[codicts-css-switcher id=”346″]

Global Law Experts Logo
uks childrensprivacy enforcement signal

Our Expert in United Kingdom

The Uk's Children's-privacy Enforcement Signal: What UK Organisations Must Do Now

By Global Law Experts
– posted 49 minutes ago

The UK’s children’s-privacy enforcement signal has never been louder. Through a convergence of the Online Safety Act’s platform duties, intensified ICO investigations into social-media companies’ handling of children’s data, and high-profile government proposals for device-level scanning of child sexual abuse material, regulators have made clear that protecting children’s online privacy is the single highest enforcement priority in UK data protection today. For in-house counsel, data-protection officers and product teams, the question is no longer whether stricter scrutiny is coming, it is how quickly organisations can close the gap between current controls and the standard regulators now expect.

This article translates the enforcement signal into a practical compliance roadmap, broken down by entity type, with checklists, timelines and risk scenarios designed for teams that need to act within the next 90 days.

Executive Summary, The Enforcement Signal and What It Means

Three regulatory developments, taken together, form the UK’s children’s-privacy enforcement signal that every organisation handling children’s data must understand:

  • ICO investigations. The Information Commissioner’s Office has launched investigations into social-media and video-sharing platforms’ use of children’s personal data, scrutinising algorithmic profiling, default privacy settings and age-verification gaps (ICO, Children’s Code Strategy Progress Update, December 2025).
  • Online Safety Act obligations. Core safety duties under the Online Safety Act 2023 came into force for regulated platforms, requiring “highly effective” age assurance and child-safety risk assessments (GOV.UK, Online Safety Act collection).
  • Government scanning proposals. In June 2026, the UK government signalled support for requiring platforms and device manufacturers to implement automated detection of child sexual abuse imagery, a proposal that prompted an immediate public rebuke from Signal, the encrypted-messaging provider, which warned the measure would undermine end-to-end encryption without meaningfully protecting children (The Register, 9 June 2026; BBC, June 2026).

Immediate actions for UK organisations:

  1. Conduct a Data Protection Impact Assessment (DPIA) for every child-facing feature, service or product.
  2. Review and strengthen age-assurance mechanisms against the “highly effective” standard.
  3. Map all processing activities involving children’s data and verify lawful bases.

Industry observers expect the enforcement tempo to accelerate through the remainder of 2026, making proactive compliance the most cost-effective strategy available.

Legal Framework, Statutes, Codes and Regulator Priorities

Understanding the UK’s children’s-privacy enforcement signal requires a clear view of the overlapping legal instruments that create obligations for data controllers and processors. Four pillars form the current framework for children’s online privacy in the United Kingdom.

UK GDPR and the Data Protection Act 2018

The UK General Data Protection Regulation (retained from EU law post-Brexit) and the Data Protection Act 2018 (DPA 2018) remain the foundational data-protection statutes. They impose general obligations on all controllers and processors, lawful basis, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and add specific protections for children. Article 8 of the UK GDPR, read together with section 9 of the DPA 2018, sets the age at which a child can independently consent to the processing of their personal data by information-society services at 13 years in the UK. Below that threshold, the holder of parental responsibility must provide or authorise consent (NSPCC Learning).

Controllers must also apply the principle of data protection by design and by default, which takes on heightened significance when users are likely to include children.

Online Safety Act 2023, Platform Obligations

The Online Safety Act 2023 introduced statutory safety duties for user-to-user services and search services. Key obligations relevant to children’s data include the duty to carry out children’s risk assessments, to implement “highly effective” age assurance so that children cannot normally encounter harmful content, and to apply child-safety duties proportionate to the risk profile of the service (GOV.UK, Online Safety Act collection). Ofcom, as the online-safety regulator, has published codes of practice detailing how platforms should comply. The practical effect is that platforms must now treat age assurance not as a voluntary feature but as a statutory prerequisite, and failure to implement it invites regulatory action from both Ofcom and the ICO where data-protection breaches overlap.

ICO Children’s Code, Strategy and Progress

The ICO’s Age Appropriate Design Code, commonly called the Children’s Code, establishes 15 standards of age-appropriate design that online services likely to be accessed by children must follow. In its Children’s Code Strategy Progress Update published in December 2025, the ICO confirmed that it was moving from a guidance-first posture to an enforcement-led approach, having observed persistent non-compliance among major platforms (ICO, December 2025). The progress update outlined ongoing investigations into social-media and video-sharing platforms, signalling that the regulator views the Children’s Code not merely as best practice but as the benchmark against which enforcement decisions will be measured. Organisations that treat the Code as advisory rather than binding do so at considerable regulatory risk.

