Why Children's Data Has Become GDPR's Biggest Flashpoint
Across Europe, the rules governing how brands collect and use children's personal data have quietly become the most contested, and most fined, corner of digital marketing law. Regulators are no longer treating children's privacy as an afterthought bolted onto standard GDPR compliance. It has evolved into its own enforcement priority, with brands that still treat it as a simple checkbox exercise facing some of the largest penalties on the books.
The pattern is consistent: companies build consent flows, age gates, and privacy notices designed to satisfy a general compliance checklist, then discover too late that regulators expect something far more rigorous when children are involved. GDPR's provisions around minors were written with the assumption that children cannot meaningfully consent to data processing the way adults can, and enforcement bodies across the EU and UK have leaned into that assumption aggressively.
What GDPR Actually Requires for Children's Data
Unlike a single, uniform rule, GDPR's approach to children's data is layered and, in some ways, deliberately ambiguous. It sets a default age of consent at 16 but allows individual member states to lower that threshold to as young as 13, meaning a brand operating across multiple EU countries can face different legal thresholds for the same product depending on where a user is located. That patchwork alone makes checkbox compliance risky: a consent mechanism built for one jurisdiction's rules may fail entirely in another.
Beyond age thresholds, the regulation expects brands to demonstrate that privacy notices, consent requests, and data collection practices are genuinely understandable to a child, not just legally sufficient for an adult reader. Age verification, parental consent mechanisms, and data minimization all fall under heightened scrutiny when the data subject is a minor. Regulators have shown they are willing to dig into the specifics of how a platform actually functions, not just what its privacy policy claims.
This is exactly the gap that has already produced major penalties elsewhere. The UK's data protection regulator recently upheld a £12.7 million fine after TikTok lost its appeal over child data handling tied to more than 1.4 million children's personal data. That case underscored a point regulators keep making: platforms are expected to know, and act on, the fact that children are using their services, even when age verification is imperfect. Ignorance of a young user base is not treated as a defense.
The Cost of Getting It Wrong Is Rising Globally
Europe is not operating in isolation here. Similar scrutiny of children's and student data is emerging in other major markets, raising the compliance bar for any brand operating internationally. In India, for example, the DPDP Act is already squeezing compliance budgets in the ed-tech sector, forcing companies that handle student data to rebuild how they collect, store, and process it. Brands operating across both the EU and markets like India increasingly need compliance frameworks flexible enough to satisfy multiple, non-identical children's data regimes at once, rather than a single template applied uniformly.
What ties these cases together is a shift in regulatory posture. Data protection authorities are moving away from accepting generic, adult-oriented consent frameworks as sufficient cover when children are part of the user base. The expectation now is that companies actively design for the possibility that minors are using their products, rather than assuming that terms-of-service language alone shields them from liability.
What This Means For You
For marketing and legal teams, the practical implication is straightforward: children's data compliance can no longer be an add-on to a broader GDPR program. It needs its own risk assessment, its own consent design, and its own ongoing review, because regulators are actively testing whether platforms know their real user base and are adjusting practices accordingly.
For parents and everyday users, this wave of enforcement is a reminder that regulators are increasingly on your side when it comes to how platforms treat younger users. Fines like the one upheld against TikTok exist precisely because authorities found that stated policies didn't match actual practice. If you manage a child's access to apps or online services, it's worth reviewing what data those platforms collect and whether their privacy settings for minors are genuinely restrictive by default, rather than relying on assurances in a privacy policy.
Key Takeaways
Brands operating in Europe should treat GDPR children's data rules as a distinct compliance category, not a subset of general data protection obligations. That means auditing age verification methods for actual effectiveness, tailoring consent language to be genuinely understandable to younger users, and building data minimization into product design rather than retrofitting it after a regulatory inquiry. Given how member states vary on age thresholds, multinational brands especially need country-specific reviews rather than a single EU-wide template. The organizations still writing the largest fines into their budgets are, almost without exception, the ones that assumed a generic privacy policy was enough.




