Skip to content
← GDPR: overview of provisions

Regulation (EU) 2016/679 (GDPR) · Chapter II · Principles

Art. 8 · Conditions applicable to child's consent in relation to information society services

Text

  1. Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.

Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.

  1. The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.

  2. Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child.

Text: EUR-Lex, CELEX 32016R0679 (consolidated text with corrigenda).

Commentary

A child's consent for information-society services. The default threshold is 16 years, and States may lower it to 13. The Czech Republic lowered it to 15 years (§ 7 of Act No. 110/2019 Sb.).

How content is made

Content is produced in the Legal To Code legal workflow for Claude Code (version 1.131.0). Cited provisions are verified against a local library of their verbatim wording. Where the wording is not in the library, it is verified in the Czech Collection of Laws. For case-law research the workflow is connected to the Salvia MCP server. Automated checks of citations and internal consistency are part of the workflow. Even those checks do not rule out an error. Verify decisive information against the original sources.

How this works · What has changed