Recent Children’s-Privacy Enforcement Signals, A 2026 News Timeline

The enforcement signal did not emerge overnight. A series of dated events between late 2025 and mid-2026 have progressively intensified regulatory pressure. The following timeline captures the key developments that compliance teams should track.

  • December 2025, ICO Children’s Code Strategy Progress Update. The ICO published its formal progress review, confirming investigations into platforms’ use of children’s personal data and announcing a shift toward proactive enforcement. The update explicitly referenced concerns about algorithmic profiling, default-on geolocation and inadequate parental controls (ICO, December 2025).
  • Early 2026, Ofcom codes of practice finalised. Ofcom issued finalised codes of practice under the Online Safety Act, setting out detailed technical standards for age assurance, content moderation and children’s risk assessments. Industry observers noted that these codes gave Ofcom and the ICO concrete benchmarks for enforcement.
  • June 2026, Government device-scanning proposals. The UK government publicly signalled support for requiring technology companies to implement automated scanning, potentially at device level, to detect and block child sexual abuse material (CSAM). The announcement, covered extensively by the BBC, positioned the proposal as a natural extension of the Online Safety Act’s child-protection objectives (BBC, June 2026).
  • 9 June 2026, Signal’s public response. Signal, the encrypted-messaging provider, responded publicly to the UK proposals, warning that device-level scanning would compromise end-to-end encryption, undermine user privacy for all age groups, and fail to deliver meaningful child-protection outcomes (The Register, 9 June 2026). The response crystallised the tension between child-safety objectives and privacy-by-design principles that UK organisations must now navigate.
  • June–July 2026, Industry and advocacy commentary. DLA Piper published analysis framing the developments as a “changing regulatory landscape” for children’s online protection, while the 5Rights Foundation urged stronger data-protection provisions in any new legislation (DLA Piper, June 2026; 5Rights Foundation). These commentaries underscored that the enforcement signal affects not only platforms but any organisation processing children’s data in the UK.

The cumulative effect of these events is that the UK’s children’s-privacy enforcement signal now extends across legislation, regulatory strategy and executive-branch policy, creating a compliance environment in which inaction carries material legal and reputational risk.

Who Is in Scope, Entity-by-Entity Obligations

Not every organisation faces identical obligations. The following breakdown helps compliance teams identify which requirements apply to their specific entity type and where immediate action is needed. Organisations searching for specialist guidance can consult data privacy lawyers with UK children’s-data expertise.

Major Social Platforms and Video-Sharing Platforms (VSPs)

  • Conduct and publish children’s risk assessments under the Online Safety Act.
  • Implement “highly effective” age assurance to prevent children from accessing age-inappropriate content.
  • Align default settings with the ICO Children’s Code (privacy set to high by default, geolocation off, profiling off).
  • Review algorithmic recommendation systems for compliance with data-minimisation and fairness principles when applied to child users.
  • Appoint a nominated individual to liaise with Ofcom and the ICO on children’s-safety matters.

Messaging Apps and End-to-End Encrypted Providers

  • Maintain clear privacy policies and lawful processing grounds for all user data, including metadata.
  • Monitor and assess the legal feasibility and data-protection implications of government device-scanning proposals.
  • Prepare a board-approved position on content detection that balances child-safety obligations with encryption commitments.
  • Complete DPIAs addressing any proposed scanning or detection feature before deployment.

EdTech Providers and Schools’ Suppliers

EdTech privacy compliance is an area of acute regulatory focus. Suppliers must:

  • Ensure a valid lawful basis for every processing activity, typically consent (with parental authorisation for under-13s) or contract performance.
  • Implement parental consent flows that are genuinely informed, specific and revocable.
  • Restrict automated decision-making and profiling of pupils unless strictly necessary and justified by DPIA.
  • Provide transparent data-retention schedules and respond to data-subject access requests (DSARs) within statutory timescales.

Small App Developers

  • Apply data minimisation from the design phase, collect only what is strictly necessary.
  • Implement practicable age gating (even neutral-age-gate screens substantially reduce regulatory exposure).
  • Update privacy notices to describe children’s-data processing in plain, accessible language.
  • Conduct proportionate vendor due diligence on any third-party SDKs or analytics tools that process user data.

