Abstract
The new European Union (EU) General Data Protection Regulation aims to adapt children’s right to privacy to the ‘digital age’. It explicitly recognizes that children deserve specific protection of their personal data, and introduces additional rights and safeguards for children. This article explores the dilemmas that the introduction of the child-tailored online privacy protection regime creates – the ‘empowerment versus protection’ and the ‘individualized versus average child’ dilemmas. It concludes that by favouring protection over the empowerment of children, the Regulation risks limiting children in their online opportunities, and by relying on the average child criteria, it fails to consider the evolving capacities and best interests of the child.
Introduction
Children, who are increasingly becoming active Internet users at an ever-younger age, are either intentionally providing or unconsciously ‘bleeding’ increasing amounts of their personal data online. This growing intensity in providing personal data is seen as enhancing online privacy risks, such as the loss of reputation, commercial exploitation of personal data, profiling, identity theft, cyber harassment and discrimination. Given these risks, there have been increasing calls among policy makers and academics to provide exceptional treatment for children online, that is, to transform children’s rights to privacy (established in Article 16 of the United Nations (UN) Convention on the Rights of the Child, UN CRC) for the ‘digital age’ (UN, 1989).
The most recent example of how such calls have been translated into practice in Europe is the General Data Protection Regulation (2016/679) (hereafter ‘Regulation’), the main personal data protection legislation recently adopted in the European Union (EU). 1 The Regulation updates the Data Protection Directive (95/46/EC) and aims to strengthen citizens’ fundamental rights, especially the right to privacy and personal data protection, in the digital age. At the same time, it allows for free data flows in the Digital Single Market by simplifying rules for companies. It establishes, among other requirements, general data protection principles and legal grounds for data processing, and imposes various duties on entities processing, or deciding how to process, personal data (data controllers). The Regulation also provides individuals whose data is processed (data subjects) with certain rights, such as the right of access to their personal data, rights to data correction and erasure.
The Regulation, in contrast to its predecessor, explicitly recognizes that children deserve their personal data to be specifically protected, ‘as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data’ (Recital 38). It introduces far-reaching changes in relation to the processing of children’s personal data: it requires prior parental consent before the processing of children’s personal data and foresees other additional rights and safeguards.
Although much scholarly attention has been paid to the effectiveness of the new data protection framework, the Regulation has rarely been examined in relation to the nature and extent of the protections afforded to children’s personal data online (Jasmontaite and De Hert, 2014; Mantelero, 2016; Mc Cullagh, 2016; Savirimuthu, 2016; Van Der Hof, 2014). This article, therefore, explores the way in which the Regulation responds to the ‘empowerment versus protection’ dilemma in relation to children, that is, empowers children as Internet users able to grasp the opportunities of playing, learning and communicating, while protecting them from privacy violations and harm. It also explores the extent to which the individual understanding and development of each child is taken into consideration by the Regulation when balancing child rights against the powers and responsibilities of the parents (‘individualized vs average child’ dilemma).
The article begins with a brief description of the two dilemmas, both of which are intrinsically present in child rights law, created by the adoption of the child-specific online privacy protection regime. It then analyses how the EU legislator addressed these dilemmas and foresees future challenges.
Two old dilemmas in child rights law
The ‘empowerment vs protection’ dilemma is not new to child rights debates, but is, rather, part of a larger fundamental conflict underlying the whole of child rights law. This conflict is intrinsic to the UN CRC, due to the potential tensions between articles pertaining to protective rights and those pertaining to participatory (emancipatory) rights. Children’s protective rights, such as the right to protection from ill treatment and abuse, as well as the right to state intervention in order to guarantee said protection, stem from their vulnerability, dependence on adults and need for physical and psychological care and nurture. Participatory (emancipatory) rights include children’s claims to ‘decision-making rights’ (Fortin, 2009: 17), and are close to adult human rights, such as the right to freedom of expression and thought. The dilemma also relates to the tensions among several principles on which the UN CRC is built, such as the best interests of the child and the evolving capacities, participation and self-determination of the child. Efforts to support the best interests of children require participation from children, but there is an inherent contradiction between the two children’s roles as ‘beneficiaries of intervention by adults’ and ‘competent social agents in their own right’ (Boyden and Levison, 2000: 52). The dilemma, therefore, can be seen as being ‘one of the most fundamental challenges posed by the Convention on the Rights of the Child’ (Lansdown, 2005: 32).
