Boxfish Labs home
Boxfish Labs
  • Solutions
  • Resources
  • About
  • EN
  • DE
  • HU
Book a Call
Boxfish Labs home
Boxfish Labs

Menu

    • By service
      • Information Security Advisory
      • External CISO
      • External DPO
      • Data Residency & Sovereignty
      • Human-Centric Cybersecurity Awareness
      • Security Check for Vibe-Coded Apps
    • By Framework
      • GDPR
      • ISO 27001
      • DORA
      • TISAX
      • EU AI Act
      • Cyber Resilience Act
    • Audience
      • Startups and Scaleups
      • Fintech
      • Technology suppliers
      • Educators
      • Individuals
    • View all solutions
    • Articles
    • Courses and Webinars
    • Downloads
    • Compliance Glossary
    • CRA applicability quiz
    • View all resources
    • About us
    • Pledge
    • Social impact
    • Partnerships
    • Contact
    • View about Boxfish Labs

Featured

Dot-matrix letters CRA on a black grid background

Pass EU Cyber Resilience Act (CRA) applicability assessment test

  • EN
  • DE
  • HU
Book a Call

The EU KIDS Act: What the Proposal Could Mean for Children, Platforms and Privacy

The proposed EU KIDS Act would introduce graduated access rules for children on social media and other high-risk services. A clear comparison of the EU approach with Australia, the UK, the US, California and China, and what platforms should do now.

Boxfish Labs

September 17, 2026 • 12 min read
Cover graphic for The EU KIDS Act: What the Proposal Could Mean for Children, Platforms and Privacy

The proposed EU KIDS Act would introduce a more structured approach to children's access to high-risk online services. Its central idea is simple: social media and similar services should not treat a seven-year-old, a fourteen-year-old and an adult as if they face the same risks or need the same protections.

The proposal is not law yet. But it points to a clear policy direction in Europe and beyond: platforms may increasingly need to prove that their services are appropriate for young users, rather than relying on a date-of-birth field and general terms of service.

What is the EU KIDS Act?

The EU KIDS Act is a European Commission proposal for stronger protections for children using digital services. It would cover social media, video-sharing services, online games, AI chatbots and AI companions, while educational tools are expected to sit outside its main scope.

The proposal uses a graduated model rather than one single rule for everyone under 18:

Age groupProposed access model
Under 3No access to social media and other high-risk services
3 to 12Child-friendly services only, through accounts controlled by a parent or guardian
13 to 14Parent-created and supervised introductory accounts, with limited features, contacts and time controls
15 to 17Independent accounts, but services must be safe by design for minors
18+Standard adult access

The headline rules are "no social media under 13" and "no personal account under 15". In practice, the proposal is less a blanket ban than a framework for age-appropriate access.

Why is the EU taking this approach?

The Commission is responding to concerns about harmful content, unwanted contact, compulsive design, recommender systems, targeted advertising, privacy risks and the impact of some online experiences on young people.

The important shift is responsibility. The proposal would move the burden towards providers. A platform would need to show that its design, controls and safeguards are suitable for the age group it serves.

This matters because age limits in terms of service have often been easy to bypass. A meaningful model needs more than an age gate. It needs an account design that changes what a child can see, who can contact them, which recommendations they receive, how much data is collected and how easily a parent or guardian can support them.

How does it fit with existing EU rules?

The EU already has rules that protect children online, but they do not set one general minimum age for social-media accounts.

The GDPR sets rules for children's consent to information-society services. The default age is 16, although EU Member States can set it as low as 13. The Digital Services Act requires online platforms accessible to minors to take appropriate and proportionate measures to ensure a high level of privacy, safety and security for children.

In 2025, the European Commission issued guidance under the Digital Services Act on protecting minors. It recommends age assurance that is accurate, reliable, robust, non-intrusive and non-discriminatory. It also distinguishes between age verification, where a service checks a precise age or threshold, and age estimation, where it assesses whether someone is likely to be within an age range.

The EU KIDS Act would build on this direction by setting clearer access categories and more explicit expectations for high-risk services.

How does it compare globally?

Countries are increasingly regulating children's online experiences, but they are not taking identical approaches. Some focus on account access. Others focus on data protection, harmful content, product design or parental controls.

