Skip to main content
Category: Data Classification & Identifiers

Children's Data

Also known as: Children's Personal Data, Personal Data of Children
Simply put

Children's data is personal information relating to children, who are generally treated as a vulnerable group deserving of extra protection. Because of this vulnerability, such data is typically subject to special rules and safeguards. The specific age threshold and the exact protections that apply depend on the applicable law and jurisdiction.

Formal definition

Children's data refers to the personal data of individuals who qualify as children under the applicable legal framework. Under the GDPR, Article 8 sets conditions applicable to a child's consent in relation to information society services offered directly to a child, providing that processing based on consent is lawful where the child is at least 16 years old; however, member states may derogate to set a lower age, which cannot generally be below 13, so the operative threshold varies by member state. The GDPR does not exhaustively define 'child' for all processing purposes, and Article 8 addresses only the specific scenario of consent for information society services rather than every context in which children's data is processed. Children are widely regarded as a vulnerable demographic, and children's data is commonly subject to heightened protections; note that requirements diverge significantly across jurisdictions (for example, between the EU/UK GDPR frameworks and various U.S. state and sectoral regimes), so the applicable rules, age thresholds, and safeguards should be verified against the relevant law. This entry addresses the concept of children's personal data and should not be confused with the similarly named 'Children's Data Network,' an unrelated research collaborative.

Why it matters

Children's data attracts heightened attention because children are widely regarded as a vulnerable demographic that may be less able to understand the risks, consequences, and safeguards associated with the processing of their personal data. As a result, this data is commonly treated as warranting extra protection, and many legal frameworks place it in a category subject to special rules and safeguards. Organizations that fail to account for these enhanced expectations risk both regulatory scrutiny and reputational harm, since processing involving children is often viewed as higher risk.

The practical significance is compounded by divergence across jurisdictions. Under the GDPR, Article 8 addresses the specific scenario of a child's consent to information society services offered directly to a child, but the operative age threshold varies because member states may derogate from the default position. In the United States, children's privacy is governed by a patchwork of state and sectoral regimes, and most states treat children's data as a class by itself subject to special rules and protections. Because thresholds and requirements differ significantly between these frameworks, an approach that is compliant in one jurisdiction may not satisfy another.

For compliance programs, this means the applicable rules, age thresholds, and safeguards should be identified and verified against the relevant law for each context in which children's data is processed, rather than assuming a single global standard applies.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need to identify where children's data is processed and map the applicable thresholds and safeguards across the relevant jurisdictions. Because the operative age under the GDPR varies by member state derogation, and because U.S. state regimes treat children's data differently, they should verify the specific requirements against the applicable law rather than relying on a single default.
Compliance and Legal Counsel
Counsel advising on services that may reach children should assess how the relevant frameworks apply, including whether Article 8 of the GDPR is engaged in the context of information society services offered directly to a child. Given significant divergence between EU/UK GDPR frameworks and various U.S. state and sectoral regimes, they should confirm thresholds and safeguards for each jurisdiction in scope.
Product and Engineering Teams
Teams building information society services that may be offered directly to children need to account for heightened protections and, where relevant, age-related conditions for consent. Because thresholds and requirements differ by jurisdiction, engineering approaches such as age assurance or data handling controls should be designed with the applicable legal requirements confirmed rather than assumed.
Organizations Handling Administrative or Research Records
Organizations processing children's personal data for research or analytical purposes should note the heightened protections commonly applied to this vulnerable demographic. This concept of children's personal data should not be confused with the similarly named 'Children's Data Network,' which is an unrelated data and research collaborative focused on the linkage and analysis of administrative records.

Inside Children's Data

Special protection rationale
The GDPR recites that children merit specific protection regarding their personal data because they may be less aware of the risks, consequences, safeguards, and their rights. This principle informs how obligations are interpreted where children are affected.
Age threshold for information society services consent
Under Article 8, where consent is relied upon to offer information society services directly to a child, processing is lawful only if the child is at or above a specified age. The Regulation sets a default age but permits member states to set a lower age within a defined floor, so the applicable threshold varies by member state and must be checked against national implementing law.
Parental or guardian authorisation
Where a child is below the applicable age threshold, consent for information society services must generally be given or authorised by the holder of parental responsibility. The controller must make reasonable efforts, taking available technology into account, to verify that such authorisation was given.
Legal basis is not limited to consent
Article 8 addresses the consent basis specifically, but processing of children's data may in appropriate cases rest on other Article 6 bases (such as contract, legal obligation, or legitimate interests, subject to assessment). The child-protection considerations remain relevant to that assessment.
Transparency toward children
Information provided to data subjects should be concise, transparent, intelligible, and in clear and plain language, in particular for any information addressed specifically to a child. This shapes how notices and privacy information are drafted where children are the audience.
Interaction with special category data
Some children's data may also constitute special category data under Article 9, which requires an additional condition beyond an Article 6 basis. The child's age does not by itself change this; each layer must be satisfied separately.

