Protecting Children Online in the EU and UK: What Online Service Providers Need to Know in 2026
How the DSA, GDPR, the AI Act and the UK's Online Safety Act are converging on child protection
Source: https://prighter.com/tr/resources/protecting-children-online-eu-and-uk
In July 2026, the European Commission preliminarily found that TikTok had breached the Digital Services Act ("DSA") because the settings of minors' accounts did not provide the level of safety required by the DSA. Among other concerns, minors could make their accounts public and content posted by 16 and 17-year-olds could be recommended through TikTok's "For You" feed. The Commission's position closely reflects its Guidelines on the protection of minors, which favour private-by-default accounts and safer recommender systems.
The UK is moving in the same direction. Ofcom recently fined the provider of Xgroovy £700,000 for failing to implement highly effective age assurance as required under the Online Safety Act, plus another £30,000 for failing to respond to a legally binding information request. Earlier this year, the ICO fined Reddit £14.47 million for failures involving children's personal data and age assurance.
For online service providers, protecting children is no longer limited to removing obviously harmful content. Regulators are looking at account settings, recommender systems, age assurance, advertising, profiling, AI features and the overall design of the service. Extraterritorial reach is now the legislative norm and the laws governing children's online safety in the EU and UK are no exception. For global platforms, this means a single product design choice on minors' safety can trigger parallel regulatory exposure, making this a compliance issue that must be addressed at a global, not merely regional, level.
EU: The DSA is becoming the central online safety framework
For online platforms, the Digital Services Act is now the key EU-level framework for protecting minors. The DSA applies to any provider offering services to recipients in the EU, regardless of where the provider is established, so long as it has a "substantial connection to the Union", for example, a significant number of users in a Member State, or activities clearly targeted there. Providers with no EU establishment are required to designate a legal representative in a Member State.
Article 28 requires online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of their privacy, safety and security.
To meet this requirement, it is essential for platforms to carry out a structured, risk-based review of whether and how children access and use the service. Such an assessment must be conducted both at inception and at regular intervals or times of material service change. In its guidance on the protection of minors online (the Guidelines), the EU Commission frames this around a “5Cs” typology of online risks to children: content risks (exposure to harmful or age-inappropriate material), conduct risks (the child's own behaviour, including bullying or sharing self-generated content) contact risks (unwanted contact from strangers or adults), consumer risks (commercial exploitation through in-app spending, advertising or loot-box mechanics), and cross-cutting risks that cut across all categories and are considered highly problematic as they may significantly affect minor’s lives, arising from design features such as recommender systems, addictive design patterns and AI functionalities.
The assessment should weigh the likelihood that minors will access the service (informed by the platform's actual user base and whether any age restriction is genuinely effective) and the severity of the potential harm. The output informs what measures are “appropriate and proportionate” to meet the standard set by Article 28(1): a service with a young, high-risk user base is expected to adopt materially stronger safeguards than one where children's presence is marginal and the risk profile low.
The Guidelines then provide practical expectations on how to meet the broad obligations of the DSA. Only once such a risk assessment is done does the menu of safeguards make sense - safer default account settings, restrictions on unwanted contact, changes to recommender systems, child-friendly reporting mechanisms and proportionate age assurance are the levers a provider selects based on what its own risk assessment shows, not a fixed checklist applied uniformly.
Accessibility and age assurance go hand in hand. Importantly, simply stating in the terms and conditions that a service is “18+” will not necessarily keep the platform outside Article 28. The Guidelines explain that a platform may still be considered accessible to minors if the age restriction is not effectively enforced, or where the provider otherwise knows that children are using the service.
The Guidelines' own test for age assurance methods is that they be "accurate, reliable, robust enough to prevent circumvention, non-intrusive... and non-discriminatory" with each limb raising a practical question:
- Non-discriminatory means asking whether everyone actually has access to binding proof of age, or whether the chosen method simply screens out those who don't;
- Robust means resilient not just to casual circumvention but to increasingly convincing deepfakes; and
- Non-intrusive is where the user experience question sits; what it's like to be asked to verify your age repeatedly, by different methods, across every platform you use.
- Platforms must also not present profiling-based advertising to users where they are aware with reasonable certainty that the user is a minor. The restriction at Article 28(2) is deliberately widely drafted: it applies to advertising based on profiling under Article 4(4) GDPR, which includes any automated processing of personal data used to evaluate, analyse or predict a user’s behaviour, interests or preferences and not simply advertising that explicitly targets children. In practice, this means interest-based targeting built from browsing history, engagement patterns or inferred characteristics falls within scope once the platform has the requisite awareness, regardless of how that profile was generated.
Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) must also comply with the requirements of Articles 34 and 35 for a formal, documented risk assessment and risk mitigation, including identifying and mitigating systemic risks to the rights of the child enshrined in Article 24 of the Charter of Fundamental Rights of the European Union.
