Skip to main content
Category: Legal Basis and Consent

Parental Consent

Also known as: Parental Permission
Simply put

Parental consent is agreement given by a parent or legal guardian on behalf of a minor child, authorizing an action that affects the child. It is used across many settings, including medical treatment, research participation, school decisions, and travel or passport issuance for a minor. In each case the parent or guardian is generally expected to be informed about the action before agreeing to it.

Formal definition

Parental consent is a mechanism by which a parent or legal guardian provides authorization on behalf of a minor who is not legally able to consent independently. The evidence shows it applied in several distinct domains: as a legal requirement for a child's medical treatment or medication, as informed permission for a child's participation in research, as agreement to school-system actions requiring parental input, and as documented consent for a minor's passport issuance or travel without one or both legal parents present. Practitioners should note that the specific requirements, standards for what counts as informed, and the identity of who may consent (legal parent versus legal guardian) vary by domain and jurisdiction. This definition is drawn from the domains present in the evidence and does not cover data-protection-specific treatment of children's consent under instruments such as the EU GDPR, UK GDPR, or CCPA/CPRA; the mechanics of age thresholds, verification of parental identity, cross-border variation, and revocation are out of scope here and are not established by the cited sources.

Why it matters

Parental consent functions as the bridge that allows action to be taken on behalf of a minor who is not legally able to consent independently. Across the domains reflected in the evidence, medical treatment, research participation, school-system decisions, and passport or travel authorization, the common thread is that a parent or legal guardian must be informed about the action before agreeing to it. This matters because the validity of the action often depends on that consent being both properly obtained and genuinely informed, and the standard for what counts as informed varies by domain and jurisdiction.

The evidence shows that parental consent is not a single, uniform requirement but a set of domain-specific mechanisms. In a medical setting it is described as a legal requirement that the parent understand and agree to the treatment or medication a child may receive. In research it takes the form of a distinct parental permission document. For a minor's U.S. passport, a specific government form is used when one or both legal parents or guardians cannot appear in person, and for travel without both legal parents present, a consent letter serves as documentation. Because the specific requirements and the identity of who may consent, a legal parent versus a legal guardian, differ across these settings, practitioners should not assume that a form or process valid in one domain satisfies the requirements of another.

This entry addresses parental consent only as it appears in the domains present in the evidence. It does not cover the data-protection-specific treatment of children's consent under instruments such as the EU GDPR, UK GDPR, or CCPA/CPRA. Age thresholds, verification of parental identity, cross-border variation, and revocation are out of scope here and are not established by the cited sources; readers handling children's personal data should consult the applicable data-protection regime separately.

Who it's relevant to

Healthcare providers and clinics
In a medical setting, parental consent is described as a legal requirement that the parent understand and agree to the treatment or medication their child may receive. Providers generally need to ensure the consenting party is a legal parent or guardian and that they have been adequately informed before treatment proceeds.
Research institutions and review boards
When a research participant is a child, consent is provided through a distinct parental permission document rather than the participant's own consent. Institutions and their review processes typically use a dedicated parental permission form for this purpose.
Schools and education systems
Parental consent in a school context means the parent has been fully informed regarding the action of the school system for which consent is being requested. It is relevant wherever a school action requires informed parental input.
Passport and travel authorities, and notaries
For a minor's passport, a specific government consent form is used when one or both legal parents or guardians cannot appear in person with the minor. For travel without both legal parents present, a consent letter documents the authorizing parent's agreement. These contexts turn on documented consent tied to the identity of the legal parents or guardians.

Inside Parental Consent

Age Threshold for Children's Consent
The age below which a child cannot validly consent to certain processing on their own behalf, requiring the consent or authorization of a holder of parental responsibility. Under the EU GDPR the default threshold relates to information society services offered directly to a child and Member States may set a lower age within a permitted range, so the applicable age varies by jurisdiction. Under the UK GDPR a separate national threshold applies. Other regimes such as the US COPPA framework set their own age criteria for online services directed to children. Practitioners should confirm the specific threshold for each jurisdiction rather than assuming a single universal age.
Holder of Parental Responsibility
The person authorized to give or authorize consent on behalf of a child, typically a parent or legal guardian. The concept of who holds parental responsibility is generally determined by applicable national family law rather than by data protection instruments themselves.
Reasonable Efforts to Verify
The obligation, where consent is relied upon for a child, to make reasonable efforts to verify that consent is given or authorized by the holder of parental responsibility, taking into account available technology. What is considered reasonable is generally proportionate to the nature of the processing and its risks, and the standard differs between regimes such as the EU GDPR and the US COPPA framework.
Scope of Application
Parental consent requirements typically apply to specific processing contexts, such as information society services offered directly to a child, rather than to all processing of children's data. Consent is only one of several possible lawful bases; where another lawful basis applies, parental consent may not be the relevant mechanism.
Relationship to the Child's Own Rights
Parental consent does not permanently transfer the child's data protection rights. As a data subject the child retains rights that may become exercisable by the child directly, and a child may generally withdraw or revisit consent upon reaching the relevant age, subject to jurisdiction-specific rules that are out of scope for this entry.

