Skip to content

Evidence request lists

UK Age Appropriate Design Code (Children's Code)

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Age-Appropriate

UKAADC-2
Age-Appropriate Application and Transparency

Per AADC: age-appropriate application + transparency including child-friendly language.

Artefacts an auditor will ask for
  • UK AADC evidence for UKAADC-2
Where this commonly fails
  • DPIA + nudge + geolocation partial

Best Interests

UKAADC-1
Best Interests of the Child and DPIA

Per UK AADC (Children's Code) under DPA 2018: best interests + Data Protection Impact Assessment.

Artefacts an auditor will ask for
  • UK AADC evidence for UKAADC-1
Where this commonly fails
  • DPIA + nudge + geolocation partial

Children's Code Standards 1 to 3: Best Interests, DPIA and Age Assurance

Standard 1
Best Interests of the Child

The best interests of the child must be a primary consideration when designing and developing online services.

Artefacts an auditor will ask for
  • Content moderation policy referencing illegal content
  • Hash matching deployment records
  • NCMEC or NCA reporting workflow evidence
  • Reviewer wellbeing and rotation plan
Where this commonly fails
  • Hash database refresh cadence unclear
  • Reporting clock starts after triage rather than detection
  • Reviewer welfare programme thin
  • Appeals process omitted for false positives
Standard 2
Data Protection Impact Assessments

Undertake a DPIA to assess and mitigate risks to children arising from data processing.

Artefacts an auditor will ask for
  • DPIA template aligned to regulator guidance
  • Completed DPIA reports for high risk processing
  • Consultation evidence with privacy office
  • DPIA review cadence and triggers register
Where this commonly fails
  • Triggers for DPIA not codified
  • Mitigations identified but not tracked to closure
  • Consultation with regulator skipped where mandatory
  • DPIA not refreshed after material change
Standard 3
Age Appropriate Application

Take a risk-based approach to recognizing the age of users and apply the standards accordingly.

Artefacts an auditor will ask for
  • Documented procedure addressing age appropriate application
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems

Children's Code Standards 10 to 13: Geolocation, Parental Controls, Profiling and Nudge

Standard 10
Geolocation

Switch geolocation options off by default and provide an obvious sign when location tracking is active.

Artefacts an auditor will ask for
  • Design records showing privacy defaults for children
  • Geolocation precision and consent flow evidence
  • Profiling switch off availability and discoverability
  • Parental controls user research
Where this commonly fails
  • High privacy not the default for child accounts
  • Geolocation always on without justification
  • Profiling enabled by default
  • Parental controls hard to find
Standard 11
Parental Controls

If parental controls are provided, give the child age-appropriate information about monitoring.

Artefacts an auditor will ask for
  • Design records showing privacy defaults for children
  • Geolocation precision and consent flow evidence
  • Profiling switch off availability and discoverability
  • Parental controls user research
Where this commonly fails
  • High privacy not the default for child accounts
  • Geolocation always on without justification
  • Profiling enabled by default
  • Parental controls hard to find
Standard 12
Profiling

Switch off profiling by default unless a compelling reason exists and appropriate safeguards are in place.

Artefacts an auditor will ask for
  • Design records showing privacy defaults for children
  • Geolocation precision and consent flow evidence
  • Profiling switch off availability and discoverability
  • Parental controls user research
Where this commonly fails
  • High privacy not the default for child accounts
  • Geolocation always on without justification
  • Profiling enabled by default
  • Parental controls hard to find
Standard 13
Nudge Techniques

Do not use nudge techniques to lead children to provide unnecessary personal data or weaken privacy settings.

Artefacts an auditor will ask for
  • Design records showing privacy defaults for children
  • Geolocation precision and consent flow evidence
  • Profiling switch off availability and discoverability
  • Parental controls user research
Where this commonly fails
  • High privacy not the default for child accounts
  • Geolocation always on without justification
  • Profiling enabled by default
  • Parental controls hard to find

Children's Code Standards 14 to 15: Connected Toys and Online Tools

Standard 14
Connected Toys and Devices

Connected toys and devices must comply with the code including providing effective privacy protections.

