FieldRegister
Every field · Demographics

Date of birth or age

Date of birth identifies a person on its own and reveals whether the person is a child. Age-based profiling needs a basis and a notice.

personal data
personal data?
confidential
sensitivity
needs a basis
AI use
contract or consent; check for children under the age of digital consent in the member state (13 to 16, Art. 8)
lawful basis usually relied on

Keep it how long

Only where age verification or the contract needs it; otherwise store an age band, not a date.

The gap we see most

Collected for birthday marketing, with no check for minors and no consent for the marketing.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Date of birth: age and children GDPR Art.8 · GDPR Art.5 · ISO/IEC 27701:2019 7.4.1
GDPR Art.8 Conditions applicable to child's consent

Where consent is the lawful basis and information society services are offered directly to a child, processing the child's personal data on the child's own consent is lawful only from age 16, or from the lower age a Member State has set in law, which may be no lower than 13. Below that age the proce...

Evidence an auditor accepts: The assessment of whether the service is an information society service offered directly to children; The age threshold applied per Member State, with evidence the applicable national lower age was checked rather than assumed; The age assurance mechanism, and the reasoning for why it is a reasonable effort given available technology
GDPR Art.5 Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, e...

Evidence an auditor accepts: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose
ISO/IEC 27701:2019 7.4.1 Limit collection

The organization must limit collection of personal data to the minimum that is adequate, relevant, proportional and necessary for the identified purposes, including data collected indirectly through means such as web and system logs, and where any optionality in collection and processing exists each...

Evidence an auditor accepts: Field level justification linking each item collected to an identified purpose; Assessment of indirectly collected data such as logs, telemetry and tracking; Evidence optional collection is off by default, captured from the live configuration

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Child or dependant details · Consent or opt-in record