MustInformation Commissioner's Office (ICO), the data-protection regulator

Privacy information for children

Privacy information a child can understand, explaining what a school-run app or portal does with children's data. Any organisation that runs an online service children are likely to use must provide it, and a public information website alone does not count.

Check this on my website

Who it applies to

Published on
Every school and trust website
School type
Academies and maintained schools
School stage
All stages, from early years to sixth form
Only applies to
Where the school or trust itself provides an online service likely to be accessed by children (portals, apps); a public information website alone is not treated as such a service
Does not apply to
No school types are excluded

When is it due?

Renewal
No fixed date

The official sources set no renewal date. Keep it accurate whenever it changes.

What's needed

Publish a short, child-friendly explanation of how pupil data is used for any website service children use, linked beside the main privacy notice.

What it must contain

4 parts
  • Says what the service does with children's dataMust
  • Gives children the privacy information in clear, plain language they can understandMust
  • Provides the privacy information in a format suitable for parentsShould
  • Lets children or parents choose which version of the privacy information they seeShould

What the official sources say

Set out in 1 official source:

Children's code: standard 4 transparency

Version 2026-09-13

  • “The controller shall take appropriate measures to provide any information referred to in Article 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject the information may be provided orally, provided that the identity of the data subject is proven by other means.”

    Must§ 'Why is it important?' section, block quote of GDPR Article 12 (introduced by 'Article 12 of the GDPR requires you to provide children with this information in a way in which they can access and understand it')

  • Firstly you need to provide the privacy information set out in Articles 13 and 14 in a clear and prominent place on your online service. You should make this information easy to find and accessible for children and parents who seek out privacy information.

    Should§ 'How can we make sure that we meet this standard?', 'Provide clear privacy information'

Show 3 more from this source
  • Provide full privacy information as required by Articles 13 & 14 of the GDPR in a format suitable for children within this age group. Allow children to choose between written and video/audio options.

    Expected§ 'Tailor your information to the age of the child', recommendations table, row 10-12 (rows 13-15 and 16-17 carry an equivalent sentence)

  • Provide full privacy information as required by Articles 13 & 14 of the GDPR in a format suitable for parents.

    Expected§ 'Tailor your information to the age of the child', recommendations table, rows 0-5, 6-9 and 10-12 (identical sentence in each)

  • You should make all versions of resources (including versions for parents) easily accessible and incorporate mechanisms to allow children or parents to choose which version they see, or to down-scale or up-scale the information depending on their individual level of understanding.

    Should§ 'Tailor your information to the age of the child'

Questions schools ask

Does every school have to publish the privacy information for children?

The official sources we check set no requirement for academies. The official sources we check set no requirement for maintained schools. It only applies to where the school or trust itself provides an online service likely to be accessed by children (portals, apps); a public information website alone is not treated as such a service.

When does the privacy information for children need to be published?

Renewal: No fixed date. The official sources set no renewal date. Keep it accurate whenever it changes.

What must the privacy information for children include?

Says what the service does with children's data; Gives children the privacy information in clear, plain language they can understand; Provides the privacy information in a format suitable for parents; Lets children or parents choose which version of the privacy information they see.

Where does the requirement for the privacy information for children come from?

It is set out in Children's code: standard 4 transparency.

Changes to the official sources

The sources for this item do not publish dated change notes. Their current versions are listed above.

We last checked these sources on 21 September 2026.

Is this on your school's website?

We check your site the way an inspector or a parent would find it: page by page, against the official wording of each requirement. If it's there, you get the page and the words we found. If it isn't, you get every place we looked.

Check this one requirement free, or scan your whole site against every requirement.

Any format works: .co.uk, .sch.uk, .org.uk or .com.

We email the result here. Privacy notice

Free: check up to 3 requirements a year, results by email. Paid: every requirement checked, re-checked after you fix it, and monitored all year.

Or scan your whole site free →
Official wording that does not apply to schools (5)
– While schools are not Information Society Services (ISS) and are not in scope of the Children’s code, edtech providers may be in scope of the code.
The Children's code and education technologies (edtech)§ 'At a glance' list, second bulletVersion 2026-09-13ico.org.uk ↗
The code applies to edtech services that are likely to be accessed by children on a direct-to-consumer basis. These are services which are directly available to users on open platforms, such as the web or via an app store.
The Children's code and education technologies (edtech)§ 'When does the code apply to edtech service providers?', first paragraphVersion 2026-09-13ico.org.uk ↗
This code applies if children are likely to use your service. A child is defined in the UNCRC and for the purposes of this code as a person under 18.
Children's code: services covered by this code§ 'When are services ‘likely to be accessed by children’?', first paragraphVersion 2026-09-13ico.org.uk ↗
The code does not apply to edtech providers where all the following criteria are met: – the edtech service is not accessed on a direct-to-consumer basis; – the edtech provider only processes children’s personal information to fulfil the school’s public tasks and educational functions (as determined by the school); and – the edtech provider acts solely on the instruction of the school, and does not process children’s personal information in any other form beyond these instructions.
The Children's code and education technologies (edtech)§ 'When does the code not apply to edtech service providers?', criteria listVersion 2026-09-13ico.org.uk ↗
This code does not apply to websites or apps specifically offering online counselling or other preventive services (such as health screenings or check-ups) to children. This is because s123 scopes out ‘preventive or counselling services’. However, more general health, fitness or wellbeing apps or services are covered.
Children's code: services covered by this code§ 'What types of online services are not ‘relevant ISS’?', 'Preventive or counselling services'Version 2026-09-13ico.org.uk ↗

Official sources last checked 21 September 2026 · register version 1.0.4