The transition period for the Age appropriate design code, also called the Children’s code, ended on September 2nd, 2021. The code is now six months into its supervision phase, with an evaluation due to be completed in late 2022.
Backed up by data protection legislation and based on the UN Committee of the Rights of, the code contains 15 standards to help ensure children and their data are safe online.
These include restricting data sharing and ensuring the minimum amount of data is collected, along with rules on geolocation, transparency, and ensuring the highest privacy settings are enabled by default.
Ahead of his presentation at Data Protection Summit 2022, DIGIT spoke with Head of Regulatory Strategy at the Information Commissioner’s Office (ICO) Michael Murray to find out what lessons have been learnt since the code was implemented.
Online challenges
Children are some of the most enthusiastic users of the internet. Research from Ofcom found that 97% of all children aged 5-15 were online in some form or another in 2020, slightly above the national average.
“From the minute they’re born and take their first steps into the digital world, their data is being collected and shared across the internet between companies and, in some cases, with individuals,” Murray noted.
When operating online, data-sharing is a fact of life. But parents are increasingly uneasy about the amount of data being gathered on their children.
“ICO research conducted last year found that only 15% of parents were comfortable with their children’s data being shared with third parties,” Murray said. “So while most children are online, most parents aren’t comfortable with kids’ data being shared.
“We also know that kids with parents who aren’t digitally savvy often don’t know what their data rights are. They don’t know how to protect themselves online,” he adds.
For everyone, online spaces come with a range of challenges and dangers. Even for adults, risks from scams, malware, and misinformation are everywhere. But for younger people, these can be even greater, especially as children are generally less capable of spotting potential risks compared to adults.
“Young people don’t have as developed a sense of risk and understanding of strategies to reduce risk, potentially, as adults do,” Murray said.
“While some kids are very savvy about protecting themselves online, many parents don’t know how to do it. There are also many children who don’t have parents or don’t have engaged parents.”
This is exacerbated by opaque design of many data-gathering and sharing systems. In addition, the internet is built on data sharing. When data is entered into one place, it can be hard to track where it ends up.
Maintaining agency
As such, the code was designed to switch the balance of power away from making children and parents responsible for online digital safety towards making industry itself improve how their services are designed.
However, these protections must be balanced with allowing children to maintain freedom and agency online.
“We don’t want the code to freeze children out,” Murray says. “Much of life is digital these days and the internet is so important for kids’ learning, entertainment, and communications.
“So, the code is designed to stop children’s data being collected and shared across the Internet where data collection is not required for the core purposes of the service being offered. It requires that information about what children’s data that is used is presented in clear, age-appropriate language that allows children themselves to make informed choices about their data as they get older.”
Take advertising for example – while many children might not be able to spot sponsorships, many more can. Engaging with influencers is a big part of children’s online lives. Not being able to follow their favourite celebrities on social media would curtail their online freedoms.
“We are not saying that children should not be able to see ads if it’s what they choose, but they should have access to age-appropriate information informing their choices” Murray says.
“So part of the code is to have defaults on. Profiling should be off by default. But if children – when they’re old enough – want to see some ads, then they can choose to alter the settings themselves and take control over their data.”
Lessons learned
Since being implemented six months ago, the Children’s code has helped companies shape their digital offering to protect children.
“Mostly, the attitude has been positive,” Murray notes. “Our surveys have found that many companies are in the process of reviewing the risks to children, reviewing and redrafting their privacy information and developing their data protection impact assessments.”
However, there have still been lessons learned so far during its supervision phase.
“Some in industry don’t fully grasp that they are in the scope of the code,” Murray notes. “The code applies to online services that are likely to be accessed by children.”
This means that it applies not just to services designed for children, but also adult-orientated services that children use.
“I think some organisations still don’t fully understand that distinction, so part of the issue is trying to work with industry to help services understand who are in scope and what they need to do.”
Despite the September 2nd 2021 deadline, some groups have been slow to ensure their data protection standards meet the code’s specifications.
“Another challenge is around the development of assurance technologies to help online services know who their users are to make sure under-age users don’t access their services,” Murray notes
“That’s a technical challenge, but also a policy challenge for companies who potentially have not looked at their userbase in detail before and made sure that the services that they’re offering are age appropriate.”
Helping hand
For organisations struggling to implement the Children’s code, the ICO offers a range of support. These include an advice hub and resources like data protection impact assessment templates.
“We’ve done a lot of work to help online services embed privacy by design principles from the beginning,” Murray notes. “That helps new-born sites conform from inception.
“And if they’re in the process of updating their transparency notices, there’s good practice examples on our Children’s code hub site.
“We also have an ongoing engagement programme that focuses on higher risk sectors, including the games sector, social media, and streaming.”
Recommended
- Leader Insights | Scotland’s AI Strategy one year in
- Sword Group announces Ping Networks purchase
- The best and worst places in Scotland to own an electric car
With the Children’s code evaluation planned for this autumn, Murray notes that there are no changes planned for the code. However, there are other changes in the pipeline, such as the Online Safety Bill and the government’s review of the UK’s data protection regime, that may have an impact on how industry protects children’s rights online.
“But at the moment, it’s too early in the process to give us any clues about what that evaluation is going to say. But overall, we’re quite pleased with how the code has gone to date,” Murray says.
“We’re raising awareness of the code among parents and children and industry, but we’re happy with the progress that’s been made,” he adds.
The DIGIT Data Protection Summit 2022
​The 5th annual Data Protection Summit will take place on 24th March at Dynamic Earth in Edinburgh, and streamed through our virtual conference platform.
The conference will contextualise the latest developments within the data protection field, with insight from frontline practitioners reflecting on key trends, challenges and best practice.
For more information, visit:Â www.dataprotection-summit.com





