Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 8 Conditions applicable to child's consent in relation to information society services
Summary What does Article 8 of the GDPR regulation say?
This article is a specific carve-out from the general consent rules established in Article 6(1)(a), applying them specifically to children in the context of information society services offered directly to them.
It sets 16 as the default minimum age at which a child can independently consent to data processing, while requiring parental consent for younger children.
Member States are given some flexibility to lower this threshold, but not below 13.
The article also places a verification obligation on controllers and clarifies that these rules do not disturb existing Member State contract law relating to children.
Important points:
- The default age of consent for data processing in information society services is 16, though Member States may lower this to a minimum of 13.
- Controllers are required to make reasonable efforts to verify that parental consent has been given or authorised for children below the applicable age threshold.
- These rules apply only where processing is based on consent under Article 6(1)(a) and do not affect Member State contract law regarding children.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.
Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.
The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.
Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child.
Relevant recitals
Recital 38 Extra protection for children's data
Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child. The consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
information society service
Definition
consent
Definition
personal data