WorkNest

Blog

The Age-Appropriate Design Code

Find out everything you need to know about complying with the Age Appropriate Design Code and keeping children safe – a key part of your data protection.

Background Image

A 2019 report by Ofcom shows that 50% of ten-year olds own mobile phones. While viewing of video-on-demand (with YouTube as firm favourite), has doubled in the last five years among children. Platforms like TikTok are rapidly growing in popularity. Sadly, more and more children are being exposed to hateful, violent and disturbing contents on these platforms.

The Age-Appropriate Design Code is a code of practice drafted by the ICO (the regulatory authority for data protection in the UK) as a solution to this modern problem. According to the Data Protection Act 2018, age-appropriate design means, “the design of services so they are appropriate for use by, and meet the development needs of children”. If the Data Protection Act 2018 sounds familiar to you, it’s because it’s also the legislation that implemented GDPR in the UK.

The Code was designed to ensure that organisations who provide services likely to be accessed by children take into consideration children’s best interests. The remit is as wide as possible, and includes developing apps, programs, social media platforms, streaming services, search engines, online games, news and educational websites.

The Code is not a new law. However, it sets out 15 standards of age-appropriate design which complement data protection laws in the UK. Embedding these standards in the design process would help organisations demonstrate compliance with the UK GDPR, PECR and DPA 2018. Don’t forget that the GDPR mandates extra protection measures for child personal data.

When your organisation develops a new product or a service, it is important to bear in mind the age ranges and developmental stages provided by the Code. If, for instance, a software being developed is likely to be used by children between the ages of 6 – 9 years, a data protection impact assessment (DPIA) of the potential risks to the individuals should be conducted. Although DPIAs for any new product and service is strongly recommended.

In-keeping with Article 25 of the GDPR, appropriate privacy controls should be used in designing the default privacy settings. That way, if a child does not make any changes to the settings, personal data collected cannot be accessed by other users of the service or other organisations. Furthermore, the default privacy settings should be such that profiling, and the geolocation of the child-user are switched off, unless there is a very, very compelling reason not to.

Though the code officially came into force in September of 2020, organisations were given a 12-month transition period to prepare. This means that from 2 September 2021, organisations whom the code applies to are expected to conform to the standards set by the code. The Information Commissioner’s Office (ICO) has the responsibility of enforcing data protection legislation. Children’s data is given special attention. In the event of an abuse of their data, the ICO is under a legal duty to take the provisions of the code into account when enforcing applicable laws. Some of the disciplinary tools available to the ICO include enforcement notices and penalty notices. The penalty notices can go as high as £17.5 million or 4% annual worldwide turnover of an organisation.

Talk to an expert

Share your challenge with us and we’ll help you find the right level of support for your business.

Your certified partner

Proven standards, trusted expertise, complete peace of mind

Award logo 1
Award logo 2
Award logo 3
Award logo 4
Award logo 5
Award logo 6
Award logo 7
Worknest logo
© 2020-2026 WorkNest. All rights reserved. (888) 243-3110