UK Privacy Law United Kingdom

UK Children's Code: The 15 Age Appropriate Design Standards

What the ICO's Children's Code requires from online services likely to be accessed by under-18s: high privacy defaults, age assurance, and DPIAs.

Regulation

Age Appropriate Design Code (statutory code under DPA 2018 s.123); UK GDPR

Max Penalty

GBP 17.5 million or 4% of global annual turnover (via UK GDPR)

Enforcing Authority

Information Commissioner's Office (ICO)

Official Source

ico.org.uk

Executive Summary

  • The Children's Code is a statutory code of practice under section 123 of the DPA 2018, fully in force since 2 September 2021, applying to online services likely to be accessed by under-18s.
  • It sets 15 standards, headlined by: the best interests of the child, high privacy by default, data minimisation, geolocation off by default, and no nudge techniques toward weaker privacy.
  • It is not limited to children's services: 'likely to be accessed by children' catches mainstream platforms, games, and ecommerce with a material under-18 audience.
  • The code is enforced through UK GDPR: breach of a standard evidences breach of the underlying law, at up to GBP 17.5 million or 4% of turnover.
  • TikTok's GBP 12.7 million ICO fine in 2023 for misusing children's data shows the enforcement appetite, and the code inspired the California AADC and similar laws.

The Age Appropriate Design Code, usually called the Children’s Code, changed the default question for online services in the UK from “do children use this?” to “prove you designed for the ones who do.” A statutory code under section 123 of the Data Protection Act 2018, in full force since 2 September 2021, it applies to any online service likely to be accessed by under-18s and is enforced through UK GDPR fines. Its influence is global: California’s Age-Appropriate Design Code and a wave of similar bills copied it directly.

InstrumentStatutory code under DPA 2018 s.123
In force2 September 2021 (12-month transition ended)
Max penaltyGBP 17.5M or 4% of turnover, via UK GDPR
Official textICO Children’s Code

The 15 standards, grouped

Governance: best interests of the child as the primary design consideration; DPIAs specifically assessing risks to children; policies and community standards you actually uphold.

Defaults and data: high privacy by default; data minimisation; geolocation off by default (with visible indicators when active); profiling off by default unless there are measures protecting the child from harmful effects; no data sharing unless a compelling reason serves the child’s best interests.

Design conduct: age assurance proportionate to risk; transparency in language children can understand; no nudge techniques steering children to weaker privacy; parental controls disclosed to the child (including when a parent is monitoring); connected toys and devices conveying the same protections; online tools helping children exercise their rights; and detrimental-use prohibitions tied to marketing and behavioral codes.

Enforcement reality

The ICO audited major platforms after the transition ended and reported design changes across the industry: profiling defaults, targeted advertising to under-18s, and geolocation practices all shifted. Its GBP 12.7 million fine against TikTok in 2023, for processing data of children under 13 without consent, was brought under UK GDPR with the code framing the expectations. The regulator’s current focus, set out in its children’s code strategy, is social media and video platforms’ recommender systems and age assurance.

If your audience data shows a material under-18 segment, run the child-specific DPIA, fix defaults first (profiling, location, visibility), then work through age assurance proportionate to your risk. The adjacent EU rules are covered in our GDPR children’s data guide, and a free scan will show what trackers and profiling tags your service fires before any age gate.

Frequently Asked Questions

Does the Children's Code apply to my service?

If you provide an online service (app, website, game, connected toy) likely to be accessed by anyone under 18 in the UK, yes, even if children are not your target market. The test is realistic likelihood based on content appeal, marketing, and actual user data, not your terms of service.

What does 'high privacy by default' mean concretely?

Settings default to the most protective option for child users: profiling off, geolocation off, visibility limited, data minimised. Children can change some settings, but the starting point must protect them, and nudging them toward weaker privacy breaches the code.

Do I have to verify every user's age?

You must establish age with a level of certainty proportionate to the risks of your processing, or apply the code's standards to all users. Options range from self-declaration for low-risk services to age estimation or verification for high-risk ones. Applying child-level protections to everyone is a legitimate fallback.

Is the code itself legally binding?

It is a statutory code the ICO must consider in enforcement, and courts can take it into account. Practically, failing its standards is treated as evidence of breaching UK GDPR and PECR, which carry the fines. The ICO has audited and fined on this basis.

How does it compare to COPPA?

COPPA protects under-13s and centers on parental consent for collection. The Children's Code protects everyone under 18 and centers on design: defaults, minimisation, profiling, and dark patterns. A COPPA-compliant service can easily fail the UK code; the code is closer to the California AADC, which it inspired.

Regulatory Crosswalk

GDPR Art. 8COPPACalifornia AADC

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.