Summary
- Businesses that process children’s personal data must apply the UK GDPR and the Data Protection Act 2018 with higher protections than they use for adults.
- Since 5 February 2026, providers of online services likely to be accessed by children must take children’s higher protection matters into account under Article 25 of the UK GDPR.
- The Age Appropriate Design Code sets 15 standards, including high privacy settings by default, profiling switched off and privacy information a child can follow.
- This article explains children’s data protection obligations for businesses in the United Kingdom.
- LegalVision’s business lawyers specialise in advising clients on UK data protection compliance.
Tips for Businesses
List every service a child can reach, not only those built for children. Run a data protection impact assessment before you build. Set privacy high by default, switch profiling off, and write privacy information a 10-year-old can follow. Check your age threshold: consent needs a child of 13 or over. Speak to a data protection lawyer at LegalVision about bringing a children’s online service in line with the Children’s code.
Businesses that process children’s personal data in the UK must comply with the UK GDPR and the Data Protection Act 2018, and must apply higher protections than they apply to adults. Since 5 February 2026, Article 25 of the UK GDPR requires providers of online services likely to be accessed by children to take children’s higher protection matters into account when they design those services. The Information Commissioner’s Office also enforces the Age Appropriate Design Code, a statutory code of practice setting 15 standards for online services children use. Those standards include high privacy settings by default, profiling switched off, and privacy information a child can understand. This article explores the UK’s data protection law regime, some critical considerations for protecting children’s data, and the importance of seeking tailored legal advice to help your business protect children’s data and mitigate risk.
The UK Data Protection Framework For Children’s Data
Two laws set the baseline: the UK GDPR and the Data Protection Act 2018. They apply whenever you process personal data, whether the person is 8 or 48.
What The Data (Use and Access) Act 2025 Changed
The Data (Use and Access) Act 2025 amends both laws directly. One change is specific to children. Article 25 of the UK GDPR, the data protection by design and by default obligation, now carries an extra step. If you provide an information society service likely to be accessed by children, you must take children’s higher protection matters into account when you choose your technical and organisational measures.
Which Services Are In Scope
“Information society service” covers most things you would call an online service: apps, websites, games, streaming, connected devices. “Likely to be accessed by children” does not mean aimed at children. If children use your service, you are in scope.
This factsheet sets out how your business can become GDPR compliant.
The Children’s Code
The Age Appropriate Design Code, often called the Children’s code, sits on top. It is a statutory code of practice with 15 standards for online services likely to be accessed by children. Put the best interests of the child first. Default to high privacy settings. Keep geolocation and profiling switched off unless you have a compelling reason. Drop nudge techniques that push children towards weaker privacy choices. The ICO uses the code when it assesses whether you have met your obligations under the UK GDPR.
Why Children’s Data Carries More Risk
Children often do not appreciate what they are handing over. A 12-year-old ticking a box does not weigh the consequences the way an adult does.
The data itself is frequently sensitive. Health details, learning and performance records, biometric identifiers, and behavioural data captured while a child uses an app. Mishandled, it can follow the child for years.
Then there is the commercial side. Parents decide which services their children use, and schools and other institutional buyers ask about data handling during procurement.
Continue reading this article below the formCall 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you on the same business day.
Key Considerations When You Process Children’s Data
Transparency And Age-Appropriate Privacy Information
Privacy information for children must be clear, concise and pitched at a level the child can follow. Most businesses do this with a separate children’s privacy policy.
If your service spans age groups, you may need more than one version, or one written for the youngest users. Diagrams, icons, layered explanations and just-in-time notices work better than a wall of text. A just-in-time notice appears at the moment you collect the data and explains why you need it. Check this alongside the data protection policies your business needs.
Privacy By Design And Default
Design for children from the start, not after launch. That means high privacy settings by default, collection limited to what you actually need, and a plain explanation before any data-sharing feature switches on.
For services children are likely to access, this is no longer only good practice. The UK GDPR requires you to weigh when you choose your technical and organisational measures.
Data Protection Impact Assessments
A data protection impact assessment is a written risk assessment. You must complete one whenever your processing creates a high risk to a child’s rights and freedoms. The Children’s code expects one for any service within its scope.
Security, Accuracy And Data Minimisation
Collect the minimum you need, keep it accurate, and delete it once the purpose ends. Restrict access to the people who genuinely need it.
