The protection of children online, including the safeguarding of their personal data, has emerged as a key regulatory focus in the UK, with the Government facing sustained pressure to address concerns about children’s safety online.[1] Recent developments have added further momentum – in particular, Australia’s recent prohibition on social media use by under-16s has intensified policy discussions, in the UK and more widely, around the potential introduction of similar restrictions.[2] At the same time, regulators are adopting a more assertive enforcement approach on age assurance and privacy by design and default.

Two recent enforcement decisions by the UK Information Commissioner (“ICO“) concerning failures to safeguard children’s personal data online, highlight a clear regulatory priority to strengthen the protection of children’s information in the digital environment.

In February 2026, the ICO announced that MediaLab.AI, Inc. (“MediaLab“), owner of image, meme and GIF sharing platform Imgur, had been fined £247,590 for failing to use children’s personal information lawfully. This was closely followed a fine of £14.47 million issued against social media company Reddit, Inc. (“Reddit”), for similar children’s privacy failings. 

In both decisions, the ICO’s message is clear – where a service is accessible to children, organisations must implement measures to adequately protect children from harm, regardless of whether that service is intended for use by children.

ICO enforcement decisions

On 5 February 2026, the ICO fined MediaLab £247,590 for failing to use children’s personal information lawfully. The penalty followed an ICO investigation that found MediaLab had allowed children to use Imgur without putting in place the basic safeguards required under UK data protection law. As a result, the ICO investigation found that children were exposed to harmful content on the platform.

Less than three weeks after the MediaLab decision, on 24 February 2026, the ICO imposed a significantly larger fine of £14.47 million on Reddit for similar failings giving rise to risks of harm to children.

  • No adequate age assurance measures in place

In the MediaLab decision, Imgur’s terms of service permitted children under 13 to use the platform with parental supervision. However, the ICO found that MediaLab did not implement any form of age assurance to identify users’ ages, nor did it have mechanisms in place to obtain parental consent for the relevant processing.

While Reddit’s terms of service did expressly prohibited access by children under 13, the ICO found that it had not implemented effective systems to verify or assess users’ ages, meaning the platform was openly accessible to all visitors. Although those users creating an account in order to post content or view material designated for adults were asked to confirm that they were over 18, this relied solely on self‑declaration. In the absence of any further verification, the ICO concluded that these measures were inadequate, noting that they were too “easy to bypass”.

  • No lawful basis for processing under 13’s personal information

The ICO found that both MediaLab and Reddit unlawfully processed the personal data of children under 13, in breach of Article 5(1)(a) UK GDPR. In particular, the ICO found that consent could not be relied upon as the lawful basis for processing the personal data of children under 13, where an organisation had neither ensured that consent was given or had been authorised by a person with parental responsibility, nor taken reasonable steps—taking into account available technology—to verify that such consent had been obtained.

  • Failure to carry out a DPIA

The ICO’s decisions against both MediaLab and Reddit also took a consistent approach in relation to the failure to carry out a data protection impact assessment (“DPIA”) in accordance with the requirements of Article 35(1) UK GDPR. In both decisions, the ICO found that the companies were engaged in processing that was likely to result in a high risk to children’s rights and freedoms—particularly given the scale of child users and the nature of the platforms (including profiling, advertising, and exposure to potentially harmful content).

The ICO rejected arguments that a DPIA was unnecessary because the services were “not aimed at children”, emphasising that the obligation applies where a service is likely to be accessed by children, regardless of intended audience.

Children’s privacy – the wider regulatory context

These decisions make clear that reliance on self‑declaration or terms of service alone will not meet regulatory expectations where children may be exposed to harmful content. In March 2026, the ICO reinforced this position in an open letter, calling on social media and video sharing platforms to implement robust, technology‑based age assurance measures.

The decisions also sit within a broader regulatory framework. Section 81 of the Data (Use and Access) Act 2025 (“DUAA”) amends Article 25 UK GDPR to require online services to incorporate “children’s higher protection matters” into data protection by design and default, with adherence to the Age-Appropriate Design Code to assist with compliance. The ICO’s Age-Appropriate Design Code (commonly referred to as the “Children’s Code“) sets out 15 flexible standards for services likely to be accessed by under‑18s, including child‑centred design, DPIAs, clear and age-appropriate privacy notices, and ‘high privacy’ settings by default. Its scope is broad, extending beyond child‑targeted services to all “information society services likely to be accessed by children”.

