GDPR-K Article 5(1)(c) - Data minimisation principle applied to children's data
Apply a strict data minimisation standard to children's data, collecting and processing only what is strictly necessary for the specified purpose
Where this comes from
Provision: Article 5(1)(c) - Data minimisation principle applied to children's data
Instrument: General Data Protection Regulation (EU) 2016/679
Citation: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, Article 5(1)(c), read with Recital 38
Text version: Regulation (EU) 2016/679 (GDPR), OJ L 119, 4.5.2016, consolidated
Who it applies to
It applies when all of these are true:
- Service is likely to be accessed by children under 18
- Data categories collected — any answer
…unless:
- Data may be retained for longer periods where required for archiving, research, or statistical purposes with appropriate safeguards. (UK GDPR Recital 39)
- Additional data may be collected where necessary for child safety purposes. (ICO Data Minimisation Guidance)
Scope in the source's own terms
- Service processes data of users under 18
- Service operates under GDPR (EU scope; block moved from UK-GDPR authorship)
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Each collected field is mapped to a specific, documented purpose
- Fields with no active purpose are removed from collection and storage
- Optional data is genuinely optional (service works without it)
- Collection of children's data is limited to what is strictly necessary
- System handles null/empty input gracefully (no 500 errors)
Evidence an auditor expects
- Technical controlTechnical audit
Data collection configuration
Technical documentation showing only necessary data fields collected from children
- Assessment documentDocument review
Data necessity assessment
Documented justification for each data element collected from children
- Policy documentDocument reviewRetain Duration of processing + 6 years
Data retention policy
Policy specifying retention periods for children's data with justification
Questions people ask
- Does GDPR-K Article 5(1)(c) - Data minimisation principle applied to children's data apply to my service?
- It applies when Service is likely to be accessed by children under 18; Data categories collected — any answer. It does not apply where Data may be retained for longer periods where required for archiving, research, or statistical purposes with appropriate safeguards. (UK GDPR Recital 39).
- From when does this apply?
- GDPR-K Article 5(1)(c) - Data minimisation principle applied to children's data applies from 25 May 2018. Its current status is: in force.
- What evidence does an auditor expect?
- Data collection configuration; Data necessity assessment; Data retention policy.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.