Skip to main content
Category: Consent Requirements

Age of Digital Consent

Also known as: Digital Age of Consent, Age of Consent for Information Society Services
Simply put

The age of digital consent is the minimum age at which a child can, on their own, agree to an online service collecting and using their personal data. Below this age, an online service that relies on consent generally needs to obtain and verify consent from a person holding parental responsibility over the child. The exact age varies between countries.

Formal definition

The age of digital consent is the threshold established under Article 8 of the GDPR governing a child's ability to consent to the processing of their personal data where consent (Article 6(1)(a)) is the legal basis and the processing is carried out in relation to an information society service (ISS) offered directly to a child. Where the child is below the applicable age, the controller must make reasonable efforts to obtain or verify consent given or authorised by the holder of parental responsibility, taking account of available technology. The GDPR sets a default of 16 but permits member states to lower it, subject to a floor of 13; the UK GDPR sets it at 13, and other national implementing laws fall within the 13-16 range, so the operative age is jurisdiction-specific and should be verified against the relevant national law. Several important boundaries apply: (i) the requirement is triggered only when consent is the chosen legal basis, so it does not apply where processing relies on another Article 6 basis such as contract (Article 6(1)(b)) or legitimate interests, subject to assessment; (ii) Recital 38 indicates parental consent is not required for preventive or counselling services offered directly to a child, meaning a child below the digital-consent age may access such services without parental involvement; and (iii) Article 8(3) provides that these rules do not affect national contract-law provisions on a child's capacity to enter into a contract, which remains relevant where a service relies on the contract basis. The term is not defined by that precise phrase in the Regulation text; commentators note it is sometimes considered a misnomer because the parental-consent mechanism can involve processing a parent's data alongside the child's. Age-verification and parental-consent methods, and regulatory expectations around them, continue to develop and vary between supervisory authorities.

Why it matters

The age of digital consent determines when an online service can rely on a child's own consent to process their personal data, and when it must instead obtain consent from a person holding parental responsibility. This directly shapes how services aimed at, or accessible to, children must be designed, because the operative age is not uniform: the GDPR sets a default of 16 but allows member states to lower it to a floor of 13, and the UK GDPR sets it at 13. A controller offering an information society service across multiple jurisdictions therefore cannot assume a single threshold applies and must verify the operative age against the relevant national implementing law.

The threshold matters only where consent under Article 6(1)(a) is the chosen legal basis for the processing. This is a frequent source of error: organisations sometimes treat parental consent as a universal requirement for children's data, when in practice the Article 8 mechanism is triggered only when consent is relied upon. Where processing rests on another Article 6 basis, such as contract or legitimate interests, the analysis differs and is subject to assessment. Misidentifying the basis can lead a controller either to collect parental consent unnecessarily or to overlook a genuine Article 8 obligation.

Equally important is the exemption reflected in Recital 38, which indicates that parental consent is not required for preventive or counselling services offered directly to a child. A data protection officer who overlooks this could wrongly insist on parental involvement and, in doing so, undermine a child's ability to access support services confidentially. Because age-verification and parental-consent methods, and the expectations of different supervisory authorities around them, continue to develop, the practical implementation of these rules remains an area of active regulatory attention that should be monitored.

Who it's relevant to

Data Protection Officers and Privacy Counsel
DPOs and privacy lawyers must confirm the correct age threshold for each jurisdiction in which a service is offered, since the operative age varies within the 13-16 range and the UK GDPR sets it at 13. They should verify that consent is actually the legal basis before applying Article 8, and should ensure that the Recital 38 exemption for preventive or counselling services is respected so that children are not wrongly denied access.
Product and Engineering Teams Building Online Services
Teams designing information society services offered to children need to build age-assurance and, where required, parental-consent flows that make reasonable efforts to obtain or verify consent, taking account of available technology. Because methods and regulatory expectations continue to develop and differ between supervisory authorities, these mechanisms should be treated as evolving rather than settled.
Compliance Leads Operating Across Multiple Jurisdictions
Organisations offering services across the EU, the UK, and other territories cannot rely on a single threshold, because member states may lower the default of 16 to a floor of 13. Compliance leads should map the applicable age per jurisdiction and confirm it against the relevant national implementing law, noting that member state derogations can vary the position.
Providers of Preventive and Counselling Services for Children
Organisations offering preventive or counselling services directly to children should be aware that, per Recital 38, parental consent is generally not required for such services even where the child is below the national digital-consent age. This supports confidential access, and providers should avoid imposing a parental-consent step that could deter children from seeking help.

Inside Age of Digital Consent

Article 8 GDPR (conditions applicable to child's consent)
The GDPR provision that sets a specific rule for the lawfulness of consent where information society services are offered directly to a child and consent under Article 6(1)(a) is the legal basis relied upon. It establishes an age threshold below which processing is lawful only if consent is given or authorised by the holder of parental responsibility.
Default threshold of 16 and member state derogation
Article 8 sets a default age of 16, but expressly permits member states to provide by law for a lower age, which may not be below 13. As a result the applicable digital-consent age varies across the EU/EEA and must be checked against the relevant national implementing law rather than assumed to be uniform.
Scope limited to information society services offered directly to a child
The rule applies specifically to information society services (broadly, online services normally provided for remuneration and at a distance) that are offered directly to a child. It does not, on its face, extend to all processing of children's data, and its precise edges can be subject to interpretation and regulatory guidance.
Consent by, or authorisation from, the holder of parental responsibility
Where the child is below the applicable age, consent must be given or authorised by the holder of parental responsibility over the child, for the processing to be lawful on the consent basis.
Reasonable efforts to verify parental authorisation
The controller is required to make reasonable efforts to verify that consent is given or authorised by the holder of parental responsibility, taking into consideration available technology. What counts as reasonable is proportionate and context-dependent, and verification methods remain an area of practical and regulatory discussion.
Recital 38 exemption for preventive and counselling services
Recital 38 GDPR indicates that parental consent should not be required in the context of preventive or counselling services offered directly to a child. This means such services can, in principle, be provided to a child below the national digital-consent age without seeking parental consent. As a recital it informs interpretation rather than being an operative article.
Interaction with national contract-law capacity rules
Article 8(3) states that the provision does not affect the general contract law of member states, such as rules on the validity, formation or effect of a contract in relation to a child. This is relevant where a service relies on Article 6(1)(b) (contract) rather than consent, since a child's capacity to contract is a separate national-law question.

