Meta’s US$17.1 billion child-safety settlement: implications for UK and EU businesses | #childsafety | #kids | #chldern | #parents | #schoolsafey


This article was co-authored by Andrew Simpson, Trainee Solicitor.

Meta’s historic US$17.1 billion child-safety settlement has redefined the digital enforcement landscape. The US Attorneys General have hailed it as both the largest Big Tech settlement to date, and the largest US consumer-protection resolution in US history. This outcome forces a critical regulatory shift onto UK and EU businesses: when does the fundamental design of an online service itself become a primary source of legal risk?

The parties filed the consent judgment on 26 August 2026 in People of the State of California, et al. v Meta Platforms, Inc., et al., Case No. 4:23-cv-05448-YGR, before the US District Court for the Northern District of California and within the wider In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation, MDL No. 3047. This judgment requires sweeping structural and algorithmic changes to Facebook and Instagram affecting younger users.

Although the settlement does not create new legal obligations in the UK or EU, it addresses issues that are already attracting significant regulatory scrutiny in Europe. For businesses operating across these jurisdictions, however, regulatory interest is only part of the picture. The relevant issues are already embedded in legislation: the General Data Protection Regulation (GDPR) in the EU, the UK GDPR, the EU Digital Services Act (DSA), the UK Online Safety Act 2023 (OSA), and the UK Information Commissioner’s Office (ICO) Children’s Code. While the settlement has no direct precedential effect under those regimes. Its true relevance is that it concerns design choices which UK and EU law already require businesses to assess, providing empirical evidence that particular safeguards can be deployed at scale. 

We reflect on the significance of this decision (Section 1) and its relevance for businesses in the EU (Section 2) and the UK (Section 3).

Section 1: Why does the case matter?

Meta’s settlement is notable not only because of its size, but also because the enforceable conduct remedies imposed directly affect how Facebook and Instagram are designed and operated. The measures require Meta to make changes affecting how children and teenagers access and interact with its services. Crucially, these mandates codify enhanced age-assurance measures, daily usage limits, overnight access restrictions, parental supervision tools and controls designed to influence user engagement.

The legal issue is no longer confined to harmful content. Product architecture itself has formalised into a key driver of legal risk. Recommender systems determine which content is prioritised and amplified; autoplay and infinite scroll affect the continuity of consumption; notifications encourage users to return, and default settings determine which protections apply without active intervention by the user. For services used by children, those choices may affect both the existence and the severity of an identified risk.

This focus on service architecture is particularly significant because it mirrors concerns that already being actively examined by regulators in the UK and EU are already examining. Age assurance, recommender systems, engagement-driven design and the protection of minors have become increasingly prominent features of regulatory guidance and enforcement activity.

The distinction for businesses is between content compliance and design compliance. A business may moderate individual items of harmful content effectively yet still fail to consider whether the way its service selects, presents or repeatedly recommends content creates or amplifies a separate risk. The applicable legal tests differ between the UK and EU, but both regimes now require design choices to form an integral part of the analysis.

The settlement also creates a cross-border implication. It does not make a safeguard adopted in the US mandatory in Europe. However, it creates a practical operational benchmark. Once substantially the same service operates a particular safeguard at scale in one jurisdiction, the factual basis for arguing in a European court or regulatory proceeding that the measure is technically incapable of implementation elsewhere will face far greater scrutiny.

Section 2: The EU position: product design within the Digital Services Act risk framework

The issues at the heart of the Meta settlement are already attracting significant regulatory attention in the EU.

Online platforms must comply with Article 28(1) of Regulation (EU) 2022/2065 (the Digital Services Act or DSA) if they are accessible to children. This rule requires them to put in place “appropriate and proportionate” measures to ensure a high level of privacy, safety, and security for children. Article 28 therefore applies more broadly than the DSA’s separate systemic-risk regime for Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs).

