Teen banking apps: the rules on accounts and cards for under-18s

Who holds the account, how parents pass KYC and give consent, card controls, why there is no credit, and the rules on children's data and marketing in the EU, the UK and the UAE.

A pink piggy bank with a payment card, a gold euro coin and a shield block

A teen banking app usually runs on a parent's e-money (prepaid) or bank account, with a card for each child. The financial licence covers the money. The rules for minors come from other laws: anti-money laundering (AML) law decides whom you verify, contract law who can sign, and data protection and consumer law how you use a child's data and market to them. Most of them differ by country.

This guide is general information, not legal advice: the details depend on your services and your market, so confirm them with a lawyer and the regulator before you apply.

How it works

For the family:

  1. A parent passes identity checks (KYC, know your customer) and opens the account.

  2. They add each child, confirm they are the parent or guardian, and give consent.

  3. Each child gets a balance and a card; teens may also get their own sign-in.

  4. The parent tops up, pays an allowance, sets limits and is notified of every payment. The teen saves, freezes the card and asks for money.

For the operator, a licensed e-money institution or bank holds the money and issues the cards, and each payment is checked in real time against the child's balance and the parent's rules.

What you need beyond the software

Who holds the account

In the parent-held model, the parent is the customer and each child uses a card and balance under that account. In the child-held model, the account is in the teen's name, opened with a parent's consent, and the parent acts for them. Which you can offer depends on national law:

The model also sets the data basis: the UK regulator, the ICO, warns that a contract supports processing a child's data only if the child has capacity to enter it (Children's code, Annex C).

AML law requires you to identify anyone acting for a customer and verify their authority:

In a parent-held account the parent is the customer; in a child-held one, the child is the customer and the parent is verified as acting for them, with proof of the relationship your issuer accepts.

In the UAE, the Stored Value Facilities Regulation (Article 14) treats several cards on one account, cards used by someone other than the customer and funding by unverified parties as risk factors, and limits as a mitigation. A family wallet with gifts from relatives has all three.

Keep the parent's agreement to the terms apart from data protection consent for optional processing, and record who gave each, when and to which version.

Spending controls and blocked categories

Typical controls are daily and weekly limits, permitted countries, online and cash switches, and a freeze. Category blocks use merchant category codes, which classify merchants by type of business (ISO 18245:2023). A block works on the shop, not the basket: a supermarket selling alcohol is still a supermarket. It is a parent's tool, not an age check.

No credit for minors

An e-money institution may never grant credit from the funds it holds for e-money (E-Money Directive, Article 6(1)). In the UK, sending a minor any document inviting them to borrow or buy on credit, with a view to financial gain, is an offence (Consumer Credit Act 1974, section 50). Keep overdrafts and buy now pay later out, and decide who covers a negative balance.

Children's data

EU: GDPR Article 8

Where you rely on consent for an online service offered directly to a child, a child under 16 needs consent given or authorised by the holder of parental responsibility, verified with reasonable efforts (GDPR, Article 8). Member states may lower the age, but not below 13, and chose differently: 14 in Spain (Organic Law 3/2018, Article 7), 15 in France, where younger minors consent jointly with a parent (Loi Informatique et Libertés, Article 45), and 16 in Ireland (Data Protection Act 2018, section 31).

Article 8 applies only to consent, which the ICO says is unlikely to suit a service's core processing, so it mostly concerns optional parts such as marketing and analytics cookies.

UK: the Children's code

The UK age is 13 (UK GDPR, Article 8). Since 29 April 2026 the government may raise it to as much as 16 by regulations (Children's Wellbeing and Schools Act 2026, section 72), but in July 2026 it said it would not, for now.

The ICO's Age appropriate design code, or Children's code, covers online services likely to be accessed by under-18s. Its standards include an impact assessment, high privacy by default, and profiling and geolocation off by default. Under the parental controls standard, the child should be told about the controls in age-appropriate terms, with an obvious sign while a parent is monitoring. A parent who sees every payment can count as monitoring, so tell the teen.

UAE: the Child Digital Safety Law

Federal Decree-Law No. (26) of 2025, in force since 1 January 2026, covers apps and other digital platforms operating in or directed at the UAE whenever children use them (Article 3); ask a lawyer whether yours is one. Data of children under 13 may be processed only with a parent's or guardian's explicit, documented and verifiable consent, easy withdrawal, a clear notice, minimal access, and no commercial use or targeted advertising (Article 7). Existing firms have one year from entry into force to comply, which the Cabinet may extend (Article 18).

Marketing to children

An advertisement that directly exhorts children to buy, or to persuade their parents to buy for them, is banned in all circumstances across the EU (Unfair Commercial Practices Directive, Annex I, point 28), and in the UK (Digital Markets, Competition and Consumers Act 2024, Schedule 20). Market to parents, and keep promotions out of the teen's app.

Decisions that shape the build

  • The account model, and the youngest age for a card and for the teen's app, per country.

  • More than one guardian, and gifts from relatives.

  • The 18th birthday: a move to an adult account, with new checks, terms and consents.

What drives the cost

  • Finding and onboarding partners that accept minors in your countries.

  • The family model in the ledger: balances, allowances and rules.

  • Two apps, for parents and teens, with age-appropriate design and an impact assessment.

  • Parents' identity checks and proof of the relationship.

  • Consent records and settings per country.

  • Support for disputes involving children.

Common mistakes

  • Taking the age of digital consent as the age to open an account. Article 8 leaves contract law alone.

  • Monitoring a teen without telling them.

  • An ad that tells children to ask their parents.

  • No plan for the 18th birthday.

What this means for your platform

Our white-label family banking app is built around the parent, who verifies once with an ID scan and a selfie, adds each child and gives consent for them in the app. Each child gets an account and a card; teens also get their own app. Parents set limits, blocked categories and the countries where a card works, and see every payment. The card issuing module applies those rules to every authorisation, and the KYC/AML module logs every decision.

We help you choose a partner bank or e-money institution and a card issuer that accept minors in your markets, and get the contracts in place. Parent and child accounts and the allowance are built for you, as part of the work, on modules already in production; more than one guardian, gifts from relatives or school payments come in a custom build of 2 to 3 months, and anything else can be assembled from the same modules. You own the full source code.

Sources

Checked on 7 October 2026.

Written by

Paynoramic's Head of IT

Head of IT at Paynoramic, responsible for the module library every platform is built from. Has worked on payment, banking and workforce platforms for companies including American Express, Teya and Indeed Flex, and for a global card issuer-processor. Writes about what a fintech or crypto launch needs beyond the software: licensing, certification and the real cost.