The same ‘empowerment versus protection’ dilemma has been partially embraced by Article 24 of the EU Charter of Fundamental Rights. As McGlynn (2002) frames it, ‘Article 24(1) is a curious mix of what might loosely be termed children’s “protection” and “empowerment” rights, which are often found to be in conflict’ (p. 397). The Charter explicitly echoes the tension between the child’s right to express his or her views freely, which should be taken into consideration in accordance with a child’s age and maturity, and the right to protection, when decisions are taken on behalf of the child, in his or her best interests.
In his seminal article on children’s rights, Eekelaar (1986) identified three categories of interests that children may claim: basic (physical, emotional and intellectual care), developmental (equal possibilities to maximize available resources) and autonomy (freedom to choose their lifestyle and to enter into social relations). These interests potentially interact: the developmental interests can be advanced if autonomy is exercised, even if mistakes are made, because a child can learn from them (Gilmore and Glennon, 2014). However, the different interests can also conflict, especially in cases when an adolescent’s exercising of their autonomy conflicts with their basic interests (e.g. physical wellbeing). A false dichotomy also exists between the protection of children and the protection of their interests (Freeman, 1993). Freeman (1993) points out how
[c]hildren who are not protected, whose welfare is not advanced, will not be able to exercise self-determination: on the other hand, a failure to recognize the personality of children is likely to result in an undermining of their protection with children reduced to objects of intervention. (p. 42)
Although the age and maturity (physical, emotional, cognitive and social development) of the child should guide the balancing of the protection and empowerment elements when balanced against each other, that is, help to solve the aforementioned ‘empowerment versus protection’ dilemma, it is difficult to assess when an individual child is competent to take responsibility for a decision affecting him or her. This is the second ‘individualized versus average child’ dilemma discussed in this article.
The challenge underlying the ‘individualized versus average child’ dilemma of determining the age at which specific protection for children should be lowered, taking into account the individual understanding and development of each child, is well illustrated by Lansdown (2005):
It is not possible to prescribe defined ages at which all children need greater or lesser protection or opportunities for assuming responsibility. Nor is it possible to create sufficiently flexible legal and social frameworks through which to accommodate the widely varying capacities of children over different aspects of their lives. The former flies in the face of the evidence about how children’s capacities evolve. The latter risks exposing children to exploitation and abuse. (p. xiv)
Efforts to draw a line, whereby the age demarcating the full legal capacity of children is determined, are often artificial and arbitrary when seeking, in the words of anthropologist Mary Douglas (2013), ‘to satisfy social demands for clarity, which compete with logical demands for consistency’ (p. 113). But from a legal perspective, the legislature may favour the application of a bright-line rule based on age, that is, a clearly set standard leaving no room for the exercise of discretion and assessment of an individual situation. As noted by the European Court of Human Rights (ECHR, 2006), bright-line rules can help ‘to produce legal certainty and to maintain public confidence in the law in a highly sensitive field’. They are also easy to apply and eliminate possible arbitrariness and bias (Federle, 2013). A case-by-case assessment of the individual’s abilities is, administratively, excessively burdensome, particularly in the online environment. In addition, as noted by Scarre (1980), ‘once set, the boundary introduces a quantitative distinction between adults and children, which treats (or has treated) everyone equally, namely the amount of time allocated to acquire experience before adulthood’ (p. 117). However, as bright-line rules are absolute blanket norms, they do not allow for the examining of the interests of each child on a case-by-case basis, or for the taking into account of individual ability and maturity. They are based on a generalized age limit that is used as a proxy for maturity and judgement, and thus may easily exclude children capable of maturely engaging in certain activities. Therefore, it is questionable if a bright-line rule can be justified where it is important to examine the best interests of each child on an individual basis.
