# Child Consent — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/child-consent-information-society-services
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because the content specifically addresses the unique conditions and requirements for obtaining valid consent from children in the context of information society services, which is distinct from general consent requirements and requires specialized treatment of age verification, parental involvement, and child-specific safeguards.

## Overview

## Legal Framework

Article 8 GDPR establishes the conditions under which a child's consent can serve as a valid lawful basis for processing personal data in the context of information society services offered directly to a child. Under Article 8(1), where consent is relied upon under Article 6(1)(a), processing is lawful if the child is at least 16 years old. Member States retain discretion to lower this threshold, but not below 13. Below the applicable national age threshold, Article 8(2) requires that consent be given or authorized by the holder of parental responsibility. Controllers must then make reasonable efforts to verify that such authorization was genuinely provided, using available technology. Article 8(3) clarifies that these rules do not displace Member States' general contract law, including rules on the validity of contracts involving minors.

The rationale is protective: children merit heightened safeguards given their potential vulnerability and limited awareness of data processing risks, particularly in online environments where behavioral profiling and targeted advertising are prevalent.

## Key Developments

Enforcement actions have established concrete expectations around age verification and child protection. The Italian Data Protection Authority's €5 million fine against Luka Inc. over its Replika chatbot underscored that services accessible to minors—and those presenting risks to vulnerable users—must implement robust age-assurance mechanisms and cannot rely on blanket consent flows designed for adults. The Spanish DPA's €75,000 fine against Burwebs S.L., which operates adult content websites, reinforced that providers of age-restricted content bear affirmative obligations to verify both user age and the validity of any consent obtained, and that failure to do so constitutes a standalone infringement.

The CJEU's jurisprudence under Article 17 GDPR, including *Google LLC v CNIL* and *GC and Others v CNIL*, confirms that the right to erasure applies with particular force to data collected on the basis of a child's consent, recognizing that children may not have fully understood the consequences of their consent at the time it was given. This creates an elevated erasure risk for controllers who process children's data.

## Practical Guidance

- **Determine the applicable national age threshold** before launching any information society service directed at children, since Member States may set the consent age anywhere between 13 and 16, and this threshold varies by jurisdiction of the user.
- **Implement age-verification mechanisms proportionate to risk**, drawing on available technology—higher-risk processing (profiling, targeted advertising, AI interactions) demands stronger verification than low-risk services.
- **Design parental-consent flows that are verifiable**, not merely declarative; a checkbox is insufficient where reasonable technical alternatives exist, as enforcement against Burwebs demonstrates.
- **Treat children's consent as inherently fragile**: build erasure-ready data architectures, since Article 17(1) creates a heightened erasure right for data collected during childhood and controllers must be able to delete such data without undue delay.
- **Avoid using consent as the lawful basis where an alternative under Article 6 is available and more appropriate**, particularly for services that children cannot meaningfully understand—consent obtained from a child who lacks capacity to appreciate processing consequences is vulnerable to challenge.

## Legislation (full text of key provisions)

### Conditions applicable to child's consent in relation to information society services

*Source: GDPR, gdpr-art-8-en, 2016-04-27 — https://overview.legal/posts/90292*

### Recital 5 — scope covering intermediary service providers

*Source: DSA, dsa-rec-5-en, 2022-10-19 — https://overview.legal/posts/95407*

This Regulation should apply to providers of certain information society services as defined in Directive (EU) 2015/1535 of the European Parliament and of the Council (5), that is, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. Specifically, this Regulation should apply to providers of intermediary services, and in particular intermediary services consisting of services known as ‘mere conduit’, ‘caching’ and ‘hosting’ services, given that the exponential growth of the use made of those services, mainly for legitimate and socially beneficial purposes of all kinds, has also increased their role in the intermediation and spread of unlawful or otherwise harmful information and activities.

