Children’s data · UK GDPR · Age-appropriate design
Children’s data protection is not a softer version of adult data protection. The UK GDPR, the Data Protection Act 2018 and the ICO’s children’s code require organisations to think about children’s understanding, autonomy, vulnerability and best interests from the start. The practical test is whether a child can understand what is happening to their information, exercise meaningful control, and be protected by design rather than left to navigate adult systems alone.
Publication snapshot
Children have data protection rights in their own name. Parents, carers, schools, platforms and service providers may help children exercise those rights, but the rights do not belong to the adults around the child. A compliant organisation must therefore do more than publish a generic privacy notice. It must use an appropriate lawful basis, design child-facing explanations, control unnecessary collection, assess high-risk processing, and make routes for access, erasure, objection and complaint usable in practice.
Why children need specific protection
Children use digital services before they can fully understand the records those services create. A child may leave traces through school systems, apps, games, connected toys, video platforms, social media, search, learning tools, health portals, safeguarding systems and family-facing services. Those records can reveal identity, location, friendships, interests, vulnerabilities, education, behaviour, health, family circumstances and developing beliefs.
The risk is not only a data breach. It is also routine over-collection, opaque profiling, unnecessary sharing, poor deletion processes, unclear parental controls, manipulative interface design and weak routes for complaint. A child may not know what has been collected, why it is being used, who has received it, or how to challenge it. That makes transparency and control more than formal compliance points. They are part of protecting the child’s autonomy and future development.
The legal starting point is simple: children merit specific protection because they may be less aware than adults of the risks, consequences, safeguards and rights involved in the processing of their personal information. That does not mean children have weaker rights. It means organisations must work harder to make those rights meaningful.
The legal frame
In the UK, the relevant framework is not simply “GDPR” in the abstract. It is the UK GDPR, the Data Protection Act 2018, the ICO’s statutory children’s code for online services likely to be accessed by children, and, where relevant, the Data (Use and Access) Act 2025 amendments and related regulatory guidance.
The ICO’s children and UK GDPR guidance says children have the same data protection rights as adults, but those rights have child-specific considerations. It also makes clear that children are anyone under 18, following the United Nations Convention on the Rights of the Child. For organisations, that means the analysis must address the child’s age, stage of development, capacity and level of understanding.
The children’s code applies to information society services likely to be accessed by children. It is not limited to services deliberately aimed at children. If children are likely to access the service, the provider must consider whether the code applies and how the service design protects children’s information. The code is not a separate data protection statute, but it explains how UK data protection law applies in the context of children using digital services.
UK GDPR
Sets the core principles, lawful bases, rights, transparency duties, accountability duties and design obligations.
Data Protection Act 2018
Supplements the UK GDPR and gives the domestic framework for data protection regulation and enforcement.
Children’s code
Sets age-appropriate design standards for online services likely to be accessed by children.
Rights in the child’s name
A child’s data protection rights belong to the child. That remains true where a parent gave the original consent, opened the account, bought the device, paid for the service or communicates with the organisation. Adults may act for a child in appropriate circumstances, but the controller still has to ask whether the child is competent to exercise the right, whether the adult has authority, and whether the proposed action is in the child’s best interests.
This distinction matters in subject access requests, school records, social care material, health-adjacent data, platform accounts, safeguarding concerns and family disputes. It may be wrong to assume that a parent is automatically entitled to everything simply because they hold parental responsibility. It may also be wrong to refuse to engage with a child who has sufficient understanding to exercise their own rights.
The practical question is capacity. Can the child understand what the request means and the likely consequences of exercising the right? If so, the organisation should normally deal with the child directly or in a way that reflects the child’s informed wishes. If not, an adult may need to act, but only within the limits of the child’s rights and best interests.
Inform
Explain what information is used, why it is used, who receives it and what rights the child has.
Access
Provide a route for the child or authorised adult to request the child’s personal information.
Correct or erase
Allow correction where information is inaccurate and erasure where the legal conditions are met.
Object or restrict
Give meaningful control where processing is contested, unnecessary or based on particular lawful grounds.
Consent and lawful basis
Consent is often overused in discussions about children’s data. It is only one lawful basis. An organisation must identify a lawful basis under Article 6 UK GDPR before it processes personal information, and some bases may be more appropriate than consent depending on the context.
For online services offered directly to a child, the UK position is important. If the provider wants to rely on consent as the lawful basis, only children aged 13 or over can give their own consent. If the child is under 13, consent must usually come from the person with parental responsibility, unless the service is a preventive or counselling service. Outside that information-society-service context, there is no single UK GDPR minimum age for a child’s own consent. In England, Wales and Northern Ireland, capacity depends on the child’s understanding; in Scotland, children aged 12 or over are usually presumed mature enough unless the evidence suggests otherwise.
That does not make consent a shortcut. Consent must still be freely given, specific, informed and unambiguous. A child must understand the choice. The request must be clear and age-appropriate. The child, or the person acting for them, must be able to withdraw consent as easily as it was given. In schools, care settings, youth services and platform environments, power imbalance may make consent fragile or inappropriate.
Access, erasure and control
The right of access allows a child to understand what personal information is held about them. In practice, a subject access request involving a child can be sensitive. It may involve educational records, behavioural records, platform data, safeguarding notes, family communications, health information or third-party information. The controller must identify the child’s data, assess capacity and authority, consider exemptions where relevant, and avoid disclosing information in a way that harms the child or breaches another person’s rights.
