Re: The ICO 'court'
Bullshit. GDPR doesn't say anything about age and it's *all* OSA (and other non-GDPR legislation about advertising to minors).
Wrong. And not just wrong, but trivially checkable. Try harder. The entire world's information at your fingertips and you can't be bothered to do a simple google.
Are there any specific safeguards for data about children?
Your company/organisation can only process a child’s personal data on grounds of consent with the explicit consent of their parent or guardian up to a certain age. The age threshold for obtaining parental consent varies between 13 and 16 years, depending on the age established in each EU Member State. Check with your National Data Protection Authority.
A reasonable effort must be made, taking into consideration available technology, to verify that the consent given is truly in line with the law. That means that your company/organisation must implement age-verification measures (for example control questions, actions on the website).
It is this which Imgur basically just said "Nah" to.
-----------------------------
Article 8 makes specific provisions to the legality of processing children's data - "Conditions applicable to child's consent in relation to information society services"
1. Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child. Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.
2. The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.
-----------------------------
This is further expounded in Recital 38, which is not technically an article of GDPR, but it part of it's raison d'être and would therefore be considered in interpreting and ruling on GDPR.
Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. 2Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child. 3The consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.