### Recital 10 — relationship with other union law

*Source: DSA, dsa-rec-10-en, 2022-10-19 — https://overview.legal/posts/95417*

This Regulation should be without prejudice to other acts of Union law regulating the provision of information society services in general, regulating other aspects of the provision of intermediary services in the internal market or specifying and complementing the harmonised rules set out in this Regulation, such as Directive 2010/13/EU of the European Parliament and of the Council (7) including the provisions thereof regarding video-sharing platforms, Regulations (EU) 2019/1148 (8), (EU) 2019/1150 (9), (EU) 2021/784 (10) and (EU) 2021/1232 (11) of the European Parliament and of the Council and Directive 2002/58/EC of the European Parliament and of the Council (12), and provisions of Union law set out in a Regulation on European Production and Preservation Orders for electronic evidence in criminal matters and in a Directive laying down harmonised rules on the appointment of legal representatives for the purpose of gathering evidence in criminal proceedings. Similarly, for reasons of clarity, this Regulation should be without prejudice to Union law on consumer protection, in particular Regulations (EU) 2017/2394 (13) and (EU) 2019/1020 (14) of the European Parliament and of the Council, Directives 2001/95/EC (15), 2005/29/EC (16), 2011/83/EU (17) and 2013/11/EU (18) of the European Parliament and of the Council, and Council Directive 93/13/EEC (19), and on the protection of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (20). This Regulation should also be without prejudice to Union rules on private international law, in particular rules regarding jurisdiction and the recognition and enforcement of judgments in civil and commercial matters, as Regulation (EU) No 1215/2012, and rules on the law applicable to contractual and non-contractual obligations. The protection of individuals with regard to the processing of personal data is governed solely by the rules of Union law on that subject, in particular Regulation (EU) 2016/679 and Directive 2002/58/EC. This Regulation should also be without prejudice to Union law on working conditions and Union law in the field of judicial cooperation in civil and criminal matters. However, to the extent that those Union legal acts pursue the same objectives as those laid down in this Regulation, the rules of this Regulation should apply in respect of issues that are not addressed or not fully addressed by those other legal acts as well as issues on which those other legal acts leave Member States the possibility of adopting certain measures at national level.

### Recital 32 — valid consent requirements for data processing

*Source: GDPR, gdpr-rec-32-en, 2016-04-27 — https://overview.legal/posts/91579*

Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.

### Recital 21 — Directive 2000/31 EC liability rules preservation

*Source: GDPR, gdpr-rec-21-en, 2016-04-27 — https://overview.legal/posts/91557*

This Regulation is without prejudice to the application of Directive 2000/31/EC of the European Parliament and of the Council (8), in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive. That Directive seeks to contribute to the proper functioning of the internal market by ensuring the free movement of information society services between Member States.

### Recital 72 — traceable online platform traders

*Source: DSA, dsa-rec-72-en, 2022-10-19 — https://overview.legal/posts/95541*

In order to contribute to a safe, trustworthy and transparent online environment for consumers, as well as for other interested parties such as competing traders and holders of intellectual property rights, and to deter traders from selling products or services in violation of the applicable rules, online platforms allowing consumers to conclude distance contracts with traders should ensure that such traders are traceable. The trader should therefore be required to provide certain essential information to the providers of online platforms allowing consumers to conclude distance contracts with traders, including for purposes of promoting messages on or offering products. That requirement should also be applicable to traders that promote messages on products or services on behalf of brands, based on underlying agreements. Those providers of online platforms should store all information in a secure manner for the duration of their contractual relationship with the trader and 6 months thereafter, to allow any claims to be filed against the trader or orders related to the trader to be complied with. This obligation is necessary and proportionate, so that the information can be accessed, in accordance with the applicable law, including on the protection of personal data, by public authorities and private parties with a legitimate interest, including through the orders to provide information referred to in this Regulation. This obligation leaves unaffected potential obligations to preserve certain content for longer periods of time, on the basis of other Union law or national laws, in compliance with Union law. Without prejudice to the definition provided for in this Regulation, any trader, irrespective of whether it is a natural or legal person, identified on the basis of Article 6a(1), point (b), of Directive 2011/83/EU and Article 7(4), point (f), of Directive 2005/29/EC should be traceable when offering a product or service through an online platform. Directive 2000/31/EC obliges all information society services providers to render easily, directly and permanently accessible to the recipients of the service and competent authorities certain information allowing the identification of all providers. The traceability requirements for providers of online platforms allowing consumers to conclude distance contracts with traders set out in this Regulation do not affect the application of Council Directive (EU) 2021/514 (30), which pursues other legitimate public interest objectives.

### Recital 1 — evolution of intermediary services economy

*Source: DSA, dsa-rec-1-en, 2022-10-19 — https://overview.legal/posts/95399*

Information society services and especially intermediary services have become an important part of the Union’s economy and the daily life of Union citizens. Twenty years after the adoption of the existing legal framework applicable to such services laid down in Directive 2000/31/EC of the European Parliament and of the Council (4), new and innovative business models and services, such as online social networks and online platforms allowing consumers to conclude distance contracts with traders, have allowed business users and consumers to impart and access information and engage in transactions in novel ways. A majority of Union citizens now uses those services on a daily basis. However, the digital transformation and increased use of those services has also resulted in new risks and challenges for individual recipients of the relevant service, companies and society as a whole.

