Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Roinn

3 min read

Writen by Zlatko Delev

Posted on: July 9, 2021

Dealing with Children’s Data

According to the GDPR, children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerns and their rights in relation to the processing of personal data.


Definition under the GDPR

Any information given to, or provided in communication with, a child must be in “such a clear and plain language that the child can easily understand”.

Where a child asks a business to provide a service for which payment is normally made, parental consent will be required unless the child is aged 16 years or over.

How does GDPR Age of consent differ across EU ?

Many EU member countries have the same age as the UK, with only one or two older and surprisingly some nations having no provisions at all.

  • Austria – 14 years old
  • Belgium – 13 years old
  • Czech Republic – 15 years old
  • Denmark – 13 years old
  • Finland – 13 years old
  • France – 15 years old (or younger with parental consent)
  • Germany – None
  • Hungary – None
  • Ireland – 16 years old
  • Italy – 14 years old
  • Netherlands – 16 years old
  • Poland – None
  • Slovakia – 16 years old
  • Spain – 14 years old
  • Sweden – 13 years old

What should your business be doing?

First, consider whether any of your services are targeted at children, or used by children. If so, it is important to ensure that your terms and conditions are up to date and satisfy the “clear and plain language” requirement.

Secondly, if your business does process any personal data relating to children, review how you obtain consent at the point of collecting that data. Do you take steps to verify the child’s age? Are those steps reasonable? And if the child is under 13 years old (in the UK), how can you ensure that you obtain the consent of someone with parental responsibility for that child?

And then take steps to ensure that, should a data subject ever look to exercise its rights under the GDPR, you verify the age of the data subject before responding …and if the data subject is a child, ensure you respond in suitable language. Or potentially, if the child is particularly young, consider responding instead to somebody with parental responsibility for the child.

Déan Teagmháil Linn

Tá súil agam go mbeidh sé seo úsáideach duit. Má theastaíonn Ionadaí AE uait, má tá aon cheist GDPR agat, nó má fuair tú iarratas SAR nó Rialálaí agus má theastaíonn cabhair uait, déan teagmháil linn ag am ar bith. Táimid i gcónaí sásta cabhrú ...
Foireann áitiúil GDPR.

Déan Teagmháil Linn

Recent blogs

Navigating the Contradictions: Automated Decision-Making and Regulatory Legislation in AI Systems

The Dilemma of Automated Decision-Making At the heart of AI systems lies the promise of aut

How to Implement the New AI Law in Your Company

The implementation of the AI Act marks a significant stride towards responsible and fair use of art

Article 14 Guide: Meeting Regulatory Requirements for Personal Data Not Directly Obtained from Data Subjects

Imagine a software-as-a-service (SaaS) company looking to grow its clientele by purchasing leads fr

Faigh Do Chuntas Anois

Socraigh i gceann cúpla nóiméad. Cuir isteach sonraí do chuideachta agus roghnaigh na seirbhísí a theastaíonn uait.

Cruthaigh Cuntas

Téigh i dteagmháil

Níl tú cinnte cén rogha atá le roghnú? Glaoigh, ríomhphost, comhrá a dhéanamh linn
am ar bith.

Déan Teagmháil Linn
06 EOLAS GDPR

Fan Suas chun Dáta

Fág do chuid sonraí anseo agus seolfaimid nuashonruithe agus faisnéis chugat maidir le gach gné den GDPR agus d'Ionadaí an AE. Ní bheidh muid bombard tú le ríomhphoist agus beidh tú in ann a insint dúinn chun stop a chur ag am ar bith.

Tá Ainm Iomlán ag teastáil!

Tá Ríomhphost Gnó ag teastáil!

Tá cuideachta ag teastáil!

Glac leis na Téarmaí agus Coinníollacha agus an Polasaí Príobháideachais