2026/0286 (COD)
Proposal for a
REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
EU KIDS ACT - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy'
THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof, Having regard to the proposal from the European Commission, After transmission of the draft legislative act to the national parliaments, Having regard to the opinion of the European Economic and Social Committee, Having regard to the opinion of the Committee of the Regions, Acting in accordance with the ordinary legislative procedure,
Whereas:
(1) Online social networking services, video-sharing platform services, artificial intelligence (‘AI’) companions, general conversational chatbots, online games, and software application stores that have become an important part of the daily lives of minors. Such information society services and AI systems provide opportunities for minors in the areas of identity development, learning, education, civic participation, relationship development, communication, connection and creativity. At the same time, some of those services and systems, including because of their design, may create risks to minors’ privacy, safety and security. These risks include, for example, exposure to illegal or content and risks resulting from cyberbullying or contact from individuals seeking to harm minors. Minors may also face risks as vulnerable consumers through commercial practices that may be manipulative and cause unwanted spending, compulsive and addictive behaviour. These risks can originate from the direct experience of the minor with the online social networking services, video-sharing platform services, AI companions, general conversational chatbots, online games, and software application stores or from the actions of other users on the platform or the systems.
(2) A Special panel of experts on child safety online (‘Special Panel’) was established to provide advice to the Commission on a European approach on child safety online. The report of the Co-Chairs of the Special Panel was presented in July 2026 and is based on six guiding principles: a developmental approach, equality and diversity, protection of minors, accountability of digital services and consumer rights, empowerment and media education and children’s rights and participation. In particular, the report recommends EU-wide access restrictions to social media, harmonised safety-by-design rules for social media, other digital services, online games and certain AI systems accessible to minors as well as proportionate, privacy-preserving age assurance systems. The intention is to cover the entirety of the digital environment to ensure an effective and comprehensive protection of minors online (social media+).
(3) Member States are increasingly introducing, or are considering introducing, national laws to establish a minimum age for minors to access certain online services. Those diverging national laws negatively affect the internal market, which, pursuant to Article 26 TFEU, comprises an area without internal frontiers in which the free movement of goods and services and freedom of establishment are ensured, taking into account the inherently cross-border nature of the internet and online services and systems. The conditions for providers to restrict minors’ access to certain services and systems, as well as obligations regarding the design of their services and systems, require harmonisation so as to create legal certainty for providers offering services and systems accessible to minors across the Union, and ensuring a harmonised level of protection for minors irrespective of their location in the Union.
(4) Regulation (EU) 2022/2065 of the European Parliament and of the Council establishes a horizontal framework of due diligence obligations for providers of intermediary services, including specific obligations concerning the protection of minors online. In particular, Article 28 of that Regulation provides for obligations on providers of online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors, on their service. The Commission Guidelines on measures to ensure a high level of privacy, safety and security for minors online set out a non-exhaustive list of measures that providers of online platforms accessible to minors should put in place to comply with their obligation under Article 28(1) of Regulation (EU) 2022/2065.
(5) This Regulation specifies and complements the relevant provisions of Regulation (EU) 2022/2065 as regards the protection of minors, in particular in order to ensure a high level of privacy, safety, and security of minors, taking into account the Guidelines and the report drawn up by the co-chairs of the Special Panel. To that end, this Regulation sets out rules for a harmonised minimum age for creating an account with online social networking services, video-sharing platform services, and rules for harmonised design requirements for such services, and for age assurance.
(6) For that purpose, the provisions laying down a harmonised minimum age for creating an account with online social networking services and video-sharing platform services, harmonised safety requirements for online social networking services, video sharing platform services, video gaming platform services and software application stores, and harmonised rules regarding age assurance online and parental responsibility, insofar as they operationalise the obligation to put in place a high level of privacy, safety and security of minors, specify Article 28 of Regulation (EU) 2022/2065.
(7) Nothing in this Regulation should be construed as an imposition of a general monitoring obligation or a general active fact-finding obligation, or as a general obligation for providers of intermediary services to take proactive measures in relation to illegal content.
(8) This Regulation also complements Regulation (EU) 2024/1689 of the European Parliament and of the Council, which sets out a comprehensive, risk-based framework for the regulation of AI in the Union. Regulation (EU) 2024/1689 prohibits certain AI practices, including harmful exploitation of minors’ vulnerabilities and manipulation. Furthermore, it lays down requirements for high-risk AI systems, transparency requirements for interactive and generative AI systems and obligations for providers of the most capable general-purpose AI models to assess and mitigate systemic risks, including risks to the safety and well-being of minors. Without prejudice to the requirements and obligations set out in Regulation (EU) 2024/1689, this Regulation aims to address the particular risks posed to minors by AI companions and general conversational chatbots and to specify harmonised measures that providers of those AI systems should adopt to ensure a high level of protection of minors’ health and safety and to support their physical, mental and emotional well-being and development.
(9) This Regulation should be seen as part of the EU overall efforts to protect users, including children and other vulnerable groups, from being exposed to illegal content online. This includes Directive (EU) 2024/1385 on combating violence against women and domestic violence, which criminalises the non-consensual sharing of intimate images or manipulated material, gender-based hate speech, cyber harassment, and cyber stalking, including where directed at minors.
(10) This Regulation is without prejudice to the rules laid down in Directive 2010/13/EU regulating other aspects of the provision of these services covered by this Regulation, in particular, rules on the protection of minors as viewers of the audiovisual content. Where other instruments of Union law regulate similar, but not more specific, aspects of the provision of services in scope of this Regulation, the latter should prevail.
(11) Building upon definitions covering the digital environment, this Regulation should apply to certain information society services as defined in Directive (EU) 2015/1535 of the European Parliament and of the Council, that is, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. Specifically, this Regulation should apply to providers of online social networking services and of video-sharing platform services. This Regulation should also apply to certain AI systems within the meaning of Article 3(1) of Regulation (EU) 2024/1689 that are accessible to minors and that qualify as AI companions or general conversational chatbots. In addition, this Regulation should apply to providers of operating systems as defined in Regulation (EU) 2022/1925, as well as to providers of software application stores as defined in Regulation 2022/1925, which is a type of online intermediation service focused on software applications as the intermediated product or service. For the avoidance of doubt, this Regulation applies also to those online social networking services, video-sharing platforms, and software application stores that are designated as very large online platforms pursuant to Article 33 of Regulation (EU) 2022/2065.
(12) Video games have become an important part of the digital environment in which minors participate and interact with others, in a playful, goal-oriented or entertaining manner. Certain video gaming platforms allow the dissemination and exchange of user-generated content to an indeterminate number of recipients of the service and the facilitation of contact between these recipients. Such online games fall within the definition of online platforms referred to in Regulation (EU) 2022/2065 and should be covered by the scope of this Regulation. At the same time, some online games that do not allow the dissemination of information to an indeterminate number of recipients should also fall within the scope of this Regulation. This is the case of any game that that can be played on a computer, a mobile device, or a games console, irrespective of whether the game underlying software is subsequently executed locally, remotely, such as by means of durable medium, and irrespective of whether the service is provided free of charge, against payment, or against hybrid remuneration involving in-service (or in-application) purchases. Online games that are accessible or purchasable exclusively through physical media, without any online component enabling their access, distribution, or purchase, are not considered online games for the purposes of this Regulation. For the avoidance of doubt, where an online game also has certain features corresponding to a video sharing platform, it shall be considered an online game for the purpose of this Regulation.
(13) To ensure proportionality of the Regulation, this Regulation should not apply to services or systems that, by virtue of their non-commercial, educational, scientific or public-interest nature, present a materially very low risk to minors. This exclusion should cover not-for-profit online encyclopaedias, not-for-profit educational and scientific repositories, services and systems that are designed for primarily educational purposes and operated by educational establishments or organisation, or for them; open-source software-developing and-sharing platforms, services and systems specifically developed and operated for the sole purpose of scientific research and development, and services and systems designed, developed and operated by public authorities and for exclusive use of said public authorities or on their behalf.
(14) Where providers of services falling within the scope of this Regulation are also subject to the obligation to ensure a high level of privacy, safety and security pursuant to Article 28(1) of Regulation (EU) 2022/2065, these obligations are specified for the subject matters covered in this Regulation. Compliance with the obligations set out in this Regulation should however not be construed sufficient in itself to constitute proof of compliance of such providers with Article 28(1) of Regulation 2022/2065 and should therefore be without prejudice to further mitigation measures which such providers may be required to put in place for matters not covered by this Regulation for example those related to ensuring security. Equally, Article 28(1) of Regulation (EU) 2022/2065 should remain applicable to online platforms outside of the scope of this Regulation.
(15) For the purposes of this Regulation, it is appropriate to establish a common definition of a minor or child. A ‘minor’ or ‘child’ should be understood as any natural person under the age of 18, irrespective of any provisions of national law providing for an earlier or later attainment of legal majority. Furthermore, while providers of online social networking services, of video-sharing platform services, online games, software application stores and AI systems remain primarily responsible for the safety of their services and systems when used by minors, parents and legal guardians can play a role in guiding the minors’ experience online. The notion of guardian for the purpose of this Regulation should be based on the definition of parental responsibility in Council Regulation (EU) 2019/1111.
(16) For the purposes of this Regulation, the definition of ‘AI system’ as defined in Article 3, point (1), of Regulation (EU) 2024/1689 should apply. It is furthermore appropriate to define certain types of AI systems that qualify as AI companions or general conversational chatbots and are subject to the complementary obligations under this Regulation. Where reference is made to a provider of an AI companion or of a general conversational chatbot in this Regulation, the notion of provider should be understood as defined in Article (3), point (3), of Regulation (EU) 2024/1689.
(17) The definitions relating to age assurance, including ‘age verification’, ‘age assurance’, ‘EU list of providers of EU proof of age attestations’, EU list of providers of EU Age Verification Solutions’, ‘EU Age Verification Scheme’ and ‘proof of age attestation’, should be understood as building on, and being interpreted consistently with, the Union framework established by Regulation (EU) No 910/2014 of the European Parliament and of the Council as amended by Regulation (EU) 2024/1183, as well as with Commission Recommendation (EU) 2026/1035 of 29 April 2026 on establishing a common framework for EU wide Age Verification technologies for minors and the related Commission Guidelines on the protection of minors online.
(18) To ensure that a high level of privacy, safety and security for minors is guaranteed, it is important that the obligations are applied effectively and are not circumvented. Accordingly, providers should not engage in behaviour that would undermine the effectiveness of the obligations laid down in this Regulation. Such behaviour includes the design of the service or the system, the presentation of choices to recipients of the service or user of the system in a non-neutral manner, or using the structure, function or manner of operation of a user interface or a part thereof to subvert or impair user autonomy, decision-making, or choice. For example, minors should not be requested to lower the level of sensitive settings during account creation, such as access to geolocation or camera. They should also not be enticed to circumvent the delayed access obligations. Providers should also limit the creation, by minors, of secondary accounts aimed at circumventing safety by design measures.
(19) To ensure that services that minors are accessing provide for the highest level of privacy, safety and security, the providers of online social networking services and video-sharing platforms services that have been designated as very large online platforms designated pursuant to Article 33 of Regulation (EU) 2022/2065 should notify to the Commission of measures they intend to take to ensure effective compliance with the obligations, such as delayed access to service and safety-by-design. This should enable the Commission to verify, following an assessment by independent auditors with a specific expertise that the providers subject to the obligations laid down in Chapters II to V of this Regulation have taken the measures necessary to comply with them. The Commission should respond to that compliance plan, without prejudice to its supervisory and enforcement powers, in particular the power to initiate proceedings pursuant to Article 34 of this Regulation. This notification mechanism is necessary and proportionate in view of the objective it pursues and respects fundamental rights of freedom to conduct a business enshrined in Article 16 of the Charter and with the freedom to receive and impart information under Article 11 thereof.
(20) The years from 0 to 15 are particularly important for minors’ cognitive, emotional and social developments, as well as for the development of their personality, identity and value systems. Scientific evidence shows that certain online social networking services and video-sharing platform services pose a particularly serious risk to the privacy, safety and security of minors below the age of 15 years due to their particular features and functionalities. Ranging from risks as passive online users under the age of 3, when care can be substituted by screentime affecting children’s attention span, language acquisition, and socio-emotional development, through risks of mismatch between continuous exposure to external stimulation and children’s evolving capacities and emerging self-perception, to risks of convergence of developmental sensitivities and platform-driven amplification of content and interactions, research shows mental health impacts and that children are especially vulnerable under the age of 13. Until 15, adolescents transition into autonomy, and whilst supervision by caregivers and educators becomes less effective, risks are increasingly shaped by social elements of digital services, rather than individual behaviours, and adolescents from 13 to 15 are at the peak of developmental vulnerability. It is therefore crucial to ensure that their right to development and self-determination can be enjoyed free from the substantial impacts that the risks and harms posed by certain online services can have on minors. In order to ensure an equal level of protection for minors located in the Union, introducing an EU-wide access restriction to social media+ for under 13-year-olds is necessary. In order to avoid fragmentation of the internal market by diverging national laws, a harmonised minimum age of 15 years should be established for creating autonomous accounts with online social networking services and video-sharing platform services that present features or functionalities that are particularly harmful for minors below that age. This should be without prejudice to Union laws or national laws in accordance with Union law, establishing a higher minimum age for specific categories of content such as pornographic or gambling content.
(21) The features and functionalities which are considered to pose a risk to the privacy, safety and security of minors below the age of 15 correspond to globally recognised classifications of online risks, including exposure of minors to age-inappropriate content or contacts as well as harmful conducts of other users or other commercial or cross-cutting risks such as excessive use. These therefore include features and functionalities that enable certain harmful content consumption and dissemination as well as harmful interactions or behaviour. In particular, services enabling recipients to disseminate content in real-time to an indeterminate number of people expose minors to risks for their privacy as well as to inappropriate content, such as pornographic content; enabling minors to interact with unknown users exposes them to risks of inappropriate contact by adults but also of abusive or other harmful conducts by other users; automatically suggesting content or contacts expose minors to the risk of being exposed to harmful content or so-called “rabbit-holes” of harmful content, as well as entering into potentially harmful contacts with malicious users; deploying functionalities, interface designs or characteristics that can lead to compulsive or excessive use, such as push notifications or endless content feeds, expose the minor to risks of developing behaviours that harm their mental health and wellbeing, including addictive behaviours. These functionalities are typically offered only to recipients of the service that access the service by means of an account. It is therefore proportionate, taking into account the minor’s right to freedom of expression, to delay access to the service at the point of creation and use of such accounts, as the use of the same service without an account poses a lower risk to minors.
