Article 8(1) sets it at 16, and lets each Member State legislate a lower age down to a floor of 13. So there is no single European answer, and the figure that applies depends on where the child is. There is also a prior question most guidance skips: Article 8 only engages when you are relying on consent for an information society service offered directly to a child. If your lawful basis is something else, it does not apply at all.
This article covers what Article 8 actually says, why published country tables contradict each other, the figures we could corroborate, when the provision is engaged, and what verification is expected of you.
Article 8 Sets Sixteen, With A Floor Of Thirteen
Where an information society service is offered directly to a child and processing is based on consent, Article 8(1) makes that consent lawful only where the child is at least 16. Below that age, processing is lawful only if consent is given or authorised by the holder of parental responsibility. Member States may legislate a lower age, but not below 13.
Article 8(2) adds the operational half: the controller must make reasonable efforts to verify that consent is given or authorised by the holder of parental responsibility, taking into consideration available technology.
Two consequences follow immediately. There is a legitimate range of 13 to 16 across the Union, so the answer is jurisdictional rather than European. And "reasonable efforts" is a proportionality standard, not a specification — what is reasonable scales with the risk of the processing.
Why The Tables You Find Online Disagree
Search this question and you will find country-by-country tables. Compare a few and you will find they conflict, sometimes on major markets. In preparing this article we found live sources published as recently as 2025 stating a figure for France that the French implementing law contradicts, alongside better-sourced material giving the correct one.
There are three reasons, and knowing them is more useful than any single table.
Most tables date from 2018. A great many were compiled while Member States were still legislating, and they recorded expectations rather than enacted law. Several countries landed somewhere other than predicted, and the tables were never revisited.
Spain is the cleanest illustration. EU-level tracking from the transposition period listed it at 13, explicitly flagged as draft law. What Spain actually enacted was 14. Every table that copied the draft figure without the flag has been wrong ever since, and there are a great many of them.
Copies propagate faster than corrections. A table published once is quoted, reformatted and republished, and each copy carries the original's errors without its date.
The underlying question is genuinely more complicated than one number. National rules differ not only on the age but on whether a child's consent alone is ever sufficient, and on how parental authorisation interacts with general capacity law. A single column flattens distinctions that matter in practice.
The Figures We Could Corroborate
Below are the positions we could confirm against at least two independent, credible sources as at 8 August 2026. This is not all twenty-seven Member States, and it is not offered as a complete table — we did not verify the remainder to the standard the rest of this article is held to, and publishing them anyway is exactly the failure described above.
| Jurisdiction | Age | Effect |
|---|---|---|
| GDPR default | 16 | Applies unless a Member State has legislated lower |
| Statutory floor | 13 | No Member State may go below this |
| Germany | 16 | Retained the default |
| Netherlands | 16 | Retained the default |
| France | 15 | Lowered by national law |
| Spain | 14 | Lowered by national law |
| Portugal | 13 | At the floor |
| Denmark | 13 | At the floor |
| Sweden | 13 | At the floor |
| United Kingdom | 13 | A separate regime post-Brexit, at the floor |
Confirm your own markets against the national implementing law or the relevant supervisory authority before relying on any figure, including these. That is not a disclaimer for its own sake — it is the only method that survives contact with a regime where twenty-seven legislatures each hold a pen.
Article 8 Is Only Engaged If Consent Is Your Basis
This is the part that resolves the question for most B2B SaaS companies, and it is routinely skipped.
Article 8 conditions the validity of consent. If your lawful basis for a given purpose is contract, legal obligation or legitimate interests, Article 8 does not apply to that purpose. A child using a service under a contract does not trigger a parental consent requirement merely by being a child — which is why picking your lawful basis deliberately changes what obligations you inherit.
That is not a loophole and it is not a reason to relabel consent as something else. Children remain a group whose data merits specific protection, transparency obligations still require language a child can understand, and where you have chosen consent it must still meet every ordinary condition — including that it is freely given, which is harder to establish for a child than an adult.
The provision also applies specifically to services offered directly to a child. A workplace tool that a sixteen-year-old apprentice happens to use is in a different position from a service designed and marketed for teenagers.
What "Reasonable Efforts To Verify" Actually Means
Article 8(2) asks for reasonable efforts taking into account available technology, and the EDPB's consent guidelines frame the measures as proportionate to the nature and risks of the processing.
In practice that produces a sliding scale rather than a standard. A low-risk service might reasonably rely on a self-declared date of birth with sensible design around it. A service processing sensitive data, profiling, or serving targeted advertising will be expected to do considerably more, and a tick-box will not be defensible.
Two design points are worth stating. Asking for a birth date is itself collecting personal data, so collect the minimum that answers the question. And an age gate that teaches children to enter a false year is worse than useless — it produces a record that says the user is an adult, which is a documented inaccuracy rather than a defence. This is also where signup and trial flows tend to be the only place the question is ever asked, and where it is most often not asked at all.
Common Mistakes With Children's Consent
Treating 16 as the European answer. It is the default, not the rule. Operating across the Union means the applicable age varies by where the child is, and using one figure means being wrong in a predictable subset of your markets.
Copying a table without checking its date. Most published tables were compiled in 2018 from expected rather than enacted positions. A figure without a date and a source is not information you can rely on.
Applying Article 8 when consent is not your basis. The provision conditions consent. Working through a parental consent process for processing you actually perform under contract creates obligations you did not have and muddles the record of what your basis is.
Using an age gate as a compliance artefact. A gate that any child can pass by picking an earlier year does not evidence anything. Worse, it records an assertion you know may be false, which is a weaker position than not asking.
Forgetting the transparency half. Article 12 requires clear and plain language, particularly for information addressed to a child. A privacy notice written for procurement lawyers does not meet that standard, whatever the age of consent is where the child lives.
FAQ
Our product is B2B. Do we need to worry about this at all?
Usually not, because Article 8 applies to information society services offered directly to a child, and a workplace tool is not that. But check two things: whether your free tier or self-serve signup is genuinely restricted to business users, and whether your terms set a minimum age you actually enforce. Products acquire under-16 users through consumer-style signup flows more often than their positioning suggests.
Which country's age applies — where the child is, or where we are?
Where the child is. The GDPR applies to offering services to people in the Union based on their location, so a company in one country serving users across several must apply each relevant national age. That is the practical reason a single figure does not work.
What happens if we get consent from a child below the applicable age?
The consent is not valid, so the processing has no lawful basis unless another one genuinely applies. You would need to stop the processing, consider deletion, and decide whether anyone needs to be told. Discovering this late is more common than discovering it early, because nothing in a signup flow flags it.
Does the UK still follow the GDPR age of consent?
The UK operates a separate regime since Brexit, and its age sits at the floor of 13 rather than the default of 16. If you serve both the UK and EU markets you are dealing with two regimes rather than one, which is true of a good deal more than this provision.
Closing Thought
The genuinely interesting thing about this question is not the number, it is what happens when a regulation designed to harmonise a market hands twenty-seven legislatures a range and lets each pick. You get exactly what you would expect: a spread from 13 to 16, a set of national rules that interact with domestic capacity law in ways no comparison table captures, and an internet full of confidently wrong summaries frozen at the moment the laws were still being drafted.
Which means the honest answer to "what is the GDPR age of consent" is a method rather than a figure — check your markets, against national law, with a date on it. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request forms and security page, which is where your positions become something a customer can read. It does not check national implementing law for you, and on this question there is no substitute for doing that per market.