Providers of designated VLOPs such as Facebook and Instagram are subject to stringent additional obligations under Articles 34 and 35. These provisions require providers to identify systemic risks arising from the design or functioning of their services and to implement reasonable, proportionate, and effective mitigation measures. Furthermore, Article 35 expressly identifies adapting the design, features, or functioning of a service as a possible mitigation strategy, while requiring particular consideration to be given to the effect of mitigation measures on fundamental rights.

The EU Commission’s age assurance and design findings against Meta

In April 2026, the European Commission issued preliminary findings against Meta concerning age assurance. Its preliminary view was that Meta had failed diligently to identify, assess and mitigate the risks arising from children under 13 accessing Facebook and Instagram. The Commission specifically questioned the effectiveness of a system under which a child could provide a false date of birth without an effective control capable of checking it.

Shortly thereafter, on 10 July 2026, the Commission turned its attention squarely to platform design. It questioned whether features such as recommender systems, autoplay and infinite scroll posed risks to children’s physical and mental wellbeing. The Commission’s preliminary findings also expressly identify targeted push notifications and highly personalised recommender systems. Its case is that Meta may have failed adequately to assess and mitigate systemic risks associated with what the Commission describes as the “addictive design” of the services. Those findings remain preliminary: they are not a final determination that Meta has infringed the DSA.

“Addictive design” should therefore not be treated as though it were a freestanding statutory offence. The legal analysis operates principally through the DSA’s existing risk-assessment and mitigation duties. That distinction matters because liability turns on the statutory test, including the identification of the relevant systemic risk and whether the response is reasonable, proportionate and effective, rather than on the abstract label of “addictiveness”.

The Commission’s 2025 Guidelines on the protection of minors under Article 28 of the DSA make the design analysis more concrete. They address the testing and adaptation of recommender systems, the use of behavioural data and engagement signals, the ability of minors to influence or reset recommendations and measures to prevent the repeated recommendations of content capable of harming minors. The Guidelines are not themselves a separate source of binding obligations, but they establish an evidential benchmark intended to assist the Commission, Digital Services Coordinators and providers in applying Article 28.

The DSA also contains protections that go beyond the specific concerns raised by the settlement. Online platforms cannot present advertisements based on profiling under Article 28(2) where they are aware with reasonable certainty that the recipient is a minor. Separately, Article 38 requires VLOPs using recommender systems to offer at least one option which is not based on profiling. These provisions reinforce the point that the use of personalisation in relation to children is itself a heavily restricted part of the regulatory framework. Taken together, these findings suggest that the Commission is increasingly focused on whether online safety measures work in practice. Across both investigations, the Commission questioned not simply whether safeguards existed, but whether they demonstrably altered the user experience.

Combining age assurance and data protection requirements

More effective age assurance does not mean that an online platform is free to collect whatever identity information it considers useful. Online platforms are protected by Article 28(3) of the DSA, which expressly provides that compliance with Article 28 does not oblige a provider to process additional personal data simply to determine whether a user is a minor. GDPR principles, including purpose limitation and data minimisation, therefore continue to apply.

The European Data Protection Board (the EDPB) has taken the same approach. Its 2025 statement on age assurance requires the method used to be the least intrusive measure capable of meeting the relevant objective. In many cases a business may need to establish only whether a user falls above or below an age threshold, rather than verifying the user’s exact identity or precise date of birth.

This creates a genuine legal tension for businesses. An age-assurance system may be too weak to support the protections that depend on age, whereas an unnecessarily intrusive system may create a separate data protection problem. The legal question is therefore not whether the business has adopted the strongest possible age check. It is whether the level of assurance is appropriate to the identified risk and achieved through proportionate processing.

This is also why the US settlement cannot simply be treated as a European benchmark. Compliance teams must still assess a technically available safeguard for necessity, proportionality, effectiveness, and its impact on fundamental rights under Article 35 of the DSA. Technical feasibility is relevant evidence; it is not the legal test.

The potential financial exposure is significant. The Commission can fine VLOPs and VLOSEs an amount of up to 6% of total worldwide annual turnover for a breach of the relevant obligations under the DSA.

