When is comes to the GDPR and children – of children’s data to be exact – special care must be taken.
What’s the best way to handle children’s data? It has always been, in information governance both pre- and post-GDPR, one of the weakest areas of knowledge. In terms of data sharing what can children do? What can be done for them?
GDPR and Children – What Does the GDPR Say?
Surprisingly, GDPR has little to say about children.
- Recital 38 describes them as meriting specific protection with regard to their personal data, This because they may be less aware of the risks, consequences and safeguards concerned, as well as their rights in relation to the processing of personal data.
- It goes on to recommend that such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles, and the collection of personal data with regard to children when using services offered directly to a child.
- Article 8 of the GDPR introduces an age of competence. This is the age for someone to give consent for the processing of their data. However, it allows them to reduce it, to no less than 13, if they wish. The only exception is to access preventative or counselling services.
What Does This Look Like?
When it comes to GDPR and Children, this has challenged a fundamental premise of the GDPR. The aim was to create a uniform data protection framework across Europe.

Until GDPR came in to force there was never an age beyond which people were deemed competent to control how their data are handled under any circumstances; or an age below which they were not. Best practice has always been to consider the competence of the individual and their capacity to understand the data sharing they were being asked to agree to, and the consequences of sharing/not sharing their data.
Our own research has shown that there is wide variation in what people thought the age was under the pre-GDPR regime from which people had the right to control their data
As is to be expected NHS staff were more likely to correctly recognise that ability to control information sharing was based on competence not age. However, for both cohorts a majority said the age at which people were allowed to control their data was 16 or 18.
Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.
Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Sign Up Here:
Other Lawful Bases
Nevertheless, the age of competence only applies where consent is used as the lawful basis. There is no age of competence for the exercise of a person’s rights, where again someone’s capacity to understand is key. There are wider lawful bases with it comes to GDPR and children so, in addition:
- The GDPR does not overrule contract law, so you may still enter into a contract with a child. However, you must ensure that if you are using contract delivery as your lawful basis that the child below the age of competence is able to understand the contract they are entering into.
- When using the ‘legitimate interests’ route there must be age appropriate safeguards. These are needed to mitigate the risks and consequences of the data processing to a child. For example, there may be circumstances when a child’s wish to control how his or her data are processed is against their longer term legitimate interests.
- Other legal bases, such as Vital Interests or Statutory Duty, are also age blind. Again, special protections for children given their vulnerable status may be needed.
Ultimately the principle of accountability and the concept of privacy by design require special care. This is trye when dealing with children of all ages. The level of education required by children, parents, and organisations processing data remains as high as ever.
GDPR and Children: Get More Support
If you found this content helpful, why stop there? Take the next step in your journey by exploring this comprehensive range of support options. Whether you’re looking to deepen your knowledge through training courses, access free resources, or attend expert-led events, we have something for everyone. And if you have any questions don’t hesitate to reach out to us directly for personalised guidance and support. We’re here to help




Explore the learning opportunities available to you with WuDo Solutions. Click here to learn more
Explore free resources to help you understand this topic, all curated by our team of experts
Join one of our regular, expert led events explore a range of topics in depth
If you have any questions or there is something else we can help you with get in touch
Top tips: Children and GDPR
GDPR and Children is the GDPR but more. Our top tips are:
- Make sure your privacy statement is written in a way that children can understand.
- Make sure, if you rely on consent from the age of 13, your consent is fully informed and freely given by ensuring the child understands what they are consenting to.
- Don't default to 13 when it comes to consent - you must make an assessment of the child's competence if they are younger
- If you rely on parental consent, remember the child can withdraw that consent from the age of 13 onward. Remember, a tick box or similar is not enough – you must have a copy of that freely given informed and unambiguous consent.
- As with all data collection and processing, identify the lawful basis first.
- Due to their vulnerability data breaches involving children are more likely to be notifiable to the Information Commissioner. Make sure you have systems in place to identify any breaches of a child’s data.
- Train your staff to understand the age of competence and that a child of any age may exercise their rights.
- Have systems in place to carefully record as and when you decide to override a child’s wishes in relation to their data based on your assessment of their competence.
- If you do enter into any kind of contract or service for a child have appropriate age verification systems in place.
Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.
Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: