ICO fines Reddit £14.47m
& raises the bar on children’s age assurance
The UK ICO found Reddit unlawfully processed children’s personal information and failed to implement robust age assurance. The decision underscores that self-declaration is not enough where children are at risk.
24 Feb 2026
Primary source: ICO enforcement news
Age assurance
Robust verification expected for services likely accessed by children
7 min
What product and privacy teams should do now
✍️ DPO Advisors
⏱️ 7 min read
ICO
CHILDREN
AGE ASSURANCE
What the ICO decided
On 24 February 2026, the UK Information Commissioner’s Office announced a £14.47m fine against Reddit. The ICO found that Reddit failed to process children’s personal information lawfully and did not apply robust age assurance, despite minimum age terms. The ICO also emphasized that relying on self-declaration presents risks where children can easily bypass controls.
🔍 What “good” looks like for children’s privacy controls
Controls
📊 Likely supervisory focus (qualitative)
Age assurance and children’s data: operational requirements
Children’s privacy compliance is not a single feature toggle. It is a set of end-to-end controls: how you detect age, what defaults apply, how risky features are restricted, and how you evidence decisions and outcomes.
🔑 Core principle: if children are likely users, you must be able to demonstrate that your controls prevent exposure and reduce data use — not just that your terms prohibit minors.
📱 A practical age assurance flow
- 🔒
Choose an assurance method that matches the harm. The higher the risk, the stronger and harder-to-bypass the method should be.
- 🧾
Do the DPIA early. Include children-specific harms, mitigations, and test cases for bypass attempts.
- ⚙️
Set privacy-by-default. Limit profiling, sharing, and discoverability for minors by default.
- 🧪
Test controls like security. Red-team age gates and maturity restrictions across devices and channels.
- 📋
Keep evidence. Logs, decisions, and QA outcomes should be available for regulator review.
Four concrete actions to take now
Use this enforcement outcome as a benchmark. If your platform is likely to be accessed by children, align legal basis analysis, product controls, and evidence to regulator expectations.
🧭
🔐
⚙️
📎
⚠️ Three lessons for privacy teams
Need a children’s privacy readiness review?
DPO Advisors can help you assess age assurance options, update DPIAs, and translate the Children’s Code expectations into testable product requirements.
