Under GDPR Art. 8, when does a children's photo-sharing app need parental consent, and how hard must it verify it?
answer
- information society service offered directly to a child
- 16 by default, not below 13
- reasonable efforts, available technology
- proportionate to risk
basics
~20 sUnder GDPR Art. 8, where an online service offered directly to children relies on consent, a child under 16, or a lower national age not below 13, needs parental consent or authorisation, verified with reasonable, risk-proportionate efforts.
solid answer
~50 sUnder GDPR `Art. 8(1)`, where processing rests on **consent** and an **information society service** is **offered directly to a child**, the child's own consent is enough from **16**; below that, processing is lawful only if and to the extent that consent is **given or authorised by the holder of parental responsibility**. Member States may set a **lower age, not below 13**, so a cross-border app must track the age that applies in each market. `Art. 8(2)` requires **reasonable efforts to verify** parental consent, *taking into consideration available technology*. EDPB Guidelines 05/2020 call for a **proportionate** approach: self-declared age with further checks where doubts arise, parental contact details and email confirmation for low-risk cases, stronger proof for high-risk ones, and no verification that itself collects excessive data (paras. 132-137). A photo-sharing app for children handles images and social exposure, so it sits towards the higher-risk end.
go deeper
Recall the Art. 8 rule: 16 by default, with Member States allowed to go down to 13, and parental consent below that for online services aimed at children.
Explain when Art. 8 applies (consent, information society service, offered directly to a child) and what reasonable efforts to verify means per the EDPB.
Scale verification to risk for a service like photo sharing, manage per-market ages, and handle the child reaching the age of consent.
Own the verification design across markets, weighing friction, per-market ages and the evidence burden against the risk the service poses to children.
## When Art. 8 applies `Art. 8` of the GDPR (Regulation (EU) 2016/679) is narrower than "any processing of children's data". Three conditions must all hold: 1. **Consent is the lawful basis.** It applies *where point (a) of Article 6(1) applies*. 2. **An information society service** is involved: under `Art. 4(25)`, a service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. An app qualifies. 3. **The service is offered directly to a child.** EDPB Guidelines 05/2020 say a provider that makes clear it serves only people aged 18 or over, not undermined by other evidence such as content or marketing, is not offering the service directly to a child (para. 130). A photo-sharing app built for children plainly is. Recital 38 explains the purpose: children *merit specific protection* because they may be less aware of the risks, in particular for marketing, profiling and services offered directly to them. ## The age threshold | Rule | Text | |---|---| | Default | A child **at least 16** can consent alone (`Art. 8(1)`) | | Below the threshold | Lawful only if and to the extent consent is **given or authorised by the holder of parental responsibility** | | National variation | Member States may set a **lower age, not below 13** (`Art. 8(1)`, second subparagraph) | The EDPB warns that a controller offering a cross-border service *cannot always rely on complying with only the law of the Member State in which it has its main establishment*, and may need to comply with the national laws of each Member State where it offers the service (para. 131). In practice, the app needs a table of the applicable age per market. ## Verifying age and parental authority `Art. 8(2)` requires the controller to make **reasonable efforts to verify** that consent is given or authorised by the holder of parental responsibility, *taking into consideration available technology*. The EDPB fills in what "reasonable" means: - **Age of the user.** Verifying age is implicitly required, since a child consenting below the threshold makes the processing unlawful (para. 133). If a user says they are **below** the age, the controller can accept that and move to parental authorisation (para. 134). - **Proportionality.** Verification should be proportionate to the nature and risks of the processing (para. 132) and should *not lead to excessive data processing* (para. 135); in some low-risk cases, a year of birth or a declaration may be appropriate. - **Parental authority.** A proportionate approach may focus on a limited amount of information, such as a parent's contact details (para. 136). In **low-risk** cases, verification by email may be sufficient; in **high-risk** cases, more proof may be appropriate (para. 137). - **Review.** If doubts arise, the controller should review its mechanism, and keep processes and available technology under constant review (paras. 135 and 146). The EDPB's Example 23 gives a four-step flow for an online gaming platform: 1. Ask the user whether they are under or over the age of digital consent. 2. If under, tell the child a parent or guardian must consent, and ask for the parent's email address. 3. Contact the parent, obtain consent by email, and take reasonable steps to confirm parental responsibility. 4. If complaints arise, take additional steps to verify the subscriber's age. ## Applying it to a children's photo-sharing app The app processes images of children, often including faces, locations and social connections, and lets others see them. That raises the risk level, so a bare email confirmation is weaker support than it would be for a low-risk service. The app should: - set the consent age per market; - collect parental authorisation before the child's data are processed on the basis of consent; - scale the proof of parental responsibility to the risk; - keep evidence of the verification, since `Art. 7(1)` requires the controller to demonstrate consent; - avoid verification methods that themselves collect more data than needed. ## After the child turns the relevant age The EDPB says parental consent remains a valid ground if the child takes no action after reaching the age of digital consent; the child can then confirm, modify or withdraw it, and the controller must tell the child about that possibility (paras. 147-149). ## Limits of Art. 8 - It does **not** change national **contract law** on children's capacity (`Art. 8(3)`). - Recital 38 says parental consent should **not** be necessary for **preventive or counselling services** offered directly to a child. - It does not decide whether consent is the right basis at all; that is a separate choice.
- Under GDPR Art. 8, does a service that states it is only for adults have to verify parental consent?EDPB Guidelines 05/2020 (para. 130) say that if a provider makes clear it offers its service only to people aged 18 or over, and this is not undermined by other evidence such as the site's content or marketing plans, the service is not offered directly to a child and `Art. 8` does not apply. A service aimed at children cannot escape it by a disclaimer.
- Under the GDPR, what happens to parental consent when the child reaches the age of digital consent?It remains a valid ground if the child takes no action. The EDPB says the child can then confirm, modify or withdraw that consent under `Art. 7(3)`, and the controller must inform the child of this possibility (paras. 147-149).
- Under EDPB Guidelines 05/2020, why should age verification avoid collecting identity documents by default?Para. 135 says age verification should not lead to excessive data processing and should be chosen by assessing the risk of the processing. Para. 136 recommends a proportionate approach consistent with data minimisation, such as limited parental contact details. Demanding identity documents from every user would often collect more than the risk justifies.
saying these in an interview costs you the question
- The GDPR sets one age of digital consent, 13, across the whole EU.
- Art. 8 applies to every processing of children's data, whatever the basis.
- A tick box saying 'I am a parent' is always enough verification.
- Verification should collect as much identity data as possible to be safe.
- Art. 8 decides whether a child can enter into a contract under national law.