Laws · GDPR ·art-8-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.
How it connects
Cited by
- CJEU: Processing of beneficiary data not based on consent; individuals must be informed
- CJEU Lindquist: foot injury and medical leave constitute health data under Art. 8(1)
- Guidelines 05/2020 on consent under Regulation 2016/679
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
- Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement
All 74
- Guidelines 02/2021 on virtual voice assistants
- Website providing legal information: Insufficient fulfilment of information obligations
- Online Services: Insufficient fulfilment of information obligations
- Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”
- Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Digital Rights Ireland Ltd v Minister for Communications
- GC and Others v CNIL
- Google LLC v CNIL
- Privacy International v Secretary of State
- FTT allows appeal: NMC should have neither confirmed nor denied holding nurse's data
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- CE - N. 433539
- CJEU - C-543/09 - Deutsche Telekom
- BVerwG: Registration address blocking renewed for BaFin officers facing general unit
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject
- IP v Quirin Privatbank AG
- NKL Associates s.r.o. v European Commission
- A v Patērētāju tiesību aizsardzības centrs
- ND v DR
- C.G. v Bezirkshauptmannschaft Landeck
- Criminal proceedings against HYA and Others
- La Quadrature du Net and Others v Premier ministre and Ministère de la Culture
- Criminal proceedings against Unknown individuals
- Criminal proceedings against M.N
- RL v Landeshauptstadt Wiesbaden
- UF and AB v Land Hessen
- A. G. v Lietuvos Respublikos generalinė prokuratūra
- European Commission v Republic of Poland
- European Commission v Republic of Poland
- HYA and Othersprokuratura
- Criminal proceedings against V.S
- RW v Österreichische Post AG
- TU and RE v Google LLC
- WM and Sovim SA v Luxembourg Business Registers
- Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH
- Criminal proceedings against VD bd]&
- OT v Vyriausioji tarnybinės etikos komisija
- Ligue des droits humains ASBL v Conseil des ministres
- G.D. v The Commissioner of the Garda Síochána and Others
- Criminal proceedings against HP
- European Commission v Republic of Poland
- European Commission v Republic of Poland
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Criminal proceedings against H. K
- État luxembourgeois v B and Others
- European Commission v Ireland
- Staatssecretaris van Justitie en Veiligheid v A and Others
- Proceedings brought by Ministerio Fiscal
- Tele2 Sverige AB v Post- och telestyrelsen and Secretary of State for the Home Department v Tom Watson and Others
- Safe Interenvios, SA v Liberbank, SA and Others
- KPN BV v Autoriteit Consument en Markt (ACM)
- Coty Germany GmbH v Stadtsparkasse Magdeburg
- Judgment of the Court (Third Chamber), 7 November 2013.#Institut professionnel des agents immobiliers (IPI) v Geoffrey Englebert and Others.#Request for a preliminary ruling from the Cour constitutionnelle (Belgium).#Processing of personal data — Directive 95/46/EC — Articles 10 and 11 — Obligation to inform — Article 13(1)(d) and (g) — Exceptions — Scope of exceptions — Private detectives acting for the supervisory body of a regulated profession — Directive 2002/58/EC — Article 15(1).#Case C‑47
- Asociación Nacional de Establecimientos Financieros de Crédito (ASNEF) (C-468/10) and Federación de Comercio Electrónico y Marketing Directo (FECEMD) (C-469/10) v Administración del Estado
- LSG-Gesellschaft zur Wahrnehmung von Leistungsschutzrechten GmbH v Tele2 Telecommunication GmbH
- Ireland v European Parliament and Council of the European Union
- Heinz Huber v Bundesrepublik Deutschland
- General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens?
- Tracking Walls, Take-It-Or-Leave-It Choices, the GDPR, and the ePrivacy Regulation
- CJEU - C‑769/22 - European Commission v Hungary
- Federal Administrative Court: retention of job applicant data for potential legal claims
- Persónuvernd (Iceland) - 2025010364
- European Commission v Hungary
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
- Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access
- Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service
Related across sources
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) CJEU Sep 24, 2019 Right to be Forgotten Legitimate Interest Criminal Data
C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Territorial scope (GDPR) Right to be Forgotten Direct Marketing
Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB May 4, 2020 Consent Data Portability Personal Data
Guidelines 2/2019 processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects 1 Adopted Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Version 2.0 8 October… Guidelines ·EDPB Oct 16, 2019 Personal Data Processing Child Consent