(22) Recognising the role of parents and legal guardians in supporting the evolving autonomous and safe development of minors online, it is appropriate to allow providers to exceptionally derogate from the minimum age for autonomous access laid down in this Regulation, down to a lower minimum age of 13 years, to allow the holder of parental responsibility to set up an account with limited functionalities for children between 13 and 15. Such an account should be an account of the holder of the parental responsibility and not of the respective minor. That derogation should be subject to verification of parental responsibility and should not undermine the objective pursued by this Regulation, taking into account the children’s right to protection, privacy and taking the child’s best interests as a primary consideration. Finally, that derogation should not be possible where the providers in their terms of service restrict access to and use of their service for users below a higher minimum age than 13 years.
(23) Where a video-sharing platform service is specifically designed for minors below the age of 13 years, a guardian may exceptionally enable such a minor to access the service under the conditions laid down in Article 7, exclusively through the guardian’s own account and under the guardian’s control and supervision. Such guardian-controlled access does not entail the creation or use of an account by the minor and is therefore not access by means of an account created for, or attributed to, the minor within the meaning of Article 6(1). Guardian-controlled access may be organised through child-specific settings or profiles within the guardian’s account; such settings or profiles do not constitute accounts of the minor.
(24) Nothing in this Regulation requires any provider to make its service available to minors below the age of 13, nor does it affect the terms and conditions of services that exclude such minors, which remain fully subject to the obligations of this Regulation to prevent their access. Requirements related to the age-appropriate experience on video-sharing platforms services concern solely those services whose providers have made the deliberate choice to offer an environment specifically designed for children, and subjects that choice to strict conditions.
(25) Age-appropriate and safe online experiences are paramount to protect minors in an increasingly online environment. In order to ensure that minors can benefit from a safe digital environment, providers of online social networking services, video-sharing platform services, online games, AI companions, general conversational chatbots, and software application stores, should put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors when using their service or system. To that end, providers should by-design shape their services and systems in a way that prioritises the wellbeing of minors by embedding privacy, safety and security protections into their design and operation from the start taking into account the evolving capacities of minors. Where the service or system is accessible without registration or authentication, providers should by default configure the design and settings for any unregistered or unauthenticated user in a way which guarantees a high level of privacy, safety and security of minors. Providers should only derogate from those requirements once they have established that the recipient or user is an adult by making use of age assurance in accordance with this Regulation.
(26) For online social networking services and video-sharing platform services, the measures taken by providers of those services to comply with the obligations set out in this Regulation should ensure that, once minors have created their own account to use the service, they continue to benefit from a safe digital environment. While those measures mitigate the risks arising from the particular functionalities and features of such services for minors above the age of 15 years, online social network services and video sharing platforms nevertheless remain inappropriate for minors below that age. Compliance with those obligations should therefore not affect the general restriction on minors creating their own account below that age.
(27) Certain design features of online social networking services and of video-sharing platform services may exploit minors’ vulnerabilities and contribute to extensive or excessive use of the service, compulsive behavioural patterns or addiction-like behaviour, with adverse effects on minors’ mental, emotional and physical well-being. Such features may include uninterrupted content consumption without effective stopping points, autoplay, autoscroll, autoreplay, infinite scroll, notifications artificially timed to regain attention, reward mechanisms encouraging repeated engagement, or mechanisms penalising the recipient of the service for not returning at regular intervals. Providers of online social networking services and video-sharing platform services should therefore not expose minors to manipulative or persuasive design features predominantly aimed at maximising engagement where those features may impair minors’ privacy, safety or security or undermine their autonomy. Providers of online social networking services and of video-sharing platform services should not undermine the minor’s decision to discontinue use or the absence of decision to use the service, such as notifications not triggered by, or not directly related to, the minor’s interaction or activity on the service. This should cover situations where the platform changes behaviour towards users when users do not use the service. As such, this would cover features which attempt to recapture user attention once lost, such as sending notifications about rewards for continuing to use the service. The providers should also not incentivise engagement at regular times or with greater frequency, including through penalties or loss of benefits for failing to engage regularly or within specified time intervals. The providers should implement age-appropriate time-management and agency-enhancing tools, including visible prompts, reminders and other measures that support informed and deliberate use of the service enabling effective interruption of the use of the service. As time-management tools are often overridden by the minors themselves, providers should ensure these measures are effective in reducing minors use of the service and not easily circumvented. Such tools should also ensure that minors’ sleep needs are not impaired by their use of the service. That should include effectively preventing minors from using the service during their school time and core sleep hours, which should be age-appropriate, in accordance with scientific recommendations. Core sleep hours should be understood as the period of the night during which minors are ordinarily expected to sleep, comprising at least eight consecutive hours between 22:00 and 08:00 local time. School time should be understood as the period during which minors are ordinarily expected to attend school or otherwise participate in compulsory educational activities, in accordance with applicable national law or practice and subject to adjustment by guardians.
(28) A core aspect of the design and operation of online social networking services and of video-sharing platform services is the manner in which information is prioritised and presented on the service’s online interface, which may significantly influence minors’ access to, engagement with and exposure to information. To ensure that minors are effectively protected online, providers of online social networking services and of video-sharing platform services that use recommender systems should design their recommender systems in such a way that they ensure a high level of privacy, safety and security of minors. To that end, providers should use evaluation metrics that capture quality, safety and mental-health outcomes for minors, such as metrics measuring whether the recommender system selects and prioritises content appropriate for a minor’s age and developmental stage, assessing the system’s effectiveness in preventing exposure to illegal, harmful or unsafe material, and capturing indicators of psychological well-being to assess the impact on minors’ mental health. Those metrics should inform the optimisation considerations underlying the design of recommendation objectives of online platforms. To ensure a high level of privacy, safety and security of minors, providers of online social networking services and of video-sharing platform services should give priority and primary weight to explicit user-provided preferences when recommending content, such as user feedback and interactions that indicate users’ explicit preferences, both positive and negative, including the stated and deliberate selection of topics of interest, surveys, reporting, and other quality-based signals. Furthermore, to ensure minors are provided with more agency over information being suggested to them, providers of online social networking services and of video-sharing platform services should disable by default the recommendation of information suggested by the recommender system based on implicit engagement-based signals from minors’ behaviour online. Implicit engagement-based signals should be understood as signals and data that infer user preferences from their activities (browsing behaviour on a platform), such as time spent viewing content and click-through rates. Providers of online social networking services and of video-sharing platform services should ensure that recommender systems do not rely on the collection of any personal data captured from outside the service. Providers of online social networking services and of video-sharing platform services should also ensure that minors are not exposed to content that is harmful when encountered repeatedly, which should be understood as covering the so called “rabbit holes” or “filter bubbles” of content that may pose a risk to their safety and security. The “rabbit hole” effect relate to the progressive amplification of similar recommendations of content, leading recipients of the service to endless content pathways which could potentially be extreme and harmful to minors. The “filter bubble” effect refers to the progressive amplification of content whereby a minor is predominantly exposed to content or information reducing the minors’ exposure to diverse content or information. Minors should also be given agency over their recommender systems and be able to control the content recommended through dedicated tools. Minors should be offered an easy way to reset their recommender systems by deleting all previous identified preferences and, be able to choose one option that is not based on profiling irrespective of whether they are registered or not, as provided for in Article 38 of Regulation (EU) 2022/2065, regardless of whether or not the provider concerned is a provider of a very large online platform in accordance with Article 33 of Regulation (EU) 2022/2065. To ensure the effectiveness of such measure, those providers should regularly remind minors of the option to reset their feeds and ensure that that option is not designed in a manner to entice minors into choosing the option based on profiling.
(29) Designing settings to ensure a high level of privacy, safety and security is important to minimise online risks for minors by reducing the likelihood of minors being exposed to content, interactions or functionalities that may be harmful, including in circumstances where children are unregistered on the service. To this end, providers of online social networking services and of video-sharing platform services should ensure that settings, such as those that allow tracking recipients of the service or locating them, enabling access to microphone, contacts and camera, or recommending other accounts to minors are off by default for minors. When enabled, some particularly privacy-sensitive settings, such as access to location, should be turned off after the session ends, and in any case, minors should always be made aware when activated. Furthermore, push notifications should be turned off by default and should be designed in a way that does not impair minors sleep needs and school time. To this end, push notifications should never be sent to children during their school time and core sleep hours, with the exception of where such notifications stem from urgent security alerts – for example related to account security-or interactions with their guardians. Push notifications are notifications that appear on a device to inform the recipient of the service of ongoing activities on the service regardless of whether the service is actively in use and thereby encouraging users to continue the use of the service. Additionally, where some settings and features may be particularly harmful to minors, providers should make them inaccessible for minors. Such harmful features can be filters impairing minors’ mental well-being for example by disproportionately embellishing, distorting or idealizing a child’s image – excluding harmless filters such as those mimicking animals – as well as features increasing social comparison such enabling children to see the numbers of reactions on their content.
(30) Minors should be protected from contact-related risks, including cyberbullying, harassment, and those seeking to groom, sexually abuse or extort minors, human traffickers and those seeking to recruit minors into criminal gangs or promote violence, radicalisation, violent extremism and terrorism, as perpetrators often use the digital space to reach out to children. Consequently, interactions between minors and unregistered recipients of the service, as well as unknown recipients of service, especially adults, should have robust safeguards. Providers of online social networking services and video-sharing platform services should ensure that information about the minor, such as profile information, biography, activities, list of friends, followers and similar information cannot be accessed by recipients of the service by default, and in any event, by recipients of the service without accounts. Minors should be empowered to exercise effective control over the visibility of their personal information, such as their profile photo, profile information, content shared, contacts, activities and history or any other data shared on the account or profile. Contact details from minors – including but not limited to address, email address and telephone number – should not be shared with other recipients of the service. Minors should be able to block any other recipient of the service, manage content shared and regulate the interaction and related metrics, such as likes and number of followers. By default, the hosting of livestreams or other real-time transmissions should be disabled, as should access to the minor’s account information by recipients of the service who have not been explicitly accepted. To ensure that the possibility to enable these settings remains proportionate, this should depend on the age and evolving capacities of the minor, for example by ensuring that public accounts and the possibility to host livestream should only be accessible to children above the minimum age and if explicitly consented by their guardian.
(31) Commercial practices occur in different forms on digital services and can have particular persuasive effects on minors, who face diverse, dynamic and personalised tactics, through for example, advertisements, product placements, the use of virtual currencies, influencer marketing, sponsorship or AI-enhanced nudging. In line with, and without prejudice to, the existing horizontal legal framework, in particular the Directive 2005/29/EC of the European Parliament and of the Council7 that is fully applicable to all commercial practices including towards minors as consumers and the rules in Regulation (EU) 2022/2065 on advertising (Article 26, Article 28(2) and Article 39) and dark patterns (Article 25). In the particular case of dark patterns, Regulation (EU) 2022/2065 acts as the “safety net” complementing Directive 2005/29/EC. Economic transactions may be harmful to minors’ safety and security when using the service, especially where they do not understand the consequences of the transaction they are making. Therefore, minors should be clearly informed about economic transactions taking place online. To this end, purchases carried out within the service should be labelled as an economic transaction in an easy comprehensible manner and in real time. Virtual currencies and other tokens may also cause unwanted spending, therefore all kind of purchases should be displayed in the national currency of the habitual residence of the minor. Moreover, providers of online social networking services and of video-sharing platform services should ensure that minors as vulnerable consumers are not exploited and should not design their platform in such a way that can lead to excessive, impulsive or unwanted spending. This should include notably introducing a separation or friction between content and the purchasing of related products as well as preventing minors from being exposed to loot boxes and other products, where they offer random or unpredictable outcomes or gambling-like features.
(32) Given the particular vulnerabilities of minors and the risks that AI companions and general conversational chatbots may pose to their health, safety, fundamental rights and well-being, providers of such AI systems should implement safety by design measures tailored to the specific characteristics and risks stemming from those systems in order to offer minors an age-appropriate experience. Safeguards should include safe settings and prohibitions on addictive designs. Furthermore, minors should not be exposed to features of the system displaying behaviours or simulating emotions or interpersonal relationships that are likely to create emotional and other dependencies, including when such dependencies may negatively impact relationships with other humans and the development of the minor. In order to prevent such systems from accumulating sensitive data of minors and potentially reinforce harmful interaction patterns over time, the persistent conversational memory of interactions with minors should be disabled by default except where necessary to protect their safety. AI companions and general conversational chatbots accessible to minors should also be subject to appropriate testing and evaluation before being placed on the market or put into service and at regular intervals thereafter.
(33) Providers of AI companions and of general conversational chatbots accessible to minors should also implement post-market monitoring to identify and mitigate risks to minors’ health, safety and fundamental rights and their mental, physical, mental and emotional well-being and development and to assess the effectiveness of the measures put in place, unless the provider is a micro or small enterprise. In this context, it should be borne in mind that if the AI companion or general conversational chatbot is based on a general-purpose AI model with systemic risk, that models is already subject to specific risk management obligations under Regulation (EU) 2024/1689. The systemic risk management carried out by providers of those models should include the assessment, and, if necessary, mitigation of risks to the safety and well-being of minors, including risks to minors from their legitimate use of the model and from the use of the model by other persons that may cause harm to minors. It is accordingly appropriate for relevant mitigations implemented as part of this systemic risk management pursuant to Article 55 of Regulation (EU) 2024/1689 to be relied upon by providers of AI companions and general conversational chatbots as part of their efforts to comply with the requirements of this Regulation. Similarly, risk assessments and mitigation measures implemented pursuant to Articles 34 and 35 of Regulation (EU) 2022/2065 may also be taken into account when performed by a provider of an AI companion or a general conversational chatbot deployed as a functionality of an online social networking service or of a video-sharing platform service in the provision of that service. Nevertheless, such mitigation measures should not be considered sufficient for compliance with the requirements set out in this Regulation.
(34) Where an AI companion or a general conversational chatbot is deployed as a functionality of an online platform or of an online search engine, the obligations laid down in Regulation (EU) 2022/2065 should continue to apply to the provider of those intermediary services, where the conditions for their application are fulfilled. In particular, the deployment of such functionalities should not affect the application of the rules on the assessment and mitigation of systemic risks, including risks stemming from the design, functioning or use of those functionalities, insofar as they form part of the service offered by the online platform or online search engine. To ensure transparency over interactions with such systems, providers of online social networking services, of video-sharing platform services, and of online games that deploy AI companions or general conversational chatbots as a functionality in the provision of their service should also implement measures that empower minors to make informed choices whether to use those companions or chatbots and be able to opt out from such use. This should include obligations for those providers to ensure that minors are not nudged to use those systems through design techniques, such as displaying AI companions and general conversational chatbots at the top of the minor’s contacts list. Moreover, safeguards should apply to AI companions and general conversational chatbots when they are deployed as a functionality in the provision of an online game, where in-game purchases can occur.
