A woman reading printed papers beside an open laptop at a kitchen table

Family Organiser Apps and GDPR: What Parents in Europe Should Ask

Ammar Khatib ·

Search for whether a family app is GDPR compliant and you get privacy policies. Nobody explains what you can actually do with the law once you have read one.

This is that explainer: the rights you have, the extra protection children get, and — the useful part — a way to test whether an app honours any of it, rather than taking its word.

General information, not legal advice. If you have a specific dispute with a company about your data, your national data protection authority is the place to go.

Why this matters more for a family app

Most apps hold data about you. A family organiser holds data about people who did not choose it and cannot meaningfully consent — your children.

It knows their names, birthdays, school, weekly routine, medical appointments, and often their photographs. That is a category of data worth being deliberate about, and it is the reason the law treats children's data differently.

Your six rights, in plain words

GDPR gives every person in the EU a set of rights over data held about them. The six that matter in practice:

Portability is the one families under-use. It is the right that means leaving an app does not have to mean starting from nothing.

Article 8: children get extra protection

The specific provision for children is Article 8, and it is narrower than most people assume.

Where a service relies on consent as its legal basis and is offered directly to a child, processing is lawful if the child is at least 16. Below that, it needs consent given or authorised by whoever holds parental responsibility. And member states may set a lower age in law — but never below 13.

So the range across the EU is 13 to 16, with 16 as the default where a country has not legislated otherwise.

Two precision points, because this gets misquoted constantly. Article 8 applies only where consent is the legal basis — it is not a blanket "you must be 16 to use an app" rule. And it applies to services offered directly to a child, which a family app used by a parent may or may not be.

The test: ask for your data and see what happens

Here is the part that is actually useful.

A privacy policy tells you what a company promises. A request tells you what it does. So make one.

  1. Find the contact route in the privacy policy — usually an email address or a form, sometimes with a specific subject line.
  2. Ask for a copy of all personal data held about you and your family members, in a machine-readable format. Name Article 15 and Article 20; it makes clear you know what you are asking for.
  3. Note the date.
  4. A response is generally due within one month, extendable in complex cases if they tell you.

What comes back tells you more than any policy. A prompt, complete, readable export is a company that built for this. A vague reply, a demand that you jump through hoops, or silence tells you what you needed to know before you trusted them with your children's schedule.

Red flags in a privacy policy

Things worth noticing when you read one:

None of these is proof of anything on its own. Three of them together is a pattern.

What "EU-hosted" does and does not mean

This phrase gets used loosely, including by us, so here is the honest version.

It does mean the main database sits in the EU, under EU law, and is not routinely subject to another country's legal process.

It does not automatically mean every service the app touches is in the EU. Almost every mobile app uses some non-EU infrastructure somewhere — push notifications, crash reporting, sign-in. Those transfers are lawful under mechanisms like standard contractual clauses, but they exist.

A company saying "EU-hosted, and here are the exceptions" is being more honest than one saying "EU-hosted" and stopping. Ask which one you are reading.

Frequently asked questions

Does GDPR apply to a US family app?

Generally yes, if it offers its service to people in the EU. Where the company is based does not remove the obligation. What differs is how easy it is to enforce in practice, which is a real consideration.

Can I demand my child's data be deleted?

You can make the request as the holder of parental responsibility. Erasure is not absolute — a company may keep data where it has a legal reason to — but for a family calendar there is rarely such a reason, so a refusal deserves a follow-up question.

Is a parent's consent enough for a child's account?

Under Article 8, where consent is the legal basis, yes — consent given or authorised by the holder of parental responsibility is what the law asks for below the applicable age. The company is also expected to make reasonable efforts to verify that.