GDPR treats children as data subjects who merit specific protection, and Article 8 builds a dedicated consent regime around them. When an online service is offered directly to a child and relies on consent, that consent is valid only from a user at or above the national age threshold; below it, a parent must consent or authorize, and the controller must make reasonable efforts to verify that. Recital 38 explains why: children are less aware of the risks and their rights.
| Regulation | GDPR, Article 8 |
|---|---|
| Consent age | 16 default; member states may lower to 13 |
| Max penalty | EUR 20M or 4% of global annual turnover |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The patchwork of consent ages
The single hardest operational fact: the threshold is national. Ireland, Germany, the Netherlands, and others kept 16. France chose 15, Spain 14, and a large group including Denmark, Sweden, Belgium, and Portugal went to 13. A service available across the EU cannot apply one age; it needs to know where the user is and apply that country’s rule. Age gates that ask for a birth date with no friction are widely used but increasingly criticized; regulators expect risk-proportionate assurance, and the UK’s Age Appropriate Design Code (covered in our companion guide) pushes the same direction.
What enforcement punishes: defaults
The two landmark children’s cases were about product defaults rather than data breaches. The Irish DPC fined Meta EUR 405 million in September 2022 because Instagram let 13-to-17-year-olds open business accounts that published their contact details, with public accounts as the default. A year later TikTok took EUR 345 million for public-by-default child accounts and a family pairing feature that let unverified adults link to children’s accounts. The design lesson generalizes: for minors, the private option must be the default, and features that expose children’s data need justification, not just a toggle.
The DSA reinforced this from February 2024: platforms may not serve profiling-based ads to users they should reasonably know are minors (Article 28), regardless of consent.
Compliance checklist
- Determine whether your service is “offered directly to a child”: mixed-audience services with child appeal count.
- Map the consent-age thresholds for each EU country you serve, and apply them by user location.
- Build parental consent flows with verification proportionate to the data’s sensitivity.
- Set child accounts private by default and disable behavioral advertising for them.
- Write child-facing notices in language the age group understands, as Article 12(1) requires.
- Run a DPIA; processing children’s data at scale is squarely in the high-risk criteria.
Your public site is part of the assessment: if children can reach it, its trackers and defaults are evidence. A free scan inventories what fires before consent, which for a child-directed service should be nothing at all.