Designing for Children’s Data: Four Regulator Frameworks That Converge
Ask who has actually written down how a service used by children should be designed, and the answer turns out to be: several regulators, in considerable detail — and their answers converge. This themed issue holds four frameworks together: the ICO’s Children’s Code, the Irish DPC’s Fundamentals, the CNIL’s eight recommendations, and the binding code Australia’s OAIC must register by 10 December 2026. The thread running through all four is privacy by design — Article 25 UK/EU GDPR applied with the child’s best interests as the objective the design must serve, not a compliance afterthought. And one development that is easy to miss: the EDPB is currently working on guidelines on the processing of children’s data.
1 · ICO — the Children’s Code (Age Appropriate Design Code)
The UK instrument. Fifteen standards for online services likely to be accessed by children under 18 — apps, games, connected toys and devices, social platforms, streaming, marketplaces and news services — applying even where children are not the target audience, and to non-UK services processing UK children’s data. The standards are design instructions rather than legal restatements: the best interests of the child as a primary consideration, a high level of privacy by default, geolocation off by default, restraint in nudge techniques, and checking the age of visitors and users. It is also a living instrument: the ICO published a progress update on its Children’s Code strategy in August 2026, alongside a self-assessment risk toolkit and sector FAQs for games, edtech and digital news.
2 · DPC (Ireland) — Children Front and Centre: the Fundamentals
Ireland’s DPC published the final Fundamentals for a Child-Oriented Approach to Data Processing in December 2021, after a consultation that included children themselves. Its fourteen named Fundamentals — from “floor of protection” and “know your audience” through to “do a DPIA” and “bake it in” — are interpretative: they set out how the DPC expects the GDPR’s high-level obligations to be read wherever a service is directed at, intended for, or likely to be accessed by children, online and offline, with a child defined as anyone under 18 in line with the UN Convention on the Rights of the Child. Two positions stand out: where a DPIA finds the best interests of the child in conflict with the organisation’s commercial interests, the child’s interests must prevail; and companies deriving revenue from services that process children’s data are expected to go, in the DPC’s words, “the extra mile” in proving their age verification and parental-consent measures are effective.
Go to source ↗ Full text (PDF) ↗
3 · CNIL — eight recommendations for protecting children online
Published in August 2021 on the back of a public consultation that drew over 700 contributions, a survey of children’s digital practices and workshops run with children. The CNIL’s focus is balance: children need protection and autonomy, and the eight recommendations hold both in view — regulating children’s capacity to act online, encouraging them to exercise their own rights, supporting parents with digital education, promoting parental controls “that respect the child’s privacy and best interests”, and strengthening “the information and rights of children by design”. Recommendation 8 is the design floor: stricter default privacy settings for children, profiling systems — targeted advertising in particular — deactivated by default, and no re-use of children’s data, or passing of it to third parties, for commercial or advertising purposes.
4 · OAIC (Australia) — the Children’s Online Privacy Code (in development)
A binding code in the design-code mould — the first outside Europe that we are aware of. Mandated by Australia’s Privacy and Other Legislation Amendment Act 2024, the code is being drafted by the OAIC as an APP code applying to social media services, relevant electronic services and designated internet services (as defined by Australia’s Online Safety Act 2021) that are likely to be accessed by children — in practice social media, messaging, gaming and much of the consumer internet — with health service providers excluded; a breach will be an interference with privacy under the Privacy Act 1988, carrying the same civil-penalty framework as other privacy breaches. Consultation on the exposure draft closed on 5 June 2026, and the final code must be registered by 10 December 2026. On the convergence, you do not have to take our word for it — the OAIC states that it continues “to look to international frameworks, such as the UK’s Age Appropriate Design Code and Ireland’s Children’s Fundamentals for Data Processing”, while noting the differences in the underlying legal frameworks.
The thread: privacy by design, with the child as the objective
Set side by side, fifteen standards, fourteen Fundamentals and eight recommendations are the same instinct at different grains: Article 25 UK/EU GDPR — data protection by design and by default — applied with the best interests of the child as the objective the design must serve. The recurring positions are recognisable across all four frameworks: defaults set high rather than negotiated down; profiling and behavioural advertising restrained or off; transparency written for the child who will actually read it; age assurance proportionate rather than identifying; and the best-interests assessment done at design time, not retrofitted. For the general Article 25 layer these build on, the EDPB’s Guidelines 4/2019 on data protection by design and by default sit in our Key Publications & Reports directory, and the Norwegian Datatilsynet’s software-development guidance, surfaced in an earlier issue, turns the same article into seven development activities. For a UK reader, the Children’s Code is the instrument that applies; the DPC, CNIL and OAIC documents are read-acrosses — benchmarks for services with EU or global reach.
What’s coming
Two dates worth a diary entry. First, the EDPB is currently working on Guidelines on the processing of children’s data — a stated priority of its 2024–2027 strategy, restated on Data Protection Day 2026; its February 2025 Statement on Age Assurance, with its ten principles for compliant age assurance — least-intrusive method first — signals the direction of travel. Second, Australia’s code must be registered by 10 December 2026 — the point at which the design-code model extends beyond Europe. When either lands, expect it here.
