Age-Based Limitation on Processing Children's Data, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 8(1).

Assessment Step

1
Age-Based Limitation on Processing Children's Data (Age-BasedLimitationonProcessingChildrensData)
Does the entity refrain from processing the personal data of a child in relation to the offer of information society services unless the child is at least 16 years old or, if the child is under 16, valid consent has been given or authorized by the holder of parental responsibility?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Age-Based Limitation on Processing Children's Data
The data controller must refrain from processing the personal data of a child in relation to the offer of information society services unless the child is at least 16 years old or, if the child is under 16, valid consent has been given or authorized by the holder of parental responsibility.
Citation
GDPR
Art. 8(1), Recital 38