(35) Online games can take very different forms and can be divided into categories such as action, adventure, role-playing games, strategy, sports, simulation or puzzle games and are usually played on a PC, mobile device or console. Online games can provide minors not only entertainment, but also online environments for communication and social interaction, including for minors with disabilities. Multiplayer online games enable minors to engage with other persons and to build social connections across different age groups and geographical locations. Online games can also contribute to minor´s learning of coordination, cooperation and subjects such as science, mathematics and languages. Video gaming platforms enable users to play and create their own content or games, and disseminate them to the public. Both video games and video gaming platforms may present diverse risks to minors. This was also highlighted by the Report by the Co-Chairs of the Special Panel on Child Safety Online which highlighted that video games may expose children to harmful commercial practices or dangerous contacts and age classification systems may provide orientation and insights for parents and caregivers on game ratings.
(36) Given the particular vulnerabilities of minors and the risks that online games may pose to their privacy, safety and security, it is important that providers of online games implement safety by design measures tailored to the specific characteristics and risks stemming from those online games in order to offer minors an age-appropriate experience. Such risks relate in particular to unsolicited communication in the video games, age-inappropriate content, and design mechanisms which can lead to addictive behaviours and excessive use. Online games with open communication expose minors to contact-related risks, including cyberbullying, harassment, and those seeking to groom, sexually abuse or extort minors, human traffickers and those seeking to recruit minors into criminal gangs or promote violence, radicalisation, violent extremism and terrorism, as perpetrators often use the digital space to reach out to children. Similarly certain settings may expose minors to content, interactions or functionalities that may be harmful, including in circumstances where children are unregistered on the service. Providers of online games should therefore implement safeguards to prevent the service from being used to entice minors to initiate contacts on other services which may pose a risk to their privacy, safety and security. This could be done through restricting link-outs where this may pose a risk to minors and by implementing warning messages to minors. Video gaming platforms may also increase the risk of minors being exposed to age-inappropriate content. Where video gaming platforms allow recipients of the service to create individual video games, the provider of the video gaming platform should put in place the necessary software and organisational measures to allow the provider of the newly created video game to comply with applicable rules.
(37) Certain design features of online games may exploit minors’ vulnerabilities and contribute to extensive or excessive use of the service, compulsive behavioural patterns or addiction-like behaviour, with adverse effects on minors’ mental, emotional and physical well-being. Online games should therefore not expose minors to features undermining the minor’s decision to discontinue use or the absence of decision to play the online game or features or rewards incentivising engagement at regular times or with greater frequency, including through penalties or loss of benefits for failing to engage regularly or within specified time intervals.
(38) Providers of software application stores are in a unique position concerning the way how services which pose a risk for minors may be offered recipients. To ensure a high level of privacy, safety and security for minors in the online environment, providers of software application stores should put in place an age rating system to allow to establish the age-appropriateness of software applications disseminated through their service. Such an age-rating system should apply to each software application and should take due account of the rights and best interests of the child, including minors’ evolving capacities and differing levels of maturity. Providers of software application stores should prevent minors from accessing or purchasing applications rated as age-inappropriate. Furthermore, to ensure compliance with applicable Union law and national law adopted in compliance with Union law, where the provider of a software application store becomes aware of software applications disseminated through its service that are or primarily consist of content that is subject to a higher minimum age under the applicable Union law or national law, the provider should not allow minors below that minimum age from that Member State to access or purchase those software applications through its service. For this purpose, providers of software application stores should assess the age of the recipient of the service in accordance with Chapter V of this Regulation. To ensure transparency and accountability, providers of software application stores should make publicly available, in clear and accessible terms, information on the methodology, criteria and sources underpinning their age-rating systems.
(39) Codes of conduct can be an important tool to protect minors in the online environment. In that context, the Commission should encourage the drawing up or further development of voluntary codes of conduct at Union level establishing common methodologies and criteria for age rating systems, to contribute to the harmonised operation of such systems in the application of this Regulation, including by providers of software application stores. The codes of conduct should in particular facilitate the mutual recognition and consistent application of age ratings across Member States, define appropriate criteria, methodologies and sources of information for assessing the age-appropriateness of the most relevant types of content including violent, sexual, gambling and self-harm content as well as in-app purchases, contact risks and addictive design features as well as establish the necessary remedies and redress mechanisms and ensure transparency, combined with regular, transparent and independent monitoring and evaluation of the achievement of the objectives aimed at. The refusal without proper explanations by a service provider of the Commission’s invitation to participate in the application of such a code of conduct could be taken into account, where relevant, when determining whether the service provider has infringed the obligations laid down by this Regulation. The mere fact of participating in and implementing a given code of conduct should not in itself presume compliance with this Regulation. The Pan-European system (PEGI) age classification system and PEGI Code of Conduct set a benchmark for the participating companies with respect to age labelling, promotion and marketing and reflects the video games industry’s commitment to provide information to the public in a responsible manner. The rules on codes of conduct under this Regulation could serve as a basis for already established co-regulatory efforts at the Union level to be integrated as a code of conduct. This includes, but does not concern exclusively, the PEGI age rating system, provided that it provides a high level of privacy, safety and security of minors as required by this Regulation.
(40) Minors playing online games should benefit from the same protection in respect of economic transactions as on online social networking services and video-sharing services, including transparency as to the real monetary value of transactions carried out through virtual currencies and protection from exposure to variable reward systems, whose association with gambling-related and compulsive behaviours is well documented. Codes of conduct in the area of online games should build on existing pan-European classification and self-regulatory frameworks or age classification systems at Member State level, including their recent extension to interactive risk categories and monetisation practices, and should keep such frameworks updated in light of scientific and technological developments and emerging risks to minors. Adherence to a code of conduct assessed as adequate by the Commission may serve as an indication of compliance with the measure-based obligations laid down in this Regulation, but cannot derogate from its prohibitions.
(41) In order to ensure a high level of privacy, safety and security of minors in the digital environment, providers of online social networking services, of video-sharing platform services, of AI companions and of general conversational chatbots and of online games should take into account the evolving capacities, interests and vulnerabilities of children throughout the design, development and operation of their service. The measures put in place should therefore at least be child-friendly, easy-to-understand, easily accessible to all minors, including those with disabilities or additional accessibility needs. Very large online platforms within the meaning of Article 33 of Regulation (EU) 2022/2065 shall ensure that such information is presented in the official language(s) of the Member States in which the service is provided. Providers of online social networking services, of video-sharing platform services, of AI companions and of general conversational chatbots and of online games should also enable minors to provide feedback on content, search results and prompts recommended to them on the service. Such feedback should be taken into account and have an imminent and durable impact on children’s experience on the service. Furthermore, minors should be progressively empowered to understand and manage their default settings. Where a minor changes a protective setting, providers should present clear warnings and offer easy reversibility, including the option to temporarily change the setting and one-click return to default settings. In order to ensure a high level of privacy, safety and security of minors, providers should not repeatedly prompt or entice minors to lower their level of protection.
(42) In order to ensure a high level of privacy, safety and security of minors, it is necessary to put in place effective, visible and child-friendly mechanisms for reporting and for supporting minors to report content, accounts, groups, features and behaviour that may negatively affect their privacy safety and security when using the service. This includes the reporting of accounts owned by users below the minimum age, pursuant to this Regulation. Such mechanisms should not affect the application of Article 16 of Regulation (EU) 2022/2065. In order to ensure a high level of privacy, safety and security of minors, such mechanisms should, where appropriate, enable minors to submit a report in their own words and should ensure that the identity of the minor remains confidential towards other recipients of the service or users of the system by default. Reports submitted by minors should be treated as a matter of priority. Furthermore, minors should receive a confirmation of receipt, together with age-appropriate information on the follow-up process, indicative timelines and possible outcomes. Any restrictions imposed by providers following such reports by minors should be considered as a restriction of the visibility pursuant to Article 17(1), point (a) of Regulation (EU) 2022/2065, where applicable. Additionally, minors should be able to access comprehensive and appropriate support where they encounter illegal and harmful content and activities. To that end, providers of online social networking services, of video-sharing platform services, of AI companions and of general conversational chatbots, and of video gaming platforms services, should make available support tools that are easily accessible and adapted to the needs of minors and that enable referrals or connection to national support services, including Safer Internet Centres, child help and hot lines, child protection services and, where appropriate, contact details of law enforcement. Those support tools should also be connected to national online safety apps, such as the 3018 application provided by e-Enfance, where such apps exist, as well as to the European Online Safety App when available. To ensure that minors are aware of the risks in the online environment, they should be informed of the specific risks prior to posting content or enhancing the visibility of certain content such as reposting content posted by other recipients. To that end, providers of online social networking services, of video-sharing platform services, AI companions, general conversational chatbots, and of online games, should, where appropriate, implement warning messages or other suitable measures aimed at informing minors before they undertake any actions.
(43) Guardians play an important role in the lives of minors, including in supporting their safe and informed navigation of the online environment. This is why guardians should be facilitated in providing such support through the availability of tools for guardians. Tools for guardians are software, features, functionalities, or applications designed to help guardians accompany their minor’s online activity, privacy, safety and well-being, while respecting children’s agency and privacy. Tools for guardians should be considered as complementing other safety by design measures but should never replace the providers’ own responsibility to ensure a high level of privacy, safety and security for minors. Since parental oversight is not always possible due to the realities of children’s living arrangements and since guardians might be absent or disengaged, compliance should not depend exclusively on guardians. Tools for guardians should at least include features for reporting content on behalf of their child, setting screen time limits, seeing and being informed on the accounts that the minor communicates with, managing account settings, as well as other features to supervise uses of the services in scope of this Regulation that may be detrimental to the minor’s privacy, safety and security. Such features may include warnings for guardians to be informed about potential repeated searches of minors related to suicide, self-harm, or eating disorders or initiate contact with or became friends with, including where such accounts belong to adults an adult. Where guardians manage minor’s settings, they should be able to choose the time period for which they intend to change such settings. These tools should be tailored to the age of the minor, taking due account of their gradual development. Tools for guardians should be age-appropriate, easy to access and activate, effective and not easily circumvented, while respecting minors’ rights to privacy, access to information and growing autonomy in accordance with their evolving capacities. For example, such tools should allow the guardian to use the tool without creating an account with the service and they should ensure that changes can only be made with the same degree of authorisation required for the initial activation of the tools. Minors should be clearly notified when such tools are activated and should, in particular where monitoring functionalities are used, receive a clear real-time indication. For very large online platforms within the meaning of Article 33(1) of Regulation (EU) 2022/2065, interoperability with third-party guardian tools should further enhance usability and effectiveness, in accordance with conditions set out by Article 6 of Regulation (EU) 2022/1925. The power to adopt acts in accordance with Article 290 TFUE should be delegated to the Commission in order to supplement this Regulation by laying down the necessary rules and technical criteria for the tools for guardians.
(44) Certain bodies, organisations and associations have particular expertise and competence in detecting and flagging suspected infringement of this Regulation and their complaints may have a positive impact on the freedom of expression and of the freedom of information in general. Therefore, guardians and minors should have the right to mandate such a body, organisation or association in accordance with the conditions set out in Article 86 of Regulation (EU) 2022/2065 to exercise the rights conferred by this Regulation on the minors’ behalf. In addition to the right to lodge a complaint in accordance with Article 53 of Regulation (EU) 2022/2065, minors and guardians who are recipients of the service and users of systems and any body, organisation or association should have the right to lodge a complaint against providers subject to this Regulation. Such complaints should be lodged with the competent authority determined in accordance with Article 27 of the Member State where the recipient of the service is located or established, in accordance with national principles of good administration. For AI companions and general conversational chatbots, Article 85 of Regulation (EU) 2024/1689 should apply. The possibilities to contest decisions of providers of online platforms should leave unaffected in all respects the possibility to seek judicial redress in accordance with the laws of the Member State concerned, and therefore should not affect the exercise of the right to an effective judicial remedy under Article 47 of the Charter.
(45) Ensuring a high level of protection of minors relies not only on the measures put in place by providers, but also, for providers of very large online platforms, on their ability to demonstrate through appropriate monitoring, testing and evaluating the effectiveness of the measures implemented in accordance with Chapter III, which should be part of the risk assessments conducted pursuant Article 34 of Regulation (EU) 2022/2065. Providers should consider the most up-to-date information available and insight from scientific and academic sources for that evaluation. To monitor and assess the effectiveness of the measures over time, providers should preserve all supporting documents relating to their evaluation for at least three years.
(46) To support the proper application of this Regulation, the Commission should encourage and facilitate the development, implementation, regular review and adaptation of voluntary Union-level codes of conduct involving, where appropriate, providers of online social networking services, video-sharing platform services, online games, AI companions, general conversational chatbots a, as well as competent authorities, civil society organisations, and other relevant stakeholders. Those codes of conduct should set out clear objectives, include specific commitments and reporting arrangements proportionate to the size and capacity of providers, and duly reflect the specific characteristics of the services concerned and the needs and interests of all parties, in particular minors. After consulting the European Board for Digital Services and the European Artificial Intelligence Board, within the scope of their respective competences, the Commission should assess, monitor and evaluate whether such codes are adequate to contribute to compliance with this Regulation.
(47) In the interest of clarity, simplicity and effectiveness, and to ensure the effective application and enforcement of this Regulation, providers of online social networking services, video-sharing platform services, online games, AI companions and, general conversational chatbots, which do not have an establishment in the Union should designate a legal representative in a Member State where they offer their services or systems. For simplification purposes, where such providers have already appointed a legal representative under Regulation (EU) 2022/2065 or Regulation (EU) 2024/1689, they should be able to fulfil that obligation by extending the mandate of that representative to cover all matters relating to the receipt of, compliance with and enforcement of decisions issued under this Regulation.
