GDPR Article 8: conditions applicable to a child's consent
Article 8(1) makes a child's consent to information society services lawful where the child is at least 16 years old. Below 16, processing is lawful only if consent is given or authorised by the holder of parental responsibility. Member States may set a lower age, but not below 13 years.
Applies to: Controllers offering information society services directly to children in the EU and relying on consent under Article 6(1)(a) as their lawful basis for processing the child's personal data.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanArticle 8 is short, and it is the provision that decides whether a consumer app can lawfully sign up a fifteen-year-old in the EU. It does not set a blanket minimum age for using a service. It sets the age at which a child can give their own consent, and it hands part of the answer to national law.
The official text of Article 8
Article 8(1) reads: "Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child."
A second subparagraph follows: "Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years."
Article 8(2) reads: "The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology."
Article 8(3) reads: "Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child."
What triggers it
The opening clause is the gate. Article 8(1) applies where point (a) of Article 6(1) applies, which is consent, and where the offer is of information society services directly to a child. Both conditions have to hold.
If your lawful basis is contract necessity or legitimate interests rather than consent, Article 8's parental-authorisation mechanism is not what governs the processing. That does not make children's data a free-for-all. Recital-level expectations about children's vulnerability, data protection by design, and transparency written for a child audience all continue to apply, and a regulator will still ask why consent was not the right basis for a service aimed at children.
The age is not a single number
The default of 16 years is only a default. The second subparagraph of Article 8(1) lets Member States legislate a lower age down to a floor of 13, and many have. The result is that a service available across the Union faces a patchwork somewhere in the 13 to 16 range, and the age that matters is the one in force where the child is.
For a small SaaS or consumer app, the practical options are to build to 16 everywhere, which is simplest and strictest, or to hold a per-country age table and apply it by the child's location. Building to 16 avoids the mapping work at the cost of excluding legitimate users in Member States that chose 13.
What "reasonable efforts" means in practice
Article 8(2) asks for reasonable efforts to verify that the consent was given or authorised by the holder of parental responsibility, taking into consideration available technology. The standard is deliberately relative. It does not demand identity documents from parents, and it does not accept an unverified tickbox that says "I am a parent" on a service that knows its users are children.
The proportionate reading follows the risk of the processing. A low-risk service can rely on lighter verification, such as a confirmation step sent to a parent's separate contact channel. A service processing special category data or running profiling on children should expect to do more. The phrase "available technology" means the bar moves as verification methods improve, so a method that was defensible five years ago may not be now.
Consent quality still comes from Article 7
Article 8 changes who gives consent. It does not lower what consent has to be. The Article 7 conditions continue to apply in full: the controller must be able to demonstrate consent was given, a written declaration must be clearly distinguishable from other matters and in plain language, and withdrawal must be as easy as giving it.
Article 8(3) closes with a boundary that is easy to overlook. Paragraph 1 does not affect the general contract law of Member States, such as the rules on the validity, formation or effect of a contract in relation to a child. Parental consent to data processing is not the same thing as a child's capacity to enter a contract, and satisfying Article 8 does not make a minor's subscription enforceable.
Next step
If you offer a service that children may use and you are not sure whether the GDPR reaches you or what it requires, the free 2-minute Obligation Scan maps which duties apply to your business. The GDPR compliance hub sets the rest of the obligations in order.
Compliance checklist
- Confirm that consent under Article 6(1)(a) is actually your lawful basis, because Article 8 only bites where it is.
- Identify the applicable national age for each Member State you serve, anywhere between 13 and 16.
- Where the user is below that age, obtain consent given or authorised by the holder of parental responsibility over the child.
- Make reasonable efforts to verify that the parental consent is genuine, taking into consideration available technology, as Article 8(2) requires.
- Keep Article 7 consent standards in place as well: Article 8 changes who consents, not what valid consent looks like.
- Do not assume Article 8(1) resolves contract questions; Article 8(3) leaves Member State contract law untouched.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 8 (conditions applicable to child's consent in relation to information society services), official consolidated text on EUR-Lex
- Regulation (EU) 2016/679 (GDPR), Article 6 (lawfulness of processing), official text on EUR-Lex
Last verified: 2026-09-15
Informational, not legal advice.