JurisdictionMain approachKey age pointWhat it means for providers
European Union, proposed EU KIDS ActGraduated access and safe-by-design duties across social media and other high-risk servicesNo social media under 13. Independent accounts from 15Design age-specific accounts, controls and safety features. Demonstrate protection for minors
AustraliaStatutory minimum age for accounts on age-restricted social mediaUnder 16Take reasonable steps to stop under-16s creating or keeping accounts. The provider, not the child or parent, carries the compliance burden
United KingdomOnline-safety duties, risk assessment and highly effective age assurance for relevant harmful contentNo single general social-media age in the ActAssess risks to children, enforce stated age limits and prevent children accessing pornography and other harmful content where required
United States, federal COPPAChildren's privacy and verifiable parental consentUnder 13Obtain parental consent before collecting, using or disclosing covered children's personal information. It is not a general social-media access ban
CaliforniaAge-appropriate design and high-privacy defaults for services likely to be accessed by children, subject to ongoing litigationUnder 18Consider children's privacy and well-being in product design, including protective defaults and age estimation requirements where enforceable
ChinaDevice and app-level "minor mode" with parental controls and age-based limitsUnder 18Provide child modes, content filters, time controls and parental mechanisms, with a more centrally directed model than in Europe

Australia: the clearest account-access comparison

Australia is currently the closest operational comparison. Since 10 December 2025, age-restricted social-media platforms have had to take reasonable steps to prevent Australians under 16 from creating or keeping accounts.

The law places the obligation on platforms. Children, parents and carers are not fined for access. Platforms can face penalties of up to AUD 49.5 million if they fail to meet their obligations.

The EU proposal differs in one important respect. Australia's approach is largely based on a single account threshold. The EU proposal would create different account types and safeguards at different stages of childhood and adolescence.

United Kingdom: focus on risk and enforcement

The UK Online Safety Act does not create a universal ban on social-media access below one age. Instead, it requires services to assess risks to children, enforce the age limits in their own terms consistently and protect child users from harmful content.

For services that allow pornography, age assurance must be highly effective. Ofcom describes age assurance as including age verification, age estimation or both. The UK Government has also announced an intention to require social-media services to use highly effective age assurance to prevent under-16s from accessing them.

This approach is useful because it links age checks to the actual risks of a service. Its weakness is that the outcome can be harder for users and providers to understand when duties vary by service, content and risk assessment.

United States: privacy protection, not a general access rule

The United States has a long-standing federal rule, COPPA, which applies to online services directed at children under 13 and services that know they collect personal information from children under 13.

COPPA requires verifiable parental consent before covered personal information is collected, used or disclosed. It is primarily a privacy law. It does not generally prohibit a child from holding a social-media account, and it does not create a graduated account model for teenagers.

This is an important distinction. A platform can comply with privacy consent rules while still offering an experience that is poorly designed for young users. The EU KIDS Act appears intended to address both access and product design.

China: a broader system of controls

China's "minor mode" uses device and app-level controls. It includes age-appropriate content filtering, usage limits, options to restrict communication with strangers and parental verification to change or exit certain settings.

It shares the EU proposal's interest in graduated protection and design controls. But it operates within a more centralised regulatory and content-governance environment. European implementation will need stronger safeguards for privacy, proportionality, children's rights and freedom of expression.

What will be difficult in practice?

The policy goal is understandable. The difficult question is how to implement it without creating a new system of routine identity surveillance.

Age assurance must protect privacy

A platform should usually need to know only whether a person meets a particular age threshold, not their full identity, home address or identity-document number. The most privacy-respecting systems should support a limited proof, such as "over 15", rather than a reusable record of who the person is.

The European Commission's age-verification work moves in this direction. Its stated aim is anonymous proof-of-age technology with strong privacy and data-protection safeguards. The EU's age-verification blueprint is intended to give Member States and providers a common technical starting point.

A date of birth is not enough

Self-declared age is easy to evade. But collecting identity documents or biometrics from every user can also create serious security and privacy risks. Providers will need a proportionate approach based on the service and the risk.

For example, a public platform that allows direct messages from strangers and uses engagement-driven recommendations may need stronger controls than a low-risk educational community with moderated groups and no behavioural advertising.

