OUT-LAW NEWS 4 min. read

EU Kids Act proposal introduces a three-tier approach to social media accounts

A child using the touch sensitive keyboard to write on an Apple iPad.

Photo: LeicaFoto/iStock


Online platforms could face significant new obligations to verify both the age of child users and the authority of parents seeking to manage their accounts under the European Commission's proposed EU Kids Act.

The proposed Act adopts a three-tier approach to accounts for children. 

For under 13s, social media and video-sharing platforms cannot allow children under the age of 13 to create an account. If certain measures are put in place, video-sharing platforms may enable the guardian to give the child access using the guardian’s own account.

Platforms may allow guardians of 13 to 15-year-olds to set up a limited account for the child, which is subject to mandatory parental controls. Finally, for 15-year-olds, platforms may allow them to create accounts; however, they must incorporate safety-by-design principles.

Under the proposal, social networking services and video-sharing platforms that are deemed to present risks to the privacy, safety or security of minors would generally be prevented from allowing children under 15 to create standard accounts. Instead, access for 13- to 15-year-olds would largely be channelled through restricted "limited accounts" created by a parent or guardian. These would be subject to mandatory parental controls. 

Those controls would need to include tools enabling guardians to set screen-time limits, approve contacts and restrict the number of contacts a child may have on the service. The parental controls would be required to remain active at all times.

The draft regulation defines a guardian as a person holding parental responsibility under applicable national law, but the practicalities of verifying that status are less clear.

“The practical question is how does a platform check the authority of the person claiming to be the guardian in accordance with the relevant national law,” said Lauro Fava, online safety expert at Pinsent Masons.

“The proposed regulation specifies that providers must be able to use signals of parental responsibility based on freely accessible official sources made available by member states. Until the Commission issues more detailed rules on how parental responsibility should be checked, providers are also allowed and required to rely on a self-declaration by the guardian. The catch is that the provider is still required to make reasonable efforts to verify the information it obtains, including that a self-declaration is made by an adult exercising parental responsibility,” he said.

Fava said the challenges associated with establishing parental responsibility may prove even more difficult than age verification, given the need for platforms to navigate different national rules governing parental authority. Parental authority can derive from the law, court decisions or binding agreements, and different aspects of parental authority can be governed differently.

The regulation would also create a separate model of guardian-controlled access for certain video-sharing platforms aimed at younger children. In those circumstances, children under 13 could access services through a guardian's account rather than holding an account in their own name.

Those arrangements would come with extensive safeguards, including active parental controls and restrictions on recommender systems, search tools and other personalisation features unless their use can be shown to be in the child's best interests. Providers would also be required to ensure children are informed when guardian tools are being used.

Age assurance sits at the heart of the proposed framework. Fava said the proposal takes a highly prescriptive approach to age assurance, containing detailed requirements to ensure age assurance systems are privacy-preserving. It goes as far as requiring age assurance measures to be 'zero knowledge' proof, which rules out numerous mechanisms currently in use, and in some cases mandates the use of certified EU age verification solutions.

While these requirements assume the availability of EU age verification solutions, the relevant framework is still under development and is intended to operate in tandem with the eIDAS digital identity architecture.

The draft rules could also require providers to establish the age of existing users within six months of the legislation becoming applicable, with accounts being disabled where age cannot be verified.

Alongside the account access provisions, the proposal adopts a safety-by-design approach. Under Article 8, covered services would be required to apply child protective settings by default unless they have established through age assurance that a user is an adult. The obligation could apply whether or not a service is accessed through an account, extending protections to signed-out users. 

Fava said: “This presents a major challenge for platforms who would have to provide a child-friendly experience to all signed-out users unless they carry out age assurance. Signed-out users expect to access a platform without friction and without submitting any personal data.”

The Act sets out how safety by design is to be implemented in practice, which varies according to the service in scope. It outlines separate design principles for social media networks, video sharing platforms, online gaming providers, AI companions, general AI conversational chatbots and software application stores. A key challenge for services in scope is working out what applies to them and what this means for the products they offer. 

Gemma Erskine, online safety specialist at Pinsent Masons, said: “A defining feature of the EU Kids Act is that freedom of expression and children’s fundamental rights are embedded throughout.”

“The proposed Act is very explicit that its access restrictions represent a proportionate and necessary limitation on children’s rights to freedom of expression, requires age assurance to be privacy-preserving and operationalises children’s own agency through, for example, making them aware when guardian tools are active. This stands in contrast to the UK approach of a blanket ban on social media for under 16s. The EU act seeks to make digital spaces for children to live in, the UK proposal seeks to remove them from those spaces altogether.”

Rather than establishing a dedicated EU child safety regulator, the proposal allocates enforcement responsibilities across existing frameworks, including the Digital Services Act (DSA), AI Act and General Data Protection Regulation (GDPR). Video game providers outside the scope of the DSA would instead be supervised by authorities designated by member states.

Fava said: “The approach represents a deliberate policy choice to avoid creating a new regulator altogether but carries the risk of fragmented oversight with providers who offer multiple services potentially being regulated by various regulators."

The proposal now enters the EU legislative process, where member states and the European Parliament will consider amendments before negotiations on a final text begin.

Fava said the process is likely to take many months and potentially years, despite political momentum behind stronger protections for children online. He said debates over age verification, privacy, freedom of expression and the appropriate level of restrictions for children are likely to prove contentious during negotiations.

Wesley Horion, EU digital regulatory expert at Pinsent Masons, said: “Early reactions suggest there is support for the proposal’s overall direction in most member states though differences remain on issues including mandatory age verification, the different age tiers and the level of restrictions that should apply.” 

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.