European effort to adapt children’s right to privacy to a ‘digital age’: two dilemmas
The Regulation attempts to introduce measures to achieve far-reaching changes in relation to the processing of a child’s personal data online. The question is, however, whether the Regulation will succeed in guaranteeing the universal child’s right to privacy in the online environment while adequately balancing the concerns of online risks and opportunities and accounting for the growing maturity of children.
Empowerment versus protection in EU data protection law
Since the early days of the Internet, the empowerment versus protection dilemma has been present in child safety policy. Policy makers have been faced with a need to maximize accessibility and opportunities presented by digital spaces while seeking to protect vulnerable Internet users from the potential risks and harm associated with their online activities. Dominant concerns related to child sexual abuse have led to a very protectionist stance in relation to children as Internet users. However, highly paternalistic views have problematic consequences for children as rights holders, ‘neglecting their agency and rights to access, information, privacy and participation’ (Livingstone et al., 2015: 5).
Despite strong agreement on the need to create policies that balance children’s opportunities to access information online with the need to minimize their exposure to safety and privacy risks (Livingstone et al., 2011), achieving this remains a complicated task that requires a careful balancing act. Empirical research demonstrates that opportunities and risks online go together. More Internet usage allows children to gain more digital skills, and to climb the ‘ladder of opportunities’ (Livingstone and Helsper, 2007). However, children who take up more online activities encounter more risks. These risks may not necessarily result in harm, and may be seen as risky opportunities that ‘allow children to experiment online with relationships, intimacy and identity’ (Livingstone et al., 2011: 2). On the one hand, these risky opportunities are vital for children in order for them to learn coping behaviour and to build resilience. On the other hand, risky opportunities may lead to vulnerability, depending on the specific circumstances of the child (socioeconomic and psychological factors) and on the design of the online environment (Livingstone et al., 2011).
Ideally, data protection law should protect children from privacy risks, such as commercial data exploitation and misuse, reputational damage, or harm to one’s identity, dignity and personal integrity, while also enhancing online opportunities. This requires a policy framework that not only imposes legal compliance requirements on data controllers, but that also aims to empower children while addressing the needs of those who require greater protection. The Regulation tries to do so with its new empowering and protective provisions. What remains questionable, however, is how successfully it has addressed the empowerment versus protection dilemma, that is, how well does the Regulation strike an adequate balance between the two poles?
Empowering children as Internet users
User empowerment relates to ‘the necessary capabilities for interpreting and acting upon a social world that is intensively mediated by the new media’ (Mansell, 2002: 409). Pierson (2012: 103) underlines the importance of inclusion, digital literacy and privacy as the main issues that need to be addressed before individuals can become empowered online. Following this understanding of user empowerment, several provisions in the Regulation may be seen as aiming to empower children in the digital environment. These empowering provisions are age generic, that is, they apply equally to both adults and children, but can be framed as specifically relevant to children and their online activities.
The right to be forgotten
The most prominent empowering right in the Regulation is the right to be forgotten, a facet of the right to erasure, and an updated and clarified version of the right of access, both already present in the Data Protection Directive (95/46/EC). It is an effort to address the fact that personal information on the Internet can be universally accessed and searched, but not easily removed.
Particularly aimed at children in online environments, when their data is collected based on consent, the right to be forgotten allows children to remove personal information that may be damaging to their reputation and personality. It can be exercised even if an individual is no longer a child. This right is not absolute and does not apply when the data is necessary for the exercise of the right of freedoms of expression and information, archiving purposes or scientific and historical research.
In the ruling of Google vs Spain (C-131/12) the EU Court of Justice had already decided that individuals have the right – under certain conditions – to ask search engines to remove links with their personal information that is inaccurate, inadequate, irrelevant or excessive for the original collection purposes. The ruling sparked a wide debate on both sides of the Atlantic due to a possible chilling effect on access to information and free expression.
The application of this right to children may be more problematic than to adults, demanding a dynamic perspective: with time, an unknown child may become a public figure, and his or her data may therefore change status from private (worth deleting) to something worth public interest (worth preserving) (Blume, 2015).