For businesses, product design itself is becoming a compliance issue and one worth investing in from the beginning, since it is far easier to build a safe, compliant product from the start than retrofit safety once a service has scaled. Default settings, recommender systems and age assurance are core product architecture rather than bolt-on features, so the earlier they're designed with children's safety in mind, the lower the cost, and the regulatory exposure, of getting there.
GDPR: Children's data requires additional protection
The GDPR provides the data protection layer sitting alongside the DSA.
Recital 38 recognises that children merit specific protection because they may be less aware of the risks and consequences of processing their personal data. This is particularly relevant to marketing, profiling and services offered directly to children.
Article 8 contains special rules where an information society service offered directly to a child relies on consent. The default age is 16, although Member States may lower this to no less than 13. Where the child is below the applicable national age, parental authorisation is required and the controller must make reasonable efforts to verify it.
Article 12 also requires transparency information addressed to children to be provided in clear and plain language. More generally, the GDPR’s requirements on data protection by design and default, data minimisation and DPIAs become particularly important where platforms process children’s data.
This means that measures introduced for online safety, including age assurance, cannot simply involve collecting as much identity information as possible and factors such as data minimisation and retention are equally as critical. Safety and privacy must be designed together.
AI Act: children are increasingly part of the AI safety discussion
The EU AI Act adds another increasingly important layer.
The Act prohibits certain AI systems that exploit vulnerabilities linked to a person’s age where this materially distorts behaviour and causes or is reasonably likely to cause significant harm. Article 50 also now requires transparency for certain AI interactions and AI-generated content. Now, users must generally be informed when they are interacting directly with an AI system, while AI-generated or manipulated content must meet marking requirements and deepfakes are subject to disclosure requirements.
The framework is also evolving quickly in response to AI-enabled sexual abuse. Following recent amendments to the AI Act, prohibitions concerning the generation or manipulation of non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM) are due to apply from 2 December 2026.
For services integrating AI chatbots, companions, image generators or other generative AI features, child-safety assessment therefore increasingly needs to extend beyond traditional user-generated content.
The EU AI Act includes extraterritorial scope: it applies to providers placing AI systems on the EU market, or whose output is used in the EU, regardless of where the provider is established and non-EU providers falling within scope are likewise required to designate an authorised representative in a Member State.
What comes next? The Digital Fairness Act and EU Kids Act
The forthcoming Digital Fairness Act (“DFA”) is another development to watch.
The Commission is currently preparing the proposal, with a particular focus on dark patterns, addictive design, unfair personalisation, influencer marketing and digital contracts. Minors are expressly identified as vulnerable consumers requiring greater protection. The DFA is still under preparation, but it suggests that child protection will increasingly extend beyond traditional privacy and content moderation into engagement design and monetisation models.
Set to emerge from Brussels, media reports suggest that the “EU Kids Act” would set an EU-wide minimum age of 15 for minors to hold their own social media, video-sharing or gaming accounts, with a tiered system of parent-controlled access below that age, alongside "safe by design" obligations such as banning addictive features like infinite scrolling. It forms part of a wider global trend that began with Australia's social media age restriction, which took effect in December 2025 and set 16 as the minimum age for platform access, a move regulators elsewhere, including the UK, are now actively following.
UK: Online safety and data protection operate together
The UK takes a broadly similar approach, but through two closely connected regulatory tracks.
The Online Safety Act 2023 (“OSA”), enforced by Ofcom, deals primarily with online harms. Services likely to be accessed by children must first carry out a children’s access assessment, and if children are or are likely to be users, must go on to assess risks and put appropriate safety measures in place. This includes protecting children from illegal content and from categories of content harmful to children, which Ofcom’s codes divide into primary priority content (pornography, and material promoting suicide, self-harm or eating disorders), priority content (violent, abusive or bullying material and dangerous challenges) and non-designated content presenting a material risk of significant harm. In certain circumstances, where primary priority content cannot be excluded from the service entirely, or where protections need to be targeted by age group, providers must use highly effective age assurance to determine which users are children.
This makes the OSA’s children’s risk assessment duty considerably more prescriptive than its EU DSA counterpart: it applies to every in-scope user-to-user and search service likely to be accessed by UK children regardless of size, built around named, Ofcom-defined content categories and a statutory code of practice, whereas the DSA's formal, documented systemic risk assessment under Articles 34 and 35 is reserved for designated VLOPs and VLOSEs — smaller platforms sit instead under the broader, outcome-based "appropriate and proportionate measures" duty in Article 28(1), now given practical shape by the Guidelines rather than a binding statutory code.
In certain circumstances, providers must use highly effective age assurance (HEAA). Providers who publish their own pornographic content (commercial porn sites) must use highly effective age verification or estimation to prevent children accessing it at all, and a user-to-user or search service that has concluded children are likely to access it are expected to implement HEAA wherever that service allows pornography or other primary priority content (content promoting or providing instructions for suicide, self-harm or eating disorders).