### Recital 27 — beyond intermediary service provider liability

*Source: DSA, dsa-rec-27-en, 2022-10-19 — https://overview.legal/posts/95451*

Whilst the rules on liability of providers of intermediary services set out in this Regulation concentrate on the exemption from liability of providers of intermediary services, it is important to recall that, despite the generally important role played by such providers, the problem of illegal content and activities online should not be dealt with by solely focusing on their liability and responsibilities. Where possible, third parties affected by illegal content transmitted or stored online should attempt to resolve conflicts relating to such content without involving the providers of intermediary services in question. Recipients of the service should be held liable, where the applicable rules of Union and national law determining such liability so provide, for the illegal content that they provide and may disseminate to the public through intermediary services. Where appropriate, other actors, such as group moderators in closed online environments, in particular in the case of large groups, should also help to avoid the spread of illegal content online, in accordance with the applicable law. Furthermore, where it is necessary to involve information society services providers, including providers of intermediary services, any requests or orders for such involvement should, as a general rule, be directed to the specific provider that has the technical and operational ability to act against specific items of illegal content, so as to prevent and minimise any possible negative effects on the availability and accessibility of information that is not illegal content.

## Case law

### BVwG - W292 2270002-1

*Source: Federal Administrative Court, 2023-07-27 — https://overview.legal/posts/109002 — original: https://gdprhub.eu/index.php?title=BVwG_-_W292_2270002-1*

Facts — On 4 October 2020, the controller sent a non-anonymised court judgement of the Regional Criminal Court (Landesgericht für Strafsachen) as a PDF file to a different recipient via WhatsApp. Less than a year later, on 28 July 2021, the same non-anonymised court judgement was sent to the same recipient again, this time via email. The data subject lodged two complaints with the DPA (DSB) regarding the violation of their right to secrecy under § 1(1) DSG. In the first proceedings (DSB-D124.5125), the DPA ruled on the transmission of the judgement via WhatsApp and notably highlighted that the transmission via email was not the subject of the proceedings. In the second procedure (DSB-D124.0310/22) concerning the transmission via email, the DPA dismissed the complaint on the grounds that the data subject had no legitimate interest of legal protection and referred to its first administrative decision. The data subject appealed against the second decision of the DPA and asked the court to decide in that subject matter. In their opinion, the two transmissions of the judgement at different times represent two separate data processing operations. Holding — First, the court held that, in this specific case, there was no identity of the subject matter in comparison with the first proceedings within the meaning of § 68(1) AVG. In accordance with established legal practice (VwGH 31.07.2006, 2006/05/0158; VwGH 21.06.2007, 2006/10/0093 etc.), the court based its decision on the legal and temporal identity of the case. On the one hand, the data processing operation via email took place at a later date. On the other hand, the resulting time difference could lead to a potentially different legal assessment compared to the previous proceedings. Second, the court ruled that it could only examine the rightfulness of the dismissal of the complaint and therefore could not rule on the subject matter itself (See, for example, VwGH 18.12.2014, Ra 2014/07/0002). Third, the court held that no appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof) was admissible pursuant to Article 133(4) B-VG, as the decision raised no legal questions of fundamental importance. Therefore, the court quashed the DPA's administrative decision DSB-D124.0310/22.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C

*Source: Court of Justice of the European Union, C-154/21, 2023-01-12 — https://overview.legal/posts/132299 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0154*

The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article 15(1)(c) GDPR in proceedings between data subject RW and Österreichische Post AG regarding the scope of the right of access to information about recipients or categories of recipients of personal data. The Court held that controllers must provide the actual identities of specific recipients to whom personal data have been or will be disclosed, rather than merely naming categories of recipients, unless a further specification is impossible. The Court clarified that while the right of access under Article 15(1)(c) is not absolute and may be balanced against the rights and freedoms of others, including trade secrets, such restrictions must not result in a refusal to provide all information to the data subject.

