Digital Age of Consent under the GDPR

Digital Age of Consent under the GDPR

Updated: August 2026

GDPR sets a specific rule for when children can give their own consent to have their personal data processed. Under Article 8, where a business relies on consent to process a child’s data for an information society service offered directly to them, that consent is valid once the child turns 16. The business must also make reasonable efforts, using whatever technology is available, to confirm that consent, when needed, comes from the child’s parent or legal guardian.

Below that age threshold, processing is lawful only if a parent or legal guardian gives or authorises consent. GDPR lets member states lower the default age, but not below 13, and EU countries have taken that option in very different directions: some kept 16, others dropped it to 13, and a few set it at 14 or 15. The list below sets out the specific age, the relevant national law, and the supervisory authority for each jurisdiction.

Key Takeaways

GDPR sets 16 as the default digital age of consent, but lets EU member states lower it to as little as 13. Across the EU and UK, the result is real variation: 10 jurisdictions kept 16, 9 dropped to 13, and the rest sit at 14 or 15.

Below the applicable age threshold, a business can only lawfully process a child’s data with consent from a parent or legal guardian, and it’s on the controller to make reasonable efforts to verify that.

There’s no single “EU digital age of consent.” A business serving children across multiple EU countries needs to check the specific threshold in each market it operates in, since a consent flow built for one country’s age of 13 won’t be valid in a country that requires 16.

Austria

Relevant legislation: The processing of personal data is regulated under the Federal Act concerning the Protection of Personal Data.

Digital age of consent: Under 14(4) of the Act, if a provider relies on consent as a lawful basis for processing personal data in relation to information society services offered directly to children, only children aged 14 or above can provide their own consent.

Supervisory authority: The Austrian Data Protection Authority (Österreichische Datenschutzbehörde, DSB) is responsible for ensuring compliance with data protection laws.

Belgium

Relevant legislation: The processing of personal data is regulated under the Act of 30 July 2018 on the Protection of Individuals with Regard to the Processing of Personal Data.

Digital age of consent: According to Article 7 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Data Protection Authority (L’Autorité de protection des données (APD)) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Bulgaria

Relevant legislation: The processing of personal data is regulated under the Bulgarian Personal Data Protection Act.

Digital age of consent: According to Article 25c of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 14 or above are able to provide their own consent.

Supervisory authority: The Commission for Personal Data Protection (Комисията за защита на личните данни) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Croatia

Relevant legislation: The processing of personal data is regulated under the Act on the Implementation of the General Data Protection Regulation.

Digital age of consent: According to Article 19 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The Personal Data Protection Agency (Agencija za zaštitu osobnih podataka) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Republic of Cyprus

Relevant legislation: The processing of personal data is regulated under Law 125(I) of 2018 Providing for the Protection of Natural Persons with Regard to the Processing of Personal Data and for the Free Movement of Such Data.

Digital age of consent: According to Article 8(1) of the Law, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 14 or above are able to provide their own consent.

Supervisory authority: The Commissioner for the Protection of Personal Data (Το Γραφείο Επιτρόπου Προστασίας Δεδομένων) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Czech Republic

Relevant legislation: The processing of personal data is regulated under Act No. 110/2019 Coll. on the processing of personal data.

Digital age of consent: According to Section 7 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 15 or above are able to provide their own consent.

Supervisory authority: The Office for Personal Data Protection (Úřad pro ochranu osobních údajů) is the supervisory authority responsible for ensuring compliance with data protection laws.

Denmark

Relevant legislation: The processing of personal data is regulated under Act No. 502 of 23 May 2018 on Supplementary Provisions to the Regulation of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data.

Digital age of consent: According to Section 6(2) of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Danish Data Protection Agency (Datatilsynet) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Estonia

Relevant legislation: The processing of personal data is regulated under the Personal Data Protection Act 2018 in Estonia.

Digital age of consent: According to Section 8(1) of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Data Protection Inspectorate (Andmekaitse Inspektsioon) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Finland

Relevant legislation: The processing of personal data is regulated under the Data Protection Act (1050/2018).

Digital age of consent: According to Section 5 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Office of the Data Protection Ombudsman, and their Office (Tietosuojavaltuutetun toimisto) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

France

Relevant legislation: The processing of personal data is regulated under Act No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties (as amended).

Digital age of consent: According to Article 45 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 15 or above are able to provide their own consent.

Supervisory authority: The National Commission on Informatics and Liberty (Commission nationale de l’informatique et des libertés, CNIL) is the supervisory authority responsible for ensuring compliance with the data protection laws.

Germany

Relevant legislation: The processing of personal data is regulated under the German Federal Data Protection Act.

Digital age of consent: If a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: There are several national data protection supervisory authorities in Germany responsible for ensuring compliance with the data protection laws. The Federal Commissioner for Data Protection and Freedom of Information acts as the representative of the national data protection authorities.

Greece

Relevant legislation: The processing of personal data is regulated under the Law No. 4624/2019.

Digital age of consent: As per Article 21 of the Law, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 15 or above are able to provide their own consent.

Supervisory authority: The Hellenic Data Protection Authority is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Hungary

Relevant legislation: The processing of personal data is regulated under the Information Self-Determination and Freedom of Information Act.

Digital age of consent: If a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The Hungarian Data Protection Authority (A Nemzeti Adatvédelmi és Információszabadság Hatóság) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Ireland

Relevant legislation: The processing of personal data is regulated under the Irish Data Protection Law.

