Children's data rights
Children do not enter the digital world as miniature adults. Their data can be collected, profiled, shared and used to shape what they see before they understand the bargain being made. Protecting children online is therefore not only a parental task. It is a governance problem requiring age-appropriate design, data minimisation, online safety duties, school safeguards, parental support and meaningful child participation.
Publication snapshot
Children's digital rights need a joined-up route map
The source draft argues that children’s data rights cannot be protected by one actor alone. That central point is right. Governments, regulators, platforms, schools, parents, civil society and children themselves each hold part of the map. This version turns the draft into a Legal Lens accountability framework, grounded in the ICO Children’s Code, children’s UK GDPR guidance and the current online-safety regime.
The practical issue is route discipline. A concern about a child’s online experience may be a data protection issue, an online safety issue, an education safeguarding issue, a platform design issue, a parental-support issue or a wider civil-society advocacy issue. If those routes are blurred, children and families may be left with broad assurances but no clear remedy.
Why children's data needs special care
Children’s data can reveal far more than a username or date of birth. It can show location, school, friends, interests, mood, sleep patterns, vulnerabilities, family life, spending habits, search behaviour, communication style and exposure to harmful content. In a platform environment shaped by profiling, recommendation systems and advertising, that data can also influence what a child sees next.
The ICO Children’s Code places the best interests of the child at the centre of design for online services likely to be accessed by children. It is not a ban on children using the internet. It is a design standard. The point is that children should be able to learn, play and communicate online without being pushed towards unnecessary data sharing, weak privacy settings or opaque profiling.
That distinction matters. A rights-based approach does not make children passive. It recognises that children are developing users whose autonomy grows over time. The system should therefore give them age-appropriate information, meaningful choices, privacy by default and safe routes for help when something goes wrong.
The legal and regulatory map
The UK framework is not one single law. The UK GDPR supplies the data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The ICO’s children’s guidance explains how those principles require child-specific consideration when organisations use children’s personal information.
The Children’s Code then gives online services likely to be accessed by children a practical design lens. It includes standards on best interests, data protection impact assessments, age-appropriate application, transparency, data minimisation, data sharing, geolocation, parental controls, profiling, nudge techniques, connected toys and online tools.
The Online Safety Act adds a separate safety route. Ofcom’s compliance guide states that providers of online services are legally responsible for keeping UK users, especially children, safe online, and that providers may need to complete children’s access assessments, children’s risk assessments and ongoing safety measures. The legal map is therefore layered: data protection asks how children’s data is used; online safety asks what systems protect children from harm; safeguarding and education duties ask how adults responsible for children manage risk in the real world.
Six shared responsibilities
The source draft is strongest when it treats children’s digital rights as shared responsibility. The publication-safe version turns that into six route-specific duties.
Government and regulators
Set standards, enforce the law, publish guidance, coordinate across borders where necessary and keep children’s rights visible in digital policy.
Platforms and technology providers
Build privacy and safety into design, minimise data, explain profiling, test age assurance and avoid nudging children into weaker protections.
Schools and educators
Teach digital citizenship, use education technology carefully, explain data rights and provide safe reporting routes for online risk.
Parents and caregivers
Support age-appropriate online use, understand privacy settings, maintain open communication and avoid relying on surveillance as the only safeguard.
Civil society and children themselves
Charities, researchers, youth groups and children’s advocates can surface harms, test policy assumptions and make sure children are heard in decisions about the systems that shape their lives.
The evidence map
Children’s digital-rights debates often become broad quickly. The stronger route is to identify the specific processing, design choice, platform feature or safeguarding failure being questioned.
The child and context
Identify the age range, service used, education or home context, vulnerability factors and whether the service is likely to be accessed by children.
The data involved
Map the personal data, special category data, location data, behavioural data, profiling outputs, images, messages or account records at issue.
The design or safety concern
Identify whether the concern relates to default settings, geolocation, nudges, profiling, recommender systems, age assurance, reporting tools or harmful content.
The route and remedy
Separate data protection rights, platform complaints, Ofcom online-safety concerns, school safeguarding routes, parental controls and any civil advice.
