← GDPR · Lawfulness
Art.8 — Conditions for a child's consent to online services
Requirement
Where consent is the basis for offering an information society service directly to a child, processing is lawful only if the child is at least 16 — or a lower age set by the Member State, not below 13 — or if consent is given or authorised by the holder of parental responsibility, and the controller makes reasonable efforts to verify this.
UK GDPR: UK GDPR sets the age of digital consent at 13, and the ICO's Age Appropriate Design Code applies to online services likely to be accessed by children.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| NDPA 2023 | s.31 | Processing the data of children and persons lacking capacity | consent lawful-basis children |
| CCPA/CPRA | 1798.120(c)-(d) | Opt-in consent to sell or share minors' information | children consent |
| COPPA | 312.4(b)-(c) | Direct notice to parents | consent children |
| COPPA | 312.5 | Verifiable parental consent before collection | consent children |
| COPPA | 312.5(a)(2) | Separate consent before disclosing children's data to third parties | consent children |
| NDPA 2023 | s.25 | Lawful basis for processing | lawful-basis consent |
| CCPA/CPRA | 1798.120 | Right to opt out of sale and sharing | consent |
| CCPA/CPRA | 1798.121 | Right to limit use of sensitive personal information | consent |