UK Age Appropriate Design Code (Children's Code)
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Age-Appropriate
Per AADC: age-appropriate application + transparency including child-friendly language.
- UK AADC evidence for UKAADC-2
- DPIA + nudge + geolocation partial
Best Interests
Per UK AADC (Children's Code) under DPA 2018: best interests + Data Protection Impact Assessment.
- UK AADC evidence for UKAADC-1
- DPIA + nudge + geolocation partial
Children's Code Standards 1 to 3: Best Interests, DPIA and Age Assurance
The best interests of the child must be a primary consideration when designing and developing online services.
- Content moderation policy referencing illegal content
- Hash matching deployment records
- NCMEC or NCA reporting workflow evidence
- Reviewer wellbeing and rotation plan
- Hash database refresh cadence unclear
- Reporting clock starts after triage rather than detection
- Reviewer welfare programme thin
- Appeals process omitted for false positives
Undertake a DPIA to assess and mitigate risks to children arising from data processing.
- DPIA template aligned to regulator guidance
- Completed DPIA reports for high risk processing
- Consultation evidence with privacy office
- DPIA review cadence and triggers register
- Triggers for DPIA not codified
- Mitigations identified but not tracked to closure
- Consultation with regulator skipped where mandatory
- DPIA not refreshed after material change
Take a risk-based approach to recognizing the age of users and apply the standards accordingly.
- Documented procedure addressing age appropriate application
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Children's Code Standards 10 to 13: Geolocation, Parental Controls, Profiling and Nudge
Switch geolocation options off by default and provide an obvious sign when location tracking is active.
- Design records showing privacy defaults for children
- Geolocation precision and consent flow evidence
- Profiling switch off availability and discoverability
- Parental controls user research
- High privacy not the default for child accounts
- Geolocation always on without justification
- Profiling enabled by default
- Parental controls hard to find
If parental controls are provided, give the child age-appropriate information about monitoring.
- Design records showing privacy defaults for children
- Geolocation precision and consent flow evidence
- Profiling switch off availability and discoverability
- Parental controls user research
- High privacy not the default for child accounts
- Geolocation always on without justification
- Profiling enabled by default
- Parental controls hard to find
Switch off profiling by default unless a compelling reason exists and appropriate safeguards are in place.
- Design records showing privacy defaults for children
- Geolocation precision and consent flow evidence
- Profiling switch off availability and discoverability
- Parental controls user research
- High privacy not the default for child accounts
- Geolocation always on without justification
- Profiling enabled by default
- Parental controls hard to find
Do not use nudge techniques to lead children to provide unnecessary personal data or weaken privacy settings.
- Design records showing privacy defaults for children
- Geolocation precision and consent flow evidence
- Profiling switch off availability and discoverability
- Parental controls user research
- High privacy not the default for child accounts
- Geolocation always on without justification
- Profiling enabled by default
- Parental controls hard to find
Children's Code Standards 14 to 15: Connected Toys and Online Tools
Connected toys and devices must comply with the code including providing effective privacy protections.
- Documented procedure addressing connected toys and devices
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Provide prominent and accessible tools to help children exercise their data protection rights.
- Documented procedure addressing online tools
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Children's Code Standards 4 to 6: Transparency and Policies
Privacy information must be provided in clear, age-appropriate language that children can understand.
- Privacy or transparency notice with version history
- Layered notice design records
- Just in time notice deployment evidence
- Plain language readability assessment
- Notice not aligned to actual processing
- Children friendly version absent where required
- Translation gaps for in-scope jurisdictions
- Change log not surfaced to data subjects
Do not use children's personal data in ways shown to be detrimental to their wellbeing.
- Documented procedure addressing detrimental use of data
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Uphold published terms, policies, and community standards including privacy policies and age restrictions.
- Approved Policies and Community Standards document with version control
- Board or executive sign-off record for the policies and community standards
- Annual policy review log and amendment register
- Staff acknowledgement records for the policies and community standards
- Policy not reviewed within defined cadence
- No evidence of executive approval or sign-off
- Staff acknowledgement coverage below threshold
- Policy scope omits in-scope subsidiaries or processors
Children's Code Standards 7 to 9: Defaults, Minimisation and Sharing
Settings must be high privacy by default unless a compelling reason exists for a different default.
- Design records showing privacy defaults for children
- Geolocation precision and consent flow evidence
- Profiling switch off availability and discoverability
- Parental controls user research
- High privacy not the default for child accounts
- Geolocation always on without justification
- Profiling enabled by default
- Parental controls hard to find
Collect and retain only the minimum personal data needed to provide the service elements the child uses.
- Data lineage diagrams for in scope flows
- Retention schedule by data category
- Deletion job logs
- Provenance attestation for source datasets
- Lineage stops at the data lake boundary
- Retention rules not enforced in shadow copies
- Deletion verified at logical level only
- Provenance for third party datasets thin
Do not disclose children's data unless there is a compelling reason to do so.
- Documented procedure addressing data sharing
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Default Settings
Per AADC: high-privacy default settings + data minimisation + no sharing without compelling reason.
- UK AADC evidence for UKAADC-3
- DPIA + nudge + geolocation partial
Online Tools
Per AADC: online tools for children + parental controls + reporting + complaint mechanisms.
- UK AADC evidence for UKAADC-5
- DPIA + nudge + geolocation partial
Profiling
Per AADC: profiling restrictions + nudge techniques restrictions + geolocation defaults off + connected toys safeguards + parental controls.
- UK AADC evidence for UKAADC-4
- DPIA + nudge + geolocation partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.