Common questions

Answers to the questions practitioners most commonly ask about Age of Digital Consent.

Does the age of digital consent mean children under a certain age can never use online services without parental consent?
No. The age of digital consent under Article 8 GDPR is specific to the legal basis of consent for information society services offered directly to a child. It determines the age below which parental authorisation is generally required for consent to be valid; it is not a blanket rule that children cannot use online services otherwise. Where a service relies on a legal basis other than consent under Article 6(1), Article 8 does not directly govern the position. Importantly, Recital 38 indicates that parental consent should not be required for preventive or counselling services offered directly to a child, even where the child is below the applicable national digital-consent age. The precise application should be assessed against the current official text and any relevant national implementing law.
Is the age of digital consent set at 16 across the whole EU?
Not necessarily. Article 8 GDPR sets a default position but expressly permits member states to provide for a lower age by law, subject to a floor. As a result, the applicable age varies between member states depending on national implementing legislation. For this reason you should not assume a single uniform age applies EU-wide, and the UK GDPR position may differ again. Confirm the specific age against the relevant national law for each jurisdiction in which the service is offered, and verify against the current official text.
When exactly does the age of digital consent apply to my service?
Article 8 applies where you offer an information society service directly to a child and you rely on consent as your Article 6(1) legal basis. If you are relying on a different basis, for example, contractual necessity under Article 6(1)(b) or legitimate interests under Article 6(1)(f), Article 8 does not directly set an age threshold, though other considerations for processing children's data still apply. You should first confirm the legal basis, then whether the service is directed at children, and then check the applicable national age. This is an assessment that depends on your specific processing context.
How do we handle a child using a service where we rely on contract rather than consent?
Where you rely on Article 6(1)(b) rather than consent, Article 8's age threshold does not apply in the same way. However, Article 8(3) makes clear that its provisions do not affect national contract-law rules on a child's capacity to enter into a contract. This means a child's ability to validly form the underlying contract is a separate question governed by member state law, which can vary. You should therefore assess both the data protection position and the relevant national contract-law rules on minors' capacity, as the two are distinct.
What are we expected to do to verify parental consent and the child's age?
Article 8(2) requires the controller to make reasonable efforts to verify that consent is given or authorised by the holder of parental responsibility, taking into account available technology. The Regulation does not prescribe a specific verification method, so the appropriate approach is proportionate and risk-based, considering the nature of the service and the data involved. Regulatory guidance on acceptable age-assurance and verification techniques continues to evolve and can diverge between authorities, so verify current guidance from the relevant supervisory authority and avoid treating any single method as definitively compliant.
Do we always need parental consent for services aimed at children who are below the applicable age?
Not in all cases. Recital 38 GDPR indicates that parental consent should not be required for preventive or counselling services offered directly to a child, even where the child is below the national digital-consent age. Relying on the entry to seek parental consent in those situations could undermine children's access to such services. Beyond that exemption, whether parental consent is needed depends on the legal basis you rely on and whether the service is offered directly to the child. Assess each situation against the current official text and relevant national law.

Common misconceptions

The age of digital consent is 16 everywhere in the EU.
16 is only the default under Article 8. Member states may set a lower age down to a floor of 13, so the operative threshold differs by country and must be verified against the applicable national implementing law.
Any service must obtain parental consent before processing the personal data of a child below the threshold.
The Article 8 rule applies to consent as the legal basis for information society services offered directly to a child. Other Article 6 bases may apply in appropriate cases, and Recital 38 indicates parental consent is not required for preventive or counselling services offered directly to a child. The age rule is not a blanket requirement across all child data processing.
Satisfying the age-of-consent rule means a contract with a child is valid.
Article 8(3) makes clear the provision does not affect national contract law on a child's capacity to enter into a contract. Where a service relies on Article 6(1)(b), the separate question of contractual capacity under member state law still needs to be considered.

Best practices

Identify and document the applicable digital-consent age in each member state where the service is offered, since the threshold ranges between 13 and 16 depending on national law, and revisit it if you enter new jurisdictions.
Before defaulting to parental consent, confirm the correct Article 6 legal basis for the processing, and consider whether the service falls within the Recital 38 category of preventive or counselling services offered directly to a child, where parental consent is not required.
Where consent is relied upon for a child below the threshold, implement age-appropriate mechanisms to obtain and verify parental authorisation, making reasonable efforts proportionate to the risk and available technology, and document the reasoning behind the chosen method.
Where the service relies on contract as the legal basis, assess the child's capacity to contract under the relevant national contract law separately, as Article 8 does not resolve that question.
Record the assessment of whether the service is an information society service offered directly to a child, since this determines whether Article 8 applies, and note any interpretive uncertainty at the boundary of that scope.
Monitor regulatory guidance and national implementing measures on children's data and verification methods, and verify age thresholds and requirements against the current official text before relying on them in a compliance program.