Against that background, the European Commission’s proposal of 17 September 2026 for an EU KIDS Act (EU Keeping Internet Digital Spaces Accountable and Trustworthy Regulation) is particularly relevant, as it would translate several of the same risks highlighted by the Meta settlement, including age assurance, recommender systems and engagement features such as infinite scroll and push notifications, into more specific EU safety-by-design requirements for services used by minors.

Section 3: UK position: overlapping roles of OFCOM and ICO for Children’s safety rights

Both the ICO and Ofcom have focused on two related questions: whether online services can reliably identify when users are children, and whether recommender systems and engagement-driven features expose children to additional risks.

The two regulators, however, are applying different statutory regimes. The OSA is principally concerned with risks of harm arising from content, while UK data protection law governs the processing of children’s personal data. The same product feature may engage both regimes, but the underlying legal tests should not be conflated.

Children’s safety under the Online Safety Act 2023

Providers of regulated user-to-user services likely to be accessed by children face strict duties under Section 11 of the OSA. They must carry out a suitable and sufficient children’s risk assessment that must expressly consider how the design of the service, including its functionalities and algorithms, affects the level of risk of harm to children. Furthermore, the statutory explanatory notes identify user engagement features that drive how much children use a service as critical elements of this assessment.

Organisations must then deploy proportionate s design and operational measures to mitigate and manage the risks identified under Section 12 of the OSA. Because these duties apply to how a service is designed, operated, and used, as well as to the content available on it, the current statutory framework does not impose a general prohibition on engagement-led or “addictive” design. Instead, design features become legally relevant through their direct relationship with the risks of harm addressed by the Act.

The Act also requires highly effective age assurance in specified circumstances, though, this is not a universal requirement for every online service. For user-to-user services, the obligation depends on the content and risks present on the service and the applicable child-protection duty. Where highly effective age assurance is required, Ofcom states that simple self-declaration and contractual restrictions on use by children cannot meet that regulatory standard on their own.

The UK framework is now significantly moving further. Parliament has expanded the enforcement framework via Section 70 of the Children’s Wellbeing and Schools Act 2026, which inserted a new section 214A into the OSA. Crucially, this broadens the statutory scope from user-to-user services to “internet services” and grants the Secretary of State sweeping powers to make regulations requiring providers of specified internet services to prevent or restrict children’s access to a service or to particular functionalities or features, including by limiting the amount of time or the times of day at which they may be used.

The Government has announced that the first regulations under these new powers will include restrictions on social-media access for under-16s, alongside default midnight-to-6am access restrictions, muted overnight notifications, and restrictions on autoplay and personalised feeds for 16 and 17-year-olds. However, those measures are not yet active legal duties: the Government plans that the first regulations are to be laid before the end of 2026, with implementation expected in spring 2027.

That distinction is vital for compliance strategies. The present OSA duties, the newly statutory regulation-making power, and announced future requirements represent three distinct regulatory phases and they should not be presented as though they already impose the same immediate obligations.

Children’s data under UK data protection laws

The ICO has also expressed concern regarding the use of children’s personal information in recommender systems, particularly where those systems may increase exposure to harmful content or use behavioural data to influence a child’s engagement with the service.

The Children’s Code requires information society services likely to be accessed by children to apply UK GDPR principles in a manner which reflects children’s particular interests and vulnerabilities. Relevant standards include privacy by default, data minimisation, profiling and the restriction of nudge techniques. Profiling should generally be switched off by default unless the provider can demonstrate a compelling reason for it to be active, taking full account of the child’s best interests.

The statutory framework has also changed. Parliament amended Article 25 of the UK GDPR via Section 81 of the Data (Use and Access) Act 2025 meaning that controllers providing information society services likely to be accessed by children must expressly consider specified “children’s higher protection matters” when applying data protection by design and by default. Those matters include how children can best be protected and supported when using the service, the particular protection merited by children’s personal data and structural differences between children according to age and stage of development.

