WorldPrivacyAtlas
Laws by country

Children & Minors Protections

General Data Protection Regulation — conditions applicable to a child's consent for information society services

GDPR Art. 8

European Union · May 25, 2018 (GDPR Art. 8); DSA Art. 28 applicable from February 17, 2024

Where an online service offered directly to a child relies on CONSENT as its lawful basis, Art. 8 makes that consent valid only from age 16 — below that, it must be given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that, taking available technology into account. The trap for a business treating 'the EU' as one jurisdiction is Art. 8(1)'s second sentence: member states may set a lower age, not below 13, and many have, so the operative threshold is 13, 14, 15, or 16 depending on the country — there is no single EU age of digital consent. Art. 8 also only governs consent; it does not authorise processing a child's data on another lawful basis without further care. Separately, DSA Art. 28 requires providers of online platforms accessible to minors to put appropriate privacy, safety, and security measures in place and prohibits advertising based on profiling where the provider is aware with reasonable certainty that the user is a minor.

Regulation (EU) 2016/679, Art. 8; Regulation (EU) 2022/2065 (Digital Services Act), Art. 28Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.