The European Commission has announced its proposal for the Kids Act, designed to improve children’s online safety across the Union. The proposal, which we have had access to, prohibits children under the age of 13 from accessing social media and sets a minimum age of 15 for minors to open an account on their own.
As this is a proposal from the European Commission, the text must now begin its legislative negotiation process in the European Parliament and the Council before it can be formally approved.
“It is up to platforms to prove they are safe”
In an official statement, Commission President Ursula von der Leyen explained that “Today, our children use the most sophisticated technologies ever created. Technology that was never created with their well-being in mind. Our Kids Act reverses the burden of proof: it is up to platforms to prove they are safe by design. And we are putting parents back in the driver’s seat, giving them the tools to help their children navigate a safer online world.”
A law built on three principles
Age limits
As we mentioned, the idea is that social media accounts cannot be created until the age of 15, although there is a strange and somewhat baffling option beforehand: for children aged 13 to under 15, guardians would be allowed to create “mini accounts” that children could access through the guardian’s account.
This would allow them to access age-appropriate social media and video-sharing platforms (if that concept exists or makes any sense to you).
The proposal states that these mini accounts would be restricted in certain ways: there would be a limit on social contacts, and screen time would be capped at one hour per day.
And now comes the strangest proposal in the entire text: children over the age of 3 and under 13 would not be allowed to access social media, but “they may access specially designed video-sharing services through accounts managed by their guardian.”
Whatever that means.
In addition, the Commission explains that “for that purpose, platforms must offer parents or guardians an easy-to-use tool to restrict the use of the adult’s device to such child-adapted services, when it is handed over to children, and to limit the child’s exposure to a maximum of one hour per day.”
Fighting dark patterns and protecting privacy
Once the new law is approved, all platforms offering services to minors will have to avoid addictive features and profile-based recommendation systems “that drag minors down harmful content rabbit holes.” In addition, certain dark patterns that the EU has already been fighting more broadly for some time would be banned, such as infinite scroll, rewards, and the use of push notifications during sleeping hours, as well as unsolicited contact from strangers. It also explains that “chatbots must be turned off by default and may not simulate interpersonal relationships in ways that create emotional dependency.”
Finally, one key point is that minors’ profiles must be private by default, with no access to geolocation, the camera, or the microphone.
Reversal of the burden of proof
Under this new law, providers of very large online platforms will be responsible for proving that their services are “safe by design.” To do this, they will have to submit a compliance plan to the Commission and to an independent auditor, who will be required to thoroughly assess the service, feature, or functionality.
Okay, but how will minors actually be prevented from accessing social media?
Of course, beyond the proposal’s good intentions, it does not make much sense unless effective mechanisms are put in place to verify users’ ages.
The Commission explains that online services and app stores will have to use age assurance tools. “They can, for example, use the EU age verification app, which does not retain ID documents or biometric data, thereby meeting the highest privacy protection standards. Member States will be closely involved in building this ecosystem.”
That app, unveiled just a few months ago, is something like a digital identity wallet that acts as an intermediary between the user and websites. It does not tell platforms who you are, for example; it simply transmits a “yes” or “no” in response to whether you meet the required minimum age.
The Commission is working with Member States to turn this technology into standalone national apps or integrate it into their digital identity wallets. The expectation is that it will be available across the EU by the end of 2026. Spain is one of the seven pioneering countries, along with Cyprus, Denmark, France, Greece, Ireland, and Italy.
In addition, social media service providers will have to carry out age verification when a user opens a new account. In the case of existing accounts, providers will have to estimate the user’s age based on “reasonable” data, such as the account creation date or credit card details.
Growing concern over the relationship between minors and social media
Concern over children’s and teenagers’ access to all kinds of online platforms, as well as the intensity of their use, has been growing in recent years. As we have explained many times, more and more studies agree in identifying popular services such as social media as threats to younger users’ health and well-being, and it seems that public authorities around the world are finally beginning to take action.
In fact, we recently discussed this very issue in connection with the landmark court case Meta, as the owner of Facebook and Instagram, faced in the United States. That case ended in a settlement under which the company led by Mark Zuckerberg will pay up to $17.1 billion to resolve litigation alleging that Meta was responsible for the negative consequences its social media platforms had on younger users.
Another of his most notable appearances came in January 2024: Zuckerberg and the CEOs of other major tech companies (TikTok, X, Snap, Discord) appeared before the U.S. Senate to discuss the dangers platforms pose to children and teenagers. In a tense moment, Zuckerberg apologized directly to the victims and their families who were present in the room.
Until the new rules are approved, one of the main references in Spain remains Organic Law 3/2018 on Data Protection. Article 7 allows a minor to consent on their own to the processing of their personal data from the age of 14. Below that age, parental or guardian consent is required.
As you can see, the Kids Act proposal creates an interesting obstacle for the Spanish government’s plans. Spain intends to raise the minimum age to 16, while the Commission proposes setting it at 15 across the entire EU. Since the future regulation seeks to avoid diverging national rules, its final wording could force Spain’s initiative to be adjusted.
Image: ChatGPT