(48) Given the evolving nature of cross-cutting risks that minors may be exposed to within the online world, which is driven by constant innovation, the power to adopt acts in accordance with Article 290 TFUE should be delegated to the Commissions in order to amend the prohibitions on practices intended, or which can reasonably be foreseen, to encourage compulsive or excessive use of the service by minors, the measures ensuring that recommender systems are designed in way that ensures a high level of privacy, safety and security of minors, the default settings ensuring minors’ accounts are set to a high level of privacy, safety and security, the measures ensuring a high level of privacy, safety and security of minors as regards contacts between minors and other recipients of the service, the measures limiting the visibility of any information shared by minors and their interactions with other recipients of the service, the measures ensuring a high level of protection of health, safety, fundamental rights and well-being of minors that may access AI companions and general conversational chatbot systems, the measures ensuring a high level of privacy, safety and security of minors on online games, and the measures ensuring agency for minors. This aims at ensuring that the measures on safety by design remain effective and keep pace with practices Such amendments should be limited to what is necessary to address minors’ privacy, safety and security.
(49) In order to verify the parental responsibility for the purpose of the creation of an account by the guardian for the benefit of a minor, providers should be able to use signals deriving from the publicly accessible databases at the Member States’ level, such as those related to education or public birth registries, that the respective adult is a guardian of the minor concerned. Furthermore, in certain cases providers may already possess a signal that an adult is a guardian of a minor, such as in the case of past engagements with the service by the concerned minor and respective adult. In addition, adults should be able to self-declare that they exercise parental responsibility. Where such self-declaration is made, providers should make reasonable efforts to verify that the adult is the guardian of the minor concerned. Such verification should be carried out in a manner that respects data protection principles, particularly data minimization through the use of so-called ‘zero knowledge proof’, and should not lead to additional processing of personal data enabling the determination of the identity or tracking of the adult or minor concerned. This is without prejudice to the measures that the provider should be able to take to comply with its obligation under Article 18 of Regulation (EU) 2022/2065. The power to adopt acts in accordance with Article 290 TFUE should be delegated to the Commission in order to amend this Regulation by specifying the proof and signals that might indicate the parental responsibility. The Commission should be able to further explore technical and operational requirements for the possibility to include EU age verification as a tool for verification of parental responsibility.
(50) The assessment of the user’s age is necessary for the effective implementation of the obligations laid down in this Regulation concerning registration with online social networking services, video-sharing platforms that are subject to a minimum age, access to age-inappropriate software applications and ensuring a high level of privacy, safety and security for minors through safety by design measures. The methods used should be accurate (such accuracy should be regularly assessed against appropriate, clear and publicly available metrics, under real-life circumstances and allow for correct determination of a user meeting the age threshold), reliable (for a method to be reliable, it should come from a reliable source, be available continuously at any time, and work in different real-world circumstances), robust (it should not be easy to circumvent), and should not be intrusive (not requiring recipients of the service to disclose their identity, precise age or other personal data where establishing that a relevant age threshold has been reached is sufficient) nor discriminatory (the chosen method should be appropriate and available for all users regardless of disability, language, ethnic, gender, religious and minority backgrounds). Where age assurance solutions do not meet these requirements, they should not be deemed compliant with this Regulation. Mere self-declaration by recipients of the service is not a sufficient age assurance solution for the purpose of compliance with this Regulation, and should not, on its own, be considered an appropriate nor effective measure when the protection of minors requires a reliable determination of age.
(51) The requirements of this Regulation on age assurance should be without prejudice to the application of Regulation (EU) 2016/679, notably the principles of purpose limitation and data minimisation as provided for in Article 5(1) points
b) and (c), thereof, as well as the requirements of data protection by design and by default. In particular, the requirements in this Regulation should not lead providers of services in scope to maintain, acquire or process more personal data than strictly technically necessary to assess if the recipient of the service is a minor. In addition, providers of services in scope should not further process this information or combine it with additional data for any other purpose. Data protection obligations should be applicable both to providers of services in scope and any third party involved in age assurance, such as providers of age assurance solutions. To ensure the highest level of privacy and data protection, age assurance solutions used should be based on state-of-the-art technology and be zero knowledge proof.
(52) To avoid unnecessary friction for users and to limit the instances requiring age assessment, providers of software application stores and the providers of the services and systems subject to the obligations laid down in Chapter III should be able to store in relation to an account an age signal confirming that a user has already met a given age threshold. For providers of software application this means that no assurance has to be conducted for users that have already proven to have met the age threshold when trying to access or purchase software applications subject to the same or a lower threshold. The personal data processed in such age signals should be limited to what is strictly necessary for that purpose and should not be used for any other purpose.
(53) Age assurance is an umbrella term for different age assurance methods, including both age verification and age estimation. In order to ensure that recipients of the service have reached the minimum age, or where the service concerns a child-friendly service, providers of online social networking services or video-sharing platform services in scope of the access delay should put in place appropriate age verification solutions at the moment of account creation. To facilitate compliance and promote a trusted, interoperable and privacy-preserving approach to age verification across the Union, providers should exclusively use EU age verification solutions that rely on EU proof of age attestation that certified as conforming with the requirements of the EU Age Verification Scheme EU Age Verification Scheme, which is established in Commission Recommendation (EU) 2026/1035 and that are listed in the EU list of EU Verification Solutions and the EU list of providers of EU proof of age attestations. The EU Age Verification Solution relied upon by the providers should be provided by an independent third party. The standards and criteria necessary for highly effective age verification are set out on the EU Age Verification Scheme, and any third-party certified as conforming to this scheme should be considered as providing valid proofs of age. To ensure the highest level of privacy, security, accuracy, reliability and non-intrusiveness, providers of proof of age attestations and age verification solutions no other age verification solutions shall be deemed compliant with the obligations in the Regulation to assess the age than the EU Age Verification Solutions and EU proof of age attestations. These EU Age Verification Solutions and EU Proof of age attestations should meet the requirements of the EU age verification scheme, such as the use of Zero Knowledge Proof to prevent identity tracking and online linkability. Once it is established that the providers of the proof of age attestations and age verification solution meet those requirements, and notified as such by the Member States, they should be listed in the EU list of proof of age attestations and the EU list of EU age verification solutions.
(54) For the purpose of compliance with the safety-by-design requirements laid down in Chapter III, providers should also be allowed to use alternative age assurance solutions instead of age verification, where those solutions provide a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy, and non-discrimination.
(55) In cases when recipients of services and of systems referred to in paragraphs 1 and 4 consider that the outcome of the age assurance is incorrect, they should have access to an effective internal complaint-handling mechanism. That mechanism should enable complaints to be lodged by electronic means and free of charge, and should be easily accessible and user-friendly. In order to ensure effective redress, providers should handle such complaints diligently, impartially and without undue delay. Where a provider of an operating system has obtained, in compliance with this Regulation, an age signal of a user, that provider should, with the user’s consent, enable the sharing of that age signal with providers in scope where this is necessary for compliance with this Regulation This should not lead to the processing of any additional data other than strictly necessary for the compliance with this Regulation. This obligation on providers of operating systems, should be without prejudice to the obligations for the providers to assess and verify the age to ascertain that the age signal has been obtained in accordance with the requirements set in this Regulation.
(56) For the purpose of ensuring uniform conditions for the application of the EU age verification scheme across the Union, implementing powers should be conferred on the Commission to lay down the specifications necessary as a basis for the functioning of the EU Age Verification Scheme, including the procedures for demonstrating and assessing conformity of the EU Age Verification solutions and the EU proof of age attestations by public authorities.
(57) In order to ensure uniform conditions for the application of alternative age assurance solutions, the power to adopt acts in accordance with Article 290 TFUE should be delegated to the Commission in order to supplement this Regulation by specifying the requirements and specifications necessary to ensure that an age assurance solution achieves a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy, and non-discrimination and specifying the requirements necessary to ensure the secure, privacy-preserving and interoperable sharing of age signals.
(58) Effective exercise of the possibility of the creation of a parental account for the benefit of a minor and for the effective use of tools for guardians under this Regulation requires adults with the parental responsibility to have access to the necessary means to prove such parental responsibility. Member States should therefore be required to establish at least one privacy-preserving electronic means by which a guardian can obtain and present an attestation of parental responsibility in respect of a minor. When doing so, Member States should ensure that such means are based on authentic sources established under national law, are free of charge for the guardian, and do not entail making information on parental responsibility accessible to providers or to the public beyond confirmation that parental responsibility exists. Such privacy-preserving electronic means should be effectively accessible to all guardians and minors residing in their territory, including persons with disabilities, persons with limited digital access or skills, and persons in vulnerable situations such as refugee and displaced families.
(59) No minor should be deprived of the protection under this Regulation, and no guardian of the means to exercise it, on account of the family’s administrative, social or residence situation. Member States should therefore ensure that attestations of parental responsibility can also be obtained by families whose circumstances are not reflected in ordinary civil status records, including refugee and displaced families and legally appointed guardians of unaccompanied minors, on the basis of decisions or attestations issued by the competent authorities.
(60) Effective age verification across the Union requires recipients of the service to have access to suitable means of obtaining proof of age attestations. Without the availability of proof of age attestations, recipients of the service are prevented from accessing services solely because they lack access to a means to verify their age. Member States should therefore ensure the availability in their territory of different means of obtaining proof of age attestations, such as through biometric identity cards and passports, digital identity schemes, third party applications or in-person age verification. Member States should ensure that these means of obtaining proof of age attestation will enable the recipients to proof that they meet the age thresholds set in this Regulation a. This should include proof of age attestations for younger children Furthermore, Member States should ensure that an EU age verification solution is available free of charge. Member States should designate public authorities for the purposes of certifying EU age verification solutions and EU proof of age attestations. To that end, Member States should communicate to the Commission the names and addresses of the public authorities designated in their territory, together with any subsequent changes, and the Commission should make that information publicly available. Member States should also notify the Commission without undue delay of EU age verification solutions and EU proof of age attestations certified as conforming with the requirements of the EU Age Verification Scheme, together with the corresponding certificate of conformity, as well as of any subsequent suspension or withdrawal of such a certificate. In order to guarantee the effective and uniform application of this Regulation across the Union, an EU age verification solution or EU proof of age attestation that has been certified that has been included in the lists referred to in Article 30(1) should be recognised by all Member States. Member States should therefore not restrict or hinder, the use within their territory of an EU age verification solution that has already been included in that list by nomination of another Member State.
(61) The age requirements established by this Regulation should apply effectively to both new and existing accounts. Providers of services and systems subject to the minimum age should therefore establish, within an appropriate time period, whether recipients of services or users of systems holding existing accounts have reached the applicable minimum age. Providers should not be required to carry out a new age verification where they can establish with a high degree of confidence that the applicable minimum age has already been reached, including, where appropriate, on the basis of the date on which the existing account was created. The same principle should apply where providers are required to assess the age to distinguish adults from minors for the purposes of determining the parental responsibility and for providers of software applications stores to prevent minors from accessing or purchasing age inappropriate or by applicable Union law or national law adopted in compliance with Union age restricted applications. This approach is intended to avoid requiring all recipients of the service to undergo age verification or age assurance where there is already a high degree of confidence that a user is an adult, for example on the basis of reliable information such as through previously legitimately acquired credit card details. High confidence should be based on expected performance in practice on the full user base. In order to facilitate effective oversight of the implementation of these requirements by providers of very large online platforms, those providers should set out in advance how they intend to comply with these requirements concerning existing accounts and where applicable, how they intend to rely on the relevant exceptions.
(62) In order to ensure that existing accounts are brought into compliance with the minimum age obligations, providers of very large online platforms should before the expiry of the six month time period, submit to the competent authority a detailed implementation plan that corroborates the required high degree of confidence. To this end, the plan should set out a schematic description of the complete process pipeline used to determine the age of existing users, together with a clear account of each technical tool or measure and the underlying decision rules. Where relevant, it should be supported by robust evidence of performance under real-life circumstances derived from a statistically representative sample of the full user base – the representativeness of the sample with respect to the relevant age signals should be demonstrated – and should present accuracy, precision and recall for underage recipients as well as a full confusion matrix with granular age buckets, together with a description of how the sample and the age labels were obtained. Where the year of account creation is relied upon as a derogation, the plan should additionally provide empirical evidence and the statistical confidence that this single signal is sufficient to infer that the user has reached the applicable minimum age. The plan should also outline how the provider will monitor that the expected performance has been achieved, for example through a post-implementation audit. Finally, the plan should demonstrate that the proposed measures respect the general age-assurance principles of this Regulation, including accuracy, reliability, security, robustness, non-intrusiveness, privacy and non-discrimination.
(63) Recognising that effective protection of minors requires not only regulatory measures but also awareness, education and empowerment, Member States should establish national strategies building on the Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee of the Regions: A digital Decade for children and your: the new European strategy for a better internet for kids (BIK+) of 11 May 2022 and its network of Safer Internet Centres with awareness activities, helplines supporting children, guardians and educators and hotlines to report suspected illegal content. Notably, Member States should promote the development of minors’ digital literacy skills so that, by the time they reach the minimum age, they are able to understand the risks of the online environment covered by this Regulation, to use digital services and systems safely and critically, and to make informed use of the protections, settings and tools that providers are required to make available. Minors, and their guardians, should have easy, free and confidential access at national level to channels through which minors can seek assistance in relation to the harms addressed by this Regulation, including unwanted contact and cyberbullying in line with the Communication from the Commission to the European Parliament, the Council, the European Economic and social Committee and the Committee of the Regions: Action plan against cyberbullying “Safer online, stronger together” of 10 February 2026. Those channels should complement the reporting and support tools provided pursuant to this Regulation, be capable of providing rapid assistance, and direct minors to further sources of support available at national level. It should be possible to support these activities, including those carried out by the Safer Internet Centres, by Union funding made available under the relevant Union programmes and instruments established under the multiannual financial framework, such as the National and Regional Partnership Plans. In order to support effective implementation, Member States should communicate the measures taken to the Commission, and the Commission should facilitate the exchange of best practices between Member States.
(64) This Regulation should specify certain provisions of Regulation (EU) 2022/2065. In order to ensure effective supervision and enforcement of this Regulation, Chapter IV of Regulation (EU) 2022/2065 should apply to the extent that the relevant provisions regulate providers of intermediary services in scope of that Regulation. The Commission should have exclusive powers to supervise and enforce obligations laid down in this Regulation that apply to providers of very large online platforms within the meaning of Article 33 of Regulation (EU) 2022/2065.
(65) Similarly, to avoid overlaps and ensure consistency with the existing horizontal framework applicable to AI systems under Regulation (EU) 2024/1689, the enforcement of the specific safety requirements provided for in this Regulation for AI companions and general conversational chatbots should be based on the supervisory and enforcement framework and procedures set out in Regulation (EU) 2024/1689.
(66) Providers of online games that are video gaming platforms are subject to the supervision and enforcement structure pursuant to Regulation (EU) 2022/2065. In order to ensure coherence with enforcement under this Regulation, the competent authority responsible for the supervision of providers of online games that are video games should be a competent of the Member State of main establishment of the provider.