The right to rectification matters because inaccurate child records can follow a child into later decisions. Incorrect safeguarding notes, wrong contact details, mistaken educational information, inaccurate behavioural records or outdated risk labels may affect how professionals treat the child. Where the information is wrong, the route for correction should be real, not merely theoretical.
The right to erasure is particularly important for childhood records placed online. A child may grow beyond material posted about them, accounts created for them, content uploaded during adolescence or data collected before they understood the consequences. Erasure is not automatic in every case. Some records may need to be retained for legal, safeguarding, contractual or public-interest reasons. But a refusal should be reasoned and linked to a lawful ground, not hidden behind a generic retention policy.
Restriction and objection also matter. They allow the child or authorised person to challenge processing that is disputed, unnecessary, unlawful or based on a ground that requires balancing. Used properly, these rights create a pause for analysis before data use continues unchecked.
Design, defaults and DPIAs
Children’s privacy cannot depend on a child finding a hidden settings page. The legal direction is towards protection by design and by default. Article 25 UK GDPR requires appropriate technical and organisational measures to implement the data protection principles effectively and protect people’s rights. For children, that means building child-friendly design into systems and processes from the start.
The ICO’s children’s code translates that principle into practical standards. High privacy settings should be the default unless there is a compelling reason not to. Only the minimum necessary personal data should be collected and retained. Children’s data should not usually be shared without a compelling reason. Geolocation should be off by default. Profiling should be off by default unless appropriate protective measures are in place. Nudge techniques should not encourage children to provide unnecessary data or weaken their privacy protections.
Data protection impact assessments are part of that discipline. Where processing is likely to result in a high risk to children’s rights and freedoms, a DPIA is required. The ICO’s guidance states that organisations must always complete a DPIA for activities such as using children’s personal information for marketing, profiling or other automated decision-making purposes, or offering online services directly to children.
Recognise the child user. Assess whether children use or are likely to access the service.
Reduce the data load. Collect only what is necessary and retain it only for a justified period.
Set protective defaults. Do not make privacy depend on a child opting out of intrusive settings.
Record the reasoning. Use DPIAs, policies and review logs to show how risks were identified and controlled.
Profiling, marketing and sharing
Profiling children is a high-sensitivity activity because it can shape what a child sees, how they are categorised, what they are offered and how adults or systems respond to them. The concern is not limited to advertising. Profiling may affect content recommendation, educational support, behavioural prediction, risk scoring, service eligibility, safeguarding alerts or user experience.
Marketing to children requires particular care because children may be less able to identify persuasion, understand tracking, or resist design choices that exploit attention. If an organisation relies on legitimate interests, it must still balance its interests against the child’s rights and freedoms. If it relies on consent, the consent must be real. If the processing involves profiling or automated decision-making, the safeguards must be stronger.
Sharing children’s information also needs justification. It is not enough to say that sharing is operationally convenient. A controller should be able to explain why sharing is necessary, what information is shared, who receives it, what safeguards apply, how long it is retained, and how the child’s interests have been considered. In safeguarding contexts, sharing may be necessary. In commercial contexts, it may be much harder to justify.
The practical evidence test
For parents, carers, schools, platforms, charities and service providers, children’s data protection becomes clearer when the issue is reduced to evidence. Can the organisation show the lawful basis? Can it show the privacy information given to the child? Can it show how the child’s age and understanding were considered? Can it show why the data was needed, why it was retained, why it was shared and how the child can challenge it?
Where the answer is no, the issue is not merely administrative. It may indicate a wider failure of accountability. Data protection compliance is not demonstrated by policy language alone. It is demonstrated by design choices, records, decisions, training, review, response quality and the practical ability of a child to exercise their rights.
For families
Keep the privacy notice, screenshots, account settings, SAR correspondence, deletion request, refusal reasons and any impact on the child.
For organisations
Keep the lawful-basis assessment, DPIA, age-assurance reasoning, design decisions, retention schedule and response records.
For escalation
Separate data protection issues from safeguarding, consumer, education, online safety or equality issues before choosing the route.
Source anchors
These sources support the legal and regulatory framework used in this article. They do not prove any disputed complaint, breach or organisation-specific failure.
ICO children and UK GDPR guidance
Child-specific considerations, lawful basis, consent, rights, profiling and children’s information.ICO children’s code
Age-appropriate design duties for online services likely to be accessed by children.Children’s code standards
The 15 standards, including best interests, transparency, high privacy defaults and data minimisation.Data (Use and Access) Act 2025 factsheet
UK GDPR and DPA 2018 changes, including subject rights, automated decision-making and children’s higher protection matters.The Legal Lens point
The central lesson is that children’s data protection is not a paperwork exercise. It is a design, evidence and accountability exercise. The child’s understanding, development and best interests must be built into the way information is collected, explained, used, shared, retained and challenged.
For organisations, the question is whether they can prove that discipline. For parents and children, the question is whether the system gives them a real route to understand and control what is happening. If the route exists only in a privacy policy that a child cannot read, the right is being treated as a formality. Children’s data protection requires more than that.
Children’s data route map
Get a free written assessment of the route
If a children’s data issue needs structure, Legal Lens can help organise the facts, documents and potential route before a complaint, regulator referral, correspondence step or publication decision.
Clarify whether the concern is access, erasure, consent, profiling, sharing, safeguarding, platform design or automated decision-making.
Collect policies, notices, screenshots, requests, responses, account records and the child-specific impact.
Separate data protection from safeguarding, education, online safety, consumer or equality issues before escalation.
Rights, routes, documents, safeguards and live disputes.
Notices, requests, responses, screenshots, chronology and missing records.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors' firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