Common questions

Answers to the questions practitioners most commonly ask about Children's Data.

Is there a single age across the EU below which a child cannot consent to information society services?
No. While the GDPR sets a default age threshold for a child's consent to information society services offered directly to them, it expressly allows member states to provide for a lower age in their national implementing law, subject to a floor. As a result, the applicable age varies between member states, so you should verify the specific threshold for each relevant jurisdiction rather than assume a single EU-wide figure. Note also that this consent-age rule concerns online services offered directly to children and does not automatically govern every processing activity involving children's data.
Does the GDPR require consent for all processing of children's data?
No. Consent is only one of the Article 6 legal bases, and it is not a universal requirement for children's data. Other bases, such as contract, legal obligation, vital interests, public task, or legitimate interests, may apply depending on the context, though legitimate interests requires particular care where children are concerned because they are recognised as meriting specific protection. Where special category data is involved, an additional Article 9 condition is also needed. The consent-age provisions apply to a defined situation (typically information society services offered directly to a child) and do not convert every activity into a consent-based one; each processing activity should be assessed on its own facts.
When offering an online service to children, how should we approach obtaining and verifying consent?
Where consent is the chosen basis and the child is below the applicable national age threshold for information society services, the GDPR generally requires that consent be given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that such consent has been given, taking account of available technology. What counts as reasonable is proportionate and risk-based rather than absolute, and regulatory guidance on age assurance and verification continues to evolve and can diverge between regulators. You should confirm the applicable age in each relevant member state and check current guidance before finalising your approach.
How does the transparency obligation apply when we communicate with children?
Information addressed to children generally needs to be provided in a way that is clear, concise, and appropriate to their level of understanding, so that a child can understand what will happen to their data. In practice this typically means using plain, age-appropriate language and formats rather than relying solely on standard adult-facing privacy notices. The precise expectations are shaped by regulatory guidance, which can vary, so treat this as a context-dependent design task and confirm against current guidance for the relevant jurisdiction.
Should we carry out a Data Protection Impact Assessment when processing children's data?
In many cases a DPIA under Article 35 will be appropriate, because children are recognised as vulnerable data subjects and processing that may result in a high risk to their rights and freedoms typically calls for an assessment. Whether a DPIA is required depends on the nature, scope, context, and purposes of the processing, and some supervisory authorities publish lists of operations that require one. A DPIA is distinct from a Data Processing Agreement under Article 28; the former assesses risk while the latter governs the controller-processor relationship. Assess the specific processing and consult applicable regulatory lists and guidance.
How does the position on children's data differ between the EU GDPR and the UK regime?
The core principles are similar, but the applicable age threshold for a child's consent to information society services and the accompanying regulatory expectations can differ between the EU GDPR, the UK GDPR, and national implementing measures. UK-specific guidance addressing the design of online services likely to be accessed by children exists and may impose particular expectations. Because these regimes and their guidance can diverge and evolve, you should identify which regime applies to a given service and verify the specific requirements and current guidance for that jurisdiction rather than assuming alignment.

Common misconceptions

There is a single EU-wide age of consent for children's online services.
The GDPR sets a default age for information society services consent but expressly allows member states to provide for a lower age within a defined floor. The applicable age therefore varies across member states, and the UK GDPR and national implementing laws should be checked separately.
Consent is always required to process a child's personal data.
Consent is one of several Article 6 legal bases. The specific child-consent rule in Article 8 applies where consent is relied upon for information society services offered directly to a child. Other bases may apply in appropriate cases, subject to assessment, though the heightened protection of children remains a relevant factor.
Obtaining a click confirming the user is an adult, or a parent's tick-box, fully satisfies the verification requirement.
The Regulation requires reasonable efforts to verify parental authorisation, taking available technology into account, rather than a fixed method. What is reasonable is context and risk dependent, regulator expectations and guidance in this area continue to evolve, and readers should verify current guidance.

Best practices

Confirm the applicable age threshold for information society services in each relevant member state, and check the UK GDPR and national implementing law separately, since the position can diverge.
Identify and document the correct Article 6 legal basis before defaulting to consent, and where special category data under Article 9 is involved, record the additional condition relied upon.
Where consent is relied upon for a child below the applicable age, design a mechanism to obtain or verify parental or guardian authorisation using reasonable efforts proportionate to the risks and available technology.
Draft privacy information and notices in concise, clear, and plain language suited to a child audience where information is addressed specifically to children.
Assess and document the risks to children as part of your accountability record, and consider whether a Data Protection Impact Assessment under Article 35 is warranted where processing is likely to result in high risk.
Monitor evolving regulator guidance on age verification and children's data, and revisit your approach periodically rather than treating a current implementation as permanently compliant.