The Age Appropriate Design Code, usually called the Children’s Code, changed the default question for online services in the UK from “do children use this?” to “prove you designed for the ones who do.” A statutory code under section 123 of the Data Protection Act 2018, in full force since 2 September 2021, it applies to any online service likely to be accessed by under-18s and is enforced through UK GDPR fines. Its influence is global: California’s Age-Appropriate Design Code and a wave of similar bills copied it directly.
| Instrument | Statutory code under DPA 2018 s.123 |
|---|---|
| In force | 2 September 2021 (12-month transition ended) |
| Max penalty | GBP 17.5M or 4% of turnover, via UK GDPR |
| Official text | ICO Children’s Code |
The 15 standards, grouped
Governance: best interests of the child as the primary design consideration; DPIAs specifically assessing risks to children; policies and community standards you actually uphold.
Defaults and data: high privacy by default; data minimisation; geolocation off by default (with visible indicators when active); profiling off by default unless there are measures protecting the child from harmful effects; no data sharing unless a compelling reason serves the child’s best interests.
Design conduct: age assurance proportionate to risk; transparency in language children can understand; no nudge techniques steering children to weaker privacy; parental controls disclosed to the child (including when a parent is monitoring); connected toys and devices conveying the same protections; online tools helping children exercise their rights; and detrimental-use prohibitions tied to marketing and behavioral codes.
Enforcement reality
The ICO audited major platforms after the transition ended and reported design changes across the industry: profiling defaults, targeted advertising to under-18s, and geolocation practices all shifted. Its GBP 12.7 million fine against TikTok in 2023, for processing data of children under 13 without consent, was brought under UK GDPR with the code framing the expectations. The regulator’s current focus, set out in its children’s code strategy, is social media and video platforms’ recommender systems and age assurance.
If your audience data shows a material under-18 segment, run the child-specific DPIA, fix defaults first (profiling, location, visibility), then work through age assurance proportionate to your risk. The adjacent EU rules are covered in our GDPR children’s data guide, and a free scan will show what trackers and profiling tags your service fires before any age gate.