GDPR and children: what are the rules?

When is comes to the GDPR and children – of children’s data to be exact – special care must be taken.

What’s the best way to handle children’s data? It has always been, in information governance both pre- and post-GDPR, one of the weakest areas of knowledge. In terms of data sharing what can children do? What can be done for them?

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

GDPR and Children – What Does the GDPR Say?

Surprisingly, GDPR has little to say about children.

  • Recital 38 describes them as meriting specific protection with regard to their personal data, This because they may be less aware of the risks, consequences and safeguards concerned, as well as their rights in relation to the processing of personal data.
  • It goes on to recommend that such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles, and the collection of personal data with regard to children when using services offered directly to a child.
  • Article 8 of the GDPR introduces an age of competence. This is the age for someone to give consent for the processing of their data. However, it allows them to reduce it, to no less than 13, if they wish. The only exception is to access preventative or counselling services.

What Does This Look Like?

When it comes to GDPR and Children, this has challenged a fundamental premise of the GDPR. The aim was to create a uniform data protection framework across Europe.

GDPR and Children

Until GDPR came in to force there was never an age beyond which people were deemed competent to control how their data are handled under any circumstances; or an age below which they were not. Best practice has always been to consider the competence of the individual and their capacity to understand the data sharing they were being asked to agree to, and the consequences of sharing/not sharing their data.

 

Our own research has shown that there is wide variation in what people thought the age was under the pre-GDPR regime from which people had the right to control their data

 

As is to be expected NHS staff were more likely to correctly recognise that ability to control information sharing was based on competence not age. However, for both cohorts a majority said the age at which people were allowed to control their data was 16 or 18.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Other Lawful Bases

Nevertheless, the age of competence only applies where consent is used as the lawful basis. There is no age of competence for the exercise of a person’s rights, where again someone’s capacity to understand is key. There are wider lawful bases with it comes to GDPR and children so, in addition:

  • The GDPR does not overrule contract law, so you may still enter into a contract with a child. However, you must ensure that if you are using contract delivery as your lawful basis that the child below the age of competence is able to understand the contract they are entering into.
  • When using the ‘legitimate interests’ route there must be age appropriate safeguards. These are needed to mitigate the risks and consequences of the data processing to a child. For example, there may be circumstances when a child’s wish to control how his or her data are processed is against their longer term legitimate interests.
  • Other legal bases, such as Vital Interests or Statutory Duty, are also age blind. Again, special protections for children given their vulnerable status may be needed.

Ultimately the principle of accountability and the concept of privacy by design require special care. This is trye when dealing with children of all ages. The level of education required by children, parents, and organisations processing data remains as high as ever.

 

GDPR and Children: Get More Support

Get More Support

If you found this content helpful, why stop there? Take the next step in your journey by exploring this comprehensive range of support options. Whether you’re looking to deepen your knowledge through training courses, access free resources, or attend expert-led events, we have something for everyone. And if you have any questions don’t hesitate to reach out to us directly for personalised guidance and support. We’re here to help

legal requirementQuick WinTop TipSignpost

 

 

 

Explore the learning opportunities available to you with WuDo Solutions. Click here to learn more

 

Explore free resources to help you understand this topic, all curated by our team of experts

 

Join one of our regular, expert led events explore a range of topics in depth

 

If you have any questions or there is something else we can help you with get in touch

 

Top tips: Children and GDPR

GDPR and Children is the GDPR but more. Our top tips are:

  • Make sure your privacy statement is written in a way that children can understand.
  • Make sure, if you rely on consent from the age of 13, your consent is fully informed and freely given by ensuring the child understands what they are consenting to.
  • Don't default to 13 when it comes to consent - you must make an assessment of the child's competence if they are younger
  • If you rely on parental consent, remember the child can withdraw that consent from the age of 13 onward. Remember, a tick box or similar is not enough – you must have a copy of that freely given informed and unambiguous consent.
  • As with all data collection and processing, identify the lawful basis first.
  • Due to their vulnerability data breaches involving children are more likely to be notifiable to the Information Commissioner. Make sure you have systems in place to identify any breaches of a child’s data.
  • Train your staff to understand the age of competence and that a child of any age may exercise their rights.
  • Have systems in place to carefully record as and when you decide to override a child’s wishes in relation to their data based on your assessment of their competence.
  • If you do enter into any kind of contract or service for a child have appropriate age verification systems in place.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial