CHAPTER IIPRINCIPLES

Article 8Conditions applicable to child's consent in relation to information society services

Official text

(1)Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child. Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.

(2)The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.

(3)Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child.

Commentary

I. Introduction: Article 8 Is Not About Children's Privacy - It Is About Children's Capacity to Consent

Article 8 is frequently misunderstood as the GDPR's "children's privacy provision." That description is inaccurate. The GDPR protects every data subject equally, irrespective of age. Article 8 does not create additional privacy rights for children; instead, it addresses a much narrower but legally significant question:

When can a child independently consent to the processing of personal data in connection with information society services?

This distinction is fundamental. The provision does not prohibit the processing of children's personal data. Nor does it establish that children's data enjoy a higher degree of substantive protection than adults' data. Instead, it regulates the validity of consent as a lawful basis under Article 6(1)(a) where the data subject is a child and the processing relates to an information society service offered directly to that child.

Accordingly, Article 8 should be understood as a rule governing legal capacity, not as a general provision on children's privacy. Its function is analogous to legal rules determining when a minor can validly enter into contracts. Just as contract law sometimes restricts a child's ability to assume legally binding obligations, Article 8 restricts the circumstances in which a child can independently authorise the processing of personal data.

The legislature recognised that children occupy a distinctive position within the digital ecosystem. They engage extensively with online services, often from a very young age, yet may lack the cognitive maturity to understand the long-term implications of extensive data collection, profiling, behavioural advertising or algorithmic recommendation systems. The provision therefore seeks to reconcile two potentially competing objectives:

  • protecting children from exploitation and manipulation; and

  • respecting their evolving autonomy as they mature.

Unlike many child protection provisions that adopt an absolute prohibition, Article 8 deliberately attempts to balance these objectives.

II. Why Did the GDPR Introduce a Special Rule for Children?

The rationale for Article 8 becomes apparent when one considers the realities of modern digital services.

Most online platforms are designed to maximise engagement. They rely upon persuasive design, personalised recommendations, behavioural analytics and algorithmic optimisation. Adults may struggle to appreciate the implications of these practices. Children are considerably less equipped to evaluate them.

The legislature therefore identified three principal concerns.

(a) Cognitive Development

Children frequently lack the experience necessary to appreciate future privacy risks.

Unlike adults, they may not fully understand:

  • long-term profiling;

  • targeted advertising;

  • permanent digital records;

  • biometric processing;

  • cross-platform tracking;

  • secondary uses of personal data.

Consequently, their apparent willingness to disclose information may not reflect genuine informed decision-making.

Illustration 1

A twelve-year-old downloads a gaming application that requests access to contacts, precise location, photographs, microphone and advertising identifiers. The child eagerly accepts every request because the application promises additional game features. Although the child technically agrees, the legislature questions whether such agreement genuinely reflects informed and autonomous decision-making.

(b) Commercial Vulnerability

Children are particularly susceptible to commercial influence.

Gamification, rewards, social validation, scarcity messages and influencer marketing may affect children's choices far more significantly than adults'.

The GDPR therefore recognises that children's apparent consent may often be shaped by persuasive design rather than rational evaluation.

Illustration 2

A social media platform informs young users: "Accept personalised advertising and unlock exclusive stickers." The reward is insignificant economically but highly attractive socially. The child's decision is influenced less by an understanding of data processing than by the desire to participate in peer interactions.

(c) Long-Term Consequences

Personal information disclosed during childhood may remain available for decades.

Children rarely appreciate that information shared today may later influence:

  • university admissions;

  • employment opportunities;

  • insurance assessments;

  • reputation;

  • algorithmic profiling.

Article 8 therefore reflects a precautionary approach to long-term informational autonomy.

III. Article 8 Does Not Apply to Every Processing Operation

One of the most overlooked aspects of Article 8 is its limited scope.

The provision applies only where three cumulative conditions are satisfied.

Article 8 is engaged only where processing relies upon Article 6(1)(a).

If another lawful basis applies, Article 8 becomes irrelevant.

Illustration 3

A school processes students' examination records because national education law requires it. The lawful basis is legal obligation or public task. Article 8 does not apply.

Illustration 4

A hospital processes a child's medical records to provide emergency treatment. The lawful basis derives from healthcare legislation rather than consent. Again, Article 8 is inapplicable.

Illustration 5

An online language-learning platform requests permission to send personalised marketing emails to children. The controller relies exclusively upon consent. Article 8 becomes directly relevant.

Critical Interpretation

Many organisations incorrectly assume that because children are involved, parental consent is automatically required.

That is incorrect.