Schools and Public Bodies

  • Comply with public-law obligations alongside data-protection requirements.
  • Ensure a designated data-protection officer (DPO) oversees all children’s-data processing.
  • Coordinate with EdTech suppliers to verify contractual data-protection provisions (data-processing agreements, sub-processor controls, breach-notification clauses).

Practical Technical and Legal Controls, A Compliance Checklist

Responding to the UK’s children’s-privacy enforcement signal demands both legal and technical measures. The following checklist prioritises controls by impact and implementation complexity, providing a practical reference for product, engineering and legal teams.

Privacy by Design and Default

Every service likely to be accessed by children must embed privacy protections into the architecture from the outset, not retrofit them after launch. In practice this means: geolocation services disabled by default for users identified or reasonably suspected to be children; profiling and personalisation features switched off unless a DPIA demonstrates they serve the child’s best interests; and data collection limited to the minimum necessary for the core service.

Age Assurance, Meeting the “Highly Effective” Standard

The Online Safety Act requires age assurance to be “highly effective.” Industry observers expect regulators to interpret this as requiring more than a simple self-declaration tick-box. Mechanisms that satisfy the standard are likely to include age-estimation technology (e.g., facial-age estimation with privacy safeguards), age-verification through identity documents (with immediate data deletion after verification), or a combination of signals (device settings, account metadata, behavioural indicators) assessed through a risk-based model. Organisations should document their choice of mechanism, its accuracy rate, and the privacy safeguards applied, this documentation becomes critical evidence in any regulatory inquiry. Further technical guidance is covered in the age assurance for platforms compliance checklist.

Parental Consent Flows

Where consent is the lawful basis and the user is under 13, the controller must obtain verifiable parental consent. Best-practice approaches include email-plus-confirmation loops, credit-card micro-transactions for verification, or integration with digital-identity services. The consent mechanism must be auditable, meaning the organisation can demonstrate, for each child user, when consent was obtained, from whom, and for which processing activities.

Data Retention and DSAR Handling

Retention schedules for children’s data should be shorter than for adult data, reflecting the principle that children’s data should not follow them into adulthood unless strictly necessary. Organisations must be prepared to handle DSARs from parents (on behalf of children under 13) and from young people themselves (who may exercise rights directly from age 13). Response timescales remain one calendar month under the UK GDPR.

DPIAs for Child-Facing Features

A DPIA is mandatory under Article 35 of the UK GDPR where processing is likely to result in a high risk to individuals’ rights and freedoms. Processing children’s data, particularly through automated profiling, behavioural tracking or large-scale collection, will almost always meet this threshold. The DPIA should specifically assess risks to children and identify mitigations proportionate to those risks. It should be reviewed and updated whenever the processing changes or new regulatory guidance is issued.

Technical Notes for Engineering Teams

  • Implement server-side age flags that restrict data flows for users identified as children, rather than relying solely on client-side controls.
  • Ensure analytics and advertising SDKs respect age flags and suppress data collection for child users.
  • Log consent events immutably for audit purposes.
  • Design data-deletion pipelines that can target children’s data specifically in response to DSARs or retention-schedule triggers.

Enforcement Risk and Response Playbook

Understanding what triggers an ICO investigation, and preparing a response before one arrives, is essential in the current enforcement climate. The ICO children’s data investigations announced in the December 2025 progress update demonstrate that the regulator is actively using its compulsory audit and assessment powers (ICO, December 2025).

Common Investigation Triggers

  • Complaints from parents or advocacy groups about a service’s handling of children’s data.
  • Sector sweeps targeting industries (social media, gaming, EdTech) with high volumes of child users.
  • Data-breach notifications involving children’s personal data.
  • Referrals from Ofcom where an Online Safety Act investigation reveals overlapping data-protection concerns.
  • Proactive ICO monitoring of services that have failed to implement Children’s Code standards.

Potential Enforcement Outcomes

The ICO’s enforcement toolkit includes information notices, assessment notices, enforcement notices, penalty notices (fines up to £17.5 million or 4% of global annual turnover, whichever is higher), and reprimands. For children’s-data breaches, industry observers expect the ICO to pursue penalties at the higher end of available ranges, given the political salience and regulatory priority of the issue.

Incident Response Checklist for Children’s-Data Incidents

  1. Activate the data-breach response team and notify the DPO immediately.
  2. Preserve all relevant logs, processing records, DPIAs and consent records.
  3. Assess whether the breach meets the 72-hour ICO notification threshold (likely risk to rights and freedoms).
  4. Notify affected individuals, including parents where the data subjects are children, without undue delay where the risk is high.
  5. Appoint a single point of contact for regulator engagement.
  6. Conduct a root-cause analysis and document remedial actions.
  7. Brief the board and update risk registers.

