OFCOM’s guidance about children’s access assessments (“CAA guidance”)
Children’s access assessments
Guidance¶
Published 24 April 2025
Contents¶
Section¶
1. Overview ............................................................................................................................. 3
2. Duties about children’s access assessments ...................................................................... 6
3. Stage 1: is it possible for children to access the service or part of it? ............................. 12
4. Stage 2: is the child user condition met? ......................................................................... 15
5. Carrying out a new children’s access assessment ............................................................ 24
Annex¶
A1. Recording the outcome of children’s access assessments .............................................. 28
A2. Case studies ...................................................................................................................... 31
Section 1 Overview¶
• carry out children’s risk assessments (for more details, see the Children’s Risk Assessment Guidance7); and • take steps to comply with the relevant safety duties protecting children (for more details, see the Protection of Children Codes8).
1 Section 4(3) of the Act. 2 As required under section 36 of the Act. 3 Section 35 of the Act defines a “children’s access assessment”; Section 37 of the Act explains the meaning of “likely to be accessed by children”. 4 Section 35(2) of the Act.
5 Information Commissioner’s Office (ICO), 2023. Likely to be accessed by children guidance. Nothing in this guidance should be taken to comment on the data protection law requirements. 6 Ofcom is required under section 52(3)(b) of the Act to produce guidance for Part 3 services to assist them with complying with their duties relating to children’s access assessments. 7 Children’s Risk Assessment Guidance 8 Protection of Children Code of Practice for user-to-user services; Protection of Children Code of Practice for search services
Figure 1: Carrying out a children’s access assessment
This guidance was originally published on 16 January 2025. This updated version was published on 24 April 2025. We have replaced references to the draft versions of the Children’s Risk Assessment Guidance and Protection of Children Codes of Practice with references to the final versions, and have updated and simplified the sub-section ‘When do services need to carry out the first children’s access assessment?’ to reflect that the original deadline of 16 April 2025 has now passed.
Section 2 Duties about children’s access assessments¶
What are children’s access assessments and what do Part 3 services need to do?¶
• to determine whether it is possible for children to access the service or a part of the service (stage 1), and • if it is possible for children to access the service or a part of the service, to determine whether the child user condition is met in relation to the service or a part of the service (stage 2).
• carry out children’s risk assessments (for more details, see the Children’s Risk Assessment Guidance 9); and • take steps to comply with the relevant safety duties protecting children (for more details, see the Protection of Children Codes of Practice10).
• there is a significant number of children who are users of the service; and/or • the service is of a kind likely to attract a significant number of users who are children.12
9 Children’s Risk Assessment Guidance 10 Protection of Children Code of Practice for user-to-user services; Protection of Children Code of Practice for search services 11 Section 35(2) of the Act. 12 Section 35(3) of the Act.
• Stage 1: is it possible for children to normally access the service? • Stage 2: is the child user condition met?
• You must complete the relevant stages of the children’s access assessment outlined in the Act. • In certain cases, your assessment must be supported by evidence.16
13 Section 35(4)(b) of the Act. 14 Section 227(1) of the Act. 15 Section 36(6) of the Act. 16 Further detail on whether you need to record evidence is set out in paragraphs 2.26-2.31 and Annex 1 of this guidance.
Figure 2: Children’s access assessments process
Source: Ofcom
Which services need to carry out children’s access assessments?¶
• User-to-user services: services on which content is generated directly by users to be uploaded or shared on that service and which may be encountered by other users;18 and • Search services: services that are, or comprise, a search engine.19
17 This may be because part of your service publishes or displays regulated provider pornographic content and is in scope of the Part 5 duties. It is not necessary to complete a children’s access assessment for a service that is only in scope of the Part 5 duties relating to regulated provider pornographic content. 18 Section 3(1) of the Act. 19 Section 3(4) of the Act.
When do services need to carry out the first children’s access assessment?¶
Source: Ofcom
Keeping a written record of children’s access assessments¶
• Ensuring that the written record is legible and in as simple and clear language as possible. • Keeping your written records in English (or for service providers based in Wales, in English or Welsh). • Ensuring you have dated your written record, reflecting when the record was made.
20 Part 1 of Schedule 3 to the Act: Timing of Illegal Content Risk Assessments and Children’s Access Assessments. 21 Paragraph 4, Part 1 of Schedule 3 to the Act. 22 Risk Assessment Guidance and Risk Profiles 23 Paragraph 4, Part 1 of Schedule 3 to the Act 24 Section 36(7) of the Act.
