Child Consent
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the content specifically addresses the unique conditions and requirements for obtaining valid consent from children in the context of information society services, which is distinct from general consent requirements and requires specialized treatment of age verification, parental involvement, and child-specific safeguards.
Overview
24 sources · Jul 23, 2026Legal Framework
Article 8 GDPR establishes the conditions under which a child's consent can serve as a valid lawful basis for processing personal data in the context of information society services offered directly to a child. Under Article 8(1), where consent is relied upon under Article 6(1)(a), processing is lawful if the child is at least 16 years old. Member States retain discretion to lower this threshold, but not below 13. Below the applicable national age threshold, Article 8(2) requires that consent be given or authorized by the holder of parental responsibility. Controllers must then make reasonable efforts to verify that such authorization was genuinely provided, using available technology. Article 8(3) clarifies that these rules do not displace Member States' general contract law, including rules on the validity of contracts involving minors.
The rationale is protective: children merit heightened safeguards given their potential vulnerability and limited awareness of data processing risks, particularly in online environments where behavioral profiling and targeted advertising are prevalent.
Key Developments
Enforcement actions have established concrete expectations around age verification and child protection. The Italian Data Protection Authority's €5 million fine against Luka Inc. over its Replika chatbot underscored that services accessible to minors—and those presenting risks to vulnerable users—must implement robust age-assurance mechanisms and cannot rely on blanket consent flows designed for adults. The Spanish DPA's €75,000 fine against Burwebs S.L., which operates adult content websites, reinforced that providers of age-restricted content bear affirmative obligations to verify both user age and the validity of any consent obtained, and that failure to do so constitutes a standalone infringement.
The CJEU's jurisprudence under Article 17 GDPR, including Google LLC v CNIL and GC and Others v CNIL, confirms that the right to erasure applies with particular force to data collected on the basis of a child's consent, recognizing that children may not have fully understood the consequences of their consent at the time it was given. This creates an elevated erasure risk for controllers who process children's data.
Practical Guidance
- Determine the applicable national age threshold before launching any information society service directed at children, since Member States may set the consent age anywhere between 13 and 16, and this threshold varies by jurisdiction of the user.
- Implement age-verification mechanisms proportionate to risk, drawing on available technology—higher-risk processing (profiling, targeted advertising, AI interactions) demands stronger verification than low-risk services.
- Design parental-consent flows that are verifiable, not merely declarative; a checkbox is insufficient where reasonable technical alternatives exist, as enforcement against Burwebs demonstrates.
- Treat children's consent as inherently fragile: build erasure-ready data architectures, since Article 17(1) creates a heightened erasure right for data collected during childhood and controllers must be able to delete such data without undue delay.
- Avoid using consent as the lawful basis where an alternative under Article 6 is available and more appropriate, particularly for services that children cannot meaningfully understand—consent obtained from a child who lacks capacity to appreciate processing consequences is vulnerable to challenge.