Skip to main content
Category: Consent Requirements

Information Society Services Consent

Also known as: ISS Consent, Child's consent for information society services, Article 8 consent, Children's consent for online services
Simply put

When an online service (such as an app, website, or e-commerce platform) is offered directly to a child and relies on consent to process their personal data, special rules apply to whether that child can consent themselves. Under the GDPR, a child below a set age generally cannot give valid consent on their own; instead, consent must be given or authorised by a person holding parental responsibility. This rule does not mean consent is always required for online services, only that where consent is the chosen legal basis, these age conditions apply.

Formal definition

Information Society Services Consent refers to the conditions in Article 8 of the GDPR governing the validity of a child's consent where an information society service (ISS) is offered directly to a child and processing relies on consent under Article 6(1)(a). An 'information society service' is defined as any service normally provided for remuneration, at a distance, by electronic means, and at the individual request of a recipient. Under Article 8(1), where the child is below the applicable age, processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility; the controller must make reasonable efforts to verify such authorisation, taking account of available technology (Article 8(2)). The EU GDPR sets a default age of 16, but Article 8(1) permits member states to lower this by national law to no less than 13, so the applicable threshold varies between member states and must be checked against national implementing legislation. In the UK GDPR the relevant age is 13. Article 8 does not itself require consent for every ISS, other Article 6 lawful bases may apply, and it does not override the additional conditions required for special category data under Article 9. Verification standards and the practical meaning of 'reasonable efforts' remain subject to regulator guidance (for example, the ICO's age-appropriate design considerations) and may evolve; practitioners should verify the current age threshold and requirements against the applicable official text and national law.

Why it matters

Article 8 of the GDPR addresses a specific vulnerability: children may not fully understand the consequences of agreeing to have their personal data processed, particularly in online environments designed to encourage engagement. Where an online service is offered directly to a child and the controller relies on consent under Article 6(1)(a), Article 8 conditions the validity of that consent on the child's age. This matters because a consent that fails these conditions is not a valid legal basis, which can render the underlying processing unlawful and expose the organisation to enforcement and complaints.

The practical difficulty is that the applicable age threshold is not uniform. The EU GDPR sets a default of 16 under Article 8(1), but member states may lower it by national law to no less than 13. As a result, an online service operating across the EU may face different age thresholds in different member states, and must check each against national implementing legislation. Under the UK GDPR the relevant age is 13. Organisations offering cross-border services therefore cannot assume a single figure applies everywhere.

Article 8 also imposes a verification obligation: where the child is below the applicable age, the controller must make reasonable efforts to verify that consent has been given or authorised by a person holding parental responsibility, taking account of available technology (Article 8(2)). What counts as 'reasonable efforts' is not defined precisely in the Regulation and remains subject to regulator guidance, so the standard should be treated as evolving rather than settled. Practitioners should verify the current age threshold and verification expectations against the applicable official text, national law, and regulator guidance such as the ICO's age-appropriate design considerations.

Who it's relevant to

Online service and app providers offering services to children
Organisations providing information society services directly to children need to determine whether consent is the appropriate legal basis and, if so, which age threshold applies in each market. Because the EU default is 16 and member states may set anything down to 13 (with the UK GDPR using 13), providers operating across borders should map the thresholds in each jurisdiction they serve rather than assume one figure applies.
Data protection officers and privacy compliance leads
DPOs and compliance leads should assess whether Article 8 is engaged at all, it applies only where an ISS is offered directly to a child and processing relies on consent under Article 6(1)(a). They also need to design and document age-verification and parental-authorisation processes that reflect 'reasonable efforts' under Article 8(2), recognising that the expected standard is shaped by evolving regulator guidance and is not fixed by the Regulation text.
Product designers and engineers building age-sensitive features
Teams implementing sign-up, age-assurance, and consent flows translate the Article 8 conditions into technical controls. They should account for differing national age thresholds, build mechanisms to obtain or verify parental authorisation where a user is below the applicable age, and revisit these controls as available technology and regulatory expectations (such as age-appropriate design considerations) develop.
Legal advisers assessing cross-border and multi-jurisdiction exposure
Advisers should confirm the applicable age against national implementing legislation for each relevant member state and against the UK GDPR separately, since member state derogations can vary the position. They should also flag that Article 8 does not create a blanket consent requirement and does not override the separate Article 9 conditions for special category data, and should verify the current position against the official text before advising.

Inside ISS Consent

Legal Basis (Article 8 GDPR)
Article 8 of the GDPR sets specific conditions for the consent of a child in relation to information society services offered directly to a child. It supplements the general consent requirements and applies where processing is based on consent under Article 6(1)(a). The provision does not create a standalone lawful basis; consent under Article 6 must still be present.
Default Age Threshold (16)
Under Article 8(1), where an information society service is offered directly to a child, the processing of a child's personal data is lawful on the basis of consent only where the child is at least 16 years old. Below that age, such processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.
Minimum Floor (13) and Member State Variation
Article 8(1) permits member states to provide by law for a lower age, provided that such lower age is not below 13 years. This means the applicable threshold generally ranges between 13 and 16 depending on the national implementing law of the relevant member state, and practitioners should verify the specific age set in each jurisdiction rather than assume 16 uniformly applies.
UK GDPR Position (13)
Under the UK GDPR and the UK Data Protection Act, the relevant age is set at 13. This is one example of divergence from the GDPR default of 16 and illustrates why the applicable threshold must be checked against the law governing the specific processing rather than treated as a single EU-wide figure.
Parental Authorisation and Reasonable Efforts
Where the child is below the applicable threshold, consent must be given or authorised by the holder of parental responsibility. Article 8(2) requires the controller to make reasonable efforts to verify that consent is so given or authorised, taking into consideration available technology. The standard is one of reasonable effort rather than absolute certainty.
Information Society Services Scope
The rule applies to information society services offered directly to a child, generally meaning services normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. Whether a given service is offered 'directly to a child' is a fact-sensitive assessment.
Interaction with National Contract Law
Article 8(3) clarifies that Article 8 does not affect the general contract law of member states, such as rules on the validity, formation or effect of a contract in relation to a child. The children's consent rule sits alongside, and does not displace, national capacity and contract rules.

