Blog Post

AI Governance When the Data Subject Is a Minor

September 26, 2026

Table of Contents

The assumption about AI systems affecting children is that the consent structure carries the difficulty. The subject cannot consent, so a parent consents instead, and the governance problem is collecting and tracking that permission.

‍

The assumption is backwards. Consent is usually the wrong lawful basis for these deployments, so the parental consent machinery is not required at all. What differs is something else entirely.

‍

When Does the Parental Consent Rule Apply?

‍

Narrowly, and both of its conditions have to hold at once.

‍

Article 8 applies where consent is the lawful basis being relied on, and where the service is an information society service offered directly to a child. Guidance is explicit that the phrase indicates the provision reaches some services and not all of them, and that a provider stating it serves only adults sits outside it where nothing else undermines the claim.

‍

Which Excludes Most Institutional Deployments

‍

A school running an assessment or admissions system is not relying on consent, since core educational functions rest on public task or legal obligation. The system is also not offered directly to the child, it is operated by the institution. Both conditions fail, so the provision that dominates the discussion frequently does not apply to the case people have in mind.

‍

Why Does Asking for Consent Make It Worse?

‍

Because it offers a choice that does not exist, which is a fairness problem rather than a paperwork one.

‍

Data category policy showing per-category actions and severities, with health and date of birth categories carrying their own handling rules
Handling that differs by category rather than by a single consent decision is what a special protection requirement calls for.

Consent has to be freely given and capable of being withdrawn without detriment. A parent cannot decline the system a school uses to allocate places and expect the place to be allocated some other way. Presenting the processing as consent-based creates an expectation the institution cannot honor, and withdrawing it later has no available effect.

‍

What Should Be Presented Instead?

‍

The basis that genuinely applies, with the rights attaching to it. Where processing rests on public task there is a right to object and a right to information, and no right to refuse outright. Stating that plainly is more defensible than an unenforceable consent request, and what an obligation genuinely requires is worth establishing before designing around the wrong one.

‍

What Differs Then?

‍

The person the decision affects cannot exercise their own rights, which is the structural feature and the one no governance program is built for.

‍

Every rights process assumes the subject makes the request. A request to access, to object, to have a decision explained or to have data erased arrives from the individual, gets verified against that individual, and is answered to them. Where the subject is a child, the request arrives from somebody else on their behalf, and capacity to act is governed by national law rather than by the regulation itself.

‍

Which Breaks Verification Rather Than Consent

‍

The hard question is not whether a parent may act, it is establishing that this person holds parental responsibility for this child. Establishing that is a family law question arriving at a service desk, and a process designed to match a requester against an account has no way to answer it. Answering on somebody else's timeline is harder again when the requester's standing has to be established first.

‍

What Does Special Protection Require?

‍

Three things that survive whatever the lawful basis turns out to be, which makes them the safe place to put effort.

‍

Privacy control panel showing detection running on the device with a list of fields transmitted and a separate list never transmitted, including message content and file contents
Governing an interaction without capturing its content is the distinction that matters most where the subject cannot consent to being observed.

Recital 38 establishes that children merit specific protection, particularly around profiling and the creation of user profiles. Information has to be age-appropriate rather than merely accurate. The right to erasure is also applied more strictly where the data was collected in childhood.

‍

Which Makes Profiling the Sensitive Operation

‍

An assessment system that scores work is doing something narrower than one that builds a durable profile of a pupil across years. The second is closer to what the specific protection language targets, and the distinction is about data retained and reused rather than about the model, which categorizing deployments by what they do is the prior step for.

‍

Is the Age Threshold the Same Everywhere?

‍

No, and an organization operating across borders faces different lines in each.

‍

The default sits at sixteen with member states permitted to lower it to no less than thirteen, and the result is thirteen in some member states and sixteen in others with several at fourteen. So the same deployment can be inside the provision in one country and outside it in another, for pupils of identical age.

‍

What Follows Operationally?

‍

Where consent genuinely is the basis, the threshold has to be applied per jurisdiction rather than once. A single age gate set at the highest threshold is conservative and defensible, and setting it at the lowest is not.

‍

Where Does the AI Act Sit?

‍

Later than most coverage suggests, which matters for sequencing rather than for whether the work is needed.

‍

Systems used to determine access to education, to evaluate learning outcomes and to monitor candidates during assessment sit in the high-risk annex. Regulation (EU) 2026/1744 deferred that section to December 2027 for standalone systems and August 2028 for those embedded in regulated products, so the obligations following from the classification are not yet in force.

‍

Which Leaves Data Protection Carrying the Weight

‍

The protections that apply now are the data protection ones, and they were never deferred. An organization waiting for the AI obligations before addressing rights requests, retention or profiling is waiting on the wrong instrument, and sequencing obligations by date separates the two.

‍

Does the Same Structure Appear Elsewhere?

‍

In several places, and recognizing the pattern stops this being filed as an education peculiarity.

‍

Anywhere the person a decision affects cannot act for themselves, the rights process needs a proxy path. Paediatric care, guardianship for adults lacking capacity, and decisions about a deceased person's data all have the same shape. In each case the subject is identifiable, the decision is consequential, and somebody else holds the standing to question it.

‍

What Do Those Cases Share Operationally?

‍

Verification of standing rather than verification of identity. A conventional process proves the requester is who they claim to be. These require proving the requester is entitled to act for somebody else, which is a different evidentiary question and one that arrives with documents a service desk is not equipped to assess.

‍

What Is the Workable Arrangement?

‍

Routing standing questions to whoever already handles them. Schools have admissions records establishing parental responsibility, and health providers have next-of-kin and guardianship records. The governance process should query that source rather than build its own, and an obligation split across functions is the failure mode when it tries.

‍

What Should Be Established?

‍

Four things, and the first frequently corrects a design decision already made.

‍

What lawful basis each deployment rests on, since consent is usually not it and presenting it as such creates a problem. How a rights request from somebody acting for a child is verified, since that is the mechanism no process contains. What is retained and reused across years rather than scored once, since profiling is the sensitive operation. Then which age threshold applies in each jurisdiction where consent genuinely is the basis. An AI governance record holding the basis and the retention position per deployment answers the first and third without a survey.

‍

The Difficulty Is Standing, Not Consent

‍

The parental consent provision applies only where consent is the lawful basis and the service is offered directly to a child, and institutional deployments usually satisfy neither, so the machinery everyone builds is machinery the situation does not call for. Presenting public task processing as consent-based offers a choice that cannot be honored. What genuinely differs is that the person the decision affects cannot exercise their own rights, so the request arrives by proxy and the hard part is verifying that the proxy holds parental responsibility, which is a family law question at a service desk. Specific protection attaches to profiling and retention rather than to scoring. The AI obligations were also deferred while the data protection ones were not. Kovrr's AI compliance readiness records the lawful basis and retention position against each deployment.

‍

To see the lawful basis and retention position recorded against each AI deployment, book a demo mapped to your own estate.

Or Amir

Product & Customer Growth Manager

Children's Data and AI FAQs

Speak to an Expert

Does GDPR Article 8 apply to AI systems used in schools?

Is parental consent the right lawful basis for AI in education?

What is the GDPR age of digital consent by country?

Who exercises a child's GDPR rights?

What does GDPR Recital 38 require for children's data?

Are AI grading and admissions systems high-risk under the EU AI Act?