(67) In order to ensure legal certainty and consistent application throughout the Union, and to avoid fragmentation of the internal market resulting from divergent national interpretations, Member State authorities should not adopt decisions that run counter to a decision taken by the Commission pursuant to this Regulation. The Commission, Digital Services Coordinators and competent authorities, where applicable, should work in close cooperation and coordinate their enforcement actions to ensure coherent, effective and complementary enforcement of this Regulation on the one hand, and Regulations (EU) 2022/2065 and 2024/1689 on the other, including by drawing on the cooperation and consistency mechanisms established in Chapter IV of Regulation (EU) 2022/2065.
(68) The Commission should aim to adopt a final decision within 90 days from the opening proceedings for suspected infringements of this Regulation. It should also communicate its preliminary findings to the provider concerned within 30 days from opening proceedings.
(69) The Commission should be in possession of all the necessary resources, in terms of staffing, expertise, and financial means, for the performance of its tasks under this Regulation. In order to ensure the availability of the resources necessary for the adequate supervision at Union level under this Regulation the Commission should charge an annual supervisory fee, the level of which should be established on an annual basis, on providers of online social networking services, video-sharing platform services, of software application stores and of AI companions and of general conversational chatbots, which it enjoys the competence to supervise with regard to compliance with Chapters II to V of this Regulation and that are designated as very large online platforms pursuant to Article 33 of Regulation (EU) 2022/2065. The annual supervisory fee required for the enforcement of this Regulation vis-à-vis those providers should be integrated in the supervisory fee charged to such providers of very large online platforms pursuant to Article 43 of Regulation (EU) 2022/2065. Similarly to that supervisory fee, the external assigned revenues resulting from the annual supervisory fee under this Regulation should cover additional human resources in the Commission, including officials, contract agents and national experts. Finally, the cap on the supervisory fee introduced in this Regulation should be taken together with the cap laid down in Regulation (EU) 2022/2065 and should ensure that overall resources of the Commission are sufficient to carry out its tasks under this Regulation and Regulation (EU) 2022/2065.
(70) The overall amount of the annual supervisory fee under this Regulation should include costs related to the exercise of the Commission’s specific powers and tasks of supervision, monitoring, investigation, and enforcement in respect of the providers of the very large online platforms and search engines covered by this Regulation. In particular, it should include the costs related to the set-up, maintenance and operation of the EU Age Verification Scheme, including funding related to activities concerning the roll out the EU Age verification solution across the EU and the development of expertise and capabilities pursuant to Article 36. However, the individual annual supervisory fee should not exceed an overall ceiling for each provider of very large online platforms taking into account the economic capacity of the provider of the designated service or services.
(71) The Commission should apply the rules and principles laid down in Article 43 of Regulation (EU) 2022/2065 when charging the annual supervisory fee under this Regulation.
(72) In view of the importance of protecting children, the Commission, in cooperation with the Digital Services Coordinators and the Board, should develop the Union expertise and capabilities as regards the supervision of services in scope of this Regulation.
(73) Given the importance of the impact of the services and systems in scope of this Regulation on the protection of minors, the failure of the providers to ensure a high level of privacy, safety and security and comply with the specific obligations applicable to them may rapidly come to seriously affect a substantial number of minors using their services or systems across different Member States and may cause substantial harms, while such failures may also be particularly complex to identify and address timely. The Commission, in cooperation with the competent authorities, should develop the Union expertise and capabilities, including establishing knowledge sharing networks, to respond quickly to such incidents affecting the protection of minors. Such incidents should be understood as fast-evolving situations taking place within or outside the EU, with an online dimension and presumed connection to the scope of this Regulation, that seriously and negatively affect the privacy, safety, security or health and well-being of minors the service in the Union, and that requires an immediate response, such as dangerous or harmful challenges circulating among minors and posing them at immediate risk. The Commission should therefore be able to coordinate and rely on the expertise and resources of competent authorities, for example by analysing, on a permanent or temporary basis, specific trends or issues emerging regarding those fast-evolving situations which impact minors’ health, well-being, privacy, safety, and security. Member States should cooperate with the Commission in developing such capabilities, including through secondment of personnel where appropriate, and contributing to the creation of a common Union supervisory capacity, as well as an administrative arrangement setting out procedures to facilitate a rapid response in the event of an incident affecting the protection of minors. Member States should establish minimum preparedness levels for national authorities to ensure regular communications channels between relevant national authorities and third parties and map and where relevant incident reaction protocols at national level.
(74) This Regulation respects the fundamental rights, including children’s rights, recognised by the Charter and the fundamental rights constituting general principles of Union law. Accordingly, this Regulation should be interpreted and applied in accordance with those fundamental rights, including the respect for private and family life enshrined in Article 7 of the Charter, to the protection of personal data enshrined in Article 8 of the Charter, to freedom of expression and information, including the freedom and pluralism of the media, enshrined in Article 11 of the Charter, to non-discrimination enshrined in Article 21 of the Charter, to respect for the rights of the child enshrined in Article 24 of the Charter. When exercising the powers set out in this Regulation, all public authorities involved should achieve, in situations where the relevant fundamental rights conflict, a fair balance between the rights concerned, in accordance with the principle of proportionality.
(75) Since the objectives of this Regulation, namely to contribute to the proper functioning of the internal market and to ensure a high level of privacy, safety, and security of children cannot be sufficiently achieved by the Member States because they cannot achieve the necessary harmonisation and cooperation by acting alone, but can rather, by reason of territorial and personal scope, be better achieved at the Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve those objectives.
(76) The European Data Protection Supervisor was consulted in accordance with Article 42(2) of Regulation (EU) 2018/1725 of the European Parliament and of the Council, and delivered its opinion on [DATE]. HAVE ADOPTED THIS REGULATION:
CHAPTER I – GENERAL PROVISIONS
This Regulation contributes to the proper functioning of the internal market and ensures a high level of protection for minors online in the Union by setting out harmonised rules for a safe and empowering online environment for minors, including the principle of consumer protection. It specifies and complements Regulation (EU) 2022/2065, and complements Regulation (EU) 2024/1689. In particular, this Regulation establishes:
a) a harmonised minimum age for creating an account with online social networking services and video-sharing platform services;
b) harmonised safety requirements for online social networking services, video-sharing platform services, video gaming platforms, and software application stores and harmonised safety requirements to protect minors online for video games, AI companions and general conversational chatbots;
c) harmonised rules regarding age assurance online.
1. This Regulation applies to providers of the following services or systems accessible to minors:
a) online social networking services;
b) video-sharing platform services;
c) software application stores
d) online games;
e) operating systems;
f) AI companions;
g) general conversational chatbots.
2. For the services referred to in paragraph 1 points
a) to (e), this Regulation applies to providers of services irrespective of where they have their place of establishment where they offer those services to recipients of the service that have their place of establishment or are located in the Union.
3. For the AI systems referred to in paragraph 1 points
f) and (g), this Regulation applies to providers placing on the market or putting into service such AI systems in the Union, irrespective of where those providers are established or located.
4. This Regulation does not apply to the providers of any of the following:
a) not-for-profit online encyclopaedias;
b) not-for-profit educational and scientific repositories;
c) services and systems that are designed for primarily educational purposes, and operated by educational establishments or organisations, or on their behalf;
d) open-source software-developing and-sharing platforms, unless the platform itself constitutes an AI system in scope of this Regulation or Regulation (EU) 2024/1689;
e) services and systems specifically developed and operated for the sole purpose of scientific research and development;
f) services and systems designed, developed and operated by public authorities and for exclusive use of those public authorities or on their behalf.
5. Where justified in view of the potential risks to the privacy, safety and security of minors posed by a service or a system or where a service or a system poses such a risk that is equivalent to, or lesser than, the risks posed by the services or systems already referred to in paragraph 4, the Commission is empowered to adopt delegated acts in accordance with Article 40 to amend paragraph 4 of this Article by adding other types of services or systems to the list of exempted services or systems or removing services or systems from that list.
6. Providers of online social networking services, video-sharing platform services, and video gaming platforms subject to Article 28(1) of Regulation (EU) 2022/2065 that comply with the obligations laid down in this Regulation shall be deemed to comply with that Article for matters covered by this Regulation, including as regards AI systems that are deployed as a functionality of online platforms in scope of Article 28(1) of Regulation (EU) 2022/2065 in the provision of that service.
7. This Regulation is without prejudice to the rules laid down by other Union legal acts regulating other aspects of the provision of intermediary services and Union legislation applicable to AI systems in the internal market, including the following:
a) Directive 2010/13/EU;
b) Union law on consumer protection and product safety, including, Directives 2005/29/EC, 2011/83/EU, (EU) 2019/770, Council Directive 93/13/EEC, and Regulations (EU) 2019/1020, (EU) 2023/988 and (EU) 2024/1689;
c) Union law on the protection of personal data, in particular Regulation (EU) 2016/679 and Directive 2002/58/EC;
d) Directive (EU) 2024/1385.
1. For the purposes of this Regulation, the definitions of ‘online platform’, ‘recipient of the service’, ‘online interface’, ‘recommender system’ set out in Article 3 of Regulation (EU) 2022/2065 shall apply.
2. For the purposes of this Regulation, the definitions of ‘online social networking service’, ‘video-sharing platform service’, and ‘software application store’ set out in Article 2 of Regulation (EU) 2022/1925 shall apply. Those services shall be considered an ‘online platform’ within the meaning of Article 3, point (i), of Regulation (EU) 2022/2065 for the purpose of this Regulation.
3. For the purposes of this Regulation, the definitions of ‘AI system’ and ‘general-purpose AI system’ offset out in Regulation (EU) 2024/1689 shall apply; the definition of ‘provider’ as defined in Article 3 point
(3) of that Regulation shall apply with regard to AI systems regulated by this Regulation.
4. For the purposes of this Regulation, the definition of ‘operating system’ set out in Article 2, point (1), of Regulation (EU) 2022/1925 shall apply.
5. For the purposes of this Regulation, the following additional definitions shall apply:
a) ‘minor’ or ‘child’ means any natural person under the age of 18;
b) ‘guardian’ means any person holding parental responsibility over a minor pursuant to applicable national law;
c) ‘AI companion’ means an AI system, including a general-purpose AI system, that provides sustained, personalised interaction or companionship which simulates or facilitates a social, emotional or interpersonal relationship with a user;
d) ‘general conversational chatbot’ means a general-purpose AI system with general conversational functionalities for direct interaction with users that is capable of providing assistance across multiple domains and tasks; this definition excludes AI systems whose conversational functionality is limited to a specialised service, task or pre-defined set of functions, including specialised customer-service, business operation, technical-support, transactional, educational, information-retrieval, industrial or manufacturing AI applications;
e) ‘online games’ means a video game or video gaming platform;
f) ‘video game’ means an information society service as defined in Article 1(1), point (b), of Directive (EU) 2015/1535, that allows the recipients of the service to engage, by means of application accessed locally or remotely, including through the use of a durable medium and that involves interaction with a user interface or input device to generate visual feedback from a display device in a simulated environment for play or entertainment purposes;
g) ‘video gaming platform’ means an “online platform” as defined in Article 3, point (i) of Regulation (EU) 2022/2065, that involves interaction with a user interface or input device to generate visual feedback from a display device in a simulated environment [for play or entertainment purposes];
h) ‘age verification’ means a process or system for establishing, with a high degree of certainty, whether the recipient or user of a system of the service has attained a specific age or age threshold, on the basis of information derived from identification documents or other reliable, verified sources of identification;
i) ‘age assurance’ means the set of methods, that can be used to determine, estimate or verify the age of a natural person, encompassing age estimation and age verification and excluding self-declaration by recipients of the service;
j) ‘age signal’ means any data, attribute, token, credential, or other information provided, transmitted, or generated for the purpose of establishing, verifying, or demonstrating a specific age, age threshold, or age range of an individual;
k) ‘EU age verification solution’ means an age verification solution that meets the requirements of the EU Age Verification Scheme and is certified by a public authority and included in the EU list of EU age verification solutions after notification by a Member State;
l) ‘EU list of providers of EU proof of age attestations’ means the list established and published by the Commission of providers issuing EU proof of age attestations
m) ‘EU list of EU age verification solutions’ means the list established and published by the Commission of EU age verification solutions certified as conforming with the EU Age Verification Scheme and notified by Member States;
n) ‘EU Age Verification Scheme’ means a scheme for the attestation of attributes as defined in Article 2(4) of Commission implementing Regulation (EU) 2025/1569 with the rules applicable to providers of EU age verification solutions and of EU proof of age attestation, their approval and inclusion in the EU list of providers of EU proof of age attestations and the certification of EU age verification solutions for their inclusion in the EU list of EU age verification solutions;
o) ‘proof of age attestation’ means an electronic attestation of attributes, as defined in Article 3(44) of Regulation (EU) No 910/2014, that allows the authentication of the fact that its holder meets a given age, age threshold, or age range;
p) ‘tools for guardians’ means software, features, functionalities, or applications designed to help guardians accompany minors’ online activity to ensure their privacy, safety and well-being.
Article 4 – Anti-circumvention
Providers of online social networking services, of video-sharing platform services, of online games, of software application stores, of operating systems, of AI companions, and of general conversational chatbots:
a) shall not engage in any behaviour that undermines effective compliance with their respective obligations under this Regulation, regardless of whether that behaviour is of a contractual, commercial or technical nature, or of any other nature, or consists in the use of behavioural techniques or interface design;
b) shall be prohibited from taking knowingly and intentionally any other actions whose object or effect is, directly or indirectly, to circumvent their respective obligations under this Regulation, with a view to avoiding compliance with those obligations.
Article 5 – Notification and independent audit of a compliance plan
1. Within 4 months following the notification of the decision designating them as a very large online platform pursuant to Article 33 of Regulation (EU) 2022/2065, the providers of online social networking services and video-sharing platform services that have been designated as a very large online platform pursuant to Article 33 of Regulation (EU) 2022/2065 shall notify to the Commission a compliance plan describing in a detailed manner compliance with the obligations laid down in Chapters II to V of this Regulation. For providers referred to in the first sub-paragraph already designated as a very large online platform pursuant to Article 33 of Regulation (EU) 2022/2065, such notification shall occur within 30 days from the date of the entry into application of this Regulation. Article 34(3) of Regulation (EU) 2022/2065 shall apply mutatis mutandis to the supporting documents of those notifications.
