Skip to main content

Children and the UK GDPR

Contents

Latest updates - last updated 15 May 2026

15 May 2026 - The updated guidance reflects changes under the Data (Use and Access) Act 2025 (DUAA) that are likely to have particular impacts on how organisation’s use children’s information. It contains improved signposting to specific requirements for information society services likely to be accessed by children and relevant children’s code standards. We’ve also added new case examples to show best practice across a range of issues where children’s information is often or likely to be used.

About this guidance

Who is this guidance for?

This guidance forms part of our children’s information guidance and resources page. It provides detailed, practical guidance for organisations that handle children’s personal information under the UK GDPR by focusing on additional, child-specific considerations.

If you haven’t yet read the brief guidance, read that first. It introduces this topic and sets out the key points you need to know.

Read our other UK GDPR guidance and resources for more information on the requirements that apply to both adults and children.

If you provide an information society service (ISS) likely to be accessed by children, also see our Age appropriate design code of practice (the children’s code) for detailed guidance on how to protect children’s information effectively in this context. We explain this term further in the next section under What is an ISS?.

This guidance doesn’t cover the use of children’s personal information for law enforcement or intelligence services purposes. See our Guide to law enforcement processing and Guide to intelligence services processing for more detail on the requirements that apply in these contexts.

How is this guidance structured?

This guidance explains the key considerations for organisations when handling children’s personal information. This includes:

  • designing your processing activities and business practices with children’s best interests in mind;
  • choosing an appropriate lawful basis for using a child’s personal information;
  • the requirements that apply when you offer an ISS to a child, particularly when you use their personal information on the basis of consent; 
  • factors to consider if you’re thinking about marketing or profiling children;
  • what to include in your privacy information for children; and 
  • what rights children have under the UK GDPR.

For an introduction to the key themes and provisions of the UK GDPR, see our UK GDPR guidance and resources page.

Links to other relevant guidance and sources of further information are provided throughout.

Contents

Overview and key definitions

What should our general approach be to handling children’s personal information?

How do the lawful bases apply to children’s personal information?

Can we use children’s personal information for direct marketing purposes?

What if we want to profile children or make automated decisions about them?

Can we share children’s personal information?

What data protection rights do children have?