What happens if you do not complete a suitable and sufficient children’s access assessment?¶
Additional cases when your service will be considered ‘likely to be accessed by children’¶
25 Online Safety Enforcement Guidance 26 Sections 135(4) and 135(5) of the Act. 27 Section 37 of the Act.
• You fail to carry out your first children’s access assessment. In this case your service will be treated as likely to be accessed by children from the date by which your first children’s access assessment should have been completed.28 • Following an investigation into a failure to comply with any of the children’s access assessment duties, Ofcom determines that your service should be treated as likely to be accessed by children.29 In this case, your service is to be treated as likely to be accessed by children from the date of, or specified in, the confirmation decision given to you as the provider of the service.30
28 Section 37(4) and 37(5)(a) of the Act. Your service will continue to be considered as ‘likely to be accessed by children’ until you have completed your first children’s access assessment, and if the outcome of this first assessment is that your service is not likely to be accessed by children. 29 This refers to an investigation into a failure to comply with a duty set out in section 36 of the Act. See sections 135(4) and (5) of the Act. 30 Sections 37(6), 37(7) and 135(5) of the Act.
Section 3 Stage 1: is it possible for children to access the service or part of it?¶
31 Section 35(2) of the Act. 32 We use the term "access controls" to describe a technical mechanism(s) which prevents users who have not been age assured, or having been age assured, did not meet the requirements of the age assurance process, from accessing a service (or part of it) or certain content.
33 Section 12(6) of the Act explains that this is age verification or age estimation of such a kind and used in such a way, that it is highly effective at correctly determining whether or not a particular user is a child. 34 Our draft Protection of Children Codes are discussed at Volume 5 of our May 2024 Consultation. The draft Code for U2U services is published as Annex 7 to our May 2024 Consultation. We will update this guidance with references to final versions of our Protection of Children Codes when they are published. 35 Guidance on highly effective age assurance for Part 3 services
Figure 4: Overview of Stage 1 - Can children normally access my service?
Source: Ofcom
Services that deploy highly effective age assurance and have effective access controls meaning children cannot normally access the service or part of it¶
All other services¶
• You do not use any kind of age assurance on your service. • You use age assurance to prevent children from accessing the service or part of the service, but it is of such a kind that is not capable of being highly effective. For example, you rely solely on self-declaration, general contractual restrictions, or payment methods which do not require a user to be over 18. • The age assurance is not used or implemented in such a way that it is highly effective at correctly determining whether or not a particular user is a child. To be considered highly effective, the age assurance should be technically accurate, robust, reliable, and fair. • The age assurance does not ensure that children are not normally able to access your service. We expect service providers to identify and take appropriate steps to mitigate against methods of circumvention that are easily accessible to children, and where it is reasonable to assume that children may use them. • You use highly effective age assurance on your service but still allow children to access the service, or certain parts of the service. For example, your service uses highly effective age assurance to limit children’s access only to certain features, functionalities, communities or content, or if you do not use access controls alongside the age assurance process.
Section 4 Stage 2: is the child user condition met?¶
• there is a significant number of children who are users of the service; and/or • the service is of a kind likely to attract a significant number of users who are children.36
36 Section 35(3) of the Act. 37 The Act does not specify a particular order or sequence in which the two criteria of the child user condition should be considered. The approach we present above is a suggested approach, and you may wish to consider the criteria in an order that is most appropriate for your service.
Figure 5: Stage 2 of the children’s access assessment (the child user condition) and next steps
Source: Ofcom
Significant number of users who are children¶
38 Section 227 of the Act says that a UK user of a service means an individual who is in the UK. It also makes clear that a user does not need to be registered to use the service in question to be counted as a user for the purposes of determining whether there is a significant number of UK users. 39 Section 35(4)(a) of the Act. 40 Section 1(3)(b)(i) of the Act. Note that conversely, self-declared age data may be relevant for establishing that the child user condition is met, as users who declare that they are children are likely to be children. 41 See Section 3.
• Self-declaration of age: If you allow users to self-declare their age, you should not rely on this data alone to conclude that you do not have a significant number of users who are children, as the Act states that measures which require users to self-declare their age (without other methods) are not to be regarded as age assurance.42 • Online payment methods: You should not rely on data from online payment methods which do not require a person to be over the age of 18, for example debit cards or any other card where the card holder is not required to be 18.
