Skip to main content
Category: Consent Requirements

Child's Consent

Simply put

In data privacy law, a child's consent generally refers to permission given by or on behalf of a minor to allow the processing of their personal data. Because children are considered less able to understand the risks involved, additional safeguards typically apply and parental authorization may be required depending on the child's age. The precise rules, including the relevant age thresholds, vary and should be checked against the applicable law.

Formal definition

Child's consent, in the GDPR context, concerns the conditions under which consent can serve as a lawful basis under Article 6 for processing a child's personal data, particularly in relation to information society services offered directly to a child. The GDPR generally requires that where consent is relied upon for such services, it be given or authorized by the holder of parental responsibility for children below a specified age threshold, with the controller making reasonable efforts to verify such authorization taking account of available technology. The applicable age threshold is subject to member state derogation and therefore varies across jurisdictions, so the reader should verify the specific age and verification requirements against the current official text and any national implementing law; note that the evidence packet provided does not contain GDPR-specific source material, so this definition should be corroborated against authoritative Regulation text before citation.

Why it matters

A child's consent sits at the intersection of two demanding areas of privacy compliance: the strict validity requirements for consent as a lawful basis and the heightened protection the law affords to minors. Because children are generally regarded as less able to appreciate the risks, consequences, and safeguards involved in processing their personal data, organizations that rely on consent for services aimed at children face additional obligations that do not apply when the data subject is an adult. Getting this wrong can undermine the lawfulness of the entire processing activity, since consent that is not validly given or authorized may not constitute a valid Article 6 basis at all.

The practical difficulty is that the rules are not uniform. Under the GDPR, the age threshold below which parental authorization is required for information society services offered directly to a child is subject to member state derogation, meaning the applicable age can differ from one jurisdiction to another. An organization operating across the EU cannot assume a single age applies everywhere, and the position under the UK GDPR and national implementing laws may differ again. This variability makes cross-border services particularly exposed to compliance risk if a single threshold is applied uniformly without checking local law.

Beyond the age question, controllers are generally expected to make reasonable efforts to verify that consent was given or authorized by the holder of parental responsibility, taking account of available technology. The standard is one of reasonableness rather than certainty, and there is recognized uncertainty and regulatory divergence around what verification methods are adequate. Because this is an evolving area, organizations should treat any current approach as provisional and revisit it against updated guidance.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for compliance programs need to identify where consent is relied upon for services directed at children and confirm the correct age threshold in each jurisdiction of operation, since member state derogation means a single figure will not apply across the EU. They should also document the verification approach for parental authorization and note where regulatory expectations remain uncertain or divergent.
Privacy and Technology Engineers
Engineers building age-gating, parental authorization, and verification flows must design mechanisms that reflect a reasonable-efforts standard appropriate to available technology, rather than assuming certainty is achievable. Because thresholds differ by jurisdiction, systems may need configurable age logic and should be revisited as guidance evolves.
Privacy Counsel and Advisers
Lawyers advising on services aimed at minors should verify the applicable age threshold against the relevant national implementing law and confirm whether the UK GDPR position differs. They should also assess whether consent is the right Article 6 basis at all, and whether Article 9 conditions apply to any special category data involved.
Product and Service Owners
Teams offering information society services directly to children need to understand that reliance on child consent carries additional safeguards and verification obligations. Because the requirements vary and continue to develop, product decisions should be made in consultation with compliance and legal functions rather than on assumptions about a uniform standard.

Inside Child's Consent

Information society services context
Under Article 8 GDPR, the specific rules on a child's consent apply where information society services (broadly, online services provided at a distance for remuneration or on a commercial basis) are offered directly to a child, and where consent is the Article 6 legal basis relied upon.
Age threshold and member state variation
Article 8 sets a default age below which a child's consent for information society services must be authorised or given by the holder of parental responsibility, but member states may provide for a lower age within a range specified in the Regulation. The exact figures should be verified against the current official text and the relevant national implementing law, as the position varies across member states.
Parental authorisation or consent
Where the child is below the applicable age, consent must generally be given or authorised by the holder of parental responsibility over the child, rather than by the child alone.
Reasonable efforts to verify
The controller must make reasonable efforts to verify that consent is given or authorised by the holder of parental responsibility, taking into consideration available technology. The Regulation does not prescribe specific verification methods, and proportionate approaches are expected.
General conditions for valid consent still apply
A child's consent remains subject to the general consent standard under the GDPR, which requires it to be freely given, specific, informed, and unambiguous. Consent is only one Article 6 basis and is not a universal requirement for processing children's data.
Relationship to national contract law
Article 8 states it does not affect the general contract law of member states, such as rules on the validity, formation, or effect of a contract in relation to a child.

