⚠️ DRAFT — not yet in force. This document is published in draft, for transparency, while our organisation's registration is being completed. It has not yet been reviewed by a solicitor or a Data Protection Officer, and any detail shown as 'to be confirmed' is not yet finalised. We will replace it with a reviewed, signed version.

Minimum Age & Parental-Consent Thresholds (per jurisdiction) — TEMPLATE — physmat.org

This is an internal, parameterised module that sits behind our Privacy Policy and Children's Privacy Notice. It records, per jurisdiction, the age at which a child may consent to our service themselves and below which a parent or guardian must consent on their behalf. The per-market Article 8 figures below are stated thresholds, each carrying a to be verified against current national law; stating a value here is not a claim that we operate in that market today.

This service is offered in the United Kingdom. It is not offered in the United States at this time, and we do not target US users.


1. Why age matters

Where we rely on a child's consent as the lawful basis for offering an "information society service" (broadly, an online service like ours) directly to that child, data-protection law sets a digital age of consent:

This rule comes from GDPR (Regulation (EU) 2016/679) Article 8 and, for the UK, its retained equivalent UK GDPR Article 8 (read with the Data Protection Act 2018). Article 8 fixes a default of 16 but expressly allows each EU member state to lower it, to no younger than 13. The UK has set its threshold at 13.

Scope note. This threshold governs consent-based processing of a child's data for our service. It is distinct from (a) the lawful basis we actually rely on for a given purpose, which is a separate determination, and (b) any contract-competence question under our Terms of Service.

2. United Kingdom (current launch market)

JurisdictionDigital age of consentBelow this ageSource
United Kingdom13parental consent requiredUK GDPR Art. 8; Data Protection Act 2018 s. 9

The UK is the only live market at launch. In addition to Article 8, UK children's data is processed in line with the ICO's Age Appropriate Design Code (Children's Code), as described in our Privacy Policy.


3. European Union member-state thresholds (stated values — verify against national law)

GDPR Article 8(1) defaults to 16 and permits member states to set a lower age, not below 13. The figures below are stated now as our per-market thresholds, taken from the standard national transpositions of Article 8. Each carries a to be verified against current national law. Stating a value is not a decision to launch that market — only the United Kingdom is a live launch market.

Member stateDigital age of consentBelow this ageVerify
Ireland (IE)13parental consent required
Spain (ES)14parental consent required
France (FR)15parental consent required
Germany (DE)16parental consent required
Netherlands (NL)16parental consent required
Default (any EU state not listed)16parental consent required

Source for all EU rows: Regulation (EU) 2016/679 (GDPR), Article 8, as transposed into national law by each member state — see EUR-Lex (eur-lex.europa.eu, document 32016R0679). National transpositions can change; each value must be re-confirmed against the member state's current implementing law before that market goes live.

Important. This table is not exhaustive and stating these values is not a live operating claim — only the UK is a live launch market. The wider EU/EEA contains member states with their own Article 8 figures (which range from 13 to 16) that are not listed here. Do not infer a threshold for any unlisted state — confirm it directly before entry.

4. How a user's age is determined (age assurance)

We capture each student's date of birth at sign-up, alongside the year_group. The date of birth is used to derive the child's age and so to apply the correct jurisdictional threshold and to serve age-appropriate content.

Our approach to age assurance is self-declared date of birth at sign-up, together with parental involvement (mirroring the Privacy Policy §3 position): a parent leads the consumer sign-up flow, or a school acts under its own authority, so the stated age is not relied on in isolation. How robustly this establishes a genuine age (and, where required, a parent's authority to consent), proportionate to the risk, remains. This module records which threshold applies per market; it does not by itself settle how age is assured.


5. Below-threshold flow (parental consent required)

Where a prospective or current user is below the applicable jurisdictional threshold, our intended design is:


6. Cross-references

Questions about age thresholds or the parental-consent flow: mail@physmat.org.


This module is iterated with the founder and then handed to the DPO/solicitor. Every per-market figure carries a to be confirmed against the current national implementing law before that market is launched. No EU market is live; only the United Kingdom is.