UK AADC Standard 2 - Data protection impact assessments
Conduct DPIAs for services likely accessed by children, accounting for age differences
Where this comes from
Provision: Standard 2 - Data protection impact assessments
Instrument: UK Age Appropriate Design Code
Citation: Information Commissioner's Office, Age Appropriate Design: a code of practice for online services, Standard 2
Text version: ICO Age Appropriate Design Code (statutory code under Data Protection Act 2018 s 123), issued 2 Sept 2020
Who it applies to
It applies when all of these are true:
- Service is likely to be accessed by children under 18
…unless:
- A compelling reason exists where the setting serves the best interests of the child (e.g., safety features). (ICO AADC Guidance, Standard 2.3)
- Low-risk services with minimal data processing may have relaxed default requirements. (ICO AADC Guidance, Standard 2.5)
Scope in the source's own terms
- Service is likely to be accessed by children (under 18)
- Service is offered to users in the United Kingdom
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Assessment covers data flows, the risks to the affected group, and likelihood/severity
- Each identified risk has a mitigation mapped to a concrete control or backlog item
- The assessment is dated, has named sign-off, and is scheduled for review
- The assessment is retrievable for regulators on request
- Signed assessment document is stored and version-controlled
Evidence an auditor expects
- User-interface evidenceUser testing
Screenshots of default privacy settings for new child accounts
UI evidence showing all privacy settings default to most protective options for users under 18
- Technical controlTechnical audit
Default configuration in codebase
Code showing default values for privacy settings differentiated by user age
- Policy documentDocument reviewRecommended
Privacy defaults rationale document
Document explaining each privacy setting default and why it serves best interests of children
Questions people ask
- Does UK AADC Standard 2 - Data protection impact assessments apply to my service?
- It applies when Service is likely to be accessed by children under 18. It does not apply where A compelling reason exists where the setting serves the best interests of the child (e.g., safety features). (ICO AADC Guidance, Standard 2.3).
- From when does this apply?
- UK AADC Standard 2 - Data protection impact assessments applies from 2 September 2021. Its current status is: in force.
- What evidence does an auditor expect?
- Screenshots of default privacy settings for new child accounts; Default configuration in codebase; Privacy defaults rationale document.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.