Skip to content

Regulatory Pulse

UK ICO extends Children’s Code strategy: priorities for platforms, games and age assurance

The ICO extended its Children’s Code strategy for six months and highlighted compliance gaps across platforms, games, age assurance and edtech.

United Kingdom
Children’s privacy & online services
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published UK children’s privacy regulatory strategy update · Reviewed 24 August 2026 · 8 min read

The 60-second summary

On 19 August 2026, the UK Information Commissioner’s Office published its latest Children’s Code strategy update and extended the current strategy for a further six months. The ICO will continue scrutinising social-media and video-sharing platforms and expand its work on mobile games, while monitoring risks in AI chatbots and health apps. Its reviews highlight recurring weaknesses in age-assurance providers and edtech: unclear controller and processor roles, weak processor and subprocessor oversight, incomplete data-flow mapping, poor data minimisation and retention, gaps in DPIAs, and inadequate privacy information. This is not a new statute or a change to the Children’s Code. It is a clear statement of enforcement priorities and practical evidence about the controls the regulator expects organisations to demonstrate.

Timeline that matters

  1. April 2024

    Children’s Code strategy launched

    The ICO began its focused strategy for social-media and video-sharing platforms.

  2. 2024–2025

    Edtech audit programme

    The ICO audited 28 providers used across primary and secondary schools.

  3. April 2024–July 2026

    Platform improvements assessed

    The ICO estimates improvements across several platforms affected close to five million child users.

  4. 19 August 2026

    Strategy update published

    The ICO released research, compliance findings and its updated priorities.

  5. Next six months

    Extended supervisory period

    Assessment of platforms and mobile games continues, with priorities adapting to wider regulatory developments.

  6. Winter 2026/27

    Impact findings expected

    The ICO aims to publish findings covering the lifetime of the current strategy.

What changed

The ICO has moved its Children’s Code strategy into an additional six-month enforcement and assessment period. It is continuing work with social-media platforms and video-sharing platforms, extending scrutiny of mobile gaming, and considering targeted intervention in areas including AI chatbots and health apps. The update also consolidates findings from risk reviews of 14 age-assurance providers and audits of 28 edtech providers. The ICO says it will follow up where potential non-compliance remains and anticipates future work on an edtech code and children within its AI and automated-decision-making code. These are regulatory priorities and findings under existing UK data-protection law, not newly binding rules.

Who should pay attention?

Social-media and video-sharing platforms

The ICO is continuing assessment and enforcement around age assurance, high-privacy defaults, location features, profiling and children’s use of services.

Mobile-game providers

Mobile gaming is now an explicit part of the extended strategy, with the ICO reviewing privacy practices and following up on commitments.

Age-assurance providers and customers

The ICO identified recurring role-mapping, processor due-diligence, subprocessor, DPIA and transparency weaknesses across its risk reviews.

Edtech providers and schools

Audits found gaps in contracts, data-flow mapping, minimisation, retention, privacy notices and DPIAs; supporting evidence remains important.

AI chatbot and health-app teams

The ICO has named these as horizon-scanning areas where targeted regulatory intervention may be considered, particularly where children use the services.

What the guidance clarifies

No new legal effective date
The update does not amend the UK GDPR or Children’s Code. It explains the ICO’s current priorities, findings and intended supervisory work.
Strategy extended six months
The ICO will continue assessing social-media and video-sharing platforms and reviewing the mobile-games sector during the extension.
Vendor governance is central
Controller and processor allocation, processor due diligence, subprocessor oversight and detailed contracts are recurring weaknesses.
DPIA quality remains an issue
The ICO reports weak DPIA governance or gaps in documentation for both age-assurance and edtech providers.
Children remain an AI priority
The ICO expects children to feature in future work on AI and automated decision-making and is monitoring AI-chatbot risks now.

