The UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals.

The Children’s Code (or the Age Appropriate Design Code) contains 15 standards that online services need to follow. This ensures they are complying with the their obligations under data protection law to protect children’s data online.

Online services covered by the code are wide ranging and include

  • apps;
  • games;
  • connected toys and devices; and
  • news services.

If children are likely to access your service, even if they are not your target audience or user, then you need to consider the Children’s Code.

Who does the code apply to?

The code applies to “information society services likely to be accessed by children”. The definition of an ISS is “any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.”

What this means in practice is that most for-profit online services are ISS, and therefore covered by the code. This includes:

  • apps;
  • programs;
  • search engines;
  • social media platforms;
  • online messaging or internet based voice telephony services;
  • online marketplaces;
  • content streaming services (eg video, music or gaming services);
  • online games;
  • news or educational websites; and
  • any websites offering other goods or services to users over the internet.

Electronic services for controlling connected toys and other connected devices are also ISS.

If your online service is likely to be accessed by children under the age of 18, even if it’s not aimed at them, then you are probably covered by the code. This means you may need to make some changes to how you design your service and how you process personal data to ensure you conform with the code.

Does the code only apply to UK-based companies?

No. The code applies to UK-based companies and non-UK companies who process the personal data of UK children.

What do I have to do to conform with the code?

Things you may need to think about or implement are:

  • Mapping what personal data you collect from UK children.
  • Checking the age of the people who visit your website, download your app or play your game.
  • Switching off geolocation services that track where in the world your visitors are.
  • Not using nudge techniques to encourage children provide more personal data.
  • Providing a high level of privacy by default.

Our guidance on the 15 standards gives you the information you need to get started. You can also watch our refresher webinar here (hosted on YouTube), hear about the importance of the code from Elizabeth Denham on a #kidtech podcast and read a blog from Deputy Commissioner Steve Wood about how businesses can benefit from ICO support when implementing the code.