GDPR
Chapter II - Principles

GDPR GDPR-Art.8: Conditions applicable to child's consent

Where consent is the lawful basis and information society services are offered directly to a child, processing the child's personal data on the child's own consent is lawful only from age 16, or from the lower age a Member State has set in law, which may be no lower than 13. Below that age the processing is lawful only to the extent consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that it was, taking available technology into consideration.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 37 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • BIK-IG1 Strategy alignment with DSA, AVMSD, GDPR and the eID Regulation
  • BIK-P4 Children as content creators with safeguards
  • BIK-S1 EU code of conduct on age-appropriate design
  • BIK-S2 Age verification and EU-wide digital proof of age
  • BIK-S7 EU code of conduct for childrens privacy

CCPA/CPRA · 2 controls

  • 1798.120(c) Obtain opt-in before selling or sharing data of consumers under 16
  • §1798.120 Right to Opt Out of Sale or Sharing of Personal Information
  • AVMSD-Art.28b Platform measures for video-sharing platforms (Article 28b)
  • AVMSD-Art.6a Protection of minors from harmful content (Article 6a)
  • BM-PIPA-16 Personal information about children in the information society

COPPA · 1 control

  • COPPA-312.5a Verifiable Parental Consent Requirement
  • PIPL-Art31 Minors Under 14
  • CZ-110-§7 Zpusobilost ditete pro souhlas (child's capacity to consent - age 15)
  • DUAA-P5-CHILDREN Children's data protection by design (ISS)
  • ESRB-PC-08 Verifiable Parental Consent (VPC)
  • EGY-PDPL-Art.12 Processing of sensitive personal data and children's data
  • EST-IKS-§8 Processing of children's personal data for information society services
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

ISO 27701:2019 · 1 control

  • 7.2.3 Determine when and how consent is to be obtained
  • Art. 2-quinquies(1) Art. 2-quinquies(1) Obtain parental consent for information society services offered to children under 14
  • 5(1) Art. 5(1) Obtain the legal representative's consent for data subjects under 16
  • RO-LAW190-015 Children's Consent for Information Society Services
  • CIA-CHILD-17 Protection of minors credit information
  • UZB-DPL-17 Children's Data
  • ZDPA-15 Children and Vulnerable Persons

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter II - Principles

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.