Digital age of consent: According to Section 31(1) of the Law, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The Data Protection Commission is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Italy

Relevant legislation: The processing of personal data is regulated under the Personal Data Protection Code, Legislative Decree No. 196/2003.

Digital age of consent: According to Article 2-quinquies of the Code, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 14 or above are able to provide their own consent.

Supervisory authority: The Italian Data Protection Authority (Garante per la protezione dei dati personali) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Latvia

Relevant legislation: The processing of personal data is regulated under the Personal Data Protection Law of 21 June 2018.

Digital age of consent: According to Section 33 of the Law, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Data State Inspectorate (Datu valsts inspekcija) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Lithuania

Relevant legislation: The processing of personal data is regulated under the Law on Legal Protection of Personal Data.

Digital age of consent: According to Article 6 of the Law, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 14 or above are able to provide their own consent.

Supervisory authority: The State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Luxembourg

Relevant legislation: The processing of personal data is regulated under the Act of 1 August 2018 on the organisation of the National Commission for Data Protection and implementation of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

Digital age of consent: If a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The National Data Protection Commission (Commission nationale pour le protection des données, CNPD) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Malta

Relevant legislation: The processing of personal data is regulated under the Data Protection Act.

Digital age of consent: If a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Information and Data Protection Commissioner is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Netherlands

Relevant legislation: The processing of personal data is regulated under the Dutch GDPR Implementation Act.

Digital age of consent: According to Article 5 of the Law, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The Dutch Data Protection Authority is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Poland

Relevant legislation: The processing of personal data is regulated under the Act of 10 May 2018 on the Protection of Personal Data.

Digital age of consent: If a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The Personal Data Protection Office is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Portugal

Relevant legislation: The processing of personal data is regulated under Law No. 58/2019.

Digital age of consent: According to Article 16, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The National Data Protection Commission (Comissão Nacional de Protecção de Dados) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Romania

Relevant legislation: The processing of personal data is regulated under Law No. 190 of 18 July 2018 on the implementation of the GDPR (Regulation (EU) 2016/679).

Digital age of consent: If a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The National Supervisory Authority for Personal Data Processing is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Slovakia

Relevant legislation: The processing of personal data is regulated under Act No. 18/2018 Coll. on the protection of personal data and on amendments to certain acts.

Digital age of consent: According to Section 15 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 16 or above are able to provide their own consent.

Supervisory authority: The Office for Personal Data Protection is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Slovenia

Relevant legislation: The processing of personal data is regulated under Law No. 94/07 on Protection of Personal Data.

Digital age of consent: As per the proposed law, a child should be at least 15 years old to provide consent in relation to the processing of personal data offered through information society services, yet the current digital age limit, which is set as 16 under Article 8 of the GDPR, applies until the proposed law enters into force.

Supervisory authority: The Information Commissioner is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Spain

Relevant legislation: The processing of personal data is regulated under the Spanish Data Protection and Digital Rights Act 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights.

Digital age of consent: According to Article 7 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 14 or above are able to provide their own consent.

Supervisory authority: The Spanish Data Protection Agency (Agencia Española de Protección de Datos) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Sweden

Relevant legislation: The processing of personal data is regulated under the Data Protection Act (Act 2018:218) with supplementary provisions to the GDPR.

Digital age of consent: As per Chapter 2, Section 4 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Swedish Authority for Privacy Protection (Datainspektionen) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

United Kingdom

Relevant legislation: The processing of personal data is regulated under the Data Protection Act 2018 (DPA 2018).

Digital age of consent: According to Section 9 of the Act, if a provider relies on consent as a lawful basis for the processing of personal data in relation to information society services offered directly to children, only children aged 13 or above are able to provide their own consent.

Supervisory authority: The Information Commissioner’s Office (ICO) is the supervisory authority that is responsible for ensuring compliance with the data protection laws.

Conclusion

The digital age of consent isn’t a single EU-wide number. It’s a GDPR baseline of 16 that each member state can lower to 13, and most have used that flexibility in one direction or another. For a business operating in a single country, the answer is straightforward: check that country’s threshold and build a consent flow around it. For a business operating across several EU countries, or the UK, the safer approach is usually to apply the highest threshold among the markets served, since that keeps the consent flow valid everywhere rather than needing a different age check for each jurisdiction.

Frequently Asked Questions

What is the default digital age of consent under GDPR?

16, under Article 8(1) of GDPR, for a child to give their own consent to have their personal data processed for an information society service offered directly to them.

Can EU member states change the digital age of consent?

Yes. GDPR lets each member state lower the default age of 16, as long as it doesn’t go below 13. That’s why the age varies across the EU and UK, from 13 in countries like Belgium, Denmark, and Sweden, up to 16 in countries like Germany, Ireland, and Poland.

What happens if a child is below the applicable age of consent?

Processing is lawful only if a parent or legal guardian gives or authorises consent. The controller must also make reasonable efforts, taking available technology into account, to verify that the consent came from someone with parental responsibility.

What should a business serving multiple EU countries do about the digital age of consent?

Since the threshold ranges from 13 to 16 depending on the country, a business offering services to children across several EU markets typically needs either a country-specific consent flow for each jurisdiction, or one consent flow built around the highest age threshold among the markets it serves.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.