Nearly 25% of children’s apps available on Google Play are in violation of the UK’s Information Commissioner’s Office (ICO) age-appropriate design code, according to Comparitech.
Comparitech investigated 409 apps labeled under ‘children’ on the Google Play application store against the 15 standards in the ICO’s children’s code. This included app developers targeting children under 18 as well as those that may appeal to children through imagery or terminology used by the app.
The vast majority of apps found to be in breach of at least one standard collected personal data without a clear and comprehensive section on children’s data protection within their privacy policy.
The survey also found that 5.5% of the apps reviewed claimed to not be geared toward children despite being featured in the child-specific section on Google Play and even sometimes featuring the word “kids” in the app name. Of those 5.5%, all but one had an age rating suitable for all ages, with the only exception being suitable for those seven years old and up.
Over 11% of the app’s privacy policies studied either collected personal data without a child-specific policy or were vague, open to interpretation, or unclear. A further 4% have data collection practices without the right parental permission or protocols in place.
As well, companies seemed to be confused by terminology defined by the ICO – they claimed that IP addresses they collected was “non-personal” data, despite the ICO deeming it as personal data.
In BreachÂ
Of the 24% found to be ICO non-compliant, they were split into six different categories of infringement:
- 48% had no child policy but did collect some form of personal data without a child-specific policy or a policy that is open to interpretation.
- 23% claimed to not be aimed at children, though they had age ratings for children
- 18% failed to implement the correct protocols for collecting children’s data
- 5% put the onus on parents to ensure their children’s data policy
- 3% do not collect data themsevles but allow third parties to and do not have a child policy for this
- and 19 apps deemed the IP address they collected as non-personal data in contrast to ICO definitions
Alarmingly, the survey also found that 100% of the apps found to be in breach of ICO regulations were “expert approved” for children.
Google’s “Teach Approved” program puts apps through a second layer of review to assess their appeal to children, if they are age appropriate, and their design quality.
Even the apps which claimed to not be targeting children had this seal of approval.
Complying with ICOÂ
To remain within the ICO code, app developers should have:
- A map of the personal data they are collecting from UK children
- Age verification
- Geolocation services switched off as degault
- No nudge techniques that may encourage children to hand over more personal data
- A high privacy level as default
Who’s At Fault?
Google does have their own list of regulations – apps designed for children or multiple age groups must protect every age group and comply with varying regulations.
Recommended
- Women Entrepreneurship: New Scot Gov Report Tackles Gender Barriers
- Soaring Levels of Cyber-crime and Fraud Prompt SBRC Rebrand
- New Climate Change Hub Launched for UK Forestry Sector
The ICO’s guidelines are only a year old, so there is so far no precedent with how to deal with apps found in breach – whether it is the responsibility of the app developers, the app store (Google, in this case), or users.
The ICO did suggest it was going to look into how different online services are conforming to the new children’s code.
App developers are likely to be on the hook for breaches in the code – but Google’s approval of the apps may make it liable to the ICO, especially with the “expert approval” it has provided to certain apps with unclear child data policies.
The ICO’s enforcement powers mean it can issue fines of up to £17.5 million or 4% of an organisation’s annual worldwide turnover – whichever is higher – for non-compliance.
With the Online Safety Bill still being debated and consistently changed, it will be interesting to see if the ICO’s child data protection policy reaches into the pockets of big tech for overall violations, or if they only target app developers rather than app marketplaces.
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





