EU KIDS Act Would Restrict Social Media Access for Children
The European Commission has presented the proposed EU KIDS Act, a new regulation aimed at strengthening protections for minors using social media and other digital services. The proposal would prohibit children under 13 from creating social media accounts. Users aged 13 and 14 could access only limited, parent- or guardian-linked accounts for child-friendly video-sharing services. Full accounts would be available from age 15.
The proposal would apply extensive safety-by-design duties to very large online platforms under the Digital Services Act. Covered services include social media, video-sharing platforms, online games, AI companions, and chatbots offered to users under 18. Platforms would need to show that their services do not harm minors, shifting the evidentiary burden toward providers.
The draft restricts several product features associated with excessive engagement and unwanted contact. These include profiling-based recommender systems, infinite scroll, reward-based design, notifications during sleeping hours, and unsolicited communications from strangers. Platforms would also need to implement privacy-preserving age-assurance measures, potentially including the Commission’s planned open-source EU Age Verification Solution.
Enforcement would be centralized at EU level for the largest platforms. Providers would have to submit compliance plans and arrange independent audits for new products or services. The Commission could impose corrective measures and fast-track investigations, with a target completion period of 90 days. Fines could reach up to 6% of worldwide annual turnover, alongside supervisory fees.
The proposal is likely to prompt significant debate on proportionality, data protection, and practical implementation. Consumer advocates and industry representatives have warned that age assurance can create new privacy and cybersecurity risks, particularly where platforms process age, identity, and parent-child relationship data at scale. The legislative process will therefore need to address how child protection duties can operate consistently with the GDPR, the Digital Services Act, and fundamental rights standards.