### Google LLC v CNIL

*Source: CJEU, C-507/17, 2019-09-24 — https://overview.legal/posts/51476 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0507&ref=51476*

Right to delisting does not require global de-referencing under EU law.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Judgment of the Court (Fourth Chamber) of 16 July 2015.#Coty Germany GmbH v Stadtsparkasse Magdeburg.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling — Intellectual and industrial property — Directive 2004/48/EC — Article 8(3)(e) — Sale of counterfeit goods — Right to information in the context of proceedings for infringement of an intellectual property right — Legislation of a Member State which allows banking institutions to refuse a request for

*Source: Court of Justice of the European Union, C-580/13, 2015-07-16 — https://overview.legal/posts/132361 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0580*

The Court of Justice of the European Union ruled on a preliminary reference from the German Bundesgerichtshof in proceedings between Coty Germany GmbH and Stadtsparkasse Magdeburg concerning whether EU intellectual property enforcement law overrides national banking secrecy rules. The core issue was whether Article 8(3)(e) of Directive 2004/48/EC, which permits Member States to maintain protections for personal data processing, allows a bank to refuse disclosure of account holder information to a trademark holder seeking to identify counterfeit goods distributors. The Court held that Member States may not invoke banking secrecy to refuse such information requests where the disclosure is made in the context of intellectual property infringement proceedings, as a blanket refusal would undermine the right to information established by the Directive.

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### Bundesverband der Verbraucherzentralen v Planet49 GmbH

*Source: CJEU, C-673/17, 2019-10-01 — https://overview.legal/posts/51473 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0673&ref=51473*

Pre-ticked checkboxes do not constitute valid consent. Consent must be active.

### Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’

*Source: Court of Justice of the European Union, C-740/22, 2024-03-07 — https://overview.legal/posts/132269 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0740*

In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland) concerning whether the oral disclosure by a court of data relating to a natural person's criminal convictions to Endemol Shine Finland Oy, a commercial company organizing a competition, constitutes "processing of personal data" under the GDPR. The Court held that such oral disclosure falls within the scope of GDPR Article 2(1), as the concept of processing is not limited by the means or format of transmission, and that national legislation governing public access to official documents must reconcile the right of access with the GDPR's data protection requirements, particularly given the sensitive nature of criminal conviction data under Article 10. No fine was imposed, as the ruling solely addressed the interpretation of EU law.

### CJEU: Ordering platform to filter uploads violates fundamental rights

*Source: GDPRhub, C-360/10, 2012-02-16 — https://overview.legal/posts/122868 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-360/10_-_SABAM*

Facts — SABAM is a management company which represents authors, composers and publishers of musical works. Netlog ran an online social networking platform. On their Netlog profile, users could keep a diary, indicate their hobbies and interests, show who their friends are, display personal photos or publish video clips. However, SABAM claimed that the social network offered all users the opportunity to make use, by means of their profile, of the musical and audio-visual works in SABAM’s repertoire, making those works available to the public in such a way that other users of that network could access them without SABAM’s consent and without Netlog paying it any fee. SABAM first unsuccessfully tried to negotiate a licensing agreement with the social network, then gave it a notice that it should give an undertaking to cease and desist from making available to the public musical and audio-visual works from SABAM’s repertoire without the necessary authorisation - also without results. Given the lack of action taken by the social network, SABAM had it summoned before the Brussels Court of First Instance (rechtbank van eerste aanleg te Brussel) in injunction proceedings under Article 87(1) of the Law of 30 June 1994 on copyright and related rights. It requested that Netlog be ordered immediately to cease unlawfully making available musical or audio-visual works from SABAM’s repertoire and to pay a penalty of €1000 for each day of delay in complying with that order. The social network submitted that granting SABAM’s injunction would (1) effectively impose on Netlog a general obligation to monitor, which was prohibited by Article 15(1) of Directive 2000/31 and (2) introduce, at Netlog's own cost and for an unlimited period, a system for filtering most of the information which is stored on its servers in order to identify and block electronic files containing musical, cinematographic or audio-visual work in respect of which SABAM claims to hold rights. The rechtbank decided to stay the injunction proceedings and refer the following question to the CJEU: "Do Directives 2001/29 and 2004/48, in conjunction with Directives 95/46, 2000/31 and 2002/58, construed in particular in the light of Articles 8 and 10 of the European Convention on the Protection of Human Rights and Fundamental Freedoms [signed in Rome on 4 November 1950], permit Member States to authorise a national court, before which substantive proceedings have been brought and on the basis merely of a statutory provision stating that “[the national courts] may also issue an injunction against intermediaries whose services are used by a third party to infringe a copyright or related right”, to order a hosting service provider to introduce, for all its customers, in abstracto and as a preventive measure, at its own cost and for an unlimited period, a system for filtering most of the information which is stored on its servers in order to identify on its servers electronic files containing musical, cinematographic or audio-visual work in respect of which SABAM claims to hold rights, and subsequently to block the exchange of such files?" Holding — The CJEU first essentially restated its judgment in Scarlet Extended, finding it had to determine whether the injunction would require Netlog to carry out general monitoring of all the information that it stores. It then considered the requirements that stem from the protection of the applicable fundamental rights, namely SABAM's copyright, referring to the judgment in Promusicae to highlight that rights linked to intellectual property must be balanced against the protection of other fundamental rights. It then carried out this balancing exercise in the context of the case at hand, finding that because the injunction would result in a serious infringement of Netlog's freedom to conduct its business since it would require the company to install a complicated, costly, permanent computer system at its own expense, which would also be contrary to the conditions laid down in Article 3(1) of Directive 2004/48, which requires that measures to ensure the respect of intellectual-property rights should not be unnecessarily complicated or costly. To come to this conclusion, it took into account that the contested filtering system would (1) involve monitoring all or most of the information stored by the hosting service provider concerned, (2) with no limitation in time, (3) be directed at all future infringements and (4) be intended to protect not only existing works, but also works that have not yet been created at the time when the system is introduced. Moreover, it held "the effects of that injunction would not be limited to the hosting service provider, as the contested filtering system may also infringe the fundamental rights of that hosting service provider’s service users, namely their right to protection of their personal data and their freedom to receive or impart information, which are rights safeguarded by Articles 8 and 11 of the Charter respectively." As a result, the CJEU held that: "Directives: 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (Directive on electronic commerce); 2001/29/EC of the European Parliament and of the Council of 22 May 2001 on the harmonisation of certain aspects of copyright and related rights in the information society; and 2004/48/EC of the European Parliament and of the Council of 29 April 2004 on the enforcement of intellectual property rights, read together and construed in the light of the requirements stemming from the protection of the applicable fundamental rights, must be interpreted as precluding a national court from issuing an injunction against a hosting service provider which requires it to install a system for filtering: information which is stored on its servers by its service users; which applies indiscriminately to all of those users; as a preventative measure; exclusively at its expense; and for an unlimited period, which is capable of identifying electronic files containing musical, cinematographic or audio-visual work in respect of which the applicant for the injunction claims to hold intellectual property rights, with a view to preventing those works from being made available to the public in breach of copyright."

