Our Expert in United Kingdom
No results available
The UK’s children’s-privacy enforcement signal has never been louder. Through a convergence of the Online Safety Act’s platform duties, intensified ICO investigations into social-media companies’ handling of children’s data, and high-profile government proposals for device-level scanning of child sexual abuse material, regulators have made clear that protecting children’s online privacy is the single highest enforcement priority in UK data protection today. For in-house counsel, data-protection officers and product teams, the question is no longer whether stricter scrutiny is coming, it is how quickly organisations can close the gap between current controls and the standard regulators now expect.
This article translates the enforcement signal into a practical compliance roadmap, broken down by entity type, with checklists, timelines and risk scenarios designed for teams that need to act within the next 90 days.
Three regulatory developments, taken together, form the UK’s children’s-privacy enforcement signal that every organisation handling children’s data must understand:
Immediate actions for UK organisations:
Industry observers expect the enforcement tempo to accelerate through the remainder of 2026, making proactive compliance the most cost-effective strategy available.
Understanding the UK’s children’s-privacy enforcement signal requires a clear view of the overlapping legal instruments that create obligations for data controllers and processors. Four pillars form the current framework for children’s online privacy in the United Kingdom.
The UK General Data Protection Regulation (retained from EU law post-Brexit) and the Data Protection Act 2018 (DPA 2018) remain the foundational data-protection statutes. They impose general obligations on all controllers and processors, lawful basis, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and add specific protections for children. Article 8 of the UK GDPR, read together with section 9 of the DPA 2018, sets the age at which a child can independently consent to the processing of their personal data by information-society services at 13 years in the UK. Below that threshold, the holder of parental responsibility must provide or authorise consent (NSPCC Learning).
Controllers must also apply the principle of data protection by design and by default, which takes on heightened significance when users are likely to include children.
The Online Safety Act 2023 introduced statutory safety duties for user-to-user services and search services. Key obligations relevant to children’s data include the duty to carry out children’s risk assessments, to implement “highly effective” age assurance so that children cannot normally encounter harmful content, and to apply child-safety duties proportionate to the risk profile of the service (GOV.UK, Online Safety Act collection). Ofcom, as the online-safety regulator, has published codes of practice detailing how platforms should comply. The practical effect is that platforms must now treat age assurance not as a voluntary feature but as a statutory prerequisite, and failure to implement it invites regulatory action from both Ofcom and the ICO where data-protection breaches overlap.
The ICO’s Age Appropriate Design Code, commonly called the Children’s Code, establishes 15 standards of age-appropriate design that online services likely to be accessed by children must follow. In its Children’s Code Strategy Progress Update published in December 2025, the ICO confirmed that it was moving from a guidance-first posture to an enforcement-led approach, having observed persistent non-compliance among major platforms (ICO, December 2025). The progress update outlined ongoing investigations into social-media and video-sharing platforms, signalling that the regulator views the Children’s Code not merely as best practice but as the benchmark against which enforcement decisions will be measured. Organisations that treat the Code as advisory rather than binding do so at considerable regulatory risk.
The enforcement signal did not emerge overnight. A series of dated events between late 2025 and mid-2026 have progressively intensified regulatory pressure. The following timeline captures the key developments that compliance teams should track.
The cumulative effect of these events is that the UK’s children’s-privacy enforcement signal now extends across legislation, regulatory strategy and executive-branch policy, creating a compliance environment in which inaction carries material legal and reputational risk.
Not every organisation faces identical obligations. The following breakdown helps compliance teams identify which requirements apply to their specific entity type and where immediate action is needed. Organisations searching for specialist guidance can consult data privacy lawyers with UK children’s-data expertise.
EdTech privacy compliance is an area of acute regulatory focus. Suppliers must:
Responding to the UK’s children’s-privacy enforcement signal demands both legal and technical measures. The following checklist prioritises controls by impact and implementation complexity, providing a practical reference for product, engineering and legal teams.
Every service likely to be accessed by children must embed privacy protections into the architecture from the outset, not retrofit them after launch. In practice this means: geolocation services disabled by default for users identified or reasonably suspected to be children; profiling and personalisation features switched off unless a DPIA demonstrates they serve the child’s best interests; and data collection limited to the minimum necessary for the core service.
The Online Safety Act requires age assurance to be “highly effective.” Industry observers expect regulators to interpret this as requiring more than a simple self-declaration tick-box. Mechanisms that satisfy the standard are likely to include age-estimation technology (e.g., facial-age estimation with privacy safeguards), age-verification through identity documents (with immediate data deletion after verification), or a combination of signals (device settings, account metadata, behavioural indicators) assessed through a risk-based model. Organisations should document their choice of mechanism, its accuracy rate, and the privacy safeguards applied, this documentation becomes critical evidence in any regulatory inquiry. Further technical guidance is covered in the age assurance for platforms compliance checklist.
Where consent is the lawful basis and the user is under 13, the controller must obtain verifiable parental consent. Best-practice approaches include email-plus-confirmation loops, credit-card micro-transactions for verification, or integration with digital-identity services. The consent mechanism must be auditable, meaning the organisation can demonstrate, for each child user, when consent was obtained, from whom, and for which processing activities.
