Child's Consent
In data privacy law, a child's consent generally refers to permission given by or on behalf of a minor to allow the processing of their personal data. Because children are considered less able to understand the risks involved, additional safeguards typically apply and parental authorization may be required depending on the child's age. The precise rules, including the relevant age thresholds, vary and should be checked against the applicable law.
Child's consent, in the GDPR context, concerns the conditions under which consent can serve as a lawful basis under Article 6 for processing a child's personal data, particularly in relation to information society services offered directly to a child. The GDPR generally requires that where consent is relied upon for such services, it be given or authorized by the holder of parental responsibility for children below a specified age threshold, with the controller making reasonable efforts to verify such authorization taking account of available technology. The applicable age threshold is subject to member state derogation and therefore varies across jurisdictions, so the reader should verify the specific age and verification requirements against the current official text and any national implementing law; note that the evidence packet provided does not contain GDPR-specific source material, so this definition should be corroborated against authoritative Regulation text before citation.
Why it matters
A child's consent sits at the intersection of two demanding areas of privacy compliance: the strict validity requirements for consent as a lawful basis and the heightened protection the law affords to minors. Because children are generally regarded as less able to appreciate the risks, consequences, and safeguards involved in processing their personal data, organizations that rely on consent for services aimed at children face additional obligations that do not apply when the data subject is an adult. Getting this wrong can undermine the lawfulness of the entire processing activity, since consent that is not validly given or authorized may not constitute a valid Article 6 basis at all.
The practical difficulty is that the rules are not uniform. Under the GDPR, the age threshold below which parental authorization is required for information society services offered directly to a child is subject to member state derogation, meaning the applicable age can differ from one jurisdiction to another. An organization operating across the EU cannot assume a single age applies everywhere, and the position under the UK GDPR and national implementing laws may differ again. This variability makes cross-border services particularly exposed to compliance risk if a single threshold is applied uniformly without checking local law.
Beyond the age question, controllers are generally expected to make reasonable efforts to verify that consent was given or authorized by the holder of parental responsibility, taking account of available technology. The standard is one of reasonableness rather than certainty, and there is recognized uncertainty and regulatory divergence around what verification methods are adequate. Because this is an evolving area, organizations should treat any current approach as provisional and revisit it against updated guidance.
Who it's relevant to
Inside Child's Consent
Common questions
Answers to the questions practitioners most commonly ask about Child's Consent.