### Order of the President of the Court of 12 February 2025.#European Commission v Hungary.#Expedited procedure.#Case C-829/24.

*Source: Court of Justice of the European Union, C-829/24, 2025-02-12 — https://overview.legal/posts/132151 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62024CO0829*

The President of the Court of Justice of the European Union granted the European Commission's request for an expedited procedure in its infringement action against Hungary over Law No LXXXVIII of 2023 on the protection of national sovereignty, which established an Office for the Protection of National Sovereignty with extensive investigative powers. The Commission alleges the law violates multiple EU provisions including the GDPR (Articles 5, 6, 9, and 10), the TFEU fundamental freedoms, and the Charter of Fundamental Rights, arguing it threatens civil society organizations, media pluralism, and the rights of natural and legal persons. Hungary opposed the expedited procedure, contending the alleged impacts are unproven, judicial remedies exist under the law, and the complexity of the case warrants standard examination rather than expedited treatment.

## Guidance

### Statement 1/2025 on Age Assurance

*Source: EDPB, statement-12025-on-age-assurance-en, 2025-02-12 — https://overview.legal/posts/125696 — original: https://www.edpb.europa.eu/documents/statement/statement-12025-on-age-assurance_en*

1 Statement 1/2025 on Age Assurance Adopted on 11 February 2025 1 The European Data Protection Board has adopted the following statement: 1. BACKGROUND AND PURPOSE OF THIS STATEMENT 1. The European regulatory framework calls for the increased protection of children in the digital environment. For example, the Audiovisual Media Services Directive 2 , which Member States have transposed into their national laws, highlights the possibility to implement age verification measures (Articles 6a and…

### EDPB-EDPS Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse

*Source: EDPB, edpb-edps-joint-opinion-042022-on-the-proposal-for-a-regulation-of-en, 2022-07-28 — https://overview.legal/posts/125917 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-042022-on-the-proposal-for-a-regulation-of_en*

Adopted 2 EDPB-EDPS Joint Opinion 0 4/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse Adopted on 28 July 2022 Adopted 3 Adopted 5 Executive Summary On 11 May 2022, the European Commission published a Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse. The Proposal would impose qualified obligations on providers of hosting…

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

### Guidelines 05/2020 on consent under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-consent, 2020-05-04 — https://overview.legal/posts/38053 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en*

