05 October 2026

Teenagers are still scrolling at one in the morning, on apps built to keep them there. Two weeks after the Commission tabled its EU Kids Act proposal, the European Internet Forum brought together a Commission director, a telecom operator, a privacy think tank and the web standards community to discuss whether Europe needs stronger enforcement, new industry practices, or both. Age verification, default design rules and parental controls came up in every contribution.

How to protect minors online?

Opening Remarks

Stéphanie Yon-Courtin MEP described infinite scroll, autoplay and notifications as a business model in which children's attention is the product, noting that 78% of 13 to 17 year olds check their phone at least once an hour. She welcomed the Kids Act as a response to Parliament's report on minors online. Parliament had asked for a minimum age of 16 and the Commission proposed 15, but she said the principle of a single European digital minimum age is now settled. She warned that the Act will probably not apply before 2028, and that protection cannot wait, pointing to the Commission's preliminary finding that addictive design itself can breach the DSA. With at least 17 Member States preparing their own rules, she called for a European approach. She also argued that enforcement and industry practices are two sides of the same trust, built on three principles: safe, private and accountable by design.

The Commission's View

Prabhat Agarwal, Acting Director for Online Platforms: Society at DG CNECT, explained that the Commission's guidelines under Article 28 of the DSA produced little visible change in platform design, which, together with Parliament's calls, national measures and the scientific evidence gathered by an expert panel, led to the Kids Act. The proposal has four elements. The first is delayed access to social media, with no autonomous accounts below 15 and parent supervised accounts from 13. The second is a scope that extends to AI chatbots and video games. The third is binding design rules on defaults, scrolling, notifications and night time use, complemented by codes of conduct for fast moving areas. The fourth covers age verification and interoperable parental controls, enforced through the existing DSA architecture. He described the European age verification blueprint as working much like the Covid certificate, revealing only whether a user is above a given age. He stressed that the Irish presidency treats the file as a priority, since every year without these protections is a year lost.

Further Perspectives

Nadia Jouravleff, CSR Director and Head of Children's Rights and Protection at Orange, shared a telling figure: only 30% of parents who subscribed to the operator's safer phone offer activated its parental controls. For that reason, she said, Orange supports the Kids Act, which shifts responsibility from parents to the source. Orange's awareness programme has reached more than a million young people. Its survey of over 5,000 teenagers across nine countries found that they want safer technology rather than bans. The company is now developing an assessment tool, based on UNICEF's Children's Rights Impact Assessment, to identify risks before a product is launched.

Bianca-Ioana Marcu, Managing Director for Europe at the Future of Privacy Forum, explained that age assurance methods involve a trade-off in which higher assurance generally means higher privacy risk. Self declaration sits at one end and government ID at the other, with age tokens, double blind architectures and zero knowledge proofs as promising but imperfect options in between. Citing the French Constitutional Court's rejection of a ban for under 15s, she stressed necessity and proportionality, as well as the European Data Protection Board's principles on data protection by design and accountability. She called for the Kids Act to refer explicitly to GDPR obligations, and for data protection authorities to be involved in drafting its implementing measures.

Tara Whalen, Principal Privacy Specialist at the World Wide Web Consortium, drew on a 2025 workshop on age based restrictions that W3C co-organised with the Internet Architecture Board. She noted that the technical community is often underrepresented in consultations, which leads to underestimating the effects of design choices on the web's architecture. In her view, zero knowledge proofs are still maturing. Relying on a single provider would concentrate trust in one actor, and users could become used to sharing personal data with unknown parties. Online safety, she concluded, needs more than technology: parents, educators, governments and services all play a role, including through age appropriate design.

Videos

  • How to protect minors online?
  • 1:48 #EIFasks - Ivan Štefanec MEP on the EIF visit to Israel 2023
  • 32:19 Digital Skills in Education: Equipping Learners for the Digital Decades of the Future

Related content