• User traffic data from only one type of device (desktop, mobile, or tablet): You should not rely on data from only one type of device if your service can be accessed using multiple different types of devices. • Data that only counts registered users: if your service allows access by unregistered users, you should not rely only on data about registered users. This data source may not be a reliable indicator of the number of children on your service.
Services of a kind likely to attract a significant number of users who are children¶
42 Section 230(4) of the Act.
advertising, in-service payments or other ways), it is reasonable to assume that your service is likely to attract a significant number of users who are children.
Factors to consider when assessing whether the child user condition is met¶
43 See for example Annex 3 of Ofcom’s Age Assurance and Children’s Access Statement. 44 Services may consider a range of functionalities, as illustrated in the Children’s Risk Profiles included in the Children’s Risk Assessment Guidance for content harmful to children. You do not need to consult the Risk Profiles to make this decision as risk is not a consideration at this stage. The Risk Profiles, however, may be a useful resource.
Table 6: Factors to consider when assessing whether the child user condition is met¶
Your service has the potential to benefit children¶
• Providing educational value for children. • Entertaining or allowing children to be creative.
• Enabling children to express themselves. • Facilitating the sharing of advice and support between children. • Providing a supportive environment for child users, where some may feel a sense of belonging. • Facilitating children connecting with others, including to build friendships or relationships.
The content on your service appeals to children¶
Table 7: Content that appeals to children¶
45 By esports, we mean electronic sports, often in the form of multi-player games with the ability to communicate between players.
The design of your service appeals to children¶
Children form part of your commercial strategy¶
consider their business model, marketing strategy and growth plan when thinking about their commercial strategy.
Additional evidence¶
• Evidence from internal sources, including information set out in your terms of service or publicly available statements; the number of complaints (if any) that you have received relating to children accessing your service (e.g., reports flagging users below the age permitted on your service; and any actions taken previously in connection with children to enforce your terms, for example the number of accounts previously removed of users below the age permitted on your service). • Evidence from external/third party sources demonstrating that your service is not likely to attract children. This may include market research and quantitative evidence from third parties that track child media consumption, for example media trackers.
46 Marketing your service on other services that are targeted at children, through AdTech providers in the open display market, is also relevant to this assessment.
Recording the outcome¶
Section 5 Carrying out a new children’s access assessment¶
Annual assessment¶
Circumstances that trigger a new assessment¶
• before making any significant change to any aspect of the service’s design or operation to which such an assessment is relevant. • in response to evidence about reduced effectiveness of age assurance. • in response to evidence about a significant increase in the number of children using the service.
47 See Protection of Children Code for user-to-user services. 48 Sections 36(3)and (4) of the Act. 49 Sections 36(3) of the Act.
Before making any significant change to any aspect of your service’s design or operation¶
In response to evidence about reduced effectiveness of age assurance¶
50 Section 36(4)(a) of the Act. 51 Section 36(4)(b) of the Act.
• The reduced effectiveness of the technical operation of age assurance methods or processes. The reduced effectiveness of the age assurance may potentially affect a service’s ability to correctly determine whether or not a particular user is an adult or a child. • The reduced effectiveness of access control methods which prevent children from gaining access to a service. The reduced effectiveness of the access control method may potentially affect a service’s ability to prevent children from normally being able to access the service.
Table 8: Examples of reduced effectiveness of age assurance¶
In response to evidence about a significant increase in the number of children using the service¶
52 Section 36(4)(c) of the Act.
53 If a service has highly effective age assurance and blocks under 18s from accessing, then any increase in general users is not relevant.
A1 Recording the outcome of children’s access assessments¶
Approach¶
Stage 1: Can children normally access the service or part of it?¶
Stage 2: Is the child user condition met?¶
Timing¶
54 Section 36(7) of the Act. 55 See Guidance on highly effective age assurance for Part 3 services.
Template¶
This template may assist you in carrying out a children’s access assessment. You are not required to use this template, but it may help guide you through the process.
A2 Case studies¶
SME retirement forum¶
A micro-business sets up a forum where users can discuss retirement plans.
Such a service would not be targeted at children, and this would likely be reflected in its business plan and marketing, therefore the service may conclude that children do not form part of the service’s commercial strategy. The service provider may also consider that the service does not provide a benefit to children, that the content would not appeal to children, and that the design is not attractive to children. The content on the forum is about retirement plans and would therefore appeal to adults. The service provider in this case may therefore conclude that the service is not of a kind likely to attract a significant number of users who are children.
