What is Age-Appropriate Design Code, and why All Digital Services Must Know It?

In the age of information, data is a currency; preserving data privacy is arguably a right. Measures are already in place to inform users about the data collection policies of online services they use, as well as have a say in how much data they’re willing to collect. However, further measures are now set in place to maximize the data protection impact to keep in mind the interests of young people

The age appropriate design code is a set of regulations meant to do just that. The aim of the code is to put the onus on developers to refrain from unscrupulous data-gathering practices, whenever there’s a chance their service will be used by minors. This is a step forward in general data protection, and while it’s, for now, regulatory rather than legally binding – it does introduce a new set of standards that will likely pave the way to subsequent laws.

What Is The age-appropriate design code?

The code is essentially a set of data protection best practices, formulated as 15 standards which are somewhat flexible. It calls all kinds of digital service developers to keep their data collection methods set to high privacy, whenever their service is likely to be used by children (even if they’re not the main audience). It also assigns levels of risk to different types of services, and it calls for these principles to become default settings rather than presenting them to the end user as options.

The application of the age-appropriate design code will be monitored by the Information Commissioner in the United Kingdom. It was implemented late in 2020, with a transition period of one year. Similar initiatives are underway worldwide, such as the California design code bill (CA Kids code) which was unanimously approved in 2022. This statutory code was created from an amendment to the Data Protection Act in 2018 and it derives from DGPR – meaning that digital services which already comply with this protocol shouldn’t have to worry about making additional changes.

What Does The Code Require?

The code also restrains the use of nudge techniques that might trick child users into divulging their personal data, as well as carrying out minimal data processing on all data retrieved from all users who are minors of age. Its application hinges on an age assurance principle, meaning that all users identified as minors should get access to a user experience that defaults to high privacy.

Whenever an organization needs to gather data from their users as part of the actual service they provide, they need to effectively demonstrate how the collected data indeed serves a direct and specific purpose. Moreover, they should keep all data collected from minors to a minimum, as well as refrain from sharing the data with third parties or using them as part of profiling techniques. Additionally, it establishes that geolocation services should be disabled by default whenever the user of the service is a minor of age and, minors should be informed when their experience is being monitored by any existing parental controls system.

Who Does The Code Apply To?

The code applies not only to social media websites but to all sorts of digital services. A simple rule of thumb to keep in mind is that any online service that collects any type of data from its users is likely to be encompassed by this initiative. All organizations operating in the digital space will therefore need to accommodate these guidelines sooner than later, in order to minimize the chances of subsequent regulatory actions.

This includes online games, social media platforms, apps, and websites in general. The aim is to provide a risk-based approach encompassing the entire digital world – so all businesses that operate in this space will need to keep the appropriate design guidelines in consideration, going forward.

How Is The Code Implemented?

The code does not specifically tell organizations how they should go about implementing its principle. The actual implementation is up to the developers, who are expected to find the most effective and least intrusive possible way to perform age verification – and supply all visitors under 18 years old with a version of their services that conforms to age-appropriate design. This can be tricky in some situations, since verifying user age can in itself lead to the collection of sensitive data such as photographs and identification documents – which would go very much against the principles being upheld.

jpcache