The right to data portability
This new right should allow Internet users to shift from one service provider to another by moving their personal data. This, according to the European Commission (EC, 2015), should benefit both individuals and companies, as ‘start-ups and smaller companies will be able to access data markets dominated by digital giants and attract more consumers with privacy-friendly solutions’. In fact, an easier exit from ‘walled gardens’, such as Facebook (Barnett, 2010), can reinforce the ongoing trend of social media platform diversification (Cortesi, 2013) among children, and consequently empower children to choose more privacy-friendly online services.
‘Data protection by design’ and ‘data protection by default’
The ‘data protection by design’ and ‘data protection by default’ principles require data protection requirements and safeguards to be built into products and services from the initial stage of their design. Privacy-friendly default settings are expected to be the norm on social networks or mobile apps (EC, 2015), vital for children, as empirical research indicates that on social networking sites (SNSs) ‘not everyone has the digital skills to manage privacy and personal disclosure and many 9- to 12-year-olds use SNSs underage, including 20 percent on Facebook and 38 percent using SNSs overall’ (Livingstone et al., 2011: 2).
Transparent information and awareness
As highlighted by Van Dijk (2013), ‘user empowerment is dependent on knowledge of how mechanisms operate and from what premise, as well as on the skills to change them’ (p. 171). The Regulation obliges data controllers to give information to all data subjects in a clear, audience-appropriate language, for example, by using standardized icons, and the time that their personal data is collected. Recital 58 frames this requirement in relation to children as giving information ‘in such a clear and plain language that the child can easily understand’. The challenge that will be faced by data controllers in practice, however, is how to implement the transparency requirement in a meaningful way in the case of children (Savirimuthu, 2016).
Protecting children as data subjects
Along with a number of empowering provisions, the Regulation introduces two protective provisions, specifically for children as data subjects, that is, subjects whose personal data is collected, held or processed. Protective provisions impose obligations on external parties: negative obligations on data controllers to abstain from certain data collection practices, and positive obligations on parents to engage in activities to secure the effective enjoyment of their child’s fundamental rights.
Prohibition of profiling
The Regulation prohibits certain potentially harmful data collection and usage practices through restrictions on the activities of data controllers. Recital 38 generally emphasizes that specific protection should be afforded to children against marketing or profiling. Under Article 4(4), ‘profiling’ means any automated data processing activity that involves (a) automated processing of personal data and (b) using that personal data to evaluate certain personal aspects relating to a natural person, such as personal preferences, interests, behaviour and location. Recital 71 acknowledges that automated decision making based on profiling should not concern children. This leads to the conclusion that the profiling of children is prohibited, even if the articles of the Regulation do not specifically state so. 2 The prohibition against creating personality or user profiles of children follows the position of the Article 29 Working Party (A29WP, 2013), which stated that behavioural advertising ‘will be outside the scope of a child’s understanding and therefore exceed the boundaries of lawful processing’.
The prohibition of profiling has the potential to diminish the commercial exploitation of children’s data that is now happening through complex marketing, tracking and targeting systems used by many online service providers that monitor and monetize children’s online behaviour and interactions (Montgomery and Chester, 2015). It may also foster the use of contextual, instead of behavioural, advertising by children’s websites and services. Nonetheless, it remains to be seen how effectively such a prohibition can be enforced in practice. For example, Savirimuthu (2016) claims that children might feel only marginal benefits, as profiling is not entirely forbidden in the Regulation and can be carried out in the legitimate interests of the data controller, subject to ‘suitable’ instead of ‘effective’ safeguards (p. 244). Also, even though it might be possible to infer that a user is a child using modern profiling and data mining techniques (European NGO Alliance for Child Safety Online [eNACSO], 2016), it is still difficult to reliably distinguish between adults and children online (Van Der Hof, 2014). An obligation to identify children in order to completely remove them from all targeting may lead to excessive data collection of a large number of adults, and instead of protecting one’s privacy and anonymity online, it could diminish and erode both.