Global relevance — scope depends on your services and users

Why this matters for global organisations

SaaS, gaming, education-technology, AI, moderation and age-assurance providers can supply regulated organisations or operate services accessible to children across multiple markets. Distributed delivery does not remove the need for defensible role mapping, impact assessments, processor controls, transparent notices and evidence. Applicability depends on the service, users, establishment, targeting and processing activities.

  • Global product teams should assess whether children access a service rather than relying only on a stated minimum age.
  • Distributed delivery teams may hold operational evidence needed by customers, controllers or regulators.
  • Vendor contracts should cover subprocessors, deletion, audit evidence, incident cooperation and limits on data reuse.
  • Age assurance can introduce additional privacy risks; collect the minimum necessary information and separate verification from advertising or profiling.
  • Coordinate children’s privacy controls across applicable data-protection and online-safety frameworks without assuming their requirements are identical.

12 actions to start now

  1. Determine whether each service is offered to, directed at or likely to be accessed by children in the UK; document the evidence and review trigger.
  2. Map every child-data flow, purpose, data source, recipient, retention period, location feature, profiling activity and automated decision.
  3. Record controller, joint-controller and processor roles for the service, age-assurance vendors and other partners; reconcile contracts with actual processing.
  4. Review subprocessor inventories, due-diligence evidence, international transfers, onward disclosure and audit or assurance rights.
  5. Refresh DPIAs for age assurance, geolocation, recommender systems, targeted advertising, AI chatbots, mobile gaming and sensitive health-related features.
  6. Test whether privacy settings are high by default, geolocation is off by default where required, and children are not nudged to weaken protections.
  7. Assess age-assurance methods for proportionality, accuracy, data minimisation, purpose limitation, deletion, transparency and risks to both children and adults.
  8. Rewrite child-facing notices and in-product explanations using age-appropriate language and test whether users understand the choices.
  9. Verify that retention schedules work technically across production systems, analytics stores, backups, vendors and inferred profiles.
  10. Create evidence packs for regulator engagement: design decisions, test results, DPIAs, supplier assessments, change logs, complaints and remediation proof.
  11. Add children-specific review gates to AI and product-development lifecycles, including red-team scenarios for misuse, bias, manipulation and unsafe disclosure.
  12. Monitor the ICO’s anticipated edtech and AI/automated-decision-making codes and update the roadmap when formal consultations or binding changes occur.

Evidence worth retaining

  • Documented assessment of whether the service is likely to be accessed by children in the UK.
  • Current child-data inventory and end-to-end data-flow diagrams.
  • Role-allocation analysis and contracts for controllers, processors and subprocessors.
  • Supplier due-diligence records, security assurances and follow-up actions.
  • DPIAs with named owners, risk scoring, mitigations, approvals and review dates.
  • Screenshots and test scripts proving high-privacy defaults, geolocation controls and age-appropriate notices.
  • Age-assurance design records covering necessity, proportionality, accuracy, minimisation, retention and fallback paths.
  • Retention and deletion test results across active systems, analytics, backups and vendors.
  • Evidence that profiling and recommender-system controls protect children from detrimental effects.
  • Product-governance records showing consideration of the child’s best interests.
  • Training and escalation records for product, moderation, support, sales and engineering teams.
  • Remediation trackers and proof that agreed improvements were implemented and verified.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Is the service likely to be accessed by children even if the stated target audience is adults?
  • What evidence supports each controller, joint-controller or processor classification?
  • Is the selected age-assurance method proportionate to the risk, and what happens when it is wrong?
  • Could age-assurance data be reused for advertising, profiling, analytics or another incompatible purpose?
  • Are subprocessors visible, contractually controlled and included in DPIAs and transfer assessments?
  • Do location, messaging, profiling and recommendation features use high-privacy defaults for children?
  • Can a child understand the notice and consequences without relying on an adult or lengthy legal text?
  • Which personal information and inferences are genuinely necessary, and can retention be shortened?
  • How are risks to children addressed in AI-chatbot prompts, model outputs, memory, safety testing and incident response?
  • What evidence could be produced quickly if the ICO requests proof of compliance or remediation?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.