Artefacts an auditor will ask for
  • Documented procedure addressing connected toys and devices
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
Standard 15
Online Tools

Provide prominent and accessible tools to help children exercise their data protection rights.

Artefacts an auditor will ask for
  • Documented procedure addressing online tools
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems

Children's Code Standards 4 to 6: Transparency and Policies

Standard 4
Transparency

Privacy information must be provided in clear, age-appropriate language that children can understand.

Artefacts an auditor will ask for
  • Privacy or transparency notice with version history
  • Layered notice design records
  • Just in time notice deployment evidence
  • Plain language readability assessment
Where this commonly fails
  • Notice not aligned to actual processing
  • Children friendly version absent where required
  • Translation gaps for in-scope jurisdictions
  • Change log not surfaced to data subjects
Standard 5
Detrimental Use of Data

Do not use children's personal data in ways shown to be detrimental to their wellbeing.

Artefacts an auditor will ask for
  • Documented procedure addressing detrimental use of data
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
Standard 6
Policies and Community Standards

Uphold published terms, policies, and community standards including privacy policies and age restrictions.

Artefacts an auditor will ask for
  • Approved Policies and Community Standards document with version control
  • Board or executive sign-off record for the policies and community standards
  • Annual policy review log and amendment register
  • Staff acknowledgement records for the policies and community standards
Where this commonly fails
  • Policy not reviewed within defined cadence
  • No evidence of executive approval or sign-off
  • Staff acknowledgement coverage below threshold
  • Policy scope omits in-scope subsidiaries or processors

Children's Code Standards 7 to 9: Defaults, Minimisation and Sharing

Standard 7
Default Settings

Settings must be high privacy by default unless a compelling reason exists for a different default.

Artefacts an auditor will ask for
  • Design records showing privacy defaults for children
  • Geolocation precision and consent flow evidence
  • Profiling switch off availability and discoverability
  • Parental controls user research
Where this commonly fails
  • High privacy not the default for child accounts
  • Geolocation always on without justification
  • Profiling enabled by default
  • Parental controls hard to find
Standard 8
Data Minimisation

Collect and retain only the minimum personal data needed to provide the service elements the child uses.

Artefacts an auditor will ask for
  • Data lineage diagrams for in scope flows
  • Retention schedule by data category
  • Deletion job logs
  • Provenance attestation for source datasets
Where this commonly fails
  • Lineage stops at the data lake boundary
  • Retention rules not enforced in shadow copies
  • Deletion verified at logical level only
  • Provenance for third party datasets thin
Standard 9
Data Sharing

Do not disclose children's data unless there is a compelling reason to do so.

Artefacts an auditor will ask for
  • Documented procedure addressing data sharing
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems

Default Settings

UKAADC-3
Default Settings, Data Minimisation, Sharing

Per AADC: high-privacy default settings + data minimisation + no sharing without compelling reason.

Artefacts an auditor will ask for
  • UK AADC evidence for UKAADC-3
Where this commonly fails
  • DPIA + nudge + geolocation partial

Online Tools

UKAADC-5
Online Tools, Parental Controls, Reporting

Per AADC: online tools for children + parental controls + reporting + complaint mechanisms.

Artefacts an auditor will ask for
  • UK AADC evidence for UKAADC-5
Where this commonly fails
  • DPIA + nudge + geolocation partial

Profiling

UKAADC-4
Profiling, Nudge, Geolocation, Connected Toys

Per AADC: profiling restrictions + nudge techniques restrictions + geolocation defaults off + connected toys safeguards + parental controls.

Artefacts an auditor will ask for
  • UK AADC evidence for UKAADC-4
Where this commonly fails
  • DPIA + nudge + geolocation partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.