Parental consent
The requirement of prior parental consent or authorization before the processing of the personal data of children when they are directly offered ‘Information Society services’ (Article 8) is probably the most controversial and important protective provision. As the EC explains, this provision ‘aims at protecting children from being pressured to share personal data without fully realising the consequences’ (EC, 2015). As a general rule, protection through the parental consent mechanism is applicable to children under the age of 16. However, 16 years is not an absolute threshold, as member states are allowed to apply a lower age limit, which nevertheless cannot be lower than 13 years. 3 The parental consent requirement is applicable online, excluding offline data processing practices, such as those in the context of school or leisure activities. However, virtual and physical realities are frequently entirely intertwined and mixed for children, creating one total ‘inter-reality’ (Van Kokswijk, 2007: 40), and thus the consent requirement will significantly affect the daily lives of many children.
The default age of 16 is the most debatable legislative choice, raising concerns of being too inclusive and over-protective for several reasons. First, the consent requirement in the Regulation is fully applicable. Instead of protecting the most vulnerable Internet users from harm, it risks limiting all children in their online activities and restricting their opportunities. Except for the preventive or counselling services offered directly to a child, an area where children and parents may often have conflicting interests, or where the parental consent requirement could cause a delay in an emergency situation, the Regulation does not foresee consent exceptions for less risky data collection practices. Rather than being subject to one single rule, the consent requirement could foresee several different scenarios. For example, nuanced risk-based requirements for parental consent exists in the US Children’s Online Privacy Protection Act (COPPA) and could have been considered by the EU legislator. Under COPPA, commercial services that are not interactive or do not share children’s personal data need not obtain parental consent. Where a service uses children’s data for internal purposes, it has to employ a lighter consent mechanism, such as the sending of an email to the parent and taking an additional confirming step after receiving the parent’s response (‘email plus’ method). The highest risk services are those that disclose personal data to third parties, use behavioural advertising and enable children to publicly post information. These services must comply with the most rigid consent mechanisms, such as parents filling in and returning consent forms by mail, fax or scan, the provision of a credit card number, contacting the service provider via a toll-free number or video conference, and the verification of an official identification document.
Second, the consent rule is very broad in scope. An Information Society service is ‘any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services’. 4 As a result, consent will be sought from parents for all types of services in different sectors, that not only include social media, but also online gaming, entertainment sites, instant messaging and email services (Jasmontaite and De Hert, 2014). Some of these services have nothing to do with disclosing personal data online or behavioural tracking, the main worries that seem to be driving the establishment of a specific child data protection regime. An overload of consent requests may result in ‘consent fatigue’ among parents, when a constant consenting process becomes a disturbing irritation rather than a serious choice. This can make the entire parental consent provision illusionary.
Third, the UN CRC obliges state parties to encourage, through legislation and policy, parents ‘to listen to children and give due weight to their views in matters that concern them’ (CRC, 2009). However, the consent requirement in the Regulation positions parents as arbiters in deciding what is both allowed and beneficial for their children, without formally allowing children to influence their decisions. Such a concentration of decisional power placed in the hands of parents raises several issues. Parents may not always be in a position to fully grasp the best interests of the child. There could be cases of disagreement between parents and children over the usefulness and risks in relation to social media, and emotional, moral panic-driven or simply unjustified consent request rejections from parents. According to boyd (2014), adults are not always able to understand the positive and complex interactions between technology and young people. Empirical evidence shows that ‘one in three parents (51 percent of parents of 9- to 12-year-olds, 15 percent of parents of 13- to 16-year-olds) do not want their child to use SNSs’ (Livingstone et al., 2011: 19), even if social media has become a space for the exercise of the freedom of expression, access to information, civic engagement and public participation for children and young people (boyd, 2014). Even worse, parents may become potential invaders of their children’s privacy. For example, by using the right of access to personal data on behalf of their children, parents could get to know about their children’s online activities (Hoofnagle, 2016). Also, parental consent mechanisms may become parental control systems restricting the online freedoms of children (Van Der Hof, 2014). These concerns are not reflected in the logic of the Regulation, even if the right to privacy of children against their parents and the complexity of privacy boundaries within the family have been evidenced by academics (Newell et al., 2015; Shmueli and Blecher-Prigat, 2011).
