Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 8 Conditions applicable to child's consent in relation to information society services


Summary What does Article 8 of the GDPR regulation say?

This article is a specific carve-out from the general consent rules established in Article 6(1)(a), applying them specifically to children in the context of information society services offered directly to them.

It sets 16 as the default minimum age at which a child can independently consent to data processing, while requiring parental consent for younger children.

Member States are given some flexibility to lower this threshold, but not below 13.

The article also places a verification obligation on controllers and clarifies that these rules do not disturb existing Member State contract law relating to children.

Important points:

  • The default age of consent for data processing in information society services is 16, though Member States may lower this to a minimum of 13.
  • Controllers are required to make reasonable efforts to verify that parental consent has been given or authorised for children below the applicable age threshold.
  • These rules apply only where processing is based on consent under Article 6(1)(a) and do not affect Member State contract law regarding children.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.

    2. Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.

    1. The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.

    1. Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod