Skip to main content
Skip to main content
EdPsych Connect

Children's Code statement

How EdPsych Connect applies the fifteen standards of the Information Commissioner's Office Age Appropriate Design Code, often called the Children's Code.

Why this matters

EdPsych Connect supports children and young people, their families, and the professionals who work with them. Children are not simply small adults in data-protection terms; the Children's Code sets fifteen standards that online services likely to be accessed by a child must meet in order to comply with United Kingdom data protection law.

This page is a public summary of our position against each standard. The controlled record, including evidence, owners and review dates, is held at docs/compliance/CHILDRENS_CODE_SELF_ASSESSMENT.md.

Scope and audience

The platform is used by registered educational psychologists and other qualified professionals, by schools, multi-academy trusts and local authorities, and by parents and carers acting on behalf of a child. Where a feature is likely to be accessed directly by a child or young person, we apply the Children's Code standards in full, regardless of whether the account is held by an adult, a child, or by a professional on a child's behalf.

Our position against each of the fifteen standards

Standard 1

Best interests of the child

Every design, policy and data-processing decision is assessed first against the best interests of the child, with evidence recorded on file.

Standard 2

Data protection impact assessments

A Data Protection Impact Assessment is produced, signed off and reviewed annually for every processing activity likely to involve a child.

Standard 3

Age appropriate application

We apply an age-appropriate approach across the platform. Adult-only administrative surfaces are kept behind authenticated staff accounts.

Standard 4

Transparency

Privacy information is published in clear, age-appropriate language at the point at which data is collected, with layered explanations for younger users.

Standard 5

Detrimental use of data

We do not process children's data in ways that have been shown to be detrimental to their wellbeing or that go against published codes of practice.

Standard 6

Policies and community standards

Our published terms, privacy, safeguarding and community standards are applied in practice, and enforcement is evidenced in audit logs.

Standard 7

Default settings

Every setting that affects a child is high-privacy by default. Profile visibility, direct messaging and discovery are all closed until an adult explicitly opens them.

Standard 8

Data minimisation

We collect and retain only the minimum personal data required for the specific service the child or the commissioning professional has requested.

Standard 9

Data sharing

Children's data is not shared other than with lawful purpose, with a documented lawful basis, and with a written data-processing or data-sharing agreement.

Standard 10

Geolocation

Geolocation is not used for any child-facing feature. Technical telemetry is limited to what is needed for information security.

Standard 11

Parental controls

Where parental controls exist, the child is given an age-appropriate notice that the control is active. Covert monitoring is not supported.

Standard 12

Profiling

Profiling that could have a detrimental effect on a child is switched off by default and is never used to target advertising or cross-context marketing.

Standard 13

Nudge techniques

We do not use nudge techniques to lead children into weakening their privacy, extending screen time, or accepting settings that are not in their best interests.

Standard 14

Connected toys and devices

The platform is not designed for connected toys and does not integrate with consumer connected-device ecosystems.

Standard 15

Online tools

Age-appropriate tools are available for children to exercise their data-protection rights, including requesting access to, and deletion of, their data.

How we evidence conformance

  • A Data Protection Impact Assessment covers every activity likely to involve a child.
  • The Record of Processing Activities names each processing activity, its lawful basis, its retention schedule, and the subprocessors involved.
  • High-privacy defaults are enforced in code, and a release gate test fails the build if any child-facing setting is shipped as open by default.
  • Every member of staff completes annual data-protection and safeguarding training. Records are held for seven years.
  • The self-assessment is reviewed at least once a year and on every material change to the platform.

What we do not do

  • We do not profile children for advertising, marketing or cross-context personalisation.
  • We do not use children's data to train external large language models.
  • We do not use geolocation in child-facing features.
  • We do not use nudge techniques to weaken a child's privacy settings.
  • We do not share children's data with third parties other than under a written agreement with a lawful basis.

Talk to us

If you are a child, a parent or a carer and you have a question about how we use a child's data, please contact our Data Protection Officer at dpo@edpsychconnect.com.

For the full privacy picture, see our Privacy Policy and our Cookie Policy.