← NDPA 2023 · Children
s.31 — Processing the data of children and persons lacking capacity
high
consentlawful-basischildren
Requirement
A data controller shall obtain the consent of a parent or legal guardian before processing the personal data of a child, and shall apply appropriate mechanisms to verify age and consent.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
childchildrenminorsunder 18under the age ofage verificationage assuranceage of consentpersons lacking capacitylegal capacity
Required element 2 — any one of
parentguardianconsentverif…not permitted
Supporting terms — specificity signals
section 31age gateage assurance18capacityprohibited
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.8 | Conditions for a child's consent to online services | consent lawful-basis children |
| GDPR | Art.6 | Lawful basis for processing | lawful-basis consent |
| CCPA/CPRA | 1798.120(c)-(d) | Opt-in consent to sell or share minors' information | children consent |
| COPPA | 312.4(b)-(c) | Direct notice to parents | consent children |
| COPPA | 312.5 | Verifiable parental consent before collection | consent children |
| COPPA | 312.5(a)(2) | Separate consent before disclosing children's data to third parties | consent children |
| GDPR | Art.5(1)(a) | Lawfulness, fairness and transparency | lawful-basis |
| GDPR | Art.5(1)(b) | Purpose limitation | lawful-basis |