The European Data Protection Board (EDPB) adopted Guidelines 05/2020 on consent under Regulation 2016/679 to provide detailed interpretive guidance on the requirements for valid consent under the GDPR, including the elements of freely given, specific, informed, and unambiguous consent, as well as the conditions for explicit consent and the obligation to demonstrate consent. The guidelines address practical issues such as power imbalances, conditionality, granularity, detriment, and the minimum content requirements for informing data subjects. No fines are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects

*Source: EDPB, guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in-en, 2019-10-16 — https://overview.legal/posts/126202 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in_en*

1 Adopted Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Version 2.0 8 October 2019 2 Adopted Version history Version 2.0 8 October 2019 Adoption of the Guidelines after public consultation Version 1.0 9 April 2019 Adoption of the Guidelines for publication consultation 3 Adopted 1 Part 1 – Introduction ................................ ................................…

### Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject

*Source: EDPB, opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a-en, 2021-12-14 — https://overview.legal/posts/125971 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a_en*

Adopted 1 Opinion 39 /2021 on whether Article 58(2) ( g) GDPR coul d serve as a legal basis for a s upervisory a uthority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject Adopted on 14 December 2021 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63 and Article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

### Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria

*Source: EDPB, edpb-opinion-202516-tuv-certificationcriteria-en-0, 2025-07-14 — https://overview.legal/posts/51080 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162025-regarding-the-draft-decision-of-the-german_en*

Adopted 1 Opinion 16 /2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria Adopted on 8 July 2025 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data…

### Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria

*Source: EDPB, opinion-152023-on-the-draft-decision-of-the-dutch-supervisory-en, 2023-09-19 — https://overview.legal/posts/125831 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152023-on-the-draft-decision-of-the-dutch-supervisory_en*

Adopted 1 Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria Adopted on 19 09 2023 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

## Enforcement decisions

### Italian DPA finds GDPR applies to US-based Character.AI service

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/108999 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_487/2026*

Facts — Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to create and interact through chat with virtual characters that already exist or are created at the moment. The controller made this available to data subjects in Italian, and had a specific version for children. The DPA initiated an ex-officio investigation in 2024. The DPA requested information related to the LLM models used by the controller, the provision of the service, and data transfers. The controller provided a DPIA, and stated that it introduced an age verification system that required data subjects to register their date of birth. In 2025, the controller announced it would prevent underage data subjects from accessing open chat rooms, and would begin processing personal data of data subjects in the EEA to post-train its generative AI systems. Holding — The DPA first clarified that the GDPR is applicable even if the controller was established outside of the EU, in accordance with Article 3(2) GDPR. The DPA took into account the fact that the service was available in Italy and in Italian, as well as the privacy policy also applying to EEA residents. Given that the controller did not have an establishment in the EU, the one-stop-shop mechanism did not apply and the DPA was competent. The DPA found a violation of Articles 12(1), 13(1) and (2), and 14(1) and (2) GDPR. The DPA considered that the controller had failed to meet its information obligations. In terms of the controller’s privacy policy, the DPA considered that the controller had not provided data subjects’ with clear information regarding its processing activities, data transfers, or data subjects’ right to object and opt out. In addition, the controller failed to designate a representative in the EU, and included misleading and inaccurate statements on the processing of personal data for purposes of post-training LLMs for the service. However, the DPA also took into consideration that the controller had updated its privacy policy to make its language clearer. In terms of its pre-training activities, the DPA stated that the controller had failed to provide adequate information and therefore violated Articles 14(1) and (2) GDPR. The DPA dismissed the controller’s argument that it did not have the obligation to provide this information due to the data being collected by third parties from open sources. The DPA stated that the controller had the obligation to verify whether personal data was present. In addition, the exemption under Article 14(5)(b) GDPR does not exempt the controller from having the obligation to implement appropriate measures to protect data subjects’ rights. However, the DPA did not find a violation of Articles 21(1) and (4). The DPA referred to the EDPB opinion on processing personal data in relation to AI systems. The EDPB recommended controllers to adopt measures for data subjects to exercise their rights, including providing the option to provide data subjects with the option to object unconditionally before the processing takes place. The DPA considered that this opinion went beyond the literal wording of Articles 14 and 21 GDPR. This interpretation could not, in the DPA’s view, be interpreted retroactively to the controller’s processing activities. The DPA found a violation of Articles 24(1) and 25(2) GDPR. The DPA considered that the controller had failed to implement adequate technical and organisational measures to verify data subjects’ age. During its investigations, the DPA found that the controller’s age verification systems were not effective, as they allowed data subjects’ to access the service even after self declaring to be younger than the minimum age limit set by the controller. The DPA also found that the accounts were set to public by default. Therefore, the controller had failed to implement appropriate measures to protect underage data subjects, even if the GDPR does not set a harmonised and binding standard in relation to age verification. The DPA also found a violation of Articles 5(2) and 35 GDPR. Under Article 5(2) GDPR, the controller has the obligation to proactively demonstrate compliance with the GDPR. The DPA stated that a key tool to do this is through data protection impact assessments (DPIAs). Controllers are obliged to carry out a DPIA under Article 35 GDPR if the processing is likely to result in a high to the rights and freedoms of data subjects. The controller failed to do a DPIA on time in relation to providing the service to underage data subjects, as well as in relation to its processing activities for the purpose of pre-training its LLM. The DPA stated that the controller should have done this before launching the service in 2022, as the processing activities had a presumed high risk to freedoms and rights of data subjects (e.g. the use of large scale processing or processing data of vulnerable data subjects). However, the DPA acknowledged that the controller progressively improved its compliance by doing a (late) DPIA and updating it. Finally, the DPA found a violation of Article 27(1) GDPR, as the controller belatedly designated a representative in the EU. The DPA stated that the exemption under Article 27(2) GDPR did not apply. The DPA fined the controller €158,000. The DPA also ordered the controller to bring its privacy policy and storage of personal data for purposes of pre-training its LLM into compliance with the GDPR. The DPA also ordered the controller to implement effective age verification mechanisms.

