The General Data Protection Regulation has applied across the European Union since 25 May 2018 and has always treated children as a special case. Yet many organisations that handle children's data still assume the only child-specific rule is an age of consent. In fact, protection for children runs through the Regulation's lawful bases, transparency duties, profiling and erasure rules, and risk assessments. Regulators have issued some of the largest fines in its history over children's accounts.

How does GDPR protect children's data in the EU?

GDPR protects children because they may be less aware of data processing risks. It sets a digital age of consent between 13 and 16, depending on the member state, requires child-friendly privacy information, weighs children's interests heavily in legitimate interests assessments, strengthens their right to erasure, and restricts profiling and automated decisions about them.

The starting point: Recital 38

Recital 38 states the principle that the rest of the Regulation applies: children merit specific protection with regard to their personal data, because they may be less aware of the risks, consequences, safeguards and rights involved. It singles out two areas for particular care: using children's data for marketing or to build personality or user profiles, and collecting data from children through services offered directly to them. It also says that parental consent should not be necessary for preventive or counselling services offered directly to a child, which matters for helplines and support services.

Recitals are not binding on their own, but regulators and courts use them to interpret the articles that follow.

Article 8: the digital age of consent

Article 8 applies in a narrow situation: an organisation relies on consent as its lawful basis, and it offers an information society service (broadly, an online service) directly to a child. In that case, a child can consent on their own from age 16. Below that age, consent must be given or authorised by the holder of parental responsibility. Member states may lower the threshold, but not below 13.

The result is a patchwork. The ages set in national law for the 27 EU member states are:

  • 13: Belgium, Denmark, Estonia, Finland, Latvia, Malta, Portugal, Sweden.
  • 14: Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain.
  • 15: Czech Republic, France, Greece, Slovenia.
  • 16: Croatia, Germany, Hungary, Ireland, Luxembourg, the Netherlands, Poland, Romania, Slovakia.

Slovenia is the most recent change: its Personal Data Protection Act (ZVOP-2), in force since 26 January 2023, set the age at 15. The United Kingdom set 13 under the Data Protection Act 2018, but the UK is no longer in the EU and applies its own UK GDPR.

Three points are often missed:

  • Article 8 is not a general "age of data protection". It only governs consent for online services offered directly to children. A school relying on its public task, or a charity processing data under a contract or legitimate interests, is not applying Article 8, although every other child-specific rule still applies.
  • "Reasonable efforts" to verify parental consent. Article 8(2) requires the controller to make reasonable efforts, taking into account available technology, to verify that consent was given or authorised by a parent. What is reasonable scales with the risk of the processing.
  • Which age applies across borders. The GDPR does not say which member state's threshold governs a service offered in several countries. Services offered across the EU need a documented position on which threshold they apply, and many simply apply 16 throughout to stay on the safe side.

Transparency, legitimate interests and erasure

Several articles contain explicit references to children:

  • Article 12(1): child-friendly information. Information must be concise, transparent, intelligible and in clear and plain language, "in particular for any information addressed specifically to a child". An adult privacy notice does not meet this for a service children use.
  • Article 6(1)(f): legitimate interests. This lawful basis fails where the data subject's interests or fundamental rights override the organisation's interests, "in particular where the data subject is a child". It remains available, but the balancing test starts weighted towards the child and should be documented.
  • Article 17: erasure. Article 17(1)(f) gives a right to erasure where data was collected in relation to an online service offered to a child under Article 8(1). Recital 65 explains why: a person who consented as a child, without being fully aware of the risks, should be able to have that data removed, especially on the internet, even after they are no longer a child.

Profiling and automated decisions

Article 22 gives everyone the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Recital 71 adds that such decisions "should not concern a child". The Article 29 Working Party's guidelines on automated decision-making, endorsed by the European Data Protection Board (EDPB), recommend that organisations should not, as a rule, rely on the Article 22(2) exceptions to make such decisions about children.

For organisations using recommender systems, risk scores or AI tools that assess or target children, this is where GDPR bites hardest in practice.

Data protection impact assessments

Article 35 requires a data protection impact assessment (DPIA) where processing is likely to result in a high risk. The Article 29 Working Party's DPIA guidelines list nine criteria, and processing that meets two of them will usually need a DPIA. One criterion is data concerning vulnerable data subjects, which expressly includes children. Combined with large scale, innovative technology or systematic monitoring, a DPIA will normally be needed. Some national authorities also include children's data on their own lists of processing that requires one.

A DPIA is not the same as a child rights impact assessment, which covers children's wider rights, but the two work best together.