"Safe by design" must be measurable

Safe by design should not become a vague statement in a policy document. For young users, it should translate into decisions that can be tested and audited, such as:

  • Private-by-default accounts for minors.
  • Restricted contact from unknown adults.
  • Limits on recommendation patterns that promote harmful or compulsive use.
  • No targeted advertising based on a child's profile.
  • Clear reporting, blocking and support routes.
  • Child-friendly explanations of settings and risks.
  • A documented process for assessing child-safety and data-protection risks before release.

What should platforms and organisations do now?

Organisations do not need to wait for the final text before improving their approach. The most useful preparation work is product, governance and evidence work.

  1. Map where children and teenagers can enter the service. Check sign-up, account recovery, direct messages, recommendations, advertising, payments, creator tools and AI features.
  2. Define age bands. Avoid treating all users under 18 as one group. Identify which features should be unavailable, limited, supervised or redesigned for each band.
  3. Review your age-assurance approach. Document why it is proportionate to the risk, how it minimises data collection, how long data is retained and how users can challenge an incorrect result.
  4. Make safety defaults real. Test privacy settings, contact controls, reporting flows and recommendation systems with young users and trusted child-safety experts.
  5. Connect privacy, product and security governance. Age assurance may involve sensitive data, identity providers, device signals or third parties. It needs data-protection impact assessment, supplier assurance, access controls, retention rules and incident planning.
  6. Keep evidence. Record risk assessments, design decisions, test results, complaints, safety metrics and changes made after incidents. "Safe by design" will need demonstrable evidence, not only good intentions.

What are the main conclusions?

The EU KIDS Act signals a move away from the false choice between unrestricted access and a single age ban. Its graduated model recognises that young people's needs change with age and that products should change with them.

Its success will depend on three things.

First, the final rules must be clear enough for families and providers to understand. A complicated set of overlapping age categories, national exceptions and platform-specific interpretations would be difficult to enforce fairly.

Second, age assurance must remain privacy-preserving. Measures intended to protect children should not make identity checks and personal-data collection routine for everyone.

Third, enforcement must look beyond sign-up. A child-safe service is not created by asking for a date of birth. It is created through the defaults, features, incentives and safeguards that shape the experience after the account is opened.

For organisations building digital products, the practical lesson is straightforward: design for age-appropriate use from the beginning, minimise the data needed to provide protection and keep evidence that the approach works.

How Boxfish Labs can help

Boxfish Labs works on practical cybersecurity, privacy and digital-safety capability. Its interactive awareness resources cover topics including scams, phishing, privacy, passwords, safer browsing and digital habits, using short scenarios, mini-games and guided learning content.

For organisations responding to child-safety and age-assurance expectations, this type of work can support the human side of compliance: helping teams, parents, educators and everyday users understand online risks and make safer decisions. It should complement, not replace, secure product design, privacy governance and effective platform controls.

FAQs

No. It is a proposal. The Commission still needs to publish and progress the legal text through the EU legislative process. The final scope, obligations, timetable and enforcement details may change.

Not in the same way for every age group. Under-13s would not have social-media access. Users aged 13 and 14 could use restricted, parent-supervised introductory accounts. From 15, minors could open their own accounts, subject to safe-by-design protections.

Not necessarily. The stated European direction is toward privacy-preserving age assurance. The appropriate method should depend on the risk and should aim to prove an age threshold without collecting more personal information than necessary.

Parental involvement can help, especially for younger teenagers. But consent alone does not make a product safe. Platforms still need appropriate defaults, limits on harmful features, clear safeguards and accountable design decisions.

Start with a simple child-safety review. Identify whether minors use the service, what data is collected, which adult-to-child contact paths exist, how recommendations work and whether defaults are genuinely protective. Then prioritise the highest-risk changes before adding complex age-assurance technology.

Share this article

Need help with child-safety and privacy-by-design?

Boxfish Labs helps product and privacy teams review age-appropriate defaults, awareness needs, and practical digital-safety controls.

Book a discovery call
  • What is the EU KIDS Act?
  • Why is the EU taking this approach?
  • How does it fit with existing EU rules?
  • How does it compare globally?
  • What will be difficult in practice?
  • What should platforms and organisations do now?
  • What are the main conclusions?
  • How Boxfish Labs can help
  • FAQs
Boxfish Labs

Human-centred security for teams that need to move fast.

LinkedInInstagramYouTubeFacebook

Explore

  • Solutions
  • Resources
  • About

Legal

  • Privacy Policy
  • Impressum

© 2026 Boxfish Labs