Site navigation

ICO Fines Imgur Owner of Children’s Data Protection Failures

Elizabeth Greenberg

,

imgur children's data protection
“Ignoring the fact that children use these services, while processing their data unlawfully, is not acceptable,” John Edwards, UK Information Commissioner, said.

The Information Commissioner’s Office (ICO) has fined MediaLab.AI, Inc. (MediaLab), owner of image sharing and hosting platform Imgur, £247,590 for failing to use children’s personal information lawfully.

The penalty follows an investigation that found MediaLab allowed children to use Imgur without putting in place the basic safeguards required under UK data protection law.

The ICO’s investigation found that between September 2021 and September 2025, MediaLab processed the personal information of children using Imgur in ways that breached the UK GDPR.

UK law says that online services using the personal information of children under 13 can only rely on the lawful basis of consent if consent is given by the child’s parent or carer.

The ICO found that MediaLab failed to implement any measures to check the age of users, proceeded to process the personal information of children under 13 without parental cosent or any other lawful basis, and failed to carry out a data protection impact assessment to identify and mitigate privacy risks to children.

Personal information often drives the content children see online. MediaLab had no way of knowing the age of Imgur users, meaning that children were at risk of being exposed to harmful content on the platform, including content related to eating disorders, homophobia, antisemitism and images of a sexual or violent nature.


Recommended


“MediaLab failed in its legal duties to protect children, putting them at unnecessary risk. For years, it allowed children to use Imgur without any effective age checks, while collecting and processing their data, which in turn exposed them to harmful and inappropriate content,” John Edwards, UK Information Commissioner, said.

“Age checks help organisations keep children’s personal information safe and not used in ways that may harm them, such as by recommending age-inappropriate content.

“This fine is part of our wider work to drive improvements in how digital platforms use children’s personal data. Ignoring the fact that children use these services, while processing their data unlawfully, is not acceptable. Companies that choose to ignore this can expect to face similar enforcement action.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data