Review what you hold on a set schedule. Old records nobody uses are the ones that turn a small incident into a personal data breach you have to report to the ICO.
Children’s Rights
Children hold the same rights as adults under the UK GDPR: access, rectification, erasure, objection and portability. A child can exercise those rights personally where they are competent to do so, and otherwise through an adult with parental responsibility.
Build a route a child can actually use. A process that only works for an adult with a solicitor does not meet the code’s transparency standard.
Data Sharing For Safeguarding
Data protection law does not stop you sharing information to protect a child. You need a lawful basis, a written record of the decision, and to follow the ICO’s data sharing guidance.
Children’s Data And AI
The rules on automated decisions changed on 5 February 2026. Articles 22A to 22D of the UK GDPR replaced the single provision that governed automated decision-making before.
A significant decision is one that produces a legal effect for the person, or an effect of similar significance. Where such a decision is based solely on automated processing and uses special category data, it is restricted. Special category data includes a child’s health data, and the exceptions are narrow. Explicit consent is one of them. Where a solely automated significant decision is allowed, you must tell the person, let them make representations, give them access to human intervention, and let them contest the outcome.
Age Assurance And Consent: Getting The Age Threshold Right
Where you rely on consent to offer an online service directly to a child, Article 8 of the UK GDPR sets the threshold at 13. A child of 13 or over can consent themselves. Four decisions follow from that, and all four cost less to make before launch than after it.
| Decision | What you need to do |
| The age threshold | Consent is valid from 13. Below 13, you need consent from a person with parental responsibility, and reasonable efforts to verify that the consent is genuine, taking available technology into account. |
| How firmly you check age | Match the check to the risk. Self-declaration may be enough for a recipe app. An open messaging feed needs something stronger, such as a third-party age estimation service. If you cannot establish age, apply the Children’s code standards to everyone. |
| Data you should never have held | Under-13 sign-ups without parental consent have no lawful basis. That data has to come out of the system, including from backups and any analytics or model training set it fed into. Untangling it after two years of trading is expensive. |
| Which lawful basis applies | Consent is not your only option. Contract or legitimate interests may fit parts of the service better. Consent is hard to rely on for a child, because you must show that the child or the parent understood it. Record the basis for each purpose before launch. |
The decisions sit alongside the wider UK privacy obligations that apply to your business.
A worked example. An education platform sells subscriptions to parents, but the account is used by the child. The contract sits with the parent, so contract is the likely basis for delivering the lessons. Analytics and personalisation are separate purposes, and consent for those needs to come from the parent while the child is under 13. Two lawful bases, one product, and an impact assessment that shows you considered both.
Getting Legal Advice Before You Launch
Children’s data is one of the harder areas to get right. Whether the Children’s code applies to you, whether your age assurance is proportionate, and which lawful basis fits which purpose are judgement calls, not checklist answers.
A data protection lawyer can review what you collect and why, tell you where the exposure sits, and put the documents and settings in place before launch. That is a cheaper conversation than the one after a complaint.
Key Takeaways
Children’s data carries higher obligations than adult data. If children are likely to reach your service, you must weigh children’s higher protection matters when you design it, complete a data protection impact assessment, default to high privacy, and write privacy information a child can follow. Settle your age threshold and your lawful basis before launch.
LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced privacy lawyers help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision’s legal membership, call 0808 196 8584 or visit our membership page.
Frequently Asked Questions
Does my business need a children’s privacy policy?
If children are likely to use your service, you must give privacy information they can understand. Most businesses do this with a separate children’s privacy policy, sometimes in more than one version for different age groups.
Should my business take legal advice before using children’s personal data?
Children’s data carries higher regulatory risk. Advice helps you confirm your lawful basis, your age threshold and your impact assessment before you launch, which costs far less than reworking a service that is already live.
When must we run a data protection impact assessment for a children’s service?
Whenever the processing is likely to create a high risk to a child’s rights and freedoms. The Children’s code expects one for any online service children are likely to access. Complete it before you build the service, not after.
Can we use profiling or automated decisions about children?
Profiling should be off by default under the Children’s code. Solely automated decisions with a legal or similarly significant effect are restricted, particularly where they rely on special category data such as a child’s health information.
We appreciate your feedback! Request your free consultation now.