Modern Legal
  • Napreden AI iskalnik za hitro iskanje primerov
  • Dostop do celotne evropske in slovenske sodne prakse
  • Samodejno označevanje ključnih relevantnih odstavkov
Začni iskati!

Podobni dokumenti

Ogledaj podobne dokumente za vaš primer.

Prijavi se in poglej več podobnih dokumentov

Prijavite se za brezplačno preizkusno obdobje in prihranite ure pri iskanju sodne prakse.

The status of a minor as a controller

23. junij 2026
Z Googlom najdeš veliko.
Z nami najdeš vse. Preizkusi zdaj!

Samo zamislim si kaj bi rada da piše v sodbi, to vpišem v iskalnik, in dobim kar sem iskala. Hvala!

Tara K., odvetnica

The status of a minor as a controller

Datum

23.06.2026

Številka

07121-1/2026/636

Kategorije

Obdelava osebnih podatkov otrok in mladoletnih, Skupni upravljavci

The Information Commissioner has received your request for an opinion concerning the status of a minor as a controller under the GDPR (e.g., influencers, youtubers). In this regard, you have raised several questions, to which we provide our non-binding opinion below.

In principle, our preliminary view would be that minors can qualify as controllers within the meaning of Article 4(7) GDPR if they determine the purpose and means of processing personal data. This is because the concept of a controller under the GDPR is primarily a functional one, centred on the actual influence exercised over the purposes and means of processing, rather than being linked to individual’s capacity (to contract).

Explanation:

At the outset, we would like to emphasize that the Information Commissioner is not competent to interpret legal provisions governing the civil liability, minor offence liability, or criminal liability of minors or other individuals. We consider it important to highlight this, as several of your questions also concern areas of law that fall outside the Information Commissioner’s competence.

Q1: Do you consider a person under the age of 18 who processes personal data for purposes independently determined by that person to be a controller within the meaning of the GDPR?

The Information Commissioner has not yet had the opportunity to examine the issue of the status of a minor as a controller under the GDPR in depth in its enforcement practice. In the cases encountered so far, the processing of personal data by minors have generally fallen either within the scope of the household exception (Article 2(2)(c) GDPR) or within the context of the exercise of freedom of expression. With regard to the latter, it should be noted that under the Slovenian Personal Data Protection Act (ZVOP-2), the Information Commissioner is not competent do decide cases concerning the processing of personal data carried out for journalistic purposes, academic, artistic or literary expression, or other forms of freedom of expression. Competence to decide on such matters lies with the courts. Consequently, we have had limited opportunities to address the status of minors as controllers.

In principle, however, our preliminary view would be that minors can qualify as controllers within the meaning of Article 4(7) GDPR if they determine the purpose and means of processing personal data. This is because the concept of a controller under the GDPR is primarily a functional one, centred on the actual influence exercised over the purposes and means of processing, rather than being linked to individual’s capacity (to contract).

Q2: Does Slovenian law contain any provisions specifically regulating the legal status of a minor who processes the personal data of other individuals, whether as a controller, processor, or joint processor, including provisions governing the liability of such a person for infringements of the GDPR?

No, Slovenian law does not contain any specific provisions regulating the legal status of a minor who processes personal data of other individuals as controller, processor or joint controller / processor within the meaning of the GDPR. Likewise, Slovenian law does not contain any specific provisions governing the liability of minors for infringements of the GDPR. Questions relating to the capacity to contract (poslovna sposobnost), civil liability, representation, and the exercise of rights and obligations by minors are therefore governed by the general rules of Slovenian civil law and other relevant national legislation, rather than by specific data protection provisions.

Q3: Are there any specific legal provisions under Slovenian law governing the civil liability of a minor for infringements of the GDPR, or is such liability borne by the minor’s legal guardians, parents, or custodians?

There are no specific provisions in Slovenian data protection law governing the civil liability of minors for infringements of the GDPR. Consequently, the question of a minor’s civil liability for damages resulting from unlawful processing of personal data is subject to the general rules of civil liability for damages as set out in the Slovenian Obligations Code (Obligacijski zakonik).

Under Article 137 of the Obligations Code:

-A minor under the age of seven is not liable for damage he or she causes.

