logo

Protecting Minors in the Age of Artificial Intelligence

LetsLaw / Digital Law  / Protecting Minors in the Age of Artificial Intelligence
abogados proteccion ia menores

Protecting Minors in the Age of Artificial Intelligence

The rapid expansion of artificial intelligence (AI) is transforming the way people interact with technology. Generative AI tools, virtual assistants, recommendation algorithms and biometric recognition systems have become part of the daily lives of millions of users, including children and adolescents. This reality has placed the protection of minors at the centre of the regulatory debate, highlighting the need to ensure that the development and deployment of these technologies respect their fundamental rights.

This concern has recently gained greater international relevance following the launch of a coalition promoted by Spain, together with more than twenty countries and international organisations such as UNICEF and UNESCO, to strengthen the protection of children against the risks associated with artificial intelligence. This initiative reflects a clear trend: AI governance cannot be limited to fostering technological innovation; it must also incorporate effective safeguards to protect particularly vulnerable groups.

Against this backdrop, both the European and Spanish legal frameworks already impose significant obligations aimed at ensuring the responsible use of artificial intelligence whenever minors may be affected.

The European and Spanish Legal Framework for the Protection of Minors in the Context of AI

The AI Act forms part of a broader regulatory ecosystem in which the General Data Protection Regulation (GDPR), the Spanish Organic Law on Data Protection and the Guarantee of Digital Rights (LOPDGDD), the Spanish Charter of Digital Rights and other applicable legal instruments continue to play a fundamental role.

The AI Act adopts a risk-based approach, classifying AI systems according to the level of risk they pose to individuals’ fundamental rights. Its objective is not only to encourage innovation but also to prevent the harmful effects that certain AI systems may have on people’s health, safety and fundamental rights.

Although the Regulation does not establish a specific regime exclusively dedicated to minors, it expressly recognises the need to protect vulnerable persons and prohibits certain AI practices where they exploit vulnerabilities arising, among other factors, from a person’s age and are likely to cause significant harm.

At the same time, the GDPR remains the primary legal framework whenever an AI system involves the processing of personal data. The Regulation is built upon a fundamental principle: the protection of personal data is itself a fundamental right recognised under European Union law, and any processing operation must comply with the principles of lawfulness, fairness, transparency and proportionality.

Obligations under the AI Act and the GDPR for AI Systems Accessible to Minors

Organisations that develop, market or deploy AI systems likely to be accessed by minors must integrate regulatory compliance from the earliest stages of the system’s lifecycle.

From the perspective of the AI Act, this requires, among other things, identifying the risks that an AI system may pose to fundamental rights, implementing appropriate risk management measures, ensuring human oversight whenever required, and guaranteeing the quality of the data used to train and operate the system. In addition, providers and deployers must comply with the technical documentation, traceability and transparency requirements applicable to high-risk AI systems.

The GDPR imposes further obligations whenever personal data are processed through AI systems. Any such processing must comply with the principles of data minimisation, purpose limitation, accuracy, integrity and confidentiality. Moreover, controllers are required to implement data protection by design and by default, incorporating appropriate technical and organisational measures from the earliest stages of technological development.

Particular importance should be attached to the obligation to carry out a Data Protection Impact Assessment (DPIA) whenever the processing is likely to result in a high risk to the rights and freedoms of individuals. This may be the case where innovative technologies are used to create profiles, make automated decisions or process minors’ personal data on a large scale.

This preventive approach is fully aligned with one of the GDPR’s key objectives: strengthening citizens’ trust in the digital economy while ensuring a high level of protection against the risks arising from technological development.

Age Verification and Parental Consent on Digital Platforms

One of the main challenges facing digital platforms is ensuring that minors access their services in compliance with data protection legislation.

In recent years, the traditional approach based solely on users self-declaring their age has proven insufficient for digital services that may expose children to significant risks. Consequently, both European institutions and data protection authorities have encouraged the development of more effective age verification mechanisms, while ensuring compliance with the principles of proportionality and data minimisation.

Alongside age verification, particular attention must be paid to the parental consent regime established under Article 8 of the GDPR for information society services offered directly to children. In Spain, the LOPDGDD provides that children aged 14 and over may validly consent to the processing of their personal data. Below that age, consent must be provided or authorised by the holder of parental responsibility or legal guardianship.

However, obtaining consent does not exempt organisations from complying with the other obligations established by the GDPR. Consent must be freely given, specific, informed and unambiguous, expressed through a clear affirmative action by the data subject or, where appropriate, by their legal representatives.

Accordingly, digital platforms incorporating AI functionalities, such as conversational assistants, educational applications, social media platforms, video games or generative AI tools, should review their access procedures, privacy policies and internal governance processes to ensure the lawful and appropriate processing of minors’ personal data.

Protecting minors in the context of artificial intelligence represents one of the most significant regulatory challenges of the ongoing digital transformation. The combined application of the AI Act, the GDPR and Spanish legislation establishes a legal framework that requires organisations to adopt a preventive approach firmly grounded in the protection of fundamental rights.

Regulatory compliance can no longer be regarded as a task to be addressed after technological development has taken place. On the contrary, responsible AI governance requires organisations to embed the protection of minors into the design of AI systems, assess the risks associated with their deployment, ensure transparency throughout processing activities, and implement effective age verification and data protection measures.

Ultimately, the success of artificial intelligence will depend not only on its capacity to drive innovation but also on its ability to earn public trust. Ensuring that the rights and best interests of minors remain at the heart of the design, development and deployment of AI systems is therefore essential for achieving trustworthy and responsible artificial intelligence.

Contact Us

    By clicking on "Send" you accept our Privacy Policy - + Info

    I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our Privacy Policy - + Info