Children's Data
Children's data is personal information relating to children, who are generally treated as a vulnerable group deserving of extra protection. Because of this vulnerability, such data is typically subject to special rules and safeguards. The specific age threshold and the exact protections that apply depend on the applicable law and jurisdiction.
Children's data refers to the personal data of individuals who qualify as children under the applicable legal framework. Under the GDPR, Article 8 sets conditions applicable to a child's consent in relation to information society services offered directly to a child, providing that processing based on consent is lawful where the child is at least 16 years old; however, member states may derogate to set a lower age, which cannot generally be below 13, so the operative threshold varies by member state. The GDPR does not exhaustively define 'child' for all processing purposes, and Article 8 addresses only the specific scenario of consent for information society services rather than every context in which children's data is processed. Children are widely regarded as a vulnerable demographic, and children's data is commonly subject to heightened protections; note that requirements diverge significantly across jurisdictions (for example, between the EU/UK GDPR frameworks and various U.S. state and sectoral regimes), so the applicable rules, age thresholds, and safeguards should be verified against the relevant law. This entry addresses the concept of children's personal data and should not be confused with the similarly named 'Children's Data Network,' an unrelated research collaborative.
Why it matters
Children's data attracts heightened attention because children are widely regarded as a vulnerable demographic that may be less able to understand the risks, consequences, and safeguards associated with the processing of their personal data. As a result, this data is commonly treated as warranting extra protection, and many legal frameworks place it in a category subject to special rules and safeguards. Organizations that fail to account for these enhanced expectations risk both regulatory scrutiny and reputational harm, since processing involving children is often viewed as higher risk.
The practical significance is compounded by divergence across jurisdictions. Under the GDPR, Article 8 addresses the specific scenario of a child's consent to information society services offered directly to a child, but the operative age threshold varies because member states may derogate from the default position. In the United States, children's privacy is governed by a patchwork of state and sectoral regimes, and most states treat children's data as a class by itself subject to special rules and protections. Because thresholds and requirements differ significantly between these frameworks, an approach that is compliant in one jurisdiction may not satisfy another.
For compliance programs, this means the applicable rules, age thresholds, and safeguards should be identified and verified against the relevant law for each context in which children's data is processed, rather than assuming a single global standard applies.
Who it's relevant to
Inside Children's Data
Common questions
Answers to the questions practitioners most commonly ask about Children's Data.