This legislation has been matched by increasingly active enforcement. In February 2026, the ICO imposed a £14.47m fine on Reddit after finding that it lacked a robust age-assurance mechanism and had failed adequately to assess risks to children.

More precisely, the ICO found infringements of Articles 5(1)(a), 6, 8 and 35 of the UK GDPR: Reddit had no robust age-assurance mechanism, lacked a valid lawful basis for processing children’s data, failed to obtain proper parental consent for children under 13, and failed to conduct compliant Data Protection Impact Assessments (DPIAs).

The decision is important because it demonstrates that a minimum-age provision in a service ‘s terms of service is legally insufficient if children can routinely bypass controls and access the service. It also shows that age assurance is not merely an OSA question: the validation method used, the personal data processed, and the foundational assessment of risk to children may all engage UK GDPR obligations independently and concurrently.

For businesses, the consequence is that online-safety and privacy assessments cannot sensibly be conducted in isolation. The OSA may apply to recommender system OSA because it affects children’s exposure to harmful content, while simultaneously triggering the UK GDPR because it profiles their behaviour. An age-assurance system may be necessary to deliver an online-safety control while itself requiring a valid lawful basis, data minimisation, security safeguards, and, depending on the risk profile, a formal DPIA. 

Key takeaways

Although the Meta settlement arose from US litigation, many of the concerns underpinning it are already attracting regulatory attention in the UK and EU. Its legal significance for UK and EU businesses is that it may affect the evidential baseline available when they justify their own product choices.

Where a business has already implemented a particular safeguard on substantially the same service in one jurisdiction, it may be harder to maintain, without supporting evidence, that the measure is technically impossible elsewhere.  This may be characterised respectively as evidence of “technical feasibility” under the OSA and as an “operational baseline” for the application of the DSA. That analysis is persuasive only up to a point: feasibility is relevant to proportionality, but does not determine it.

The applicable UK and EU tests remain service- and risk-specific. A control that is technically possible may still be unnecessary, ineffective or disproportionate in a particular context. Conversely, a multinational business applying materially weaker protections to substantially the same service in one market should be able to explain the legal and evidential basis for that difference. Differences in applicable law, user population, risk, effectiveness, provider capacity or impact on other rights may justify different outcomes. They should be rigorously documented rather than assumed.

This places greater weight on product governance. For services used by children, businesses should be able to show that:

  • Product design: Relevant risk assessments address product design as well as content;
  • Pre-deployment checks: changes to recommender systems, defaults, and engagement features are assessed before deployment;
  • Dual testing: Age-assurance methods are tested against both safety and data-protection requirements; and
  • Post-launch monitoring: The effectiveness of safeguards is monitored post-implementation.

Under the OSA, Ofcom already expects children’s risk assessments to be updated before significant changes to a service are introduced.

The risk is also no longer confined to public enforcement. In September 2026, the Portuguese digital rights group D3 filed landmark collective proceedings against Facebook, Instagram, TikTok, and YouTube, challenging features including infinite scroll, autoplay, persistent notifications, and highly personalised recommender systems. Those allegations remain untested, and the procedural and substantive routes differ from the US litigation, but they demonstrate that design decisions may also become the focal point of civil class-action claims in Europe.

The financial consequences reinforce the point:

  • DSA penalties: Infringements of the DSA by Designated Very Large Online Platforms (VLOPs) can attract fines of up to 6% of worldwide annual turnover;
  • OSA penalties: Serious Online Safety Act breaches can attract penalties of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater; and
  • Data protection penalties: Infringements of data protection laws may generate separate exposure under the GDPR or UK GDPR.

The practical question for businesses is therefore not whether they should reproduce Meta’s US settlement terms. It is whether they can demonstrate that the way their service is designed, the way children are identified and profiled, and the safeguards they have chosen are lawful, proportionate and supported by evidence under the UK and EU regimes that apply to them.

————————————————


Source link