The UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals.

This document is intended as an example of good practice to help small to medium sized enterprises operating an online retail service. It will help you to understand and apply the ICO’s Children code, formally known as the Age appropriate design code. It specifically applies to Standard 2 of the code, which relates to the need for Data Protection Impact Assessments (DPIAs) for Information Society Services (ISS) likely to be accessed by children (under age 18) in the UK. Before starting to review the DPIA sample, you might find it helpful to read the code standards.

The service outlined in this sample is imaginary, and is not intended to represent an actual online retailer.

This sample DPIA is adapted from the ICO’s DPIA template, and follows the process set out in our DPIA guidance and the code. You should read it alongside the code’s DPIA guidance, and the Criteria for an acceptable DPIA set out in European guidelines.

We welcome recommendations for improvements or other feedback. Please email your comments to childrenscode@ico.org.uk.

Name of controller: The Toy Shop
Subject/title of DPIA: Online toyshop