Fourth, the Regulation fails to respect the evolving capacities of children, especially older children, and to formally involve them in decisions related to the use of their personal data. It makes no effort to adopt a sliding scale approach, and therefore to increasingly recognize the agency of children, foster the participation of children in their own protection and support coping and resilience through learning by doing. Freeman (1983) wisely states that special treatment can be justified due to a child’s incapacity and immaturity, but at the same time, children should be brought to ‘a capacity where they are able to take full responsibility as free, rational agents for their own system of ends’ (p. 57). The Regulation contradicts the right of children to be heard and taken seriously, enshrined in the UN CRC and EU Charter of Fundamental Rights. The Committee on the Rights of the Child (2009) has defined Article 12 of the UN CRC (the right to be heard) not only as a right but also as a general principle – that is, this article should be considered in the interpretation of all other child rights. It requires recognizing that children are gradually capable of contributing to decisions about them, such as the use of their images or the monitoring of their activities, and should be consulted accordingly (A29WP, 2009). In the Regulation, solutions for consent could have varied from mere consultation of the child, to the parallel or joint consent of the child and a parent, and even to the autonomous consent of a mature child (A29WP, 2009).
Individualized versus average child dilemma
Determining a precise age limit after which the processing of personal data becomes subject to fewer legal constraints is not a challenge faced solely by data protection law. Other areas such as family, civil, criminal and administrative law have also faced the question of whether a line indicating a particular age as the starting point of adulthood had to be drawn. Sometimes the law looks at the issue on a case-by-case basis, examining factors particular to the individual child, and in other situations the law adopts a bright-line (i.e. age of 14, 16, 18 years) rule. This is essentially a choice to be made in the ‘individualized vs average child’ dilemma.
The Regulation chooses to set a single age when all children can be deemed competent to consent to the processing of their personal data, relying on an ‘average child’ criteria. Such a legislative choice of determining a prescribed age limit can be criticized for several reasons.
First, the capacities of a child are personal, context-dependent and constantly evolving. An assessment in each individual case would show widely differing capacities among children of the same age and could, thereby, reflect the best interests of the child.
In fact, presently, only three member states (Spain, Hungary and the Netherlands) have chosen to explicitly state in their national data protection law the exact age threshold for consent. 5 Many remaining member states rely on the individualized child criteria and advise data controllers to perform a subjective and context-specific rather than universally applicable capacity test. In order to decide whether a child is able to consent, the data controllers should assess the concrete situation on a case-by-case basis, applying general criteria of the best interests of the child, level of moral and psychological development, the capacity to understand the consequences of giving consent and evaluating specific circumstances (age of the child, purpose of data processing, type of personal data involved, etc.). Only exemplar assumption-based age thresholds are sometimes set in case law, legal doctrine or guidelines from the data protection authorities. On the European level, national data protection authorities took a similarly flexible approach and did not set precise age limits at which parental consent is required. Instead, they underlined the importance of the maturity of a child and complexity of the data processing at hand (A29WP, 2009).
Second, the same child may need protection for one data processing purpose, and autonomy or self-determination for another, depending on the potential privacy risks and harm that are at stake. For instance, data collection for the purpose of sending a newsletter might not require parental consent, while such consent would be necessary to create a social media account in relation to the same child (UK Information Commissioner’s Office [ICO], 2010). The imposition of legal age limits may disproportionally restrict the rights of other children and data subjects, irrespective of a child’s own levels of competence.
More protection or empowerment?
At first glance, the Regulation seems to provide many innovative empowerment rights, while failing on protective rights for children. A closer look, however, reveals that paternalistic protection is a favoured approach in the Regulation over the empowerment of children. The Regulation justifies protective measures exclusively in light of children’s inadequacies by stating that children merit specific protection due to their potentially lower awareness of risks, consequences, safeguards and rights relating to the processing of their personal data (Recital 38).