Common questions

Answers to the questions practitioners most commonly ask about Parental Consent.

Does obtaining parental consent make my processing of a child's data automatically compliant?
No. Parental consent, where required, addresses only one element of lawfulness for a specific processing activity that relies on consent as its basis. It does not by itself guarantee compliance. You must still satisfy other requirements such as transparency, data minimization, purpose limitation, security, and, where applicable, a data protection impact assessment. Consent is also only one of several lawful bases; relying on parental consent does not relieve you of the broader accountability obligations that require demonstrable evidence rather than stated intent. Compliance depends on context, jurisdiction, and implementation.
Is parental consent required for all processing of children's personal data?
Not necessarily. The requirement is typically tied to particular circumstances rather than to all processing of a child's data. Under the EU GDPR and UK GDPR, parental consent is generally relevant where consent is the chosen lawful basis for offering an information society service directly to a child below a specified age threshold; other lawful bases may apply in other situations. Different regimes, such as sector-specific or jurisdiction-specific rules elsewhere, treat children's data differently, so you should not assume a single universal rule. This entry does not cover the specific age thresholds or verification mechanics of any particular regime in detail.
How do we verify that consent is genuinely being given by a parent or guardian?
In most jurisdictions that impose a parental consent requirement, the controller is expected to make reasonable efforts, taking available technology into account, to verify that consent is given or authorized by the holder of parental responsibility. What is considered reasonable typically scales with the risk of the processing. This entry does not prescribe specific verification methods, as acceptable approaches vary by jurisdiction, risk level, and regulatory guidance; you should confirm the expectations that apply to your specific context and processing.
Who bears responsibility for obtaining and evidencing parental consent?
The controller generally bears the obligation to establish a valid lawful basis, to obtain parental consent where that is the chosen basis, and to demonstrate that it was obtained, since accountability requires demonstrable evidence rather than mere assertion. A processor acting on the controller's behalf does not typically determine the lawful basis but must act on documented instructions. Where consent verification or collection is delegated to a service provider, the controller generally remains accountable for the outcome. This entry does not address the specific contractual terms governing such arrangements.
What should we record to demonstrate that valid parental consent was obtained?
Because accountability generally requires demonstrable evidence, controllers typically maintain records sufficient to show that consent was sought, what the parent or guardian was told, when and how it was given, and the scope of processing it covered. This supports the ability to respond to a withdrawal of consent and to regulatory scrutiny. This entry does not specify mandated retention periods or formats for such records, as those depend on the applicable regime and your broader records obligations.
How should we handle a child who reaches the relevant age or a parent who withdraws consent?
Where processing relies on parental consent, that consent is generally as revocable as any other consent, and withdrawal should be as easy to exercise as giving it; upon withdrawal you should cease the processing that depended on it unless another lawful basis applies. When a child reaches the age at which they can consent on their own behalf in the relevant jurisdiction, controllers often need a process to address the transition. This entry does not cover the specific age thresholds, transition mechanics, or downstream retention and erasure rules, which vary by jurisdiction and implementation.

Common misconceptions

There is a single global age below which parental consent is always required.
The age threshold is set by regime and, within the EU GDPR, may vary by Member State within a permitted range; the UK GDPR and the US COPPA framework use their own thresholds. Practitioners must confirm the applicable age for each jurisdiction and processing context.
Obtaining parental consent by itself makes the processing of a child's data compliant.
Consent is one lawful basis among several, and no single consent mechanism guarantees compliance. The processing must still satisfy other applicable requirements, and consent must meet the general validity standards. Whether consent is even the appropriate basis depends on context; another lawful basis may be more suitable.
Parental consent requirements apply to every kind of processing of children's data.
These requirements typically attach to specific contexts, such as information society services offered directly to a child, and not to all processing. The applicable scope should be assessed against the relevant instrument rather than assumed to be universal.

Best practices

Identify the specific age threshold applicable to each jurisdiction and processing context, distinguishing between the EU GDPR (including any Member State variation), the UK GDPR, and the US COPPA framework rather than applying a single assumed age.
Confirm before relying on consent that it is the appropriate lawful basis for the processing, since another lawful basis may apply and parental consent may not be the relevant mechanism.
Implement reasonable, technology-appropriate verification of parental authorization proportionate to the nature and risk of the processing, and retain demonstrable evidence of that verification consistent with accountability expectations.
Determine, under applicable national family law, who holds parental responsibility and is entitled to give or authorize consent, rather than assuming any adult can consent on the child's behalf.
Provide clear mechanisms for withdrawing consent and for the child to exercise or revisit their own rights, recognizing that parental consent does not permanently transfer the child's data subject rights.
Document the applicable threshold, the lawful basis assessment, and the verification approach so the organization can produce evidence of compliance, noting that stated intent alone does not satisfy accountability.