EU KIDS Act – What changes for digital platform operators
SÉRVULO PUBLICATIONS 25 Sep 2026
On 17 September 2026, the European Commission presented a new proposal for a regulation — the EU KIDS Act (EU Keeping Internet Digital Spaces Accountable and Trustworthy) — which will significantly change the way digital companies operate when their users are children or young people. The message is clear: it is no longer enough to comply with the DSA or the GDPR. The new framework requires digital services to be designed, from the outset, with children in mind.
The context justifies the urgency: according to Eurobarometer, around 33 per cent of European children feel stressed or sad, and 90 per cent report negative symptoms such as depression, concentration problems or eating disorders associated with the use of digital platforms. The European Parliament has already advocated for a harmonised minimum age of 16 for access to social media (with access from the age of 13 subject to parental consent), and the EDPB has issued specific guidelines on age verification.
What you need to know
1. Age-differentiated access
The Regulation defines a ‘minor’ as any person under the age of 18 and establishes four levels of access:
|
Under 3 years |
Absolute ban with no access to social media or video-sharing platforms, in line with the general recommendation against screen use in this age group. |
|
Ages 3 to 12 |
Access to social media is prohibited. However, legal guardians may allow access to video-sharing services specifically designed for children, via their own account, with a maximum limit of one hour per day. |
|
Ages 13–14 |
Legal guardians may create accounts with limited functionality, mandatory parental controls always enabled (including contact approval) and a maximum limit of one hour’s daily use. |
|
From 15 years old |
Independent access, with the option to create their own account, but the ‘safety by design’ rules continue to apply until the age of 18.
|
2. Is your organisation covered?
The Regulation will apply to:
- social media platforms
- video-sharing platforms
- app stores
- online games
- operating systems
- AI companions and conversational chatbots
Excluded are non-profit encyclopaedias, educational and scientific repositories, educational services operated by or for educational establishments, open-source platforms, scientific research services and services provided by public authorities.
3. Safety by design: the digital environment is now designed with children in mind
- Eliminate addictive design: no infinite scrolling, autoplay without effective pauses, notifications during sleep hours or variable reward systems for minors.
- Manage screen time: implement tools that protect sleep schedules and school time.
- Privacy by default: privacy and security settings must be active from the outset and may only be changed with the express consent of the child or their legal guardian.
- Block unknown contacts: by default, users outside the minor’s pre-existing connections cannot access their profile, content or contacts.
- Transparency in transactions: the child must be clearly informed before any purchase, with virtual currencies displayed in real-world value. Variable reward systems (including loot boxes) are prohibited on social media, video platforms, AI companions and chatbots — although the application of this ban to online games is not clearly set out in the operative provisions of the proposal.
- Special precautions regarding AI: AI companions and chatbots must not be designed in a way that is likely to create emotional dependencies; they must undergo pre-market risk assessment and continuous post-market monitoring. When integrated into social media, video platforms or games, they must not be activated automatically or displayed prominently, and minors must be able to disable them easily.
4. Age verification: what will change
Self-declaration of age will no longer be sufficient. To control age-based access to social media and video platforms, service providers will have to use only solutions certified under the new EU Age Verification Scheme, including the European Digital Identity Wallet (eIDAS). For the remaining ‘safety by design’ obligations, they may use alternative age verification solutions, provided they guarantee accuracy, reliability, privacy and non-discrimination.
5. Rights of underage users
Minors are now entitled to: tailored reporting mechanisms; tools to control content and recommendations; and accessible information about their rights. Parents are entitled to effective supervision tools. Both can lodge complaints with the authorities or authorise organisations to do so on their behalf.
What is at stake
The penalty regime is robust: fines can reach 6 per cent of the provider’s global annual turnover, plus an annual supervision fee of up to 0.03 per cent of global net revenue. The enforcement process is fast-tracked: the Commission may issue preliminary findings within 30 working days and adopt a final decision within 90 working days. It will be up to the company to demonstrate that it is compliant — in particular, VLOPs (platforms with more than 45 million monthly users in the EU) must submit compliance plans verified by independent auditors.
Implementation timetable
The proposal now goes to the European Parliament and the Council as part of the ordinary legislative procedure. Following approval and publication in the Official Journal:
- Entry into force: 20 days after publication. Compliance plans for VLOPs are required from this date.
- General implementation: 6 months after entry into force — companies must comply with all obligations, including age verification for existing accounts and the deactivation of accounts held by children under 15.
- Enhanced supervision: 12 months after entry into force, the provisions on supervisory fees and fast-track procedures will apply.
- First review: the Commission will submit a report to the Parliament and the Council by 31 August 2030.
Ana Ferreira Neves | afn@servulo.com
Rodrigo Barreiros Ferreira | rbf@servulo.com
Expertise Relacionadas
TMT