UK AADC Standard 8 - Data retention limits for children
Delete children's data when no longer needed; automate retention schedules
Where this comes from
Provision: Standard 8 - Data retention limits for children
Instrument: UK Age Appropriate Design Code
Citation: Information Commissioner's Office, Age Appropriate Design: a code of practice for online services, Standard 8
Text version: ICO Age Appropriate Design Code (statutory code under Data Protection Act 2018 s 123), issued 2 Sept 2020
Who it applies to
It applies when all of these are true:
- Service is likely to be accessed by children under 18
- Service collects behavioral data
…unless:
- Data may be retained beyond necessity where required by law (e.g., financial records, legal holds). (Legal retention obligations)
- Extended retention permitted for child safety purposes (e.g., abuse prevention, evidence preservation). (ICO AADC Standard 8)
Scope in the source's own terms
- Service stores personal data of children
- Service operates under GDPR (EU scope; block moved from UK-GDPR authorship)
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Retention schedule exists per data category and is enforced automatically
- Expired data is deleted or anonymized across primary and backup stores
- Children's data retention is minimized and periodically reviewed
- Backup lag does not resurrect data already deleted from primary stores past its window
- A legal hold overrides scheduled deletion and is released cleanly when lifted
Evidence an auditor expects
- Policy documentDocument review
Data retention schedule for children's data
Documented retention periods for each data type collected from children
- Technical controlTechnical audit
Automated deletion implementation
Technical evidence of automated data deletion processes
- Process recordLog analysis
Deletion logs
Records showing data deletion in accordance with retention schedule
Questions people ask
- Does UK AADC Standard 8 - Data retention limits for children apply to my service?
- It applies when Service is likely to be accessed by children under 18; Service collects behavioral data. It does not apply where Data may be retained beyond necessity where required by law (e.g., financial records, legal holds). (Legal retention obligations).
- From when does this apply?
- UK AADC Standard 8 - Data retention limits for children applies from 2 September 2021. Its current status is: in force.
- What evidence does an auditor expect?
- Data retention schedule for children's data; Automated deletion implementation; Deletion logs.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.