Child Consent
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the content specifically addresses the unique conditions and requirements for obtaining valid consent from children in the context of information society services, which is distinct from general consent requirements and requires specialized treatment of age verification, parental involvement, and child-specific safeguards.
Overview
26 sources · Aug 27, 2026Legal Framework
Article 8 GDPR establishes a specialised consent regime for processing children's personal data in the context of information society services offered directly to children. Where Article 6(1)(a) applies — meaning consent is the lawful basis — and the service is an information society service offered directly to a child, the default age at which a child may independently consent is 16. Below that threshold, parental consent or authorisation is required.
"Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child."
— GDPR Art. 8(1)
Member States may lower this threshold, but not below 13. This creates a fragmented landscape: controllers operating across borders must verify the applicable national age threshold in each jurisdiction where they offer services. Article 8(2) imposes a positive obligation on controllers to make "reasonable efforts" to verify that consent was indeed given or authorised by the holder of parental responsibility, taking available technology into account. Article 8(3) clarifies that this regime does not displace national contract law rules on validity, formation, or effect of contracts involving children.
The child-specific protections extend to the right to erasure. Article 17(1)(f) provides an independent ground for erasure where personal data were collected in relation to the offer of information society services under Article 8(1) — a provision that operates regardless of whether other erasure grounds apply.
Key Developments
The CJEU has addressed consent quality requirements that apply with particular force to children. In Planet49, the Court emphasised that consent must be a clear affirmative act and that "silence, pre-ticked boxes or inactivity should not therefore constitute consent" (Recital 32, cited by the Court). While that case concerned adult consent, the standards articulated there frame the elevated expectations for child consent under Article 8.
The EDPB's Guidelines 5/2019 on the right to be forgotten confirm that Article 17(1)(f) is purpose-built for child data:
This means the erasure right for data collected via information society services offered to children is narrower in scope than general erasure — it applies only to the ISS context — but provides a distinct, child-protective ground that does not require demonstrating unlawfulness or withdrawal of consent.
Enforcement actions signal growing regulator focus on age verification and child consent. The Italian Garante's action against Luka Inc. (Replika) addressed a generative AI companion chatbot that could not demonstrate a valid legal basis for processing, with particular concern for vulnerable users. The Garante's subsequent action against Character.AI further underscores that AI-driven services targeting or accessible to children face heightened scrutiny of consent mechanisms.
Status of the Debate
This topic is contested and actively litigated. The core statutory text is clear, but its application generates divergence. National age thresholds vary (ranging from 13 to 16), creating compliance complexity for cross-border services. Courts and regulators are grappling with what constitutes "reasonable efforts" to verify parental consent under Article 8(2) — particularly as new technologies emerge. The EDPB's February 2025 Statement on Age Assurance signals that age-verification methodology is an emerging regulatory frontier. No definitive CJEU ruling on Article 8's verification standard exists yet; a preliminary reference clarifying the proportionality and technological-neutrality requirements of "reasonable efforts" would resolve the central open question.
Practical Guidance
- Map national age thresholds: For each Member State where you offer services, identify whether the state has lowered the Article 8 age below 16 (and to what level). Apply the highest applicable threshold per user's location.
- Implement age assurance proportionate to risk: Article 8(2) requires "reasonable efforts" to verify parental consent. Higher-risk processing (AI companions, profiling, targeted advertising) demands stronger verification — consider age estimation tools, parental confirmation flows, and risk-based escalation.
- Design child-appropriate consent interfaces: Consent requests must be understandable to the child's age group. Use plain language, layered notices, and avoid dark patterns. The Planet49 standard — no pre-ticked boxes or inactivity — applies a fortiori to children.
- Build an Article 17(1)(f) erasure pathway: Ensure your systems can identify and promptly erase data collected via ISS offered to children when requested, without requiring the data subject to invoke other erasure grounds.
- Document parental verification methodology: Maintain records of the technology and process used to verify parental consent, as supervisory authorities are increasingly scrutinising whether verification efforts were genuinely "reasonable" given available technology.
why this is here
the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility
This provision directly sets out the substantive rules for child consent in information society services, including the age threshold and parental authorisation requirement, which are the core elements of this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Burwebs processed the data of minor users without requiring any parental consent
The document directly addresses the failure to obtain parental consent for minors, which is the core requirement of Article 8 GDPR on child consent for information society services.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.