2. For the purpose of enabling the Commission to assess the compliance of providers referred to in paragraph 1 with the obligations laid down in Chapters II to V, those providers shall, at their own expense, commission an audit of the compliance plan notified pursuant to paragraph 1 by one or more independent auditors. The independent auditors shall have, or shall retain experts with proven expertise in the following areas relevant for the protection of minors:
a) protection and rights of the child;
b) paediatric medicine and child psychiatry;
c) developmental science;
d) age assurance;
e) the design of online interfaces and recommender systems;
f) data protection and security.
3. Article 37(2) and
(3) of Regulation (EU) 2022/2065 shall apply mutatis mutandis to the audits carried out pursuant to this Article and to the independent auditors and any experts retained by them. The costs of the audit shall be borne by the provider concerned. These costs shall not exceed market rates for comparable assessments by the auditors. The providers referred to in paragraph 1 shall cooperate with the independent auditors and shall grant them access to all information, data, documents and personnel relevant for the performance of the audit. Providers shall ensure that any employee or contractor that has communicated with the independent auditor are protected against any adverse action by the provider.
4. The independent auditors commissioned by the provider pursuant to paragraph 2 shall:
a) assess the compliance plans submitted by the providers pursuant to paragraph 1 in view of the obligations laid down in Chapters II to V;
b) transmit a draft report to the provider, which may submit comments within 15 days of receipt;
c) issue a final report, taking into account any comments received pursuant to point (b), simultaneously to the Commission and to the provider, within two months of receipt of the compliance plan, identifying any shortcomings in the compliance measures described therein.
5. The provider concerned shall publish, without undue delay after its receipt, a summary of the final report referred to in paragraph 4, point (c), which shall not contain confidential information.
6. Where the Commission concludes by means of a decision on the basis of the final report referred to in paragraph 4, point (c) that the compliance plan contains shortcomings, the provider concerned shall submit to the Commission and to the independent auditor within 30 days of the receipt of the Commission decision report a corrective action plan identifying one or more corrective measures for each identified shortcoming. The provider shall also identify a reasonable period, which shall not be longer than 60 days, for the implementation of each corrective measure in the corrective action plan. The independent auditor shall verify the implementation of the corrective measures and shall report thereon to the Commission and to the provider concerned.
7. In assessing the compliance of the providers referred to in paragraph 1 with the obligations laid down in Chapters II to V of this Regulation, the Commission shall be entitled to consider the compliance plan referred to in paragraph 1, the final report referred to in paragraph 4, point (c) and any corrective measures communicated pursuant to paragraph 6 or any other information that the Commission may consider relevant.
8. Neither the final report referred to in paragraph 4, point (c), nor any action or absence thereof by the Commission in relation to that final report or to the compliance plan shall constitute a finding of compliance with the obligations laid down in Chapters II to V of this Regulation, or shall limit the powers of the Commission under this Regulation or under Regulation (EU) 2022/2065.
9. Providers shall, after the first notification pursuant to paragraph 1, report annually on their compliance with the obligations laid down in Chapters II to V of this Regulation as part of their annual risk assessments carried out pursuant to Article 34 of Regulation (EU) 2022/2065. Compliance with the obligations laid down in Chapters II to V of this Regulation shall be included in the independent audits carried out pursuant to Article 37 of Regulation (EU) 2022/2065.
10. This Article is without prejudice to the powers of the Commission under this Regulation and under Regulation (EU) 2022/2065, including the power to adopt interim measures.
11. The Commission may adopt implementing acts laying down templates and methodologies for the audits carried out pursuant to this Article. Those implementing acts shall be adopted in accordance with the procedure referred to in Article 39.
CHAPTER II – DELAYED CREATION AND USE OF ACCOUNTS FOR MINORS ON ONLINE SOCIAL NETWORKING SERVICES AND VIDEO-SHARING PLATFORM SERVICES
SECTION I – Delayed access for minors
Article 6 – Delayed creation and use of accounts
1. Providers of online social networking services and of video-sharing platform services shall not allow a natural person below the age of 15 years to create an account with that service or to access that service by means of an account, created for, or attributed to, that person, where the service poses a risk to the privacy, safety or security of a minor below that age. A service shall be considered to pose a risk to the privacy, safety or security of minors below 15 years of age where it meets any of the following conditions:
d) enables recipients who access the service through an account to transmit content in real-time to an indeterminate number of other recipients of the service, including through live streaming of audio-visual content;
e) enables recipients who access the service through an account to contact, communicate and otherwise interact with other recipients of the service not part of the recipient’s pre-existing connections or subscriptions;
f) uses a recommender system which is based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679;
g) uses a recommender system suggesting or prioritising to a recipient who accesses the service through an account contact suggestions or information that has not been provided by one of the recipient’s pre-existing connections or subscriptions;
h) deploys or presents functionalities, interface designs or characteristics which are intended, or can reasonably be foreseen, to enable uninterrupted content consumption, that incentivise interactions with the service or with content or other recipients of the service, or that transmit automated notifications designed to prompt the user to initiate or resume use of the service.
2. By way of derogation from paragraph 1, providers of online social networking services and video-sharing platform services may allow guardians to set up accounts for minors above the age of 13 years and below the age of 15 years with limited features so as to allow them to access the service by means of such a limited account. Such accounts shall meet at least the following conditions
a) the tools for guardians provided for in Article 20 shall always be activated;
b) guardians are enabled to set a maximum limit on the amount of time in a day the service or system may be accessed through that account, which shall not exceed one hour per day;
c) guardians are enabled to pre-approve potential new contacts and to set a maximum limit on the number of other recipients or users in the account’s contacts.
3. When creating an account for a minor pursuant to paragraph 2 of this Article, the provider of online social networking services and of video-sharing platform services shall take measures to establish whether the person creating the account is the holder of parental responsibility over that minor in accordance with Article 26 and verify that the recipient of the service has reached the age of 13 years in accordance with Article 28(1).
4. Providers of services falling within scope of paragraph 1 of this Article shall by 6 months after the entry into application of this Regulation establish whether the holders of existing accounts used to access their service are below the age of 15 years. Where holders of existing accounts are established to be below 15 years, providers of services concerned shall disable the accounts of the recipients or users of the service that have been established to be below that age or in relation to whom the age cannot be established.
5. Where providers of services falling within scope of paragraph 1 process personal data pursuant to Article 6(1), point (a) of Regulation (EU) 2016/679, the provisions set out in this Article should apply in parallel to the age limits provided in Article 8 of that Regulation.
6. The Commission may adopt delegated acts, in accordance with Article 40, in order to amend this Regulation by modifying and complementing the conditions in paragraph 1 of this Article, to include new features and functionalities or changes to existing features or functionalities that pose a risk to minor’s privacy, safety, and security online equivalent to the risks posed by the conditions set out in paragraph 1 of this Article.
SECTION II – Guardian-controlled access for minors below age of 13 years
Article 7 – Guardian-controlled access for minors below the age of 13
1. Providers of video-sharing platform services whose service is specifically designed for minors below the age of 13 years may exceptionally enable a guardian to allow a minor below the age of 13 years limited access to the service through the guardian’s own account, where all of the following conditions are met:
a) such guardian-controlled access shall take place exclusively through the guardian’s own account, and no account shall be created for, or attributed to, the minor;
b) such access shall be enabled and controlled by means of the tools for guardians referred to in Article 20 or other parental control settings in the guardian’s account or on the guardian’s device;
c) the provider expressly permits, in its terms and conditions, access by minors below the age of 13 years, clearly specifying therein the age range of minors for whom access is permitted subject to guardians’ approval;
d) the provider has carried out and published, in at least one official language of a Member State and in a publicly available section of its online interface, an assessment of the impact of the service, or of the relevant parts thereof, on minors within the specified age range, assessing the risks and demonstrating, if applicable, how any such risks have been effectively mitigated taking into account the relevant age groups. Compliance with the requirements set out in Chapter III shall not automatically entail effective mitigation of such risks;
e) the provider has set out, in a clear and transparent manner in a publicly available section of its online interface, which content or behaviour is considered as not age-appropriate or harmful to the privacy, safety and security of minors within the specified age range on the service;
f) access to the content identified pursuant to point (e) shall not be granted to minors below the age of 13 years;
g) the available features and functionalities are adapted, and gradually adjusted, to the age of the minor declared pursuant to paragraph 4, point (b);
h) all personalisation features and recommender systems, and any functionality to search for content shared by other recipients of the service, are turned off and cannot be activated, unless the assessment referred to in point (d) demonstrates that their activation is in the best interests of the minor and does not in any way negatively affect the minor’s privacy, safety and security.
2. Nothing in this Article shall be construed as requiring a provider to permit access by minors below the age of 13 years, or as conferring on any minor or guardian a right of access to a service whose terms and conditions do not permit such access or where access to the service is subject to a higher minimum age under EU law or national law in compliance with EU law.
3. The account through which guardian-controlled access pursuant to paragraph 1 is provided shall be set up, registered and held exclusively by the guardian. The minor accessing the service through the guardian’s account shall not be a party to the contract with the provider. The provider shall take measures to establish that the guardian enabling access pursuant to paragraph 1 is the holder of parental responsibility in respect of the minor concerned, in accordance with Article 26.
4. The design and functioning of the guardian-controlled access provided pursuant to this Article shall not disproportionately restrict the minor’s privacy and shall support the minor’s autonomy and agency, in accordance with the minor’s evolving capacities. The guardian-controlled access provided pursuant to this Article shall meet at least the following conditions:
a) the tools for guardians provided for in Article 20 shall be activated by default;
b) the guardian shall declare the age of the minor for whom access is enabled and such access shall not be enabled for a minor below the age of 3 years;
c) the guardian shall be able to set a maximum daily duration of access by the minor, which shall not exceed one hour;
d) the guardian shall be able to supervise the content displayed or recommended to the minor, taking into account the minor’s right to privacy and taking the minor’s best interests as a primary consideration;
e) the guardian shall be able to approve, limit and remove any other recipients of the service with whom the minor may interact through the guardian’s account;
f) the guardian shall be able to suspend the minor’s access at any time.
5. Guardian-controlled access pursuant to this Article shall be discontinued when the minor reaches the age of 13 years, to be determined on the basis of the age declared pursuant to paragraph 4, point (b) of this Article. This shall be without prejudice to the creation of an account pursuant to Article 5(2) where the conditions of that Article are met.
6. The Commission may adopt delegated acts in accordance with Article 40 in order to amend this Regulation by adapting to technological and scientific developments the conditions set out in paragraphs 1 and 4, where such changes maintain a level of protection of the minor’s privacy, safety, and security online equivalent to that provided by the conditions set out in paragraphs 1 and 4 of this Article.
CHAPTER III – SAFETY BY DESIGN
SECTION I – General obligation on safety by design
Article 8 – General obligation on safety by design
1. Providers of online social networking services, of video-sharing platform services, of online games, of AI companions, of general conversational chatbots, and of software application stores, regardless of whether those services or systems are accessible with an account, and including services and systems accessible through the accounts specified in Article 5(3) and Article 6(3), shall ensure a high level of privacy, safety and security of minors. Providers of such services or systems shall design those services and systems in accordance with the requirements laid down in this Chapter by default and shall only derogate from those requirements after they have established that the recipient of the service or the user of the system is an adult, by making use of age assurance in accordance with Chapter V.
2. Compliance with the obligations set out in this Chapter shall be without prejudice to the obligation of providers of online social networking services and of video-sharing platform services to delay the creation of accounts pursuant to Article 6 and shall be without prejudice to the obligation of providers of video-sharing platform services concerning guardian-controlled access for minors, where applicable, pursuant to Article 7.
3. Where providers of online social networking services or of video-sharing platform services deploy AI companions or general conversational chatbots as a functionality in the provision of those services, only the obligations set out in Sections III, V and VI shall apply to such AI systems.
SECTION II – Obligations for online social networking services and video-sharing platform services
1. Providers of online social networking services and of video-sharing platform services shall not design, organise or operate their services in a manner that is intended, or can reasonably be foreseen, to encourage compulsive or excessive use of the online social networking services and of video-sharing platform services by minors.
2. The following features shall be deemed to encourage compulsive or excessive use of the service by minors within the meaning of paragraph 1:
a) enabling automatic play of content and uninterrupted content consumption without effective and regular interruption moments that enable deliberation by the minor on their willingness to consume more content;
b) undermining the minor’s decision to discontinue use of the service or not providing minors with the ability to take such decision, such as notifications not triggered by, or not directly related to, the minor’s interaction or activity on the service;
c) incentivising or rewarding minors to share content or to engage in real-time transmission of content to an indeterminate number of recipients of the service;
d) incentivising engagement at regular times or with greater frequency, including through penalties or loss of benefits for failing to engage regularly or within specified time intervals.
3. Providers of online social networking services and of video-sharing platform services shall put in place effective measures to ensure:
a) time-limited access for minors on their service;
b) interruption of usage by minors on their service. Such measures shall be designed in a way that protects school time and core sleep hours of minors.
Article 10 – Recommender systems
1. Providers of online social networking services and of video-sharing platform services that use recommender systems shall design the information suggested and the optimisation of their recommender systems to minors in way that ensures a high level of privacy, safety and security of minors.
2. For the purpose of complying with the obligations set out in paragraph 1 of this Article, providers of online social networking services and of video-sharing platform services that use recommender systems shall ensure that the recommender system optimisation does not exploit minor’s vulnerability or attention and that it includes evaluation metrics capturing quality, safety and mental health outcomes for minors, by taking at least the following measures:
a) ensure that the recommender systems give priority and primary weight to explicit user-stated preferences when suggesting information;
b) disable by default the recommendation of information suggested by the recommender system based on implicit engagement-based signals from minors’ behaviour online;
c) ensure that the recommender systems do not rely on the collection of any personal data of minors captured from outside the service;
d) ensure that minors are not exposed to information suggested by the recommender systems that may pose a risk to their privacy, safety and security, including if encountered repeatedly.
3. Providers of online social networking services and of video-sharing platform services that use recommender systems shall provide and prominently display tools that enable minors to:
a) modify or control the parameters of the recommender system, including by easily deleting all previous identified preferences;
b) choose at least one option of the recommender systems which is not based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679. Tools referred to in the first subparagraph shall not be designed in a manner to entice minors into choosing the option based on profiling, shall be offered during account creation and shall remain directly accessible from the specific section of the service’s online interface where the information is being prioritised, including for recipients of the service without an account.