Retention schedules for children’s data should be shorter than for adult data, reflecting the principle that children’s data should not follow them into adulthood unless strictly necessary. Organisations must be prepared to handle DSARs from parents (on behalf of children under 13) and from young people themselves (who may exercise rights directly from age 13). Response timescales remain one calendar month under the UK GDPR.
A DPIA is mandatory under Article 35 of the UK GDPR where processing is likely to result in a high risk to individuals’ rights and freedoms. Processing children’s data, particularly through automated profiling, behavioural tracking or large-scale collection, will almost always meet this threshold. The DPIA should specifically assess risks to children and identify mitigations proportionate to those risks. It should be reviewed and updated whenever the processing changes or new regulatory guidance is issued.
Understanding what triggers an ICO investigation, and preparing a response before one arrives, is essential in the current enforcement climate. The ICO children’s data investigations announced in the December 2025 progress update demonstrate that the regulator is actively using its compulsory audit and assessment powers (ICO, December 2025).
The ICO’s enforcement toolkit includes information notices, assessment notices, enforcement notices, penalty notices (fines up to £17.5 million or 4% of global annual turnover, whichever is higher), and reprimands. For children’s-data breaches, industry observers expect the ICO to pursue penalties at the higher end of available ranges, given the political salience and regulatory priority of the issue.
| Entity Type | Key Obligations (UK) | Urgency / Recommended Action (90 Days) |
|---|---|---|
| Major social platforms & VSPs | Implement “highly effective” age assurance; content-safety duties; children’s risk assessments under Online Safety Act; Children’s Code alignment | Immediate: prioritise age-assurance roadmap; complete DPIAs for child-facing features; update terms and policies |
| Messaging apps & E2E providers | Policy/notice obligations; potential statutory pressure over device-scanning proposals (policy risk); maintain lawful processing grounds | High: legal review of product features; prepare public position and DPIA; consult counsel on technical feasibility of detection proposals |
| EdTech & schools’ suppliers | Ensure lawful basis (consent/contract); parental consent flow for under-13s; automated-decisioning restrictions | Immediate: map data flows; implement parental consent; DPIA for AI/automated-decisioning features |
| Small apps / developers | Data minimisation; practicable age gating; updated privacy notices | Medium: implement minimal age gating and privacy-notice updates; vendor checks |
| Schools / public bodies | Public-law compliance + DPO oversight; contractual protections with suppliers | High: coordinate with suppliers; confirm data-processing agreements and breach-notification clauses |
This table is intended as a starting point. Organisations should consult a qualified UK data-protection lawyer to tailor obligations to their specific processing activities and risk profile.
The following vignettes illustrate how the UK’s children’s-privacy enforcement signal translates into concrete risk for different types of organisation.
A social-media platform uses algorithmic profiling to serve personalised content to all users, including those under 18. Its Children’s Code DPIA is two years old and pre-dates the Online Safety Act duties. Legal risk: The ICO could issue an enforcement notice requiring profiling to be switched off for child users, coupled with a penalty for failure to maintain a current DPIA. Practical fix: Immediately update the DPIA; implement server-side age flags that disable profiling for child accounts; set default privacy to “high” for all users under 18. Escalation: Notify the board, engage external counsel, prepare for an ICO assessment notice.
An EdTech supplier uses an AI-driven assessment tool that automatically grades pupils and recommends learning pathways. The tool processes behavioural data, session logs and performance scores for children aged 8–16. Legal risk: Automated decision-making that produces legal or similarly significant effects on children without human review may breach Article 22 of the UK GDPR. If parental consent was not obtained for under-13s, the lawful basis may also be deficient. Practical fix: Introduce meaningful human review into the assessment pipeline; implement verifiable parental consent for under-13s; conduct a DPIA addressing the specific risks of AI-driven decisioning for children.
Escalation: Review supplier contracts with schools to ensure data-processing agreements reflect the AI processing; prepare to pause the feature if consent gaps cannot be closed.
An encrypted-messaging app faces pressure from the UK government to implement client-side scanning for CSAM. Legal risk: Implementing scanning without a clear statutory mandate could expose the provider to claims of unlawful processing (scanning all users’ content without consent), while refusing to cooperate risks political and reputational consequences. Practical fix: Commission an independent legal opinion on the data-protection implications of client-side scanning; prepare a public-facing position paper explaining how encryption protects children’s privacy; engage with Ofcom and the ICO proactively. Escalation: Board-level decision required; retain specialist counsel experienced in both data protection and investigatory-powers law.
The UK’s children’s-privacy enforcement signal demands a structured, time-bound response. The following six-point roadmap provides a framework for the next 90 days:
Organisations that act decisively in response to this enforcement signal will be materially better positioned, both to avoid regulatory penalties and to build trust with users, parents and policymakers. Those seeking tailored advice on children’s data compliance can find a UK data-protection lawyer through the Global Law Experts directory.
This article is for general information purposes and does not constitute legal advice. Organisations should consult a qualified data-protection lawyer for advice tailored to their specific circumstances.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Nigel Miller at Fox Williams LLP, a member of the Global Law Experts network.
posted 44 seconds ago
posted 29 minutes ago
posted 52 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message