More importantly, although particularly relevant to children, all the empowering provisions in the Regulation are addressed to individuals of all ages, while only the protective provisions apply exclusively to children. In what Stalford (2012) calls the ‘hegemony of child protection’, the strict consent requirement formulated in Article 8 of the Regulation seems to place children under the strict over-protection of their parents (p. 224). As a consequence, Article 8 does not address the weight to be assigned to the child’s opinion, nor does it acknowledge the interrelation between a child’s opinion and his or her best interests. The adoption of broad parental oversight through the consent mechanism also raises questions as to whether and to what extent children will be able to enjoy the empowering rights, such as the right to be forgotten and data portability, without parental involvement. In sum, the highly protective consent provision seems to distort the balance between empowerment and protection towards the latter, especially for teens.
A look to the future – beyond the letter of the law
Despite the promising rights and obligations related to children in the Regulation, in reality, only their proper and effective implementation will demonstrate any credible attempt from the EU to empower and protect children. In order to reach such implementation, a number of complex, practical, structural and intellectual challenges are to be addressed by EU policy makers, national data protection authorities and Information Society service providers.
The biggest practical challenge for the EU will be to ensure that online a child’s age and parental consent are verifiable, or the main protective provision in the Regulation will lose its effectiveness. As a side effect, an unenforced legal requirement on parental consent might lead to the loss of respect for the mere idea of rule-making (eNACSO, 2016). Up until now, there have been no foolproof, adequate mechanisms to universally verify a child’s age online. Determined children are able circumvent the majority of age verification mechanisms by simply lying about their age or pretending to be their parents without penalty. Ideally, to avoid overburdening, age verification would be based on a sliding scale approach and depend on the circumstances, such as data processing purpose and use and type of data (A29WP, 2011). Although consent verification techniques exist, they have to be both effective and easy to use, as well as having to comply with the main data protection principles, such as data minimization, purpose limitation, data adequacy and relevance (Jasmontaite and De Hert, 2014).
The Regulation encourages data controllers to determine techniques for verifiable parental consent in the codes of conduct of industry associations. Until now, the success of such voluntary codes in practice has been very limited. The number of codes approved by the national data protection authorities varies from one member state to another. On the European level, very few organizations representing specific sectors have tried, and only one of them has managed to draw up a code that was fully endorsed by the European data protection authorities. 6 Self-regulatory codes are often limited in their ability to protect children, because of vague language, inadequate enforcement and monitoring mechanisms (Macenaite, 2016). Alternative approaches, such as explicitly integrating the UN CRC principles into self-regulatory codes, instead of leaving the industry to determine their standards for respecting children’s needs and interests, could provide valuable solutions (Savirimuthu, 2016). Stronger participation of the EU public authorities in the self-regulatory process, in particular, rule formulation and enforcement, could help to achieve a better balance between the interests of children to exercise control over their personal data and the desire of businesses to valorize and profit from users’ personal data.
More fundamentally, it should be acknowledged that, on a structural level, informed consent to personal data processing is not a panacea tantamount to giving complete control to individuals over their personal data in complex networked environments. A rich body of literature points to the characteristics of the networked environments that restrain an individual’s control over their personal data (Cohen, 2012; Hildebrandt, 2008). Various scholars have emphasized the weaknesses of consent as a protection mechanism online (Mantelero, 2014; Schermer et al., 2014). Neither parents nor children can take full responsibility and control of their personal data online, as their choices and data control possibilities are shaped by the design and functionalities of communication spaces (Marwick and boyd, 2014). Although there is no easy answer to the structural power imbalances online, privacy enhancing engineering and design solutions, if enforced under the data protection by design obligations of the Regulation, could provide some realistic possibilities to affect networked environments and respond to children’s needs and expectations.
Finally, an intellectual challenge for member states will be to define an average child in different data collection scenarios based on comprehensive research and solid empirical evidence. Social and behavioural sciences should be the first areas from which national legislators should gather the evidence to justify any given age limit. As it seems highly unlikely that fixing a single age limit for consent in all data processing activities online could be the most appropriate solution, different sectors, data collection practices and age spans might require detailed examination and research. In addition, the views of children themselves should be considered in policy making, preparation of national laws related to the processing of children’s personal data, as well as their evaluation (CRC, 2009).
Footnotes
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
