UK GDPR (UK General Data Protection Regulation)
Chapter II: Principles – UK GDPR (UK General Data Protection Regulation)

UK GDPR (UK General Data Protection Regulation) Art.8: Article 8 Conditions applicable to a child's consent in relation to information society services

Where consent is the basis for offering an information society service directly to a child, processing is lawful for a child aged 13 or over; below 13 it is lawful only with consent given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts, with available technology, to verify that authorisation. Preventive or counselling services are excluded. Since 29 April 2026 (Children's Wellbeing and Schools Act 2026) the Secretary of State may by regulations raise the age to any age up to 16, for all or specified services, and Article 8ZA lets regulations impose age verification requirements; no such regulations are recorded in the held text.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter II: Principles – UK GDPR (UK General Data Protection Regulation)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.