EU Privacy Law EU/EEA

GDPR and Children's Data: Age Verification and Parental Consent Requirements

GDPR Article 8 rules for children's data: consent age thresholds by country, parental verification, transparency for minors, and the TikTok and Instagram fines.

Regulation

GDPR, Article 8

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 8 sets the digital consent age at 16, but lets member states lower it to as low as 13; the threshold varies country by country across the EU.
  • Below the threshold, consent is valid only if given or authorized by a parent, and the controller must make reasonable verification efforts.
  • Children's data enforcement has produced two of the largest GDPR fines: EUR 405 million against Instagram (2022) and EUR 345 million against TikTok (2023).
  • The DSA adds a separate prohibition on profiling-based advertising to minors (Article 28), applicable since February 2024.
  • Transparency for children must be child-comprehensible: notices written for lawyers fail Article 12's clarity requirement for this audience.

GDPR treats children as data subjects who merit specific protection, and Article 8 builds a dedicated consent regime around them. When an online service is offered directly to a child and relies on consent, that consent is valid only from a user at or above the national age threshold; below it, a parent must consent or authorize, and the controller must make reasonable efforts to verify that. Recital 38 explains why: children are less aware of the risks and their rights.

RegulationGDPR, Article 8
Consent age16 default; member states may lower to 13
Max penaltyEUR 20M or 4% of global annual turnover
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The single hardest operational fact: the threshold is national. Ireland, Germany, the Netherlands, and others kept 16. France chose 15, Spain 14, and a large group including Denmark, Sweden, Belgium, and Portugal went to 13. A service available across the EU cannot apply one age; it needs to know where the user is and apply that country’s rule. Age gates that ask for a birth date with no friction are widely used but increasingly criticized; regulators expect risk-proportionate assurance, and the UK’s Age Appropriate Design Code (covered in our companion guide) pushes the same direction.

What enforcement punishes: defaults

The two landmark children’s cases were about product defaults rather than data breaches. The Irish DPC fined Meta EUR 405 million in September 2022 because Instagram let 13-to-17-year-olds open business accounts that published their contact details, with public accounts as the default. A year later TikTok took EUR 345 million for public-by-default child accounts and a family pairing feature that let unverified adults link to children’s accounts. The design lesson generalizes: for minors, the private option must be the default, and features that expose children’s data need justification, not just a toggle.

The DSA reinforced this from February 2024: platforms may not serve profiling-based ads to users they should reasonably know are minors (Article 28), regardless of consent.

Compliance checklist

  1. Determine whether your service is “offered directly to a child”: mixed-audience services with child appeal count.
  2. Map the consent-age thresholds for each EU country you serve, and apply them by user location.
  3. Build parental consent flows with verification proportionate to the data’s sensitivity.
  4. Set child accounts private by default and disable behavioral advertising for them.
  5. Write child-facing notices in language the age group understands, as Article 12(1) requires.
  6. Run a DPIA; processing children’s data at scale is squarely in the high-risk criteria.

Your public site is part of the assessment: if children can reach it, its trackers and defaults are evidence. A free scan inventories what fires before consent, which for a child-directed service should be nothing at all.

Frequently Asked Questions

What is the age of digital consent under GDPR?

16 by default under Article 8, but member states may set it anywhere down to 13. Ireland, Germany, and the Netherlands use 16; France 15; Spain 14; Denmark, Sweden, and several others 13. Services operating EU-wide need per-country handling.

When does Article 8 apply?

When an information society service is offered directly to a child and consent is the lawful basis. If you rely on a different basis, Article 8 does not bite, but the general fairness and DPIA obligations around children still do.

How do I verify parental consent?

GDPR requires reasonable efforts taking available technology into account (Article 8(2)). Options range from confirmation emails to credit card checks or ID verification, scaled to risk. A checkbox saying 'I am my parent' is not a reasonable effort.

Can I show targeted ads to minors?

Effectively no. DSA Article 28 prohibits presenting ads based on profiling to users the platform is reasonably certain are minors, and the EDPB treats behavioral advertising to children as failing the legitimate-interests balance under GDPR.

What did TikTok and Instagram get fined for?

Instagram (Meta, EUR 405 million, 2022): business accounts for children exposed their phone numbers and emails publicly, and public-by-default settings. TikTok (EUR 345 million, 2023): public-by-default accounts for children and a weak family pairing mechanism. Defaults, not breaches, drove both fines.

Regulatory Crosswalk

UK Age Appropriate Design CodeCOPPADSA Article 28

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.