UK-AADC-AGE-BANDSMEDIUMBest PracticeGovernanceImplement age-banded service differentiation across 5 recommended age groups
ICO Guidance - Age-banded approach · Read the full page →
UK AADC
The ICO's Children's Code — data-protection-by-design standards for likely-child users.
27 obligations in this framework — full source text, applicability logic, and engineering tickets inside Landfall.
27 obligation pages · last updated 11 September 2026
UK-AADC-AGE-BANDSMEDIUMBest PracticeGovernanceImplement age-banded service differentiation across 5 recommended age groups
ICO Guidance - Age-banded approach · Read the full page →
UK-AADC-CONFORMANCEMEDIUMRecord KeepingGovernanceMaintain records showing how each AADC standard has been addressed
ICO Guidance - Conformance documentation · Read the full page →
UK-AADC-STD-01CRITICALRequirementGovernanceMake the best interests of children a primary consideration in service design and development
Standard 1 - Best interests of the child · Read the full page →
Featured — source excerpt“The best interests of the child should be a primary consideration when you design and develop online services likely to be accessed by a child.”
UK-AADC-STD-01-PARTICIPATIONHIGHRequirementUser RightsServices must provide age-appropriate mechanisms for children to express preferences and participate in decisions affecting their digital lives
Standard 1 - Best Interests of the Child (Participation Rights) · Read the full page →
Featured — source excerpt“Children have the right to have their views given due weight in matters that affect them, in accordance with their age and maturity.”
UK-AADC-STD-02CRITICALAssessmentGovernanceConduct DPIAs for services likely accessed by children, accounting for age differences
Standard 2 - Data protection impact assessments · Read the full page →
Featured — source excerpt“Undertake a Data Protection Impact Assessment (DPIA) for any online service likely to be accessed by children, which takes account of the different ages, capacities and development needs of children.”
UK-AADC-STD-02-REVIEWHIGHRequirementGovernanceKeep DPIAs under continuous review; update for new features or processing changes
Standard 2 - DPIA review and publication · Read the full page →
UK-AADC-STD-03CRITICALRequirementAge AssuranceVerify user age with certainty proportionate to risk, or apply code to all users
Standard 3 - Age appropriate application · Read the full page →
UK-AADC-STD-03-METHODSHIGHRequirementAge VerificationAge verification methods must be proportionate, robust, and data-minimizing
Standard 3 - Age estimation and verification methods · Read the full page →
UK-AADC-STD-04HIGHDisclosureTransparencyProvide clear, age-appropriate privacy information and bite-sized data-use explanations
Standard 4 - Transparency · Read the full page →
UK-AADC-STD-04-BITE-SIZEDHIGHRequirementTransparencyPrivacy information must be presented in bite-sized, layered formats appropriate to children's age and comprehension level, not buried in lengthy legal policies
Standard 4 - Transparency (Bite-sized/Layered Explanations) · Read the full page →
UK-AADC-STD-05CRITICALProhibitionData ProcessingProhibit use of children's data in ways detrimental to their wellbeing
Standard 5 - Detrimental use of data · Read the full page →
UK-AADC-STD-06HIGHRequirementGovernanceEnforce all published terms, policies, and community standards consistently
Standard 6 - Policies and community standards · Read the full page →
UK-AADC-STD-07HIGHRequirementDesign DefaultsSet all privacy and safety settings to their most protective values by default
Standard 7 - Default settings · Read the full page →
UK-AADC-STD-07-NUDGE-DEFAULTHIGHProhibitionDesign DefaultsPrivacy settings must default to the highest level for children; services must not use nudge techniques to encourage children to weaken their privacy protections
Standard 7 - Default Settings (Anti-nudge) · Read the full page →
UK-AADC-STD-08HIGHRequirementData ProcessingCollect only minimum data needed for features child actively uses; offer granular choices
Standard 8 - Data minimisation · Read the full page →
UK-AADC-STD-08-RETENTIONHIGHRequirementData ProcessingDelete children's data when no longer needed; automate retention schedules
Standard 8 - Data retention limits for children · Read the full page →
UK-AADC-STD-09CRITICALProhibitionData SharingProhibit disclosure of children's data without a compelling best-interests reason
Standard 9 - Data sharing · Read the full page →
UK-AADC-STD-09-SHARINGHIGHRequirementData SharingChildren's data must not be disclosed to third parties, shared across services, or made public unless there is a compelling, specifically justified reason with appropriate safeguards
Standard 9 - Data Sharing (Child-specific) · Read the full page →
UK-AADC-STD-10HIGHRequirementDesign DefaultsDisable geolocation by default; show active-tracking indicator; hide location from public
Standard 10 - Geolocation · Read the full page →
UK-AADC-STD-10-GEOLOCATIONCRITICALRequirementData CollectionGeolocation tracking must be off by default for children; when active it must be visually obvious; returning to off must be straightforward
Standard 10 - Geolocation (Default Off for Children) · Read the full page →
UK-AADC-STD-11CRITICALProhibitionProfiling AlgorithmsDisable profiling by default; only permit with harm-protection measures in place
Standard 12 - Profiling · Read the full page →
UK-AADC-STD-11-HARMHIGHAssessmentProfilingDocument harm-protection measures where child profiling is permitted
Standard 12 - Profiling harm assessment · Read the full page →
UK-AADC-STD-12HIGHDisclosureParental ControlsProvide age-appropriate transparency to children about parental monitoring and controls
Standard 11 - Parental controls · Read the full page →
UK-AADC-STD-13CRITICALProhibitionDesign DefaultsProhibit nudge techniques that lead children to weaken privacy or provide unnecessary data
Standard 13 - Nudge techniques · Read the full page →
UK-AADC-STD-14HIGHRequirementDesign DefaultsEnsure connected toys and devices include tools for code compliance and safe defaults
Standard 14 - Connected toys and devices · Read the full page →
UK-AADC-STD-14-CONNECTED-TOYSHIGHRequirementData CollectionConnected toys and devices processing children's data must include effective tools for code compliance, including parental controls and privacy-protective defaults
Standard 14 - Connected Toys and Devices · Read the full page →
UK-AADC-STD-15MEDIUMRequirementUser RightsProvide accessible tools for children to exercise data rights and report concerns
Standard 15 - Online tools · Read the full page →
Landfall turns each of the 27 UK Age Appropriate Design Code obligations into traceable engineering tickets — with full source text, applicability logic, and a citation chain your auditors can follow.
Critical Boundaries
Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.
This product does not provide legal advice and does not create an attorney-client relationship.
Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.
We do not quantify, calculate, or certify your compliance risk level.
No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.
This is a planning and mapping tool, not a runtime enforcement system.
Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.
Using this tool does not mean you are compliant with any regulation.
No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.
Our interpretations are not binding and may differ from regulatory guidance.
Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.
This tool does not shield you from enforcement actions or liability.
Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.
AI features assist analysis but do not make compliance decisions for you.
AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.
We do not cover all regulations, all obligations, or all jurisdictions.
Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.
What This Tool IS: