Children's Data Under GDPR Consent & Age Check

Children’s Data Under GDPR: Consent, Age Checks and the Latest Rules

Updated: October 2026

The GDPR applies the same rules to everyone but requires more from organisations when the person is a child. Recital 38 says children merit specific protection because they may be less aware of the risks, the consequences and their rights. That sentence sits behind every child-specific duty in the Regulation.

This guide covers when a child can consent for themselves, how to verify parental consent, what regulators have fined, and how the EU’s 2025 and 2026 child-safety measures sit next to the GDPR.

Key Takeaways

• Article 8 GDPR applies when you rely on consent to offer an online service directly to a child. The default age is 16; member states can lower it to 13, and you must make reasonable efforts to verify parental consent. The age differs by country, so check each market you serve.

• The Irish Data Protection Commission fined Instagram €405 million (2022) and TikTok €345 million (2023) over children’s data, mostly for default settings and the way information was presented. Protective defaults, plain-language notices and a DPIA are where a review should begin.

• The EDPB’s Statement 1/2025 says age checks must be as non-intrusive as possible. The Commission’s EU KIDS Act proposal of 17 September 2026 is still a proposal. It would restrict under-15s on social networks and video-sharing platforms and would apply alongside the GDPR’s consent rules.

Article 8 Sets the Consent Rule for Online Services Offered to Children

Article 8(1) applies where you rely on consent (Article 6(1)(a)), and you offer an information society service directly to a child. The processing is lawful if the child is at least 16. Below 16, it is lawful only if the holder of parental responsibility gives or authorises the consent. Member States may set a lower age by law, provided it is not below 13.

The rule only applies when consent is the legal basis. If you process a child’s data under a contract, a legal obligation or legitimate interests, Article 8 does not apply, although the other safeguards in this guide still do. Article 6(1)(f) adds that, under legitimate interests, you must give particular weight to the interests and rights of a child data subject.

The rule covers information society services, meaning services normally provided for remuneration, at a distance, by electronic means, and at the individual request of the user. Remuneration does not have to come from the user, so free apps, games and social platforms funded by advertising generally fall in scope.

The Digital Age of Consent Varies Across the EU

Article 8 lets each member state choose an age between 13 and 16, so the same app may require parental consent for a 14-year-old in one country but not in the next. GDPRLocal keeps a country-by-country list on its digital age of consent page. It currently shows 16 for Germany, Hungary, Ireland, Luxembourg, the Netherlands, Poland, Romania and Slovakia, 15 for France, Greece and the Czech Republic, 14 for Austria, Bulgaria, Cyprus, Italy, Lithuania and Spain, and 13 for Belgium, Denmark, Estonia, Finland, Latvia, Malta, Portugal and Sweden.

National laws change, so confirm the current age in the national statute before you set age gates for a market. A service that reaches several countries can apply the highest age it serves everywhere, which is simple to run and keeps costs down for teenagers. It can also apply the age of the user’s country, which preserves that reach but requires reliable location and age signals.

The United Kingdom sets the age at 13 in section 9 of the Data Protection Act 2018.

Controllers Must Make Reasonable Efforts to Verify Parental Consent

Article 8(2) requires the controller to make reasonable efforts to verify that the holder of parental responsibility gave or authorised the consent, taking available technology into account. The Regulation names no method, and what counts as reasonable depends on the risk.

A newsletter for teenagers and a service that collects location data from young children sit at different points on that scale. As the risk increases, a tick box stops being enough. Controllers use an email to the parent with a confirmation step, a small payment through a card the parent controls, or a check against an identity service. Each option collects more personal data, so collect only what the verification needs and delete it once the check is complete. Record why you judged the method reasonable.

Age Assurance Must Follow Data Protection Principles

Before you can apply an age threshold, you need some way to tell who is under it. The EDPB addressed this in Statement 1/2025 on age assurance, adopted on 11 February 2025. The Board lists ten principles for the compliant processing of personal data when determining the age or age range. The EDPB Chair said at the time that the method used to verify age must be as least intrusive as possible and that children’s personal data must be protected. The Board repeated that position on Data Protection Day 2026.

Asking for a full identity document to check whether someone is over 13 is therefore hard to defend where a lighter method gives the same answer. Age signals collected for one purpose should not be reused for profiling or marketing. The ten principles are set out in the statement itself: Statement 1/2025 on age assurance.

Privacy Information for Children Must Be Written for Children

Article 12(1) requires information to be concise, intelligible and easily accessible, in clear and plain language, “in particular for any information addressed specifically to a child”. Recital 58 says the same. A privacy policy written in a lawyer’s vocabulary fails this test when the user base includes 13-year-olds.

The youngest users you allow need a shorter notice that gives the same facts in simpler words, with short explanations at the point where you collect data. Test the text on people of the target age. Keep the adult notice for parents, who need to see what the service does with their child’s data.