-A minor between the ages of seven and fourteen is not liable for damage unless it is proven that he or she was capable of understanding the consequences of his or her actions at the time the damage was caused.

-A minor who has reached the age of fourteen is liable according to the general rules governing liability for damage.

Civil liability of parents and other persons responsible for supervising minors is governed by Articles 141-146 of the Obligations Code. In particular:

-Parents are strictly liable for damage caused by a child under the age of seven, subject to the general grounds excluding strict liability.

-For minors aged seven and above, parents are liable unless they prove that the damage occurred without fault on their part.

Q4: From what age does Slovenia permit a minor to enter into civil-law contracts with third parties and, consequently, to bear liability arising from a breach of contractual obligations?

A minor who has reached the age of 15 may enter into civil-law contracts independently, unless otherwise provided by law (Article 146 of the Family Code). However, the validity of such contracts requires the approval of the parents if they are of such significance that they substantially affect the minor’s life, or if they are capable of affecting the minor’s life even after reaching adulthood. Whether a particular contract has such an effect must be assessed on a case-by-case basis.

Q5: Has the same age threshold been established with regard to a minor’s liability for damage caused by a tort or other unlawful act?

No. Slovenian law establishes different age thresholds for contractual capacity and tort liability (non-contractual liability). While a minor who has reached the age of 15 may, subject to certain conditions, enter into civil-law contracts independently, liability for damages caused by a tort or other unlawful act is governed by Article 137 of the Obligations Code. See our answer above under Q3.

As explained above, the Information Commissioner has not, to date, conducted any proceedings involving a minor acting as a controller or processor of personal data relating to third parties. Consequently, we do not have any enforcement practice or examples that would provide guidance on how such situations should be assessed in practice. We are also not aware of any criminal proceedings in Slovenia in which a minor has been convicted of a criminal offence related to the unlawful processing of personal data.

It should be further noted that the Information Commissioner does not impose administrative fines under Article 83 GDPR. Instead, infringements of data protection legislation are sanctioned through minor offence procedure. Under the Slovenian Minor Offences Act, the Information Commissioner would not be competent to conduct a minor offence procedure against a minor acting as controller or processor and to impose a fine directly. In such circumstances, the Information Commissioner could only submit an indictment proposal (obdolžilni predlog) to the competent court, which would then decide on the matter in accordance with the rules governing juvenile offenders.

Should a case involving a minor acting as a controller or processor arise, the Information Commissioner would also need to take into account the provisions of the Slovenian General Administrative Procedure Act (Zakon o splošnem upravnem postopku - ZUP) concerning the procedural capacity of minors. Pursuant to Article 46(3) ZUP, a minor who has not acquired full capacity to contract has procedural capacity only within the limits of the capacity to contract granted to him or her under substantive law. Accordingly, in proceedings before the Information Commissioner involving a minor acting as controller or processor, questions relating to minor’s ability to participate independently in the proceedings, to exercise procedural rights, and to assumer procedural obligations would need to be assessed in light of the applicable rules on procedural capacity under ZUP.

Kind regards,

Prepared by: Sandra Kajtazović, univ. dipl. prav. dr. Jelena Virant Burnik Information Commissioner of the Republic of Slovenia

Financira Evropska unija. Izražena stališča in mnenja so izključno mnenja avtorja in ne odražajo nujno stališč in mnenj Evropske unije ali Evropske komisije. Niti Evropska unija niti organ, ki dodeljuje sredstva, zanje ne odgovarjata.

IP

Do relevantne sodne prakse v nekaj sekundah

Dostop do celotne evropske in slovenske sodne prakse
Napreden AI iskalnik za hitro iskanje primerov
Samodejno označevanje ključnih relevantnih odstavkov

Začni iskati!

Prijavite se za brezplačno preizkusno obdobje in prihranite več ur tedensko pri iskanju sodne prakse.Začni iskati!

Pri Modern Legal skupaj s pravnimi strokovnjaki razvijamo vrhunski iskalnik sodne prakse. S pomočjo umetne inteligence hitro in preprosto poiščite relevantne evropske in slovenske sodne odločitve ter prihranite čas za pomembnejše naloge.

Kontaktiraj nas

Tivolska cesta 48, 1000 Ljubljana, Slovenia