Minors
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Special protections for children under GDPR
Overview
28 sources · Sep 8, 2026Legal Framework
The GDPR establishes special protections for children's personal data primarily through Article 8, which sets the age of consent for information society services offered directly to children. Below the default threshold of 16, processing requires parental authorization, though Member States may lower this floor to 13. Controllers must make "reasonable efforts" to verify that consent is properly given, "taking into consideration available technology" (Article 8(2)).
"Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child."
— GDPR Art. 8
Article 40(2)(g) encourages codes of conduct specifying how parental consent is obtained, while Article 57(1)(b) requires supervisory authorities to give specific attention to activities directed at children. The DSA Article 14(3) extends analogous protections to intermediary services predominantly used by minors, requiring explanations "in a way that minors can understand."
Key Developments
Enforcement actions show DPAs apply heightened scrutiny to processing involving minors. The Swedish DPA fined a school in Skellefteå for using facial recognition to monitor student attendance, finding consent invalid because the power imbalance undermined voluntariness:
"consent can not be applied since students and their guardians cannot freely decide if they/their children want to be monitored for attendance purposes"
— Skellefteå school decision
In the Mercadona case, the Spanish DPA fined the controller EUR 2,520,000 after a facial recognition system captured all store entrants, including minors, with the DPIA failing to account for children's specific risks. The AEPD has separately treated "affecting the rights of minors" as an aggravating factor in sanction assessment. The EDPB's breach notification guidance identifies children as warranting elevated concern:
"A breach may affect personal data concerning children or other vulnerable individuals, who may be placed at greater risk of danger as a result."
— EDPB Guidelines 9/2022
Status of the Debate
The regulatory perimeter around minors remains contested. Member State divergence on the digital consent age (13 versus 16) creates cross-border compliance friction. The EDPB's February 2025 Statement on Age Assurance signals an emerging regulatory consensus on age-verification methods, but no court has yet ruled on whether specific mechanisms satisfy Article 8(2)'s "reasonable efforts" standard. National family courts have adjudicated minors' interests extensively but outside the data protection context. A CJEU preliminary reference on the proportionality of age-assurance technologies would be needed to settle whether particular methods are required or merely permitted.
Practical Guidance
- Default to 16: Apply the 16-year consent threshold unless you have confirmed the specific Member State has lowered it to 13 under Article 8(1).
- Verify parental consent: Implement age-appropriate verification — the "reasonable efforts" standard in Article 8(2) is technology-dependent, and the Skellefteå enforcement shows consent fails where the power imbalance is structural.
- Account for minors in DPIAs: The Mercadona fine demonstrates that failing to assess children's specific risks in impact assessments is independently sanctionable.
- Adapt transparency: Provide information in clear, age-appropriate language for services directed at or predominantly used by minors, per DSA Art. 14(3) and GDPR Art. 57(1)(b).
- Elevate breach response: Treat breaches involving minors' data as higher-risk events, prioritizing notification and mitigation per EDPB guidance.
why this is here
the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility
This article contains the principal GDPR provision specifically regulating the processing of children's personal data, establishing the age of consent and parental involvement, which are central to the special protections for minors.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
it should ensure that the vocabulary, tone and style of the language used is appropriate to and resonates with children
The document specifically addresses the requirement to adapt transparency information for children, which is a key aspect of minor protection.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The GDPR requires additional safeguards when the processing is about children’s personal data, as the latter may be less aware of the risks and consequences.
The document mentions children's specific vulnerability to deceptive patterns, but this is not the core focus.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the personal data have been collected in relation to the offer of information society services to a minor (Article 17.1.f)
The document lists minors as one of the grounds for erasure but does not elaborate on child-specific protections.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The more precise requirements in this regard depend on the circumstances of the data processing as well as the data subject's ability to grasp and comprehend the communication (for example taking into account that the data subject is a child or a person with special needs).
The document mentions children as a factor in tailoring information, but it is not the central topic.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Nothing of this type on this topic.
This is the top of each pile — all 62 Case Law · all 49 Guidance · all 91 Enforcement · all 31 Literature · all 70 News