1. Providers of online social networking services and of video-sharing platform services shall put in place measures to ensure that settings are set by default to a high level of privacy, security and safety of minors. To ensure compliance with this paragraph, such providers shall, by default, turn off at least the following settings:
a) geolocation and other tracking features;
b) access to microphone and camera;
c) recommendations of other accounts and synchronisation of contacts;
d) push notifications, which should, in any event, be designed in a way that protects minors’ core sleep hours and school time.
2. Default settings referred to in paragraph 1 may only be changed by the provider where the minor is above the age of 15 years and was clearly and unambiguously informed about such changes and has explicitly consented to such changes. Default settings referred to in paragraph 1 point (a), where enabled by minors, shall be turned off after their session on the service ends.
3. Where features or settings pose a risk to minors’ privacy, safety security or health and well-being providers of online social networking services and video-sharing platform services shall ensure that those features or settings are not available to minors. This shall at least include features increasing social comparison or misrepresenting minors’ image, in particular by disproportionately embellishing or idealising it.
Article 12 – Contact and interaction safeguards
1. Providers of online social networking services and of video-sharing platform services shall put measures in place that ensure a high level of privacy, safety and security of minors as regards contacts between minors and other recipients of the service. Those measures shall at least ensure that:
a) other recipients of the service are not able to initiate direct contact with the minor, if the minor has not pre-approved such contact.
b) minors with an account are not included in contact recommendations or similar features aiming to enable other recipients of the service, including minors, to expand their contacts;
c) minors can only be added to a group with a limited or unlimited number of recipients of the service after their explicit agreement;
d) minors can easily block any other recipient of the service without having their identity disclosed to the blocked recipients of the service.
2. Providers of online social networking services and of video-sharing platform services shall implement safeguards to prevent recipients of their service from enticing or manipulating minors into approving the direct contact referred to in paragraph 1, point (a).
3. Providers of online social networking services and of video-sharing platform services shall put in place measures to limit the visibility of any information shared by minors and their interactions with other recipients of the service. Those measures shall include at least the following:
a) by default, other recipients of the service not previously accepted by the minor shall not be able to access account information of the minor or content uploaded or shared by the minor on the service;
b) recipients of the service without an account shall not be able to access account information of minors or content uploaded or shared by minors on the service;
c) the personal contact details of minors, such as their name, phone number, e-mail address and address, shall not be disclosed to or shared with other recipients of the service;
d) minors shall be able to easily control the visibility of any content shared, interaction and related metrics on the service;
e) other recipients of the service shall not be able to download or take screenshots of contact, location or account information of minors or of any content uploaded or shared by minors on the service;
f) minors shall, by default, not be able to host real-time transmission of user-generated content, including through live-streaming of audiovisual content.
Article 13 – Safety and security of economic transactions
1. Providers of online social networking services and of video-sharing platform services shall ensure that, before an economic transaction takes place, a minor is made aware in a clear and easily comprehensible manner, and in real time, that this is an economic transaction. Purchases carried out within the service with virtual currency purchasable with funds within the meaning of Article 4, point
(25) of Directive (EU) 2015/2366 shall display the corresponding monetary value in the official currency of the Member State in which the recipient of the service is habitually resident.
2. Providers of online social networking services and of video-sharing platform services shall not design, organise or operate their services in such a way that can lead to excessive, impulsive or unwanted spending. That obligation shall include not exposing minors to variable reward systems including when purchased are carried out with virtual currencies purchasable with funds within the meaning of Article 4, point
(25) of Directive (EU) 2015/2366.
SECTION III – Obligations for AI companions and general conversational chatbots
Article 14 – Obligations for AI companions and general conversational chatbots
1. Providers of AI companions and of general conversational chatbots shall put in place proportionate and effective measures to ensure a high level of protection of the health, safety, fundamental rights and the well-being and development of minors that may access their AI system. Those measures shall include at least the following:
a) ensuring that minors are not exposed to addictive designs, by avoiding design features and system behaviours that simulate interpersonal relations that are likely to create emotional dependencies and by applying the measures set out in Article 9(1) and
(3) to such systems;
b) ensuring that minors are provided with safe settings, by applying the measures set out in Article 11 to such systems, including by ensuring that, by default, their system does not use information or analysis derived from a minor’s prior interactions in subsequent interactions, except where necessary to protect the minor’s safety, to give effect to the settings referred to in Article 11;
c) ensuring transparency on economic transactions, by applying the measures set out in Article 13 to such systems;
d) ensuring that access to services and systems referred to in paragraph 1 for minors below the age of 13 years is only enabled and controlled by means of the tools for guardians referred to in Article 20;
e) performing state-of-the art evaluations and testing of the system for risks to the health, safety and fundamental rights and the physical, mental and emotional well-being and development of minors that are likely to arise when minors interact with the system, and implementing appropriate safeguards to address those risks, prior to the system’s placement on the market or putting into service;
f) post-market monitoring to identify, assess and, where appropriate, mitigate harms and emerging risks referred to in point (d) of this paragraph, including through detecting and responding to serious incidents involving minors, unless the system is provided by a micro or small enterprise within the meaning of Recommendation 2003/361/EC.
2. Where an AI companion or a general conversational chatbot is deployed as a functionality of an online social networking services, video-sharing platform services, or an online game in the provision of any such service, providers of such services shall ensure that:
a) the AI companion or general conversational chatbot is not activated automatically and, that the functionality is not displayed prominently on the online interface of that service;
b) minors are not encouraged to use the AI companion or general conversational chatbot;
c) where enabled, minors have the option to opt out easily and at any time, of using the AI companion or general conversational chatbot.
3. Providers of AI companions and of general conversational chatbots that adhere to a code of conduct assessed as adequate by the Commission in accordance with Article 23 may rely upon that code to demonstrate compliance with the obligations set out in this Article.
SECTION IV – Obligations for providers of online games
Article 15 – Obligations for providers of online games
1. Providers of online games shall put in place measures to ensure a high level of privacy, safety and security of minors. Those measures shall include at least the following:
a) ensuring that compulsive or excessive use of the game by minors is not encouraged, by applying Article 9(1) and Article 9(2), points
b) and (d);
b) ensuring settings of minors are set to a high level of privacy, security and safety, by applying Article 11(1);
c) ensuring contacts between minors and other recipients of the game are subject to a high level of privacy, security and safety, by applying Article 12(1) and 12(3), points (c);
d) ensuring mandatory access to the tools for guardians referred to in Article 20 and ensuring that access to services referred to in paragraph 1 for minors below the age of 13 years is only enabled and controlled by means of the tools for guardians referred to in Article 20.
2. Providers of online games shall put in place safeguards to prevent the game from being used to entice minors to initiate contacts on other services which may pose a risk to their privacy, safety and security.
3. Where providers of video gaming platforms provide recipients of the service with the possibility to create and upload video games on the service itself, such video gaming platforms shall put in place the necessary software and organisational measures to allow compliance of such video games with paragraphs 1 and 2 and Article 18 and Article 20.
4. Providers of online games that adhere to a code of conduct assessed as adequate by the Commission in accordance with Article 17 may rely upon such adherence to demonstrate compliance with the obligations set out in this Article.
SECTION V – Obligations for age-appropriate access
Article 16 – Obligations for providers of software application stores
1. Providers of software application stores shall put in place an age-rating system to allow to establish the age-appropriateness of software applications disseminated through their service. Such an age-rating system shall apply to each software application offered on the software application store and shall take due consideration of the evolving capacities of a minor.
2. Providers of software application stores shall not allow minors to access or purchase software applications that are inappropriate for their respective age in accordance with the age rating system established pursuant to paragraph 1 of this Article. This obligation shall not affect the obligation of providers of services offered through software applications falling within the scope of Article 6.
3. Where the provider of a software application store becomes aware of software applications disseminated through its service that are subject to, or primarily consist of content that is subject to a higher minimum age under applicable Union law or national law in compliance with Union law than the one established in accordance with paragraph 1, the provider shall not allow minors below that higher minimum age from the Member State or States concerned to access or purchase such software applications.
4. In order to comply with paragraphs 2 and 3, providers of software applications stores shall assess the age of the recipient of the service, in accordance with Chapter V, including by means of the use of tools for guardians referred to in Article 20. Providers of software applications stores shall ensure that access to services referred to in paragraph 1 for minors below the age of 13 years is only enabled and controlled by means of the tools for guardians referred to in Article 20.
5. Providers of software application stores shall make publicly available information describing, in clear and accessible terms, the methodology, criteria and sources used for their age-rating systems.
6. Providers of software application stores shall allow the EU age verification solution using an EU proof of age attestation, certified as conforming with the EU Age Verification Scheme and included in the respective EU lists referred to in Article 30(1), to be offered in their store.
Article 17 – Codes of Conduct on age rating and online games
1. The Commission shall encourage and facilitate the drawing up of codes of conduct at Union level by [same day and month as the date of entry into application plus one year] with the involvement of providers of software application stores and online games, developers and providers of digital content, including software applications and online games, providers of age classification systems, organisations representing minors and their guardians, civil society organisations specialising in the protection of minors online as well as relevant authorities. The codes of conduct shall contribute to the harmonised establishing and application of age-rating systems including those referred to in Article 16(1), in particular by setting out common criteria and methodologies for such systems, and to the effective application of Article 15 with regard to online games.
2. The Commission shall aim to ensure that the codes of conduct address at least the following:
a) pursue the clearly defined and unambiguous objective to enable and facilitate the mutual recognition and consistent application of age ratings by providers of software application stores and online games across Member States;
b) define appropriate criteria, methodologies and sources of information for assessing the age-appropriateness of content in particular as regards violent, sexual, gambling and self-harm content as well as in-app purchases, contact risks and addictive design features;
c) establish free of charge remedies and redress mechanisms for content providers, including app developers to resolve disputes related to the age-rating of content provided by a body that is impartial and independent, including financially independent, of providers and recipients of the service;
d) provide harmonised, easily recognisable and understandable age-rating labels and textual descriptors to be displayed prominently and prior to accessing or purchasing content;
e) provide for regular, transparent and independent monitoring and evaluation of the achievement of the objectives, including by containing key performance indicators to measure the achievement of their objectives and regular updates to reflect technological developments and emerging risks to minors;
f) with regard to online games, define appropriate measures and methodologies to give effect to the obligations laid down in Article 15(1), (2),
(3) and (4), building, where appropriate, on existing pan-European age classification frameworks, including their criteria concerning interactive functionalities and monetisation practices, and providing for their regular update in light of scientific and technological developments and emerging risks to minors 3. By [same day as date of entry into force plus 42 months] the Commission shall assess whether the codes of conduct meet the aims specified in paragraph 2 and and are adequate to demonstrate compliance with the respective obligations. The Commission shall regularly monitor and evaluate the achievement of their objectives, having regard to the key performance indicators that they might contain and shall publish its assessment. Where the Commission assesses adherence to point (f) of paragraph 2, Article 15(4) shall apply.
SECTION VI – General obligations on agency of minors and empowering tools for minors and guardians
1. Providers of online social networking services, of video-sharing platform services, of online games, of AI companions, and of general conversational chatbots, shall ensure that the features, communication, information, user-control tools and mechanisms of the service and the system, warnings, and any other information referred to in Chapter III are easily accessible to all minors and presented in a way that minors can understand. Where a provider is a provider of a very large online platforms designated in accordance with Article 33 of Regulation (EU) 2022/2065, that provider shall ensure that information referred to in this paragraph is made available in the official language(s) of the Member State(s) in which the service is provided.
2. Providers referred to in paragraph 1 shall put in place the following:
a) tools that allow minors to control and provide feedback on content, prompts, information suggested and search results to which they are exposed and that have immediate and durable effects on such content, prompts, information suggested and search results;
b) mechanisms that allow minors to control the settings which determine how they interact and communicate with, transfer, create or generate content on the service or the system, including warning signals, and explanations, that allow for temporary changes and that ensure that minors can easily return to previous or default settings.
Article 19 – Child-friendly reporting and support tools for minors
1. Providers of online social networking services, of video-sharing platform services, of video gaming platforms, of AI companions, and of general conversational chatbots shall put in place mechanisms that allow minors to report content, accounts, groups, features or behaviour, as applicable, which they consider harmful to their privacy, safety, or security. Such mechanisms shall be easy to access and designed in a way that minors can understand. Where a provider is a provider of a very large online platform designated in accordance with Article 33 of Regulation (EU) 2022/2065, that provider shall ensure that those mechanisms are made available in the official language(s) of the Member State(s) in which the service is provided.
2. Where a provider referred to in paragraph 1 is an online platform subject to Article 17 of Regulation (EU) 2022/2065, any restrictions imposed following reports referred to in paragraph 1 of this Article shall be considered as a restriction of the visibility pursuant to Article 17(1), point (a) of Regulation (EU) 2022/2065.
3. Providers referred to in paragraph 1 shall take the necessary technical and organisational measures to ensure that reports submitted by minors in accordance with paragraph 1 are processed and addressed as a priority and without undue delay and that minors receive information about the procedure undertaken and the possibilities of redress.
4. Providers referred to in paragraph 1, shall:
a) ensure that minors have access to support and authoritative information sources when encountering illegal or harmful content on the service or system, including by informing minors of available resources and organisations at national and Union level;
b) ensure that support and authoritative information sources referred to in point (a) of this paragraph are presented to minors where necessary, and at least after minors have submitted a report pursuant to paragraph 1;
c) make reasonable efforts to display clear warning messages where minors are likely to publish or to be exposed to content or interactions presenting a risk to their privacy, safety or security.
Article 20 – Tools for guardians
1. Providers of online social networking services, of video-sharing platform services, of online games, of AI companions, and of general conversational chatbots shall implement effective, accessible and user-friendly tools for guardians that meet at least the following conditions:
a) they are tailored to the age of the minor, taking due account of the minor’s gradual development;
b) they are easy to use, access and activate for minors and guardians;
c) they ensure that changes can only be made with the same degree of authorisation that is required for the initial activation of the tools;
d) they are effective and cannot be easily circumvented or undermined by the design or operation of the service or the system.
e) they do not disproportionately restricting minors’ rights;
f) they respect minor’s agency and privacy.
2. Providers referred to in paragraph 1 shall ensure minors are informed when any tool for guardians referred to in paragraph 1 is being used.
3. Providers referred to in paragraph 1 shall encourage guardians to use the tools referred to in that paragraph and shall regularly remind them of their availability and objectives and of the need to update them. This shall include displaying clear warning messaging on managing the settings of minors.
