Minors
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Special protections for children under GDPR
Overview
21 sources · Jul 15, 2026Legal Framework
Article 8 GDPR establishes the conditions for a child's consent in the context of information society services offered directly to children. Where a controller relies on consent as the lawful basis under Article 6(1)(a), the child must be at least 16 years old to provide valid consent independently. Member States may legislate a lower threshold, but not below 13 years of age. Below the applicable national age, consent must be given or authorized by the holder of parental responsibility. Controllers must make reasonable efforts to verify that parental consent has been obtained, using means appropriate to the available technology and the level of risk involved. Article 8 does not displace national contract law, meaning Member States may permit certain contracts with minors without requiring parental authorization.
Article 35 GDPR adds a further layer: where processing is likely to result in a high risk to the rights and freedoms of natural persons—and processing children's personal data is expressly identified as a factor contributing to high risk—a Data Protection Impact Assessment is mandatory. Recital 38 reinforces the rationale: children merit specific protection because they may be less aware of risks and their rights in relation to data processing.
The Digital Services Act, through Article 28 DSA, complements these protections by imposing additional obligations on online platforms regarding the protection of minors, including restrictions on targeted advertising directed at children based on profiling.
Key Developments
The ICO's enforcement action against MediaLab.AI, Inc.—controller of the image-sharing platform Imgur—resulted in a fine of approximately EUR 284,450 and illustrates a concrete enforcement posture toward platforms accessible to minors. The Swedish DPA's fine of EUR 565,000 against Sportadmin i Skandinavien AB, arising from a cyberattack exposing personal data, underscores that inadequate security measures affecting minors' data carry significant financial consequences.
The Article 29 Working Party's transparency guidelines (WP260 rev.01) establish that privacy notices directed at children must use clear, age-appropriate language. Controllers cannot satisfy transparency obligations under Articles 12 and 13 GDPR by providing notices comprehensible only to adults when the service targets children.
CJEU jurisprudence, including the Schrems decision, confirms that supervisory authorities bear an active duty to monitor compliance with data protection rules—including transfers and processing affecting minors—reinforcing that protections for children's data are not merely aspirational but actively policed.
Practical Guidance
Determine the applicable age threshold: Identify the Member State-specific digital age of consent (ranging from 13 to 16) for each jurisdiction where your information society service is offered, as this directly governs whether a child can consent independently or requires parental authorization under Article 8(1) GDPR.
Implement age verification and parental consent mechanisms: Deploy age-assessment tools proportionate to the risk of processing. For low-risk services, self-declaration may suffice; for higher-risk processing, more robust verification methods are required. Document the technical measures chosen and the rationale for their adequacy.
Conduct a Data Protection Impact Assessment: Article 35(3)(b) GDPR mandates a DPIA where processing involves systematic monitoring of a large scale of data, and the involvement of minors is an explicit risk factor. The DPIA must specifically address vulnerabilities of child users and mitigation measures.
Draft child-appropriate privacy notices: Transparency information provided to children must be concise, intelligible, and in language suited to the child's age, consistent with Article 12(1) GDPR and the WP260 guidelines. Layered notices—summary for children, full text for parents—are a recognized approach.
Restrict profiling and targeted advertising: Article 22 GDPR and Article 28 DSA constrain automated decision-making and targeted advertising directed at minors. Controllers should disable behavioral profiling for child users unless strictly necessary and legally justified.