UK GDPR + DPA 2018 relationship
UK GDPR is the post-Brexit equivalent of EU GDPR (essentially identical substantive obligations). The Data Protection Act 2018 supplements UK GDPR with UK-specific provisions: law enforcement processing, immigration exemption, narrower lawful bases in some cases. Koydo follows UK GDPR as the primary framework + DPA 2018 where applicable.
ICO Children's Code (Age Appropriate Design Code)
The ICO's Age Appropriate Design Code applies to online services likely to be accessed by children. Koydo's K-12 surfaces fully comply: data minimization, no profiling for marketing, default high privacy settings, no nudge techniques, parental controls available + accessible.
What UK-specific contracts look like
UK K-12 + university contracts use the same Article 28 DPA structure as EU contracts. UK-to-EU + UK-to-US data transfers use the UK International Data Transfer Agreement (IDTA) or the EU SCCs with UK addendum — both are valid post-Brexit.
ICO incident notification
UK GDPR requires notification to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of a breach. Koydo's commitment: notify UK controllers within 48 hours of confirmed material breach so controllers have 24+ hours to notify the ICO under their statutory duty.
Age verification + parental consent
UK GDPR sets the digital age of consent at 13 (DPA 2018 confirmed; could rise to 16 by amendment). Koydo applies COPPA-equivalent verifiable parental consent for all UK learners under 13, regardless of the formal age-of-consent threshold — defensive posture against future regulatory changes.
How UK schools + universities engage
UK educational institutions typically engage via standard JISC (Joint Information Systems Committee) procurement frameworks for universities, or local-authority DPA templates for K-12. Koydo signs JISC + LA framework agreements as needed; we provide UK-specific addendum if institution requires.