry responses and changes in design practices, noting that many large platforms have already adjusted their operations to conform with the Code, including implementing various forms of age assurance. The ICO's commitment to regular evaluation, coupled with its enforcement capabilities, underscores its dedication to ensuring the Code remains relevant and effective in protecting children's data rights in a rapidly evolving digital landscape.
Penalties, Liability, and Appeals
Non-compliance with the UK Age-Appropriate Design Code can lead to significant penalties and enforcement actions by the Information Commissioner's Office (ICO). As the Code operates under the Data Protection Act 2018 and is consistent with the UK GDPR, breaches of its standards are treated as infringements of data protection law. This means that the ICO has the power to issue substantial fines, which can be up to £17.5 million or 4% of an organisation's annual global turnover, whichever is higher, for serious contraventions. Beyond monetary penalties, the ICO can also issue enforcement notices, requiring organisations to take specific steps to rectify non-compliance, or even stop processing personal data altogether.
Organisations found to be in breach of the Code may also face reputational damage and legal challenges from individuals or groups alleging harm due to inadequate data protection for children. While the Code itself does not establish new direct liability mechanisms beyond those in the UK GDPR, its statutory nature means that its provisions can be used as evidence in court proceedings, influencing judgments on whether an organisation has met its data protection obligations. Businesses have rights of appeal against ICO enforcement decisions, typically to the First-tier Tribunal (Information Rights). However, the ICO has made it clear that companies that fail to make the required changes risk regulatory action and being left behind by those who actively conform, highlighting the serious implications of non-compliance.
Relationship to Other Instruments
The UK Age-Appropriate Design Code is intrinsically linked to and operates within the broader framework of UK data protection law, primarily the Data Protection Act 2018 (DPA 2018) and the UK General Data Protection Regulation (UK GDPR). It serves as a statutory code of practice that provides detailed guidance on how the principles of the UK GDPR, particularly those related to children's data, should be applied by online services. Compliance with the Children's Code is therefore essential for demonstrating compliance with the UK GDPR when processing children's personal data. The Code does not create entirely new legal obligations but rather interprets and specifies how existing data protection laws apply to children in a way that respects their rights and vulnerabilities.
Globally, the UK Children's Code has been a pioneering instrument and has influenced the development of similar regulations in other jurisdictions. For instance, it served as a blueprint for California's Age-Appropriate Design Act (CAADPA) and informed the drafting of child online safety regulations in other countries. It also aligns with the principles of the UN Convention on the Rights of the Child, particularly Article 16 (right to privacy) and Article 17 (access to information), by seeking to protect children's data within online spaces without necessarily limiting their access. The Code also complements other UK initiatives related to online safety, such as the proposed Online Safety Bill, by providing a specific focus on data protection by design for children's services.
International Alignment
The UK Age-Appropriate Design Code has achieved significant international recognition and has played a pioneering role in shaping global approaches to children's online safety and data protection. It is widely considered a benchmark for how data protection laws, such as the GDPR, should be applied to children. The Code's emphasis on the 'best interests of the child' and 'data protection by design' has resonated with international bodies and other national regulators seeking to enhance protections for minors in the digital environment. Its influence is evident in legislative developments across the world, demonstrating a strong degree of international alignment in its core principles.
Notably, the UK Children's Code served as a direct blueprint for the California Age-Appropriate Design Act (CAADPA), highlighting its impact on significant regulatory frameworks in other major economies. Furthermore, countries like Ireland have published similar 'Fundamentals for a Child-Oriented Approach to Data Processing,' drawing inspiration from the UK model to guide the application of the European Union GDPR for children. Indonesian officials also consulted with the ICO during the drafting phase of their own regulations, indicating the Code's broad consultative impact. This global reach underscores the Code's success in establishing a practical and effective framework that many jurisdictions are looking to emulate or adapt, fostering a more harmonised approach to children's digital rights internationally.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Draft Code Published | 2019-04-01 | Draft Code published as instructed by the Data Protection Act 2018. |
| Final Regulations Published | 2020-01-27 | The final draft of the code was published by the ICO. |
| Code Came into Force | 2020-09-02 | The Code officially came into force. |
| Transition Period End / Full Enforcement Begins | 2021-09-02 | One-year grace period ended, and the Code became fully enforceable. |
| Evaluation of Strategy Progress (Expected) | 2025 | An evaluation of the ICO's progress in delivering their Children's Code strategy work is expected. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Best Interests of the Child | Ensure the best interests of the child are a primary consideration in the design and operation of your online service. |
| Data Protection Impact Assessment (DPIA) | Conduct and regularly update a DPIA to assess and mitigate risks to children's rights and freedoms from data processing. |
| Age-Appropriate Application | Determine if your service is likely to be accessed by children under 18; if so, the Code applies. Implement robust age assurance where proportionate. |
| High Privacy by Default | Set privacy settings to the highest level by default for child users, unless a compelling reason dictates otherwise. |
| Data Minimisation | Collect and retain only the minimum amount of personal data strictly necessary to provide the service. |
| Data Sharing Restrictions | Do not disclose children's personal data to third parties unless there is a compelling justification and it's in the child's best interests. |
