If a website is directed at children and uses non-essential cookies, organisations should treat parental consent as required for children under the applicable age threshold, which this guidance sets at under 16. Teams should also use suitable online identity verification to check that the parent or legal guardian actually provided consent before any non-essential tracking begins.
When parental consent becomes required
For websites directed at children, the decision point is not whether the cookie banner is technically present, but whether the non-essential cookie activity can start before a valid consent decision has been made. If the site is aimed at children and the cookies are not strictly necessary for the service, organisations should treat parental consent as the safe default for children below the applicable threshold, here under 16.
That threshold matters because it changes who can lawfully authorise the tracking. A child may be the site visitor, but the consent action needs to come from a parent or legal guardian where local law and guidance require that extra layer of authorisation. For organisations, the practical question is whether they can demonstrate that the consent came from the right person before any non-essential processing begins.
In practice, this means separating essential functions from analytics, advertising, profiling, or other non-essential cookies. If the cookie is not required to deliver the service the child actually asked for, it should remain disabled until the consent workflow is complete. The standard is not convenience, it is defensible permission.
What counts as a defensible consent workflow
A defensible workflow does two things: it captures consent for the relevant processing, and it verifies that the consenting person is actually the parent or legal guardian. A simple declaration on a form is usually weak on its own. Teams need a method of suitable online identity verification that is proportionate to the risk and suitable for the audience.
That verification does not have to be the same for every site, but it must be credible enough that the organisation can stand behind it if challenged. The key control question is whether the site has moved from assumed permission to evidenced permission. If not, tracking should not begin.
This is also where consent design and data-minimisation discipline intersect. The more tracking a site performs, the more important it becomes to limit collection to what is necessary and to avoid using children’s browsing behaviour as a default input for wider profiling. Identity Data Privacy and Consent Guide is useful background when the consent decision depends on proving who authorised the processing and why that authorisation is valid.
How to operationalise it without weakening the control
Organisations should design the flow so that non-essential cookies remain blocked until consent is verified, not merely requested. The implementation detail matters: if scripts load before the verification step is complete, the control has already failed even if the banner later records an approval.
Teams should also retain evidence of the consent event, the age-gating logic, and the verification method used for the parent or guardian. That evidence is what turns a policy statement into something auditable. For child-directed services, the most useful evidence is usually a combination of consent record, timestamp, policy version, and the specific verification path used.
Because this topic is fundamentally about lawful processing and consent governance, the clearest external reference point is the EU General Data Protection Regulation (GDPR). Where child audiences are involved, the same logic also aligns with privacy-by-design expectations, meaning the consent mechanism should be embedded into the site journey rather than bolted on after tracking has already started.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 5 — Principles relating to processing of personal data | Child-cookie consent and minimisation depend on lawful, fair, transparent processing. |
| Art. 25 — Data protection by design and by default | The consent gate must be built into the site flow before tracking starts. | |
| Art. 32 — Security of processing | Identity verification and consent records need appropriate protection and integrity. | |
| Recommendation — Apply Art. 5 to keep non-essential tracking off until consent is valid and proportionate. Design the child consent journey so non-essential cookies remain blocked by default. Protect consent evidence and verification records with suitable security controls. | ||
Practitioner Guidance
What to prioritise: Put the gating control before any non-essential tag fires. If analytics, advertising, or profiling scripts can execute before consent verification, the workflow is not compliant in practice even if the UI looks correct.
What to verify: Confirm that the age threshold, the consent capture, and the identity verification step all work together. A child-directed site needs more than a checkbox, it needs a traceable decision that the consent came from a parent or legal guardian.
Common mistake: Teams often treat cookie banners as the control. The real control is the combination of blocking, verification, and evidence retention. If any one of those is missing, the organisation may still be exposing children to premature tracking.
Practitioner takeaway: For child-focused websites, consent is only meaningful when the organisation can prove that non-essential tracking stayed off until an appropriately verified adult authorised it.
Related resources from NHI Mgmt Group
- How should security teams implement consent controls for non-essential cookies in identity systems?
- How should organisations implement verifiable parental consent for children’s data under COPPA?
- How should organisations set up age verification and parental consent controls so children are protected without making the experience unusable?
- Why do non-essential cookies create compliance risk for websites that process personal data?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org