Common questions

Answers to the questions practitioners most commonly ask about ISS Consent.

Does the GDPR require consent for every information society service offered to a child?
No. Article 8 of the GDPR does not impose consent as a universal requirement; it applies specifically where information society services are offered directly to a child and the processing is based on consent under Article 6(1)(a). Where a different Article 6 legal basis applies (for example, contract or legitimate interests, subject to assessment and the heightened protections children are afforded), the Article 8 parental authorisation mechanism is not the operative rule. The Article 8 condition governs the validity of consent in that specific context rather than replacing the general need to identify an appropriate lawful basis.
Is the age of consent for children under Article 8 the same across the whole EU?
No. Article 8(1) sets a default age of 16, but expressly permits member states to provide by law for a lower age, with a floor of 13. This means the applicable threshold can vary between member states depending on their national implementing legislation, so the position must be checked jurisdiction by jurisdiction rather than assumed to be uniform. In the UK-GDPR context, the relevant age is 13. Because national derogations differ, you should verify the applicable age against the relevant national law rather than relying on the EU default.
How do we determine which age threshold applies when we offer a service across several countries?
Generally you should identify the member states (or the UK) in which children are being offered the service and apply the age threshold set by each relevant national law, working from the Article 8(1) default of 16 where a member state has not legislated a lower figure, and noting the Article 8(1) floor of 13. Because thresholds can range between 13 and 16 depending on the jurisdiction, many providers applying the service to multiple countries assess the position per market. Where operational simplicity is preferred, the applicable local threshold for each user's location should still be respected; this is context dependent and should be confirmed against current national implementing law.
What steps does Article 8 expect where the child is below the applicable age?
Where consent is the lawful basis and the child is below the applicable age (the Article 8(1) default of 16, or a lower national threshold down to the floor of 13, or 13 under the UK-GDPR), Article 8(2) requires that consent be given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that such authorisation has been given, taking into account available technology. What constitutes reasonable efforts is not fixed by the Regulation text and is assessed proportionately to the risks of the processing; regulator guidance in this area continues to develop, so approaches should be verified against current guidance.
How can a service establish the user's age in practice?
The GDPR does not prescribe a specific age assurance method; Article 8(2) refers to making reasonable efforts to verify parental authorisation taking account of available technology, and age assessment more broadly is treated as proportionate to risk. In practice organisations consider measures ranging from self-declaration to more robust age assurance, calibrated to the sensitivity of the processing and the likelihood of children accessing the service. There is recognised divergence and evolving guidance among regulators on acceptable methods, and any technique must itself comply with data minimisation and other GDPR principles, so the chosen approach should be assessed and documented.
Does Article 8 override national laws on the validity of a child's contract?
No. Article 8(3) provides that the Article 8 rule does not affect general contract law of member states, such as rules on the validity, formation, or effect of a contract in relation to a child. This means the data protection consent threshold under Article 8 operates separately from national rules on a minor's capacity to contract, and both may need to be considered. Because contract capacity is governed by national law that varies between jurisdictions, that aspect should be checked against the applicable member state or UK law.

Common misconceptions

The children's consent age under the GDPR is always 16 across the EU.
Article 8(1) sets 16 as the default, but expressly allows member states to legislate a lower age down to a floor of 13. Applicable thresholds therefore vary by jurisdiction (for example, the UK GDPR uses 13), so the specific national position should be verified rather than assumed.
Article 8 applies to all processing of children's personal data.
Article 8 applies specifically where an information society service is offered directly to a child and the processing relies on consent under Article 6(1)(a). It does not govern processing based on other Article 6 bases, and it does not itself supply a lawful basis; a valid Article 6 basis is still required.
Obtaining parental consent for younger children requires guaranteed, foolproof age and identity verification.
Article 8(2) requires the controller to make reasonable efforts to verify parental consent or authorisation, taking into account available technology. It is a proportionate, risk-based standard rather than an absolute guarantee, and appropriate measures depend on the context and state of technology.

Best practices

Identify the applicable age threshold by reference to the specific national implementing law governing the processing, remembering the GDPR default is 16 and member states may set a lower age no less than 13 (for example, the UK GDPR applies 13).
Confirm before relying on Article 8 that the service is an information society service offered directly to a child and that the processing genuinely relies on consent under Article 6(1)(a) rather than another lawful basis.
Where the child is below the applicable threshold, implement reasonable, technology-appropriate measures to verify that consent is given or authorised by the holder of parental responsibility, and document why those measures are proportionate under Article 8(2).
Present privacy information and consent requests in clear, plain, age-appropriate language, consistent with transparency expectations for services directed at children.
Maintain records of the age assurance and parental authorisation approach, and review them as available technology and regulatory guidance evolve.
Coordinate with national contract law and capacity rules, since Article 8(3) confirms the children's consent rule does not override member state contract law.