| Geolocation Off by Default | Switch off geolocation services by default for child users. |
| Profiling Off by Default | Switch off profiling (e.g., for targeted advertising or content curation) by default for child users. |
| Transparent Terms & Policies | Provide privacy policies and terms of service in a clear, concise, and age-appropriate manner, using child-friendly language and visuals. |
| Parental Controls | Provide effective and easily accessible parental controls, where appropriate, with clear information to children about their use. |
| Prominent & Accessible Tools | Offer tools that allow children to exercise their data rights and make choices about their data easily. |
| No Nudge Techniques/Dark Patterns | Avoid using design features that lead children to make poor privacy choices. |
| Online Tools for Rights | Develop online tools to enable children to exercise their data rights effectively. |
| Reporting Mechanisms | Provide clear and accessible ways for children (and parents) to report concerns. |
| Uphold Children's Rights | Ensure all processing respects children's rights under the UK GDPR and the UN Convention on the Rights of the Child. |
Sources and References
| Source | Type |
|---|---|
| Children's code guidance and resources | ICO | government |
| Introduction to the Children's code | ICO | government |
| Child online safety: Data protection and privacy - GOV.UK | government |
| Children's Codes - UNICEF | official |
The UK Children's Code is a set of rules for online services that are likely to be used by children under 18, designed to protect their data and privacy. This regulation applies to any "information society service"—essentially, any online service like apps, games, social media platforms, websites, or connected toys—that children under 18 are likely to access, even if the service isn't specifically aimed at them.
It sets 15 standards, but key among them are obligations to: - Prioritise the "best interests of the child" in all aspects of service design and operation. - Set privacy settings to the highest level by default for child users, meaning features like data sharing, geolocation tracking, and behavioural profiling should be switched off unless there's a compelling, child-centric reason otherwise. - Collect and keep only the minimum personal data strictly necessary (data minimisation). - Provide clear, concise, and age-appropriate privacy information, avoiding "dark patterns" or design choices that might nudge children into making poor privacy decisions.
The Code officially came into force on September 2, 2020, with a one-year transition period, meaning full enforcement began on September 2, 2021. The Information Commissioner's Office (ICO) enforces these rules. Non-compliance is treated as a breach of UK data protection law, carrying significant penalties. The ICO can issue fines up to £17.5 million or 4% of an organisation's annual global turnover, whichever is higher, and can also order services to change their practices or even stop processing children's data. A common surprise for businesses is that the Code applies based on whether children are *likely* to access the service, not just if it's *intended* for them. This means many general audience platforms must consider their child users.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 14 marked completePlain-English obligations under Age appropriate design: a code of practice for online services. Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“The principle of the 'best interests of the child' is paramount, requiring online services to prioritise children's physical and mental health and well-being.”
- #2Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“Online service providers are mandated to conduct a DPIA to identify and mitigate risks to the rights and freedoms of children.”
- #3Critical
Applies to: Providers of online services.
“The Code applies broadly to 'information society services' (ISS) that are likely to be accessed by children under 18.”
- #4Critical⏰ Before placing on market
Applies to: Providers of online services likely to be accessed by children under 18.
“'High privacy by default' is also a foundational definition, meaning that the strictest privacy settings should be automatically applied to children's accounts.”
- #5Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“It also mandates data minimisation, meaning only the strictly necessary personal data should be collected and retained from children.”
- #6Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“It also mandates data minimisation... and it should not be shared with third parties without justification.”
- #7Critical⏰ Before placing on market
Applies to: Providers of online services likely to be accessed by children under 18.
“This includes defaults that restrict data sharing, geolocation tracking, and behavioural profiling.”
- #8Critical⏰ Before placing on market
Applies to: Providers of online services likely to be accessed by children under 18.
“This includes defaults that restrict data sharing, geolocation tracking, and behavioural profiling.”
- #9Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“Transparency is crucial, with services required to provide clear, concise, and age-appropriate privacy information.”
- #10Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“Services must also... offer prominent and accessible tools for children to exercise their data rights.”
- #11Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“The Code also implicitly defines 'age-appropriate design' as the practice of tailoring privacy information... to suit the developmental capabilities.”
- #12Critical
Applies to: Providers of online services likely to be accessed by children under 18.
“Its primary goal is to make the digital world safer, fairer, and more respectful for young people by embedding data protection by design principles.”
- #13Important
Applies to: Providers of online services likely to be accessed by children under 18.
“These standards cover areas such as... parental controls.”
- #14Important
Applies to: Providers of online services likely to be accessed by children under 18.
Related Regulations
The California Age-Appropriate Design Code Act
California, United States87% similar
Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026
United Kingdom87% similar
Online Safety Act 2023
United Kingdom85% similar
New Jersey Age-Appropriate Design Code
New Jersey, United States85% similar
Open letter to UK online service providers regarding Generative AI and chatbots
United Kingdom82% similar
© Regulations.AI — created on 20-May-2026 using Gemini 2.5 Flash