Such a service may also have user data to suggest that there are not a significant number of children on the service. For example, the service’s total user base is 5,000 UK monthly users. It has never deleted any accounts due to reports of the user being a child, or received complaints or reports about users who are children on the service.
The provider concludes that the child user condition is not met. The provider records the date, the outcome, the steps taken, and the evidence used to justify their conclusion.
Community forum¶
A service is offering an online community forum on travel, building friendships and overcoming challenges. The service is targeted at adult users who are 40 and over. The articles and discussion on the forum relate mainly to travel for women over 40. The other content on the forum discusses new job opportunities for women seeking a career change. Such a service would not be targeted at children, and this would be reflected in the content of the service. The service provider may also consider that the service does not provide a benefit to children, that the design is not attractive to children, and the advertising on the service is targeted at an older adult demographic. The provider considers that the size of its user base allows it to profile it accurately using internal information. It may analyse a range of user data, which suggest that existing users are highly unlikely to be children. It may also look at publicly available statistics on children’s access to services similar to its own. The service also considers whether there have been any reports of users being children, or any under-age accounts being blocked. It has never deleted any accounts due to reports of the user being a child, or received complaints or reports about users who are children on the service.
The provider concludes that the child user condition is not met. The provider records the date, the outcome, the steps taken, and the evidence used to justify their conclusion.
Sport service¶
A service is offering an online site for information and discussion on local sporting activities. The service does not have an age limit on users, but it targets senior citizens in London. Such a service would not be targeted at children, and this would be reflected in the content of the service. This service provides information to users on sports and other social activities across London targeted at senior citizens. The service provider may also consider that the service does not directly benefit children. In addition, although the service has particular features that children like to use, given the nature of the content and the purpose of the service, the provider may find that it is unlikely that the service will appeal to children. The provider may also consider the marketing strategy for the site. They target an older demographic only and advertising data reflects engagement with adult users. Consequently, the provider may conclude that children do not form part of their commercial strategy. The provider concludes that the child user condition is not met. The provider records the date, the outcome, the steps taken, and the evidence used to justify their conclusion.
Large dating service¶
A large dating service states in its terms of service that users must be over 18 and asks users to declare their age during registration. The service states publicly that it is not targeted at children and it does not have children on its service. The service provider is initially confident that its service will not be considered ‘likely to be accessed by children’. As the service does not have highly effective age assurance in place, the provider moves on to consider the child user condition. The provider reads through the guidance provided by Ofcom. The provider considers the list of factors provided across both criteria of the child user condition. The provider decides to start their assessment with the second criterion (whether the service is “of a kind likely to attract a significant number of children”). The provider has reviewed available evidence and information on whether children are attracted to their service or similar ones. Publicly available evidence suggests that children, particularly older children, are interested in making connections and building relationships. Research and media reports indicate that this is part of what makes a dating site appealing to children. The provider also acknowledges that some of their sites’ functionalities, such as the ability to create a user profile and to direct message other users are functionalities that are attractive to children. The provider is also aware of news reports of children who have gained access to similar services. Despite the provider’s intention, terms of service, and commercial strategy, it is evident that services similar to theirs appeal to children. In addition, the provider has also received complaints about children using the service. The provider has reason to believe that some children have given false ages. In light of this information and recognising that ‘significant’ is context-specific and can mean a relatively small number, the provider concludes that the child user condition is met. The provider records the outcome. The provider does not need to record any evidence. The provider moves on to the children’s risk assessment.
Search engine¶
A search engine provides links to other websites and information. The service’s publicly available statement does not have a minimum age requirement for users. No account is needed to access the service. However, there is an option to create an account. The provider reads through the guidance provided by Ofcom. Under stage 1 of the assessment, the provider notes that children can normally access the service. This is because the service does not have highly effective age assurance in place. The provider moves on to stage 2 of the assessment. In order to complete the assessment swiftly, the provider decides to start with the second criterion (whether the service is ‘of a kind likely to attract a significant number of children”). It is publicly known that the service is used by children. The provider also recognises that their service provides benefits from children, for example for educational and entertainment purposes. The provider concludes that the child user condition is met. The provider records the outcome. The provider does not need to record any evidence. The provider moves on to the children’s risk assessment.