The accountability record
Keep privacy notices, screenshots, settings, complaint responses, risk assessments, school policies, platform messages and regulator correspondence in date order.
Evidence does not remove the need for judgement. It makes the judgement testable. A platform can then be asked what it designed, a school can be asked what it adopted, a regulator can be asked what standard applies, and parents can be given practical information rather than general warnings.
AI, platforms and design
The source draft correctly identifies artificial intelligence and emerging technologies as future pressure points. That future is already here. Children interact with recommender systems, automated moderation, generative tools, learning platforms, connected toys, gaming systems and targeted content environments. The governance question is not only whether AI is accurate. It is whether the system is fair, explainable, proportionate and designed around children’s best interests.
The ICO’s AI and data protection guidance addresses accountability, transparency, lawfulness, fairness, accuracy, security, data minimisation and individual rights in AI systems. For children, those principles need particular care. A recommendation model may not make a legal decision about a child, but it can still shape attention, mood, behaviour, peer comparison, exposure to harm and commercial targeting.
That is why age-appropriate design should be treated as governance, not branding. A child-friendly interface is not enough if the underlying data model still maximises engagement through opaque profiling or nudges a child towards unnecessary disclosure.
Reform with children's voices
Children’s participation is not a decorative extra. If rules are designed without listening to children, they may protect adults’ assumptions rather than children’s lived experience. Young people often understand the social reality of platforms more clearly than policymakers do: what is embarrassing, what is coercive, what feels unsafe, what is ignored, and what reporting routes are not trusted.
Child-centred design
Services likely to be accessed by children should start from best interests, high privacy defaults and data minimisation.
Clear accountability
Platforms, schools and public bodies should keep decision records showing how children’s data, safety and participation risks were assessed.
Practical family support
Parents need accessible guidance, usable settings, clear reporting routes and space for open conversations rather than blame.
Youth participation
Children and young people should be consulted in age-appropriate ways when policy, product design and school technology decisions affect them.
The public lesson is that children’s digital rights cannot be outsourced to a privacy policy or a parental control panel. They require systems that are safe by design, accountable in practice and responsive to the people they are supposed to protect.
Source anchors
These source anchors support the children’s data-rights and online-safety framework discussed in this article. They do not prove any contested allegation about any platform, school, regulator, technology provider or individual case.
ICO Children’s Code
Age appropriate design code
The ICO code sets standards for online services likely to be accessed by children, including best interests, defaults, profiling and geolocation.
Children and UK GDPR
ICO guidance on children’s information
The ICO explains child-specific considerations when organisations handle children’s personal information.
Data principles
UK GDPR data protection principles
The ICO explains lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, security and accountability.
Online Safety Act
Ofcom compliance guide for services
Ofcom explains provider duties, children’s access assessments, risk assessments, safety duties and ongoing compliance.
Legislation
Online Safety Act 2023
The Act is the statutory framework for the UK online-safety regime and Ofcom’s regulatory role.
AI governance
ICO AI and data protection guidance
The ICO guidance addresses accountability, transparency, lawfulness, fairness, accuracy, security, minimisation and individual rights in AI systems.
The closing point
The source draft is right to call for a multi-stakeholder approach. The publication-safe point is more precise: every actor needs a defined role, a clear standard and an evidence trail.
Children’s digital rights are protected when services are designed with children in mind, data is minimised, risks are assessed, parents and schools are supported, children are heard and regulators can see whether the system works in practice.
Children's data route check
Get a free written assessment of the route
Legal Lens can help structure a children’s data, online safety or digital-rights concern into a clear issue map before the next step.
Separate data protection, online safety, education safeguarding, platform design, AI and complaint-route issues.
Turn policies, screenshots, privacy notices, complaint responses and chronology into a reviewable record.
Identify whether the issue belongs with the platform, school, ICO, Ofcom, safeguarding route or another forum.
Data, platform, school, ICO, Ofcom and safeguarding routes.
Key documents, chronology, settings and missing records.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