Enforcement: what regulators have fined

The two largest children's data decisions both came from Ireland's Data Protection Commission (DPC), after disputes with other EU authorities were resolved by the EDPB:

  • Instagram, €405 million (decision of 2 September 2022). Children's personal accounts were set to public by default, and children who switched to business accounts had their email addresses and phone numbers published. The DPC found infringements of Articles 5, 6, 12, 24, 25 and 35, including a failure to carry out a DPIA.
  • TikTok, €345 million (decision of 1 September 2023). Child users' accounts were public by default during the second half of 2020, and the "Family Pairing" feature allowed an unverified adult to link to a child's account. The DPC found infringements of Articles 5, 12, 13, 24 and 25. An EDPB binding decision added a finding that TikTok breached the fairness principle through design that nudged users towards more public options.

Default settings, design choices and missing risk assessments are enforcement targets, not only data breaches.

What the EDPB is doing on children

In February 2025 the EDPB adopted Statement 1/2025 on age assurance, setting out ten principles for processing personal data to determine a user's age or age range. Its core message is that age assurance should be proportionate to risk, use the least intrusive effective method, and not become a route to identifying or tracking users. On Data Protection Day, 28 January 2026, the EDPB confirmed it is working on guidelines on the processing of children's data. At the time of writing those guidelines have not been finalised.

How GDPR interacts with the DSA and the AI Act

GDPR does not operate alone. Article 28(2) of the Digital Services Act bans online platforms from showing advertisements based on profiling, as defined in GDPR, to users they are aware with reasonable certainty are minors. Article 28(3) adds that platforms are not required to process extra personal data to find out whether a user is a minor. The two regimes are designed to be read together, as the comparison of the DSA and the UK Online Safety Act explains.

The AI Act adds a further layer. Its prohibition on AI that exploits vulnerabilities due to age has applied since 2 February 2025. Obligations for high-risk AI systems listed in Annex III, which include some education uses, were deferred by the Digital Omnibus on AI and now apply from 2 December 2027. Any AI system that processes children's data must still comply with GDPR in full throughout.

National guidance worth knowing

  • Ireland: the DPC's Children Front and Centre: Fundamentals for a Child-Oriented Approach to Data Processing (December 2021) sets out 14 principles for services directed at, intended for or likely to be accessed by children.
  • The Netherlands: the Code for Children's Rights, developed by Leiden University and Waag for the Dutch government in 2021, gives app and game designers ten principles built on the UN Convention on the Rights of the Child and GDPR.
  • France: the CNIL published eight recommendations to enhance the protection of children online in June 2021, including parental consent under 15 and privacy-respecting age checks.

What this means for organisations that handle children's data

GDPR applies to any organisation established in the EU, and under Article 3(2) to organisations outside the EU that offer goods or services to people in the Union or monitor their behaviour there. An app developer in Singapore offering a service to children in Spain is within scope.

For schools, NGOs, charities, apps and platforms, the practical steps are similar:

  1. Map children's data, the lawful basis for each activity, and whether Article 8 applies.
  2. Set age thresholds by country where you rely on consent for online services, and decide how you will make reasonable efforts to verify parental consent.
  3. Carry out a DPIA for any significant processing of children's data, and record the legitimate interests balancing where you rely on it.
  4. Rewrite privacy information so that the children who use the service can actually understand it.
  5. Review defaults and design: private by default, no profiling-based marketing to children, and no nudging towards less protective settings.
  6. Make erasure easy, including for data collected in childhood.
  7. Train staff who handle children's data, and build data protection into your safeguarding policy framework rather than treating them as separate.

Child Safe ME advises organisations on online safety and regulatory compliance for children, including how GDPR, the DSA and the AI Act fit together.

Frequently asked questions

What is the age of digital consent in the EU? The GDPR default is 16, but member states may lower it to 13, 14 or 15. Eight member states use 13, six use 14, four use 15 and nine keep 16. It applies only where consent is the lawful basis for an online service offered directly to a child.

Does GDPR apply to organisations outside the EU? Yes. Under Article 3(2), it applies to organisations that offer goods or services to people in the EU, or monitor their behaviour there, wherever the organisation is based.

Do schools need parental consent to process pupils' data? Not usually. Most school processing relies on public task or legal obligation, not consent, so Article 8 does not apply. The other child-specific protections, including transparency, DPIAs and erasure rights, still do.

Is profiling children banned under GDPR? Not outright. Recital 71 says solely automated decisions with significant effects should not concern a child. The Digital Services Act separately bans profiling-based advertising to minors on online platforms.

Regulatory details cited here are accurate as of September 2026 and should be checked against EUR-Lex, the EDPB and the relevant national data protection authority before being relied on in a compliance decision.

Work with Maryam

Looking for expert guidance on child safeguarding, online safety, or AI governance? Maryam and the Child Safe ME team are here to help.

Get in Touch