
The ICO (Information Commissioners Office) has now released its code of practice on age appropriate design, targeted at online services provided and marketed for children.
The purpose of this code is to outline the expectations in relation to online information services for children and to ensure that data protection by design and privacy lie at the heart of the product.
You might question why we are letting you know about this, especially when the majority of Fusion’s audience don’t build or create online services for children? Well, the answer lies in what you provide to the children of your school, on a regular basis, that add to or complement what is taught in the classroom. This may include online products targeted at schools which children can access directly.
Taking the guidance into account, DPO’s and those tasked with procuring products should be considering whether the online product they purchase or subscribe to, meet the necessary standards set out in the code, and whilst not legislative, demonstrate the online service has complied with its data protection obligations under the GDPR.
The 15 new principles within the code apply to any service that is likely to be used by children under 18 in the UK. This includes services provided both inside and outside of the EU. The principles should form part of any DPIA that you carry out, especially in this area, to ensure that data processors are meeting your compliance requirements and further consultation with the ICO is not required.
To read the code click here and if you would like any more information on how FusionHR can help your school, with your data protection needs or HR please call 01924 827869. If you are already a DPO client, please email your consultant to discuss this further.






