Post #2345146
2026-05-10 13:42 UTC
@argv_minus_one@mastodon.sdf.org @nik@toot.teckids.org @fuchsiii@oxytodon.com @malwareminigun@infosec.exchange GDPR Article 6(1)(b): Processing shall be lawful […] if […] processing is necessary […] in order to take steps at the request of the data subject […].
GDPR Article 8(1)(1): Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least [13 to] 16 years old.
Age restrictions do not apply under 6(1)(b).
Replies (1)
-
@wizzwizz4@fosstodon.org 2026-05-10 13:47
@argv_minus_one@mastodon.sdf.org @nik@toot.teckids.org @fuchsiii@oxytodon.com @malwareminigun@infosec.exchange GDPR Recital 38 is not directly relevant, but is common-sense advice (and worth reading). You should also be aware that bases other than 6(1)(a) ("consent") are very narrow, and 6(1)(a) is the hardest basis to obtain: the loopholes that most companies use don't actually exist, and those companies are breaking the law. If you're not doing bad stuff, though – where "hoarding people's secrets" counts as bad stuff – GDPR nearly always says it's fine.