Article 8 regulates consent-based processing only.

It does not transform every processing activity involving children into consent-based processing.

IV. "Information Society Service"

The second requirement is equally important.

Article 8 applies only where processing occurs in connection with an information society service.

This expression originates in broader EU legislation and generally refers to services supplied:

  • at a distance;

  • electronically;

  • at the individual request of the recipient;

  • usually for remuneration (although remuneration is interpreted broadly and includes advertising-supported services).

The definition therefore encompasses much more than commercial websites.

Examples

include:

  • social media;
  • online games;
  • streaming platforms;
  • educational applications;
  • cloud storage;
  • search engines;
  • mobile applications;
  • messaging platforms;
  • online marketplaces.

Illustration 6

Social Media A platform allows thirteen-year-olds to create personal profiles. Because the platform constitutes an information society service offered directly to children, Article 8 applies.

Illustration 7

Online Gaming A multiplayer gaming platform requests children's consent for behavioural advertising. The service clearly falls within Article 8.

Illustration 8

Physical Toy Store A child purchases a toy from a physical retail store. The transaction occurs offline. Article 8 is generally not engaged.

Difficult Question

Suppose a physical toy includes a companion mobile application collecting behavioural data.

Does Article 8 apply?

Almost certainly yes.

Although the toy itself is physical, the associated application constitutes an information society service.

V. "Offered Directly to a Child"

Another interpretative issue concerns the phrase:

"offered directly to a child."

This wording is narrower than "accessible by children."

Almost every website is technically accessible to children.

Accessibility alone cannot determine the scope of Article 8.

Instead, regulators examine whether the controller intentionally provides services for children.

Relevant indicators include:

  • visual design;

  • language;

  • marketing;

  • animations;

  • child-oriented branding;

  • educational focus;

  • intended audience.

Illustration 9

A cartoon-based mathematics application marketed to primary school students is plainly directed at children.

Illustration 10

A professional accounting software platform is technically accessible to children but is clearly designed for accountants. Article 8 is unlikely to apply merely because a child manages to register.

Illustration 11

A video-sharing platform serves both adults and children. The assessment becomes fact-specific. Controllers may need age assurance mechanisms to distinguish between user groups.

VI. The Age Threshold: Why 16?

The GDPR establishes 16 years as the default age for independent consent while allowing Member States to reduce the threshold to13 years.

This compromise reflects the absence of European consensus regarding children's digital maturity.

The legislature deliberately refrained from imposing complete harmonisation.

Instead, Member States retain limited discretion.

Consequences of National Variation

This flexibility introduces significant practical challenges.

A multinational platform operating throughout the European Union cannot assume that a single age threshold applies everywhere.

Controllers must therefore identify:

  • the applicable national legislation;

  • the child's habitual residence;

  • appropriate age-verification mechanisms.

Illustration 12

A platform operates across France, Germany, Ireland and Spain. Different Member States have adopted different age thresholds. The platform cannot automatically apply a uniform age of sixteen unless national law permits.

VII. Does Article 8 Require Absolute Age Verification?

Perhaps the most difficult practical issue concerns verification.

Article 8 requires controllers to make reasonable efforts, taking available technology into consideration, to verify parental authorisation where required.

The legislature intentionally avoided imposing strict identity verification obligations.

Why?

Because excessive verification could itself undermine privacy.

Suppose every online service required:

  • passports;

  • facial recognition;

  • biometric verification.

Children would paradoxically disclose even more personal data merely to protect their privacy.

Article 8 therefore adopts a proportionality standard.

Controllers must implement verification measures appropriate to:

  • the risks of processing;

  • the nature of the service;

  • available technology;

  • likely age of users.

Illustration 13

Newsletter A museum asks children to subscribe to educational newsletters. The privacy risks are relatively low. A simple parental confirmation email may constitute reasonable verification.

Illustration 14

Social Network A platform collects photographs, location history, behavioural analytics and extensive social interaction data. Much stronger verification measures are likely required because of the substantially greater risks.

Illustration 15

Online Banking A financial application providing services to minors processes sensitive financial information. The expected verification standard is considerably higher than for a simple educational newsletter.

VIII. "Reasonable Efforts" Is Not Strict Liability

The phrase "reasonable efforts" deserves careful attention.

Controllers are not required to guarantee that every parent genuinely authorised every account.

Instead, they must demonstrate that the verification measures adopted were objectively reasonable under the circumstances.

This distinction reflects another recurring theme within the GDPR: accountability rather than perfection.

A controller implementing proportionate, well-documented verification measures will generally satisfy Article 8 even if isolated cases of circumvention occur.