Common questions

Answers to the questions practitioners most commonly ask about Child's Consent.

Is parental consent always required to process a child's personal data?
No. Consent is only one of the Article 6 legal bases, and it is not a universal requirement. Where consent is the chosen basis for an information society service offered directly to a child, Article 8 provides that processing is lawful where the child is at least 16, and below that age it must be authorised or given by the holder of parental responsibility. Member states may lower this age threshold, but not below 13. Other legal bases may apply depending on the context, subject to assessment, and special category data would additionally require an Article 9 condition.
Does the child's consent rule under Article 8 apply to every kind of processing involving children?
Not generally. Article 8 is specifically directed at consent as a legal basis for information society services offered directly to a child. It does not convert consent into the mandatory basis for all children's data, nor does it govern situations where a different Article 6 basis is relied upon. The precise scope of what counts as a service offered directly to a child, and how it interacts with other bases, can involve interpretive uncertainty, so the position should be assessed case by case and checked against current regulatory guidance.
How should an organisation determine which age threshold applies for its service?
Because member states may set the digital consent age anywhere between 13 and 16, the applicable threshold depends on which national implementing law governs the processing, typically linked to where the child is located. Organisations offering services across the EU generally need to identify the relevant member state rules for each jurisdiction they target, rather than assuming a single age applies everywhere. The UK GDPR position may differ from the EU position, and readers should verify the current threshold in each relevant jurisdiction.
What steps are expected when verifying that a person giving consent holds parental responsibility?
Where the applicable threshold requires authorisation by the holder of parental responsibility, the controller is expected to make reasonable efforts to verify that such consent has been given or authorised, taking account of available technology. What is reasonable is generally proportionate to the risks of the processing, so more robust verification may be expected for higher-risk activities. The Regulation does not prescribe a single method, and appropriate approaches can evolve with guidance and technology, so the specific measures should be assessed against current regulator expectations.
How should information and consent requests be presented to children?
Where information is addressed to a child, it should generally be provided in clear and plain language that the child can readily understand. This reflects the broader emphasis on transparency and on children as meriting specific protection. Practically, this can mean age-appropriate wording, layered notices, and avoiding unnecessary complexity. The design of such materials benefits from being tested against the intended audience, and regulator guidance on children's data can inform the approach.
What happens if a child reaches the applicable age after consent was originally given by a parent?
This scenario involves recognised practical uncertainty and is an area where organisational practice and guidance continue to develop. As a general matter, controllers relying on consent should ensure it remains valid and consider whether the individual, now able to consent in their own right, should be given the opportunity to make their own choice. Because the precise expectations here are not fully settled, organisations should assess the position and monitor current regulatory guidance rather than treat any single approach as definitively required.

Common misconceptions

The age of a child's consent under the GDPR is the same across all EU member states.
The GDPR permits member states to set a lower age within a defined range, so the applicable threshold can differ depending on the national implementing law. Practitioners should verify the specific age for each relevant jurisdiction rather than assuming a single figure.
Consent is always required to process a child's personal data.
Consent is only one of the Article 6 legal bases. Processing of children's data may in some cases rely on another basis, subject to assessment. The Article 8 rules on parental authorisation apply specifically where consent is relied upon for information society services offered directly to a child.
Article 8's parental consent rule applies to all processing of children's data.
Article 8 is targeted at the offer of information society services directly to a child where consent is the basis. It does not, by its terms, govern every processing activity involving children, and other provisions and safeguards may be relevant depending on context.

Best practices

Identify whether the service is an information society service offered directly to a child and whether consent is the legal basis, before applying the Article 8 requirements.
Confirm the applicable age threshold under the national implementing law of each relevant member state, and verify it against the current official text rather than assuming a uniform figure.
Where a child is below the applicable age, implement a mechanism to obtain or confirm authorisation from the holder of parental responsibility.
Adopt verification measures that are reasonable and proportionate in light of available technology, and document the rationale for the approach chosen.
Ensure any consent still meets the general standard of being freely given, specific, informed, and unambiguous, with age-appropriate information provided.
Reassess your approach where processing spans multiple member states or where national contract law may affect the position, and keep the assessment under review as guidance evolves.