### AEPD (Spain) - PS/00421/2020

*Source: AEPD (Spain), 2026-07-24 — https://overview.legal/posts/158454 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00421/2020*

Facts — The client of a financial institution lodged a complaint before the Spanish DPA (AEPD) due to the delivery of a mail for commercial purposes, even though he had expressly rejected the delivery of commercial communications and promotional offers. Dispute — Are the electronic communication sent by a financial entity to its clients to be considered as necessary for contract fulfilment or do they have commercial purposes (and thus would breach the principle of Article 21(1) of the Spanish Information Society Services Act (LSSI) regarding the delivery of electronic commercial communications to data subjects without prior authorization)? Holding — The DPA rejected the argument of transaction-based customer communication and held that the mail had marketing purposes because the Controller publicizes its services, although the data subject had expressly indicated his refusal to receive advertising content. As a result, the DPA considered that the financial entity violated Article 21(1) LSSI. Furthermore, the commercial communication did not inform the recipient about his right to object to the processing of its data for marketing purposes. As a consequence, the Spanish DPA imposed a fine of €5,000.

### Burwebs S.L.: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2022-11-03 — https://overview.legal/posts/47916 — original: https://www.enforcementtracker.com/ETid-1801*

The Spanish DPA has fined Burwebs S.L. EUR 75,000. Burwebs operates websites with adult content. During its investigation, the DPA found that Burwebs did not process users' data transparently. In addition, Burwebs retained users' personal data for an indefinite period of time. Further, the DPA found that Burwebs processed the data of minor users without requiring any parental consent. Burwebs also complicated the exercise of data subjects' rights under the GDPR and had not sufficiently informed

### Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/52327*

De Italiaanse gegevensbeschermingsautoriteit heeft Luka Inc. een boete van 5.000.000 euro opgelegd. Het bedrijf heeft een chatbot genaamd Replika ontwikkeld, met een tekst- en spraakinterface. Deze chatbot is gebaseerd op een generatief AI-systeem, specifiek een LLM-model, dat voortdurend wordt aangevuld en verbeterd door interacties met gebruikers. Replika is bedoeld als een "virtuele metgezel" die de stemming en het emotionele welzijn van gebruikers verbetert door hen te helpen hun eigen psyche te begrijpen. Replika kan worden ingesteld als een vriend, therapeut, romantische partner of mentor. De controle...

## Recent developments

### Initiatiefnota van de leden Ceder en Six Dijkstra over online kinderrechten.

*Source: Government, 2025-04-09 — https://overview.legal/posts/50732 — original: https://www.tweedekamer.nl/kamerstukken/kamervragen/detail?id=2025D14141&amp;did=2025D14141*

Kamerstukken II 2024–2025, 36 719, nr. 2 Initiatiefnota van de leden Ceder en Six Dijkstra over online kinderrechten. Drie specifieke voorstellen trekken de aandacht : (1) Kom met een proof of concept voor online leeftijdsverificatie, (2) Introduceer een «rode knop» voor gegevenswissing, (6) Betr...

