GDPR-K Article 35 / Recital 75 - Data protection impact assessment for children's data
Conduct a Data Protection Impact Assessment before processing children's data, as processing data of vulnerable persons (including children) is considered likely to result in high risk
Where this comes from
Provision: Article 35 / Recital 75 - Data protection impact assessment for children's data
Instrument: General Data Protection Regulation (EU) 2016/679
Citation: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, Article 35 and Recital 75
Text version: Regulation (EU) 2016/679 (GDPR), OJ L 119, 4.5.2016, consolidated
Who it applies to
It applies when all of these are true:
- Service is likely to be accessed by children under 18
- Data categories collected — any answer
…unless:
- DPIA not required where processing is not likely to result in high risk to individuals. (UK GDPR Article 35(1))
- DPIA not required where processing has a legal basis in law and DPIA was already carried out as part of establishing that legal basis. (UK GDPR Article 35(10))
Scope in the source's own terms
- Processing involves children's data (high risk)
- Processing subject to GDPR (EU scope; block moved from UK-GDPR authorship)
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Assessment covers data flows, the risks to the affected group, and likelihood/severity
- Each identified risk has a mitigation mapped to a concrete control or backlog item
- The assessment is dated, has named sign-off, and is scheduled for review
- The assessment is retrievable for regulators on request
- Signed assessment document is stored and version-controlled
Evidence an auditor expects
- Assessment documentDocument reviewRetain 6 years from completion
Data Protection Impact Assessment (DPIA)
Full DPIA covering: systematic description, necessity/proportionality, risks to children, and mitigation measures
- Process recordDocument review
DPIA review schedule and updates
Record of when DPIAs are reviewed and updated, triggered by changes to processing
- Audit reportDocument reviewRecommended
DPO consultation record
Evidence of DPO involvement in DPIA where applicable
Questions people ask
- Does GDPR-K Article 35 / Recital 75 - Data protection impact assessment for childr… apply to my service?
- It applies when Service is likely to be accessed by children under 18; Data categories collected — any answer. It does not apply where DPIA not required where processing is not likely to result in high risk to individuals. (UK GDPR Article 35(1)).
- From when does this apply?
- GDPR-K Article 35 / Recital 75 - Data protection impact assessment for childr… applies from 25 May 2018. Its current status is: in force.
- What evidence does an auditor expect?
- Data Protection Impact Assessment (DPIA); DPIA review schedule and updates; DPO consultation record.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.