Skip to content
Topic Contested in court

Minors

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Special protections for children under GDPR

321 linked items 18 Laws62 Case Law49 Guidance91 Enforcement70 News

Overview

28 sources · Sep 8, 2026

Legal Framework

The GDPR establishes special protections for children's personal data primarily through Article 8, which sets the age of consent for information society services offered directly to children. Below the default threshold of 16, processing requires parental authorization, though Member States may lower this floor to 13. Controllers must make "reasonable efforts" to verify that consent is properly given, "taking into consideration available technology" (Article 8(2)).

"Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child."
— GDPR Art. 8

Article 40(2)(g) encourages codes of conduct specifying how parental consent is obtained, while Article 57(1)(b) requires supervisory authorities to give specific attention to activities directed at children. The DSA Article 14(3) extends analogous protections to intermediary services predominantly used by minors, requiring explanations "in a way that minors can understand."

Key Developments

Enforcement actions show DPAs apply heightened scrutiny to processing involving minors. The Swedish DPA fined a school in Skellefteå for using facial recognition to monitor student attendance, finding consent invalid because the power imbalance undermined voluntariness:

"consent can not be applied since students and their guardians cannot freely decide if they/their children want to be monitored for attendance purposes"
— Skellefteå school decision

In the Mercadona case, the Spanish DPA fined the controller EUR 2,520,000 after a facial recognition system captured all store entrants, including minors, with the DPIA failing to account for children's specific risks. The AEPD has separately treated "affecting the rights of minors" as an aggravating factor in sanction assessment. The EDPB's breach notification guidance identifies children as warranting elevated concern:

"A breach may affect personal data concerning children or other vulnerable individuals, who may be placed at greater risk of danger as a result."
— EDPB Guidelines 9/2022

Status of the Debate

The regulatory perimeter around minors remains contested. Member State divergence on the digital consent age (13 versus 16) creates cross-border compliance friction. The EDPB's February 2025 Statement on Age Assurance signals an emerging regulatory consensus on age-verification methods, but no court has yet ruled on whether specific mechanisms satisfy Article 8(2)'s "reasonable efforts" standard. National family courts have adjudicated minors' interests extensively but outside the data protection context. A CJEU preliminary reference on the proportionality of age-assurance technologies would be needed to settle whether particular methods are required or merely permitted.

Practical Guidance

  • Default to 16: Apply the 16-year consent threshold unless you have confirmed the specific Member State has lowered it to 13 under Article 8(1).
  • Verify parental consent: Implement age-appropriate verification — the "reasonable efforts" standard in Article 8(2) is technology-dependent, and the Skellefteå enforcement shows consent fails where the power imbalance is structural.
  • Account for minors in DPIAs: The Mercadona fine demonstrates that failing to assess children's specific risks in impact assessments is independently sanctionable.
  • Adapt transparency: Provide information in clear, age-appropriate language for services directed at or predominantly used by minors, per DSA Art. 14(3) and GDPR Art. 57(1)(b).
  • Elevate breach response: Treat breaches involving minors' data as higher-risk events, prioritizing notification and mitigation per EDPB guidance.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 8 Conditions applicable to child's consent in relation to information society services Laws GDPR Apr 2016 special rules for children's data
why this is here
the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility

This article contains the principal GDPR provision specifically regulating the processing of children's personal data, establishing the age of consent and parental involvement, which are central to the special protections for minors.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

2018 Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidelines on transparency EDPB Guidance EDPB Apr 2018 Child-specific language requirements
why this is here
it should ensure that the vocabulary, tone and style of the language used is appropriate to and resonates with children

The document specifically addresses the requirement to adapt transparency information for children, which is a key aspect of minor protection.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Children as vulnerable users
why this is here
The GDPR requires additional safeguards when the processing is about children’s personal data, as the latter may be less aware of the risks and consequences.

The document mentions children's specific vulnerability to deceptive patterns, but this is not the core focus.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 5/2019 criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) Guidelines ·EDPB Guidance EDPB Jul 2020 Minor's data erasure
why this is here
the personal data have been collected in relation to the offer of information society services to a minor (Article 17.1.f)

The document lists minors as one of the grounds for erasure but does not elaborate on child-specific protections.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Consideration for child data subjects
why this is here
The more precise requirements in this regard depend on the circumstances of the data processing as well as the data subject's ability to grasp and comprehend the communication (for example taking into account that the data subject is a child or a person with special needs).

The document mentions children as a factor in tailoring information, but it is not the central topic.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 62 Case Law · all 49 Guidance · all 91 Enforcement · all 31 Literature · all 70 News