ICO Fines Reddit £14.47m: A Clear Warning on Children’s Data

Share this Article:

The Information Commissioner’s Office (ICO) has issued a £14.47 million fine to Reddit for unlawfully processing children’s personal information.

The regulator found serious failings in how the platform protected children’s data, particularly around age assurance and risk assessment. The timing is notable. There is renewed regulatory focus on children’s privacy, and the Data Use and Access Act 2025 (DUAA) introduces additional protections for children using online services.

The direction is clear: if children are likely to access your service, their data must be treated differently and more carefully.

So What Went Wrong?

The ICO’s investigation found that Reddit:

  • Did not have robust age assurance measures in place until July 2025
  • Relied on self-declaration of age when users signed up
  • Failed to carry out a Data Protection Impact Assessment (DPIA) focused on risks to children before January 2025
  • Processed the personal data of under-13s without a lawful basis

Although Reddit’s terms prohibited children under 13 from using the platform, the ICO estimated there were still significant numbers of under-13s accessing it. Without effective age checks, the company could not demonstrate it had a lawful basis for processing their data.

Why Age Assurance Matters

If your service sets a minimum age, you must take meaningful steps to enforce it.

The ICO has signalled that simply asking users to tick a box confirming their age is unlikely to be sufficient where there is risk to children. Age assurance measures need to be proportionate to the level of risk posed by the service.

Organisations essentially have two choices:

  • Apply the full protections of the Children’s Code to all users, or
  • Use effective and proportionate age assurance tools to tailor protections by age

Where under-13s are not permitted to use a service, access must be actively prevented and not just discouraged in the Terms and Conditions.

The Importance of DPIAs

A key failing in this case was Reddit’s failure to carry out a Data Protection Impact Assessment focused on children before January 2025.

Where services are likely to be accessed by children, and particularly where behavioural advertising or exposure to user-generated content is involved, a DPIA will often be required.

This is not a box-ticking exercise. A DPIA should:

  • Identify specific risks to children
  • Assess the likelihood and severity of harm
  • Set out mitigation measures
  • Demonstrate that children’s best interests have been considered

Without this documented assessment, organisations may struggle to evidence compliance.

Practical Questions for Organisations

If your service is accessible to children, you should be asking:

  • Do we actually know the age of our users?
  • Is our age assurance method proportionate to the risks on our platform?
  • Have we carried out a DPIA that specifically considers children?
  • Are our privacy notices genuinely understandable to younger users so that a ten-year-old can understand what happens to their data?
  • Are we collecting more data than we need?
  • Are we profiling or advertising to under-18s in a compliant way?
  • Are our privacy settings configured to high protection by default for younger users?
  • Should we be offering parental controls to help parents oversee or limit how their child’s data is used?

If you cannot confidently answer those questions, now is the time to review your approach.

Need Support Reviewing Your Approach?

If your organisation provides online services that may be accessed by children, it is essential that your age assurance and DPIA processes measures are robust.

At Privacy Helper, we provide expert support to review your current framework, assess risk, update policies and implement practical compliance measures aligned with ICO expectations in a clear, straightforward way.

Contact us today to discuss how we can help you strengthen your approach to children’s data protection.

About the Author:

Explore More Articles