The developing legislative landscape in this area also raises the risk that organisations will fall within the scope of both the GDPR/UK GDPR and other European legislation – each with different enforcement rules and competent authorities. In the UK, the Online Safety Act 2023 – regulated by Ofcom – requires organisations to protect children from harmful content. A joint ICO–Ofcom statement indicates increasing regulatory coordination on age assurance, signalling a more aligned and potentially coordinated enforcement approach.

At the EU level, the Digital Services Act (DSA) requires platforms to take measures to safeguard minors on their services. The European Commission has recently made a preliminarily finding that Meta’s Instagram and Facebook are in breach of the DSA for failing to diligently identify, assess and mitigate the risks of minors under 13 years old accessing their services. Similar to the two ICO decisions, despite Meta’s terms and conditions setting the minimum age to access Instagram and Facebook safely at 13, the Commission found that the measures put in place by Meta to enforce these restrictions did not adequately prevent minors under the age of 13 from accessing their services nor promptly identify and remove them, if they already gained access.

The European Commission has also published its Recommendation, which sets out a common framework for EU-wide age verification, requiring Member States to make an age verification solution available—either standalone or via the European Digital Identity Wallets—by 31 December 2026. Organisations operating across European markets will increasingly face not only UK regulatory expectations, but also EU-wide requirements enforced at the Member State level.

Beyond the EU, the G7 has now agreed a common approach to protecting children online, signalling growing international alignment. The agreement emphasises that child safety should be embedded into digital services from the outset, supported by effective age assurance.

What should organisations be doing about children’s personal data now?

In light of the recent enforcement actions and the regulatory direction of travel, organisations should consider and document the following practical steps:

  • Carry out a “likely to be accessed” assessment. Determine whether children are likely to access the service by considering factors such as user base, the appeal of content, whether children are known to access similar services, and any existing complaints received from underage users. Organisations should document and continue to update this assessment carefully.
  • Implement proportionate age assurance measures. If the service is likely to be accessed by children, organisations should not rely on a self-declaration tick-box. Instead, age estimation, digital identity verification, or other robust methods proportionate to the level of risk on the platform should be considered. The UK ICO’s age assurance advice for the Children’s Code provides further guidance on how to decide on the most appropriate data protection compliant tool.
  • Conduct a child-focused DPIA. In both the Reddit and MediaLab fines, the ICO was clear that DPIAs are mandatory for businesses offering online services to anyone under 18. The obligation applies where a service is likely to be accessed by children, regardless of intended audience. The DPIA should assess how children’s data is collected, used, and shared, and should identify and mitigate potential harms. Where harm cannot be mitigated, processing should not continue as planned.
  • Review the lawful basis for processing children’s data. When relying on consent as the lawful basis for the processing pf personal data for children under the age of 13, consent must be given by a parent or carer. Reasonable steps—taking into account available technology— must be taken to verify that such consent had been obtained. Organisations should ensure that there is a valid lawful basis in place for every age group that may access the service.
  • Apply the Children’s Code standards by age or apply them to all users by default. Organisations can either use proportionate age assurance to tailor safeguards by age or apply the full protections of the Children’s Code to all users as a baseline. Where there is no reliable age information of users, the UK ICO expects organisations to apply the Children’s Code standards to everyone.
  • Engage with the evolving regulatory framework. The UK ICO is working closely with Ofcom to coordinate efforts on children’s safety. Organisations should monitor developments from both of these regulators and ensure their compliance strategies address obligations under both data protection law and online safety legislation.

In summary

The Reddit and MediaLab fines mark a step change in the ICO’s willingness to enforce children’s data protection rules against services that are not specifically designed for children. The message is clear: businesses must explore possible interactions with children’s data. With the ICO now explicitly focusing its attention on platforms that primarily rely on self-declaration, large commercial organisations should act now rather than wait to see if they are discovered.

Children’s data protection is not a niche compliance issue to be dealt with only for children’s apps and games. It is now a mainstream obligation for any organisation whose services children can access.


[1] For example, the Government has recently announced its plans to require tech firms to activatebuilt-in features or implement technical solutions to detect and block explicit messages, This follows the Government’s report on Parental support for a social media minimum age of 16, which states that of the parents who responded “89% supported “a legal requirement for social media services to have a minimum age of access”. Of these, 96% agreed to some extent that social media services should have a minimum age of access of at least 16 and should not be accessible to any children under that age.”

[2] It has been reported that a speech from the UK Prime Minister, which will include a new policy on social media, is planned for next week – see:  Keir Starmer preparing to announce social media limits for children – BBC News.