The OSA has broad territorial reach. A provider does not need to be established in the UK. Overseas services may fall within scope where they have sufficient links with the UK, including where UK users form a target market or where the service has a significant number of UK users.
And enforcement is no longer theoretical. Ofcom is running active enforcement programmes on age assurance and CSAM risks across online services and has already imposed substantial penalties on overseas providers.
UK GDPR, the Children's Code and the DUAA
The second track is privacy and product design.
The UK GDPR and Data Protection Act 2018 provide the underlying data protection framework. The UK sets the digital consent age under Article 8 at 13, meaning that where consent is relied upon for an online service, parental authorisation is generally required below that age.
The ICO’s Children’s Code, or Age Appropriate Design Code, then translates those requirements into practical product-design standards for services likely to be accessed by children. Its 15 standards include the best interests of the child, child-focused DPIAs, high-privacy defaults, data minimisation, geolocation and profiling being off by default in appropriate circumstances, restrictions on nudging children towards weaker privacy settings, and accessible tools for exercising rights.
The Data (Use and Access) Act 2025 (“DUAA”) reinforces this direction. It amended UK GDPR Article 25 so that providers of information society services likely to be accessed by children must take account of “children’s higher protection matters” when implementing data protection by design and default.
The ICO is actively enforcing these principles. Its August 2026 Children’s Code strategy update states that regulatory interventions since April 2024 have affected close to five million child users and highlights enforcement against Reddit and MediaLab as well as commitments obtained from Snapchat to strengthen age assurance.
AI and sexualised imagery: the UK is extending the framework
The Crime and Policing Act 2026 illustrates how rapidly the UK framework is developing in response to generative AI.
The Act creates offences relating to child sexual abuse image-generators and “nudification” tools. It also addresses online facilitation of child sexual exploitation and abuse.
Importantly for the next phase of regulation, section 248 also gives the Secretary of State power to bring currently unregulated generative AI services, including AI chatbots, within the Online Safety Act through secondary legislation. Those future rules could impose duties similar to the OSA’s existing illegal-content and CSEA requirements and can extend to overseas AI services that have sufficient links with the UK.
This responds to a real regulatory gap highlighted by the Grok case. Ofcom has explained that some standalone AI chatbot outputs currently fall outside the OSA, even while its investigation into X continues over Grok-generated sexualised imagery. The ICO is separately investigating X and xAI from a data protection perspective.
Practical Steps: What should online service providers do now?
The practical starting point is not to treat child protection as a single legal compliance exercise. Businesses should:
- Know which laws apply: identify which EU and/or UK laws are applicable based on their scope;
- Assess the users: determine whether children are likely to access the service, rather than relying solely on stated minimum ages in contract terms;
- Assess the risks: use guidance from the applicable regulator to map child-specific risks including illegal and harmful content, user to user contact, data use, recommender systems, advertising, AI features and monetisation and the severity of any harms;
- Mitigate the harms: review whether accounts and high-risk features are safe and private by default;
- Age assure: implement proportionate, effective and privacy-preserving age assurance mechanisms. Keep in mind the user experience and availability of official documentation to minors;
- Test: reporting, moderation and escalation processes from the perspective of a child user;
- Evidence everything: document the risk assessment and the reasons behind design decisions; and
- Appoint a representative: for providers outside the EU or UK, check both extraterritorial scope and local representative requirements under the relevant regimes and appoint a representative that meets the relevant requirements.
Protecting children online is a product governance issue
The EU and UK are converging around a common principle: businesses should not expect children to protect themselves from products that were not designed with children’s safety in mind.
The DSA, GDPR, AI Act, UK Online Safety Act and Children’s Code approach the issue from different angles, but the practical direction is increasingly consistent. Regulators are moving from rules about content and consent towards scrutiny of how services are designed, how algorithms influence children, how age is assessed, and how AI changes the nature and scale of online harms.
For online service providers, child protection is therefore becoming a product governance issue as much as a legal one.
Resources
EU resources:
- Digital Services Act — Regulation (EU) 2022/2065
- European Commission — Guidelines on the protection of minors under the DSA
- Commission — EU Age Verification Solution / Blueprint
- General Data Protection Regulation — Regulation (EU) 2016/679
- EU AI Act — Regulation (EU) 2024/1689
- Digital Fairness Act — Commission policy page
- TikTok — DSA minors enforcement, July 2026
- TikTok — addictive design, February 2026
UK resources:
- Online Safety Act 2023
- Data Protection Act 2018
- ICO — Children and the UK GDPR
- ICO Children’s Code / Age Appropriate Design Code
- Data (Use and Access) Act 2025 — DUAA
- Crime and Policing Act 2026
- Ofcom — Grok/X investigation and AI-chatbot gap
- ICO — Reddit £14.47m enforcement
- Ofcom — Xgroovy age-assurance fine, September 2026
Stay up to date
Get the latest privacy and digital governance updates from Prighter.
Open signup form in a new tab