Design and Default Settings Carry the Most Enforcement Risk

Article 25 requires data protection by design and by default. For a child-facing service, the default should be the most protective setting, and the user or a parent should have to take a clear step to reduce it. Two of the best-known children’s data fines under the GDPR came from the Irish Data Protection Commission, and both turned on this point.

Instagram, €405 million (September 2022). The inquiry examined the public disclosure of children’s email addresses or phone numbers through the business account feature and a public-by-default setting for children’s personal accounts. The decision records infringements of Articles 5(1)(a), 5(1)(c), 6(1), 12(1), 24, 25(1), 25(2) and 35(1), and the total includes €20 million for the Article 6(1) infringement. The DPC also issued a reprimand and a compliance order. The case went to the EDPB under Article 65, which adopted its binding decision on 28 July 2022.

TikTok, €345 million (September 2023). The DPC’s final decision of 1 September 2023 followed an EDPB binding decision under Article 65. It covered the period 31 July to 31 December 2020 and users aged 13 to 17. The findings dealt with public-by-default account settings, the Family Pairing feature, age verification, transparency under Articles 12 and 13, the principle of fairness, and dark patterns. The DPC issued a reprimand, a three-month compliance order and the fine. TikTok has appealed.

Public visibility must be an opt-in for a child, and interface choices that nudge a child toward sharing more data can themselves be a fairness problem. A DPIA is expected before launch: Article 35(1) was among the Instagram infringements.

A DPIA Is the Starting Point for Any Service Used by Children

Article 35 requires a data protection impact assessment where processing is likely to result in a high risk. Children are vulnerable data subjects, and profiling, large-scale tracking, location data and age estimation all raise the risk. A children’s DPIA should cover the likely users, including those below your minimum age who sign up anyway; the data collected; the default settings; how age and parental consent are checked; retention; and what happens when a child reaches the national age of consent. If a high residual risk remains, Article 36 requires prior consultation with the supervisory authority.

Children keep every data subject right. Recital 65 stresses the right to erasure for data collected in childhood, so an adult can ask you to delete what they shared as a teenager, and you cannot rely on the original consent to refuse. Recital 71 says automated decision-making with legal or similarly significant effects should not concern a child.

The Digital Services Act and the EU KIDS Act Add Platform Duties

Article 28 of the Digital Services Act requires online platforms accessible to minors to put in place appropriate and proportionate measures for a high level of privacy, safety and security. The Commission published guidelines on that article on 14 July 2025, together with a prototype age-verification app. The EDPB adopted final guidelines on how the DSA and the GDPR relate on 21 September 2026, and it is also drafting dedicated guidelines on children’s data.

On 17 September 2026, the Commission published its proposal for the EU KIDS Act. It is only a proposal, and the European Parliament and the Council must agree before it applies. According to Latham & Watkins’ analysis, it would restrict access to social networking and video-sharing platforms for under-15s, require EU-certified age verification on those platforms, and add safety-by-design duties for users under 18 across app stores, games, operating systems, AI companions and chatbots. The proposal says its age limits apply alongside the GDPR’s parental consent rules, so a 15-year-old could open an account under the KIDS Act without being able to give valid consent to the related data processing under national law. Article 8 and the national ages remain the rules in force today.

For services offered in the UK, the ICO updated its Children and the UK GDPR guidance on 15 May 2026 to reflect the Data (Use and Access) Act 2025. The ICO guidance is the place to check the Act’s specific changes.

GDPRLocal helps organisations with children’s data assessments, DPIAs and age-assurance design. See our GDPR consultant services or our work on AI governance if your service uses AI features with young users.

Conclusion

Children’s data work under the GDPR comes down to four decisions: which legal basis you use, what age rule applies in each country, how you check age and parental consent, and what the default settings look like for a child. The fines on Instagram and TikTok were about defaults, information and design, and that is where a review should begin.

GDPR rules are changing. The EDPB is drafting its own children’s data guidelines, and the EU KIDS Act would add age limits and certified age verification if it is adopted. An organisation that already has protective defaults, a documented age rule and a DPIA will have little left to change when the new rules arrive.

Frequently Asked Questions

At what age can a child consent to data processing under the GDPR?

Article 8 sets the default at 16. Member states can lower it, but not below 13. The applicable age depends on the country, so check the national rule for each market you serve. See our digital age of consent page.

How do we verify that a parent has given consent?

Article 8(2) requires reasonable efforts, taking available technology into account. The method should match the risk of the processing and collect as little additional data as possible. Keep a record of the method and the reasons for choosing it.

Is the EU KIDS Act in force?

No. The Commission proposed it on 17 September 2026, and it still needs agreement from the European Parliament and the Council. The GDPR and the Digital Services Act remain the rules that apply today.

Disclaimer: This blog post is for informational purposes only. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.