### EFF to Gov. Pritzker: Veto Illinois’ HB 5511

*Source: Electronic Frontier Foundation, 2026-06-29 — https://overview.legal/posts/53411 — original: https://www.eff.org/deeplinks/2026/06/eff-gov-pritzker-veto-illinois-hb-5511*

The Illinois legislature recently passed House Bill 5511, which imposes a sweeping, device-level age-gating framework across nearly all internet-enabled hardware, operating systems, and online services. This well-intentioned but deeply flawed piece of legislation will harm young people who rely on the internet to access essential information and find community. That’s why we’re urging the Illinois governor to veto the measure. Under this new regime, digital platforms are forced to collect and sh

### Kort:

*Source: Government, 2025-10-13 — https://overview.legal/posts/51297 — original: https://www.tweedekamer.nl/kamerstukken/kamervragen/detail?id=2025D43416&amp;did=2025D43416*

Onder paragraaf 6 'Sociale media' wordt voorgesteld een bindende leeftijdsgrens voor het gebruik van sociale media, en als variant 6a-ii "Maatregel identiek aan maatregel 6a, met als verschil dat kinderen onder de 16 sociale media wel kunnen gebruiken als ouders of verzorgers expliciet toestemmin...

### Verandering bewerkstelligen: De menselijke kosten van online leeftijdsverificatie.

*Source: Electronic Frontier Foundation, 2026-01-06 — https://overview.legal/posts/51677*

De verplichtingen voor leeftijdsverificatie verspreiden zich snel en brengen een nieuw tijdperk van online toezicht, censuur en uitsluiting met zich mee, niet alleen voor jongeren, maar voor iedereen. Wetten die leeftijdscontrole vereisen, verplichten websites en apps doorgaans om gevoelige gegevens van elke gebruiker te verzamelen, vaak via ingrijpende methoden zoals identiteitscontroles, biometrische scans of andere twijfelachtige "schattingstechnieken", voordat ze toegang verlenen tot bepaalde inhoud of diensten. Wetgevers prijzen deze wetten als de ultieme oplossing voor de "online veiligheid van kinderen."

### States attempted to censor the online activities of children. Courts and the Electronic Frontier Foundation (EFF) largely managed to prevent this: a look back at 2025.

*Source: Electronic Frontier Foundation, 2025-12-31 — https://overview.legal/posts/52015*

In at least a dozen states, lawmakers believe they can pass laws that prohibit young people from accessing social media, or that require them to obtain parental consent before logging in. Fortunately, almost all courts that have reviewed these laws have ruled that they violate the constitution. It's not just the courts telling these lawmakers they are wrong. The Electronic Frontier Foundation (EFF) has filed briefs with courts across the country over the past year, explaining how these laws violate the freedom of speech of young people, as protected by the First Amendment.

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens?

*Source: Comparative Law Review, 2018-02-09 — https://overview.legal/posts/132416 — original: https://doi.org/10.12775/clr.2017.005*

Comparative Law Review 22 2016 Nicolaus Copernicus University http://dx.doi.org/10.12775/CLR.2016.006 Katarzyna Krupa- Lipińska  THE PROBLEM OF THE INDETERMINATE DEFENDANT IN TORT LAW IN EUROPE Abstract The article discusses the problem of the indeterminate defendant in European tort law systems and in the projects aiming to unify tort law in Europe, such as Draft Common Frame of Reference and Principles of European Tort Law. The given issue relates to a situation where there is a damage caused by one factor, yet upon available evidence one may indicate a few potential factors which might have led to the damage, but it cannot be ascertained which factor was the actual cause of it. The problem is addressed with reference to two scenarios. First, when there is a limited and known number of persons acting tortiously, each of whom potentially might have led to the damage, but only one of them had actually caused it. Second, when it is certain that one tortfeasor from the undetermined group of tortfeasors caused damage to some of the injured persons from the group of the injured persons, but it cannot be established precisely which tortfeasor caused damage to precisely which injured pe

### Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection

*Source: International Journal of Social Sciences and Public Administration, 2025-01-23 — https://overview.legal/posts/132539 — original: https://doi.org/10.62051/ijsspa.v6n1.22*

In the digital age, data breaches have become a significant threat to consumer privacy, prompting the implementation of stringent data protection regulations worldwide. This paper evaluates the effectiveness of two prominent regulatory frameworks, the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, in safeguarding consumer data and responding to data breaches. Through a comparative analysis of their key provisio

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Minors** — https://overview.legal/topics/minderjarigen
  Special protections for children under GDPR
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/child-consent-information-society-services · 2026-08-22