Comparative Table, Obligations and Timelines by Entity Type

Entity Type Key Obligations (UK) Urgency / Recommended Action (90 Days)
Major social platforms & VSPs Implement “highly effective” age assurance; content-safety duties; children’s risk assessments under Online Safety Act; Children’s Code alignment Immediate: prioritise age-assurance roadmap; complete DPIAs for child-facing features; update terms and policies
Messaging apps & E2E providers Policy/notice obligations; potential statutory pressure over device-scanning proposals (policy risk); maintain lawful processing grounds High: legal review of product features; prepare public position and DPIA; consult counsel on technical feasibility of detection proposals
EdTech & schools’ suppliers Ensure lawful basis (consent/contract); parental consent flow for under-13s; automated-decisioning restrictions Immediate: map data flows; implement parental consent; DPIA for AI/automated-decisioning features
Small apps / developers Data minimisation; practicable age gating; updated privacy notices Medium: implement minimal age gating and privacy-notice updates; vendor checks
Schools / public bodies Public-law compliance + DPO oversight; contractual protections with suppliers High: coordinate with suppliers; confirm data-processing agreements and breach-notification clauses

This table is intended as a starting point. Organisations should consult a qualified UK data-protection lawyer to tailor obligations to their specific processing activities and risk profile.

Case Studies and Hypothetical Scenarios

The following vignettes illustrate how the UK’s children’s-privacy enforcement signal translates into concrete risk for different types of organisation.

Scenario 1, Social Platform and Algorithmic Profiling of Children

A social-media platform uses algorithmic profiling to serve personalised content to all users, including those under 18. Its Children’s Code DPIA is two years old and pre-dates the Online Safety Act duties. Legal risk: The ICO could issue an enforcement notice requiring profiling to be switched off for child users, coupled with a penalty for failure to maintain a current DPIA. Practical fix: Immediately update the DPIA; implement server-side age flags that disable profiling for child accounts; set default privacy to “high” for all users under 18. Escalation: Notify the board, engage external counsel, prepare for an ICO assessment notice.

Scenario 2, EdTech Provider Using Automated Decisioning

An EdTech supplier uses an AI-driven assessment tool that automatically grades pupils and recommends learning pathways. The tool processes behavioural data, session logs and performance scores for children aged 8–16. Legal risk: Automated decision-making that produces legal or similarly significant effects on children without human review may breach Article 22 of the UK GDPR. If parental consent was not obtained for under-13s, the lawful basis may also be deficient. Practical fix: Introduce meaningful human review into the assessment pipeline; implement verifiable parental consent for under-13s; conduct a DPIA addressing the specific risks of AI-driven decisioning for children.

Escalation: Review supplier contracts with schools to ensure data-processing agreements reflect the AI processing; prepare to pause the feature if consent gaps cannot be closed.

Scenario 3, Messaging App and Device-Scanning Proposals

An encrypted-messaging app faces pressure from the UK government to implement client-side scanning for CSAM. Legal risk: Implementing scanning without a clear statutory mandate could expose the provider to claims of unlawful processing (scanning all users’ content without consent), while refusing to cooperate risks political and reputational consequences. Practical fix: Commission an independent legal opinion on the data-protection implications of client-side scanning; prepare a public-facing position paper explaining how encryption protects children’s privacy; engage with Ofcom and the ICO proactively. Escalation: Board-level decision required; retain specialist counsel experienced in both data protection and investigatory-powers law.

Conclusion, Recommended Next 90-Day Roadmap

The UK’s children’s-privacy enforcement signal demands a structured, time-bound response. The following six-point roadmap provides a framework for the next 90 days:

  1. Legal audit. Map all processing activities involving children’s data; verify lawful bases; identify gaps against the Children’s Code’s 15 standards.
  2. Technical controls. Implement or upgrade age-assurance mechanisms; deploy server-side age flags; suppress profiling and targeted advertising for child users by default.
  3. Governance. Update DPIAs for all child-facing features; assign a senior responsible owner for children’s-data compliance; ensure the DPO has direct board-reporting access on children’s-data matters.
  4. Vendor and contract review. Audit data-processing agreements with all suppliers and sub-processors handling children’s data; insert or strengthen breach-notification and audit-rights clauses.
  5. Communications. Review and update privacy notices, terms of service and parental-consent flows to reflect current processing and regulatory requirements.
  6. Board reporting. Brief the board on the enforcement signal, quantify the organisation’s residual risk, and secure budget for any remediation required.

