The UK Children’s Data Protection: What’s Law, In Power, and Still a Policy in 2026

Over the past year, UK policymakers have moved decisively to strengthen the legal framework protecting children’s personal data online. Rather than arriving as a single, sweeping reform, the changes have come through several parallel channels: primary legislation, secondary powers not yet exercised, statutory guidance, and government policy announcements that sit outside the legislative process altogether. 

For organisations operating information society services likely to be accessed by children social media platforms, gaming services, educational technology, and wellness or health apps among them understanding which of these developments are already binding law, and which remain proposals, is essential to getting compliance planning right. 

This article sets out the current state of play as of July 2026, distinguishing between what has already changed, what is legally possible but not yet in force, and what remains government policy intent. 

The Three UK Children’s Data Protection Updates in 2026 At A Glance

It is worth stepping back to see how these three developments interact, because they are frequently and incorrectly treated as a single reform: 

Development Status Nature 
DUAA’s Article 25 amendment In force Design and accountability obligation on the controller, regardless of a child’s age or consent status 
Children’s Wellbeing and Schools Act 2026 Article 8 power Live mechanism, not yet exercised Digital age of consent remains 13 today (governs lawful data processing consent)) 
Social media ban / curfew announcements Policy commitment, no legal effect yet Would likely be delivered through secondary regulations under section 214A of the Online Safety Act 2023, alongside Article 8 data powers 

All three sit on top of the ICO’s existing Age-Appropriate Design Code, which continues to represent the primary practical standard for designing services likely to be accessed by children, and against which the new statutory design obligation is most naturally read. 

Data Protection by Design: The “Children’s Higher Protection Matters” under DUAA

Status: In force since 5 February 2026 

The most concrete and immediately applicable change came into force on 05 February 2026, as part of the phased rollout of the Data (Use and Access) Act 2025 (DUAA). Section 81 of the DUAA amends Article 25 of the UK GDPR the provision governing data protection by design and by default to insert an explicit new requirement. 

What Does “Children’s Higher Protection Matters” Mean in Practice?

Where an organisation provides information society services likely to be accessed by children, it must now consider what the legislation terms the “children’s higher protection matters” when assessing what constitutes appropriate technical and organisational measures. These matters are defined in the statute as: 

  1. how children can best be protected and supported when using the service; and 
  1. the recognition that children merit specific protection because they may be less aware of the risks and consequences of data processing and their rights in relation to it, and that their needs differ across ages and stages of development. 

In practical terms, this takes principles that have existed since 2020 in the ICO’s Age-Appropriate Design Code (the Children’s Code) a code of practice and embeds an equivalent obligation directly into primary data protection law itself, via the core Article 25 design obligation. 

Organisations that already conform fully to the Children’s Code should, in principle, already satisfy this requirement. However, the shift from code-level guidance to statutory obligation raises the stakes: privacy-by-design assessments, DPIAs, and product development sign-off processes for any service likely to be accessed by children should now explicitly document how these matters were considered, rather than relying on general Children’s Code alignment as an implicit answer. 

The ICO published updated guidance on Data Protection by Design and Default to coincide with this change coming into force, including a dedicated section addressing the children’s higher protection matters directly. 

The UK Digital Age of Consent 

Status: The power exists but not yet exercised 

Separately from the DUAA, the Children’s Wellbeing and Schools Act 2026 received Royal Assent on 29 April 2026. Alongside its principal focus on education and safeguarding, the Act inserts new provisions into Article 8 of the UK GDPR the article governing a child’s own consent to information society services. 

Important
Currently, the UK’s general digital age of consent is 13. A young person of that age or older can validly consent to a service processing their personal data without a parent or guardian doing so on their behalf. 

What the Children’s Wellbeing and Schools Act 2026 Actually Changed?

The 2026 Act does not itself change that age. Instead, it grants the Secretary of State a regulation-making power to raise it, within a range of 13 to 16, and significantly to set different ages for different categories of service. A social networking service that processes personal data for personalised content, targeted advertising, or algorithmically curated recommendations could, for example, be made subject to a different (likely higher) threshold than other types of information society service. 

Any such regulations require the affirmative resolution procedure in Parliament, meaning both Houses must actively approve them before they take effect. 

The power is tied to the government’s “Growing up in the online world” consultation, launched on 02 March 2026, and the Secretary of State is required to have regard to consultation responses when deciding how to use it. As of July 2026, no regulations have yet been made under this power. The legal architecture exists, but the age of consent has not moved. 

A related development: a new power inserted into the Online Safety Act 2023 (new section 214A) enables the government to directly require providers to prevent or restrict children’s access to services and specific features (such as curfews or stranger messaging) a mechanism that works alongside the Article 8 data protection threshold and powers Section 3 below. 

The Under-16 Social Media Restrictions

Status: Policy Direction, Not Yet Law

Running alongside the legislative changes, the government has made two significant policy announcements in mid-2026 that are worth distinguishing clearly from binding law, since neither is yet legislated. 

  • 15 June 2026: The government announced its intention to ban social media use by children under the age of 16, adopting a broadly similar approach to Australia’s model but going further by also blocking functionality such as livestreaming and communication with strangers for under-16s. The stated target for implementation is early 2027
  • 15 July 2026: A month later, the government announced that default overnight curfews locking 16 and 17-year-olds out of social media apps between midnight and 6am would be switched on automatically, alongside default deactivation of design features intended to maximise engagement or scrolling time. The rationale given was to avoid a “cliff edge” in protection when a young person turns 16 and exits the protections that would apply to under-16s. 

Why These Measures Are Not Yet Law?

Neither of these measures is currently in force. Both would require secondary legislation or regulations to implement. Importantly, the under-16 social media access restrictions are intended to be introduced via secondary regulations under section 214A of the Online Safety Act 2023 (inserted by section 70 of the Children’s Wellbeing and Schools Act 2026), working alongside rather than relying solely upon the potential Article 8 UK GDPR consent-age powers described above. 

Organisations should treat these as a clear statement of policy direction rather than as compliance obligations to build toward on a fixed timetable while recognising that the direction of travel is unambiguous. 

What Should Organisations Do Next?

For organisations providing services likely to be accessed by children, three practical steps follow from the current state of the law: 

  1. Update DPIA and design-review templates to explicitly reference the “children’s higher protection matters” under Article 25(1A)–(1B), rather than relying on general Children’s Code conformity statements. 
  1. Monitor, rather than pre-empt, the Article 8 consultation outcome. Building technical age-verification capability now is reasonable given the clear policy direction, but organisations should avoid assuming a specific age threshold (14, 15, or 16) until regulations are laid. 
  1. Distinguish policy announcements from legal obligations in internal risk registers and client advice. The social media curfew and under-16 ban proposals are important signals for future product and compliance planning but should not yet be logged as active compliance deadlines. 

TenIntelligence Thoughts

The direction of UK policy on children’s data protection is unmistakable: greater statutory weight behind design obligations, an expanded ability to raise the age at which children can consent to data processing, and clear political appetite for further restricting children’s access to social media. 

What has changed in law so far, however, is narrower and more precise than the wider public conversation might suggest. For compliance teams, the discipline lies in tracking that difference building readiness for what is likely coming, without treating proposals as if they were already binding. 

Sahar Dies Avatar

Written by

Sahar Dies | Data Protection Specialist