For the purposes of this Q&A we have focused on the transparency obligations under Regulation (EU) 2016/679, the General Data Protection Regulation (the GDPR), and not on other issues, such as consent to the processing of personal data. For further guidance on consent by children, including in the context of the information society services, see Practice Note: Children and data protection law. Who is a child for the purposes of the GDPR? As explained in Practice Note: Children and data protection law, the Information Commissioner’s Office (ICO), in its guidance on Children and the GDPR, considers that a ‘child’ is anyone under the age of 18. This is in accordance with the UN Convention on the Rights of the Child, ratified by the UK, which defines a child as anyone under 18, unless ‘under the law of applicable to the child, majority is attained earlier’. How