Organisations that act decisively in response to this enforcement signal will be materially better positioned, both to avoid regulatory penalties and to build trust with users, parents and policymakers. Those seeking tailored advice on children’s data compliance can find a UK data-protection lawyer through the Global Law Experts directory.

This article is for general information purposes and does not constitute legal advice. Organisations should consult a qualified data-protection lawyer for advice tailored to their specific circumstances.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Nigel Miller at Fox Williams LLP, a member of the Global Law Experts network.

Sources

  1. Information Commissioner’s Office, Children’s Code Strategy Progress Update (December 2025)
  2. GOV.UK, Online Safety Act Collection
  3. DLA Piper, UK: Protecting Children Online – A Changing Regulatory Landscape
  4. BBC, Live Coverage: Government Announcements (June 2026)
  5. The Register, Signal Response to UK Child-Safety Proposals (9 June 2026)
  6. 5Rights Foundation, New UK Data Law: What Does It Mean for Children’s Privacy?
  7. Practical Law (Thomson Reuters), Children and the Law: Data Protection Aspects
  8. Didomi, Guide on Online Safety Act Impacts
  9. NSPCC Learning, Children and the Law

FAQs

What are the core UK laws that protect children's data?
The primary instruments are the UK GDPR (retained EU law), the Data Protection Act 2018, the Online Safety Act 2023, and the ICO’s Age Appropriate Design Code (Children’s Code). Together they impose obligations on controllers and processors to safeguard children’s personal data through lawful processing, privacy by design and age-appropriate default settings (ICO, Children’s Code Strategy Progress Update, December 2025; GOV.UK, Online Safety Act collection).
Yes, in lawful circumstances. A company offering child-tracking services must identify a valid lawful basis under the UK GDPR, typically consent, with parental authorisation required for children under 13. A DPIA is likely mandatory given the intrusive nature of location monitoring. The ICO expects tracking to be proportionate, transparent and subject to robust security measures (ICO, Children’s Code guidance).
Age assurance refers to the mechanisms platforms must use to establish whether a user is a child. The Online Safety Act requires these mechanisms to be “highly effective,” meaning simple self-declaration is unlikely to suffice. Accepted approaches include facial-age estimation, document-based verification, and multi-signal risk models. Providers must balance accuracy with privacy, retaining verification data only as long as strictly necessary (GOV.UK, Online Safety Act collection; Didomi).
As of August 2026, there is no statutory mandate requiring device-level scanning. However, the UK government signalled support for such measures in June 2026, prompting Signal to warn publicly that client-side scanning would undermine end-to-end encryption without delivering effective child protection (The Register, 9 June 2026; BBC, June 2026). The policy debate remains active, and organisations should monitor legislative developments and prepare DPIAs for any detection features they may be required to implement.
Organisations should immediately preserve all relevant records, processing logs, DPIAs, consent records and internal correspondence. Appoint a single point of contact authorised to communicate with the ICO. Conduct a rapid internal audit to identify any compliance gaps. Engage external data-protection counsel experienced in ICO investigations. Ensure the DPO and board are briefed and that remedial actions are documented (ICO, December 2025 progress update).
Under the UK GDPR and the Data Protection Act 2018, a child aged 13 or over may independently consent to the processing of their personal data by information-society services. Below 13, the holder of parental responsibility must provide or authorise consent. The age threshold applies specifically to consent as a lawful basis; other bases (such as legitimate interests) remain available but require careful assessment and a DPIA (NSPCC Learning).
Under Article 33 of the UK GDPR, controllers must notify the ICO within 72 hours of becoming aware of a personal-data breach that is likely to result in a risk to individuals’ rights and freedoms. Breaches involving children’s data are likely to meet this threshold given children’s inherent vulnerability. Where the breach poses a high risk, affected individuals, including parents of child data subjects, must also be notified without undue delay (ICO breach-reporting guidance).
how to file fc-trs online
By Global Law Experts

posted 12 minutes ago

europes insolvency harmonisation drive
By Global Law Experts

posted 49 minutes ago

irelands nis2 reckoning
By Global Law Experts

posted 49 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The Uk's Children's-privacy Enforcement Signal: What UK Organisations Must Do Now

Send welcome message

Custom Message