Rights Requests Involving Minors: Who Can Ask, and For What
Section 9's verifiable parental consent framework carries through into how rights requests for a minor's data should be handled, and who is entitled to make them.
The consent framework sets the baseline
Section 9 requires verifiable consent from a parent or lawful guardian before processing the personal data of a child under eighteen. That same relationship carries through to rights requests - if a parent or guardian was the one who provided consent on the child's behalf in the first place, it follows that they are also the appropriate person to exercise access, correction, and erasure rights on the child's behalf while the child remains a minor.
This means a rights request concerning a minor's data should generally be evaluated against the parent or guardian relationship on file, not treated identically to a first-person adult request. Verifying that the requester is actually the parent or guardian who provided the original consent is a necessary part of processing the request safely.
What happens when the minor themselves makes the request
A request submitted by the minor directly, rather than through a parent or guardian, sits in a more ambiguous position, since the underlying consent structure assumes the guardian is the one managing the relationship. In practice, the safer approach is to route such a request through parent or guardian verification as well, rather than acting on it purely on the minor's own instruction, given that the Act's consent architecture for minors is built around guardian involvement.
Where a request appears to come from the minor but raises a concern the parent might not be aware of, judgment is needed - but the underlying legal basis for processing the child's data still rests on the guardian relationship, and requests should generally be reconciled with that structure rather than bypassing it.
The transition to adulthood
Once the individual turns eighteen, the guardian-based consent and rights-handling arrangement no longer applies, and any parent or guardian access should be treated as ended unless the now-adult individual has separately authorized it, for example through the nomination mechanism under Section 14. Organizations that keep processing requests through a parent well past a user's eighteenth birthday, purely out of habit, are working from an outdated authorization.
It is worth building a process check around age transitions - a flag when an account holder turns eighteen, prompting a review of whether guardian access should be revisited - so the rights-handling process stays aligned with who is actually entitled to act.
Where to go next
The Consent Notice Builder can help make sure the original parental consent capture is structured clearly enough to support later rights-handling decisions, and the Rights Navigator can walk through who is entitled to act in a specific minor-related scenario.