4. Providers referred to in paragraph 1 shall integrate the following mechanisms into the tools for guardians referred to in that paragraph:
a) effective measures to ensure time-limited access pursuant to Article 9(3), Article 14(1), point (b) and Article 15(1), point (b);
b) mechanisms aimed at managing settings pursuant to Articles 11 and 12;
c) mechanisms aimed at enabling guardians, on behalf of minors, to report content, accounts, groups or behaviour which they consider harmful to the privacy, safety, or security of minors pursuant to Article 19(1).
5. Providers of very large online platforms designated in accordance with Article 33 of Regulation (EU) 2022/2065 shall ensure that the tools for guardians referred to in paragraph 1 are interoperable with tools for guardians provided by third parties, in accordance with the conditions set out in Article 6 of Regulation (EU) 2022/1925, where relevant.
6. Providers referred to in paragraph 1 shall ensure guardians and minors are able to report, pursuant to Article 19, where tools for guardians referred to in paragraph 1 are not operational and do not function as prescribed.
7. The Commission shall be empowered to adopt delegated acts in accordance with Article 40 to supplement this Regulation by laying down the technical and operational requirements for the tools for guardians referred to in paragraph 1 of this Article.
Article 21 – Collective complaints
1. Without prejudice to Article 86 of Regulation (EU) 2022/2065 and to Directive (EU) 2020/1828 or to any other type of rules on representation under national law, minors and guardians who are recipients of online social networking services, of video-sharing platform services, of video gaming platforms, and users of AI companions or of general conversational chatbots, shall at least have the right to mandate a body, organisation or association to exercise the rights conferred by this Regulation on the minors’ behalf, provided that the body, organisation or association meets all of the following conditions:
a) it operates on a not-for-profit basis;
b) it has been properly constituted in accordance with the law of a Member State;
c) its statutory objectives include a legitimate interest in ensuring that this Regulation is complied with.
2. In addition to the right to lodge a complaint in accordance with Article 53 of Regulation (EU) 2022/2065, minors and guardians who are recipients of online social networking services, of video-sharing platform services, of video gaming platforms, and users of AI companions and general conversational chatbots, and any body, organisation or association referred to in paragraph 1 of this Article shall have the right to lodge a complaint alleging an infringement of this Regulation against providers of the aforementioned services and systems with the competent authority determined in accordance with Article 34 of the Member State where the recipient of the service or the user of the system is located or established, or with the European AI Office for AI companions or the general conversational chatbots falling under its exclusive competence pursuant to Article 75(1) of Regulation (EU) 2024/1689.
SECTION VII – Other due diligence obligations for a safe online environment
Article 22 – Monitoring obligation for providers of very large online platforms
1. Providers of services referred to in Article 8(1) of this Regulation that have been designated as very large online platforms in accordance with Article 33 of Regulation (EU) 2022/2065 shall monitor, test and evaluate the effectiveness of the measures implemented in accordance with this Chapter.
2. The assessment referred to in paragraph 1 of this Article shall be part of the risk assessment carried out pursuant to Article 34 of Regulation (EU) 2022/2065.
1. The Commission shall encourage and facilitate the drawing up of voluntary codes of conduct at Union level to contribute to the proper application of this Regulation. The Commission shall invite providers of relevant services and systems in scope, relevant national competent authorities, civil society organisations, industry, academia, parents, educators and other relevant stakeholders to participate in the drawing-up of those codes of conduct.
2. When giving effect to paragraph 1, the Commission shall aim to ensure that the codes of conduct clearly set out their specific objectives, contain commitments to take specific measures to achieve those objectives, and take due account of the specificities of different services and systems provided, and the needs and interests of all interested parties, in particular minors, at Union level. The Commission shall also aim to ensure that participants report regularly to the Commission and their respective competent authorities under this Regulation. The reporting commitments sought by the Commission shall take into account differences in size and capacity between different providers.
3. The Commission, after consultation of the European Digital Services Board or the European Artificial Intelligence Board for aspects of codes within the remit of their competence, shall assess whether codes of conducts meet the aims specified in paragraphs 1 and 3 and are adequate to demonstrate compliance with the respective obligations set out in this Regulation. The Commission shall publish that assessment. It shall regularly monitor and evaluate the achievement of the objectives of the codes of conduct and, after consultation of the European Digital Services Board or the European Artificial Intelligence Board, shall update the assessment as appropriate.
4. The Commission shall encourage and facilitate regular review and adaptation of the codes of conduct.
5. The Commission shall also encourage developments of best practices in any area falling within the scope of this Regulation. This may include areas such as testing in the course of product developments or control standards. The is without prejudice to Article 5.
Article 24 – Legal representatives
1. Providers of online social networking services, of video-sharing platform services, of online games, of AI companions, and of general conversational chatbots, which do not have an establishment in the Union but which offer services or systems in the Union, shall designate, in writing, a legal or natural person to act as their legal representative in one of the Member States where the provider offers its services or system. However, where such providers have already designated a legal representative pursuant to Article 13 of Regulation (EU) 2022/2065 or pursuant to Article 22 or Article 54 of Regulation (EU) 2024/1689, they may extend the mandate of that legal or natural person to all issues necessary for the receipt of, compliance with and enforcement of decisions issued in relation to this Regulation.
2. Article 13(2) to
(5) of Regulation (EU) 2022/2065 shall apply and references to Regulation (EU) 2022/2065 shall be construed as references to this Regulation with regard to obligations set out in this Regulation in relation to providers of online social networking services, of video-sharing platform services, and of online games. Article 22(2),
(3) and
(4) of Regulation (EU) 2024/1689 or Article 54
(2) to
(5) of that Regulation shall apply and references to obligations set out in Regulation (EU) 2024/1689 shall be construed as references to this Regulation with regard to obligations set out in this Regulation in relation to providers of AI companions and of general conversational chatbots.
Article 25 – Amendments to listed measures
1. The Commission may adopt delegated acts in accordance with Article 40 for the purpose of amending Articles 9(2), 10(2), 11(1), 12(1), 12(2), 14(1), 15(1) and 18(2), for providers of online social networking services, of video-sharing platform services, of online games, of AI companions, and of general conversational chatbots, to ensure a high-level of privacy, safety and security of minors on their service or system. Those delegated acts shall be based on identified emerging risks which undermine the health and well-being, as well as the privacy, safety and security of minors leading to the need to keep the following obligations up to date in order to ensure effective compliance with these obligations:
a) prohibitions on practices intended, or which can reasonably be foreseen, to encourage compulsive or excessive use of the service by minors, as referred to in Article 9(2);
b) measures ensuring that recommender systems are designed in way that ensures a high level of privacy, safety and security of minors, as referred to in Article 10(2);
c) default settings ensuring that minors’ accounts are set to a high level of privacy, safety and security, as referred to in Article 11(1);
d) measures ensuring a high level of privacy, safety and security of minors as regards contacts between minors and other recipients of the service, as referred to in Article 12(1) and measures limiting the visibility of any information shared by minors and their interactions with other recipients of the service, as referred to in Article 12(2)
e) measures ensuring a high level of protection of health, safety, fundamental rights and well-being of minors that may access AI companions and general conversational chatbot systems, as referred to in Article 14(1);
f) measures ensuring a high level of privacy, safety and security of minors on online games as referred to in Article 15(1);
g) measures ensuring agency for minors as referred to in Article 18(2).
2. When considering the adoption of a delegated act, the Commission shall take into account:
a) the extent to which the risk has already caused harm to minors’ health, well-being or had adverse impact on minors’ privacy, safety and security, or fundamental rights or has given rise to significant concerns in relation to the likelihood of such harm or adverse impact, as demonstrated, for example, by reports or documented allegations submitted to national competent authorities or by other reports, as appropriate;
b) the potential extent of such harm or such adverse impact, in particular in terms of its intensity and its ability to affect multiple persons or to disproportionately affect a particular group or persons;
c) the impact of the existing measures in addressing such risks, including the intended purpose of such measures, the extent to which the measures are being used or are likely to be used, and the effectiveness of such measures for minors’ health, well-being, and privacy, safety and security.
CHAPTER IV – VERIFICATION OF PARENTAL RESPONSIBILITY
Article 26 – Verification of parental responsibility
1. For the purpose of creating an account with limited features pursuant to Article 6(2) or age-appropriate experience on video-sharing platforms pursuant to Article 7(2) and for the purpose of implementing effective, accessible and user-friendly tools for guardians pursuant to Article 20(1), a provider of a service referred in those provisions shall be able to:
a) use signals of the parental responsibility based on freely accessible official online databases or online interfaces made available by a Member State;
b) use signals of the parental responsibility that the provider may already be in possession of in view of the past engagements of the respective minor and adult with parental responsibility with the service concerned;
c) accept self-declaration by the adult with the parental responsibility at least until the delegated act as referred to in paragraph 3 is adopted.
2. When using signals referred to in paragraph 1, point (a), the provider shall make reasonable efforts to verify that the information available is reliable and complete.
3. When using self-declarations referred to in paragraph 1, point (c), the provider shall make reasonable efforts to verify that the adult making the self-declaration is exercising parental responsibility.
4. Verification of the parental responsibility pursuant to paragraph 1 shall be carried out in a privacy-preserving manner and shall not lead to additional processing of personal data that could enable the provider to determine the location of the adult or minor concerned or to track, target or profile the adult or minor.
5. The Commission is empowered to adopt a delegated act in accordance with Article 39 to supplement this Regulation by specifying signals indicating parental responsibility pursuant to paragraph 1, point a of this Article.
CHAPTER V – AGE ASSURANCE
Section I – General principles for age assurance
Article 27 – General principles for age assurance
Where providers of services and of systems subject to Chapters II and III implement age assurance solutions in order to fulfil their obligations laid down in this Regulation, they shall ensure that those solutions provide a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination.
Article 28 – Data protection in age assurance
1. Age assurance solutions shall not enable the identification of the recipient nor locate, track, target, advertise to or profile recipients for any purpose.
2. Providers of services and of systems falling within the scope of this Regulation, and any entity acting on behalf or together with such providers in age assurance, shall not maintain, acquire or process more personal data than strictly necessary to assess if the recipient of the service or the user of the system has met the age thresholds laid down in this Regulation, and shall not further process, share or combine this information with any additional data, without prejudice to Article 29(6), and they shall not combine personal data stored or relating to the use of the system with personal data from any other services offered by the provider or from third-party services.
3. Providers of services and of systems falling within the scope of this Regulation, and any entity acting on behalf or together with such providers in age assurance, shall ensure that the measures used are based on state-of-the-art technology. Any age assurance measure shall be zero knowledge proof.
4. By way of derogation from paragraph, providers referred to in Article 16(4) and Article 8(1) may store, at account level, the age signal that a user has successfully met a specific age threshold under this Regulation, for the sole purpose of avoiding repeated age assurance. Such age signal shall be limited to the minimum information necessary for that purpose.
5. Providers of services and of systems falling within the scope of this Regulation shall take the necessary technical and organisational measures to comply with paragraphs 1, 2, 3 and 4.
Section II – Specific obligations on age assurance
Article 29 – Age assurance solutions
1. Providers of services referred to in Article 6 of this Regulation shall put in place age verification solutions to verify, under the conditions set out in this Chapter, whether the recipient of the service has reached the minimum age pursuant to those provisions, or, where applicable, whether the creation of a parental account is necessary.
2. For the purpose of compliance with Article 6 providers referred to in that paragraph shall rely exclusively on an EU age verification solution using an EU proof of age attestation, provided by a third party, certified as conforming with the EU Age Verification Scheme and included in or verifiable against the respective EU lists referred to in Article 30, paragraph 1, point (a) and (b).
3. EU age verification solutions and EU proof of age attestations, shall be certified as conforming with the requirements of the EU Age Verification Scheme, as laid down in accordance with Article 30(2), by a public authority. European Digital Identity Wallets certified pursuant to Article 5c of Regulation (EU) No 910/2014 that comply with the requirements of the EU Age Verification Scheme shall be deemed to be certified in accordance with this paragraph. Providers of EU proof of age attestations and providers of EU age verification solutions shall comply with the requirements of the EU Age Verification Scheme.
4. For the purpose of complying with the obligations of Article 8(1) and Article 16(2) and 16(3), the providers concerned may use age assurance solutions other than the EU age verification solutions referred to in paragraph 2, where they can demonstrate that those solutions meet the requirements laid down in Article 27 and Article 28.
5. Providers of services and of systems referred to in paragraphs 1 and 4 shall ensure that recipients have access to an effective internal complaint-handling mechanism enabling them to lodge, by electronic means and free of charge, complaints against the outcome of the age assurance referred to in those paragraphs, where the recipient considers the outcome of the age assurance to be incorrect. Providers of online platforms, as defined in Article 3 point (i) of Regulation 2022/2065 may for the purpose of compliance with this Article use the complaint-handling mechanism laid down in Article 20 of that Regulation 2022/2065.
6. Where a provider of an operating system has obtained an age signal of a user, and where the age assurance used to obtain this age signal is in compliance with the requirements defined pursuant to Article 27, after obtaining consent of the user, the provider of an operating system shall enable the sharing of the age signal with providers in scope when such age signal of a user is required to comply with this Regulation.
Article 30 – Empowerment to the Commission
1. The Commission shall maintain:
a) an EU list of providers of EU proof of age attestations certified in accordance with Article 29(2) and notified by any Member State;
b) an EU list of EU age verification solutions certified in accordance with Article 29(2) and notified by any Member State. The Commission shall publish the EU list and keep it up to date in a secure and machine-readable form.
2. The Commission shall adopt implementing acts laying down the specifications as a basis of the functioning of the EU Age Verification Scheme, including the requirements applicable to EU age verification solutions and to the issuance, presentation and verification of EU proof of age attestations. Such implementing acts shall be limited to what is necessary to ensure the effective, secure, privacy-preserving, interoperable and uniform implementation of Article 29(2) and
(3) and shall be based on the principle of data minimisation, purpose limitation, security, technological neutrality and proportionality, and shall ensure interoperability with the European Digital Identity Wallets provided pursuant to Article 5a of Regulation (EU) No 910/2014. Those implementing acts shall specify the detailed technical, organisational, privacy and security requirements applicable to EU proof of age attestations and their providers and for EU age verification solutions and their providers, the evidence and procedures for demonstrating and assessing public authorities, and the specifications of the EU lists referred to in paragraph 1. The implementing acts may also include requirements for a trust mark for age verification solutions. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 40(2).
3. The Commission shall adopt delegated acts, in accordance with Article 39, in order to supplement this regulation by specifying:
a) the requirements applicable to alternative age assurance solutions as referred to in Article 29(4), including the requirements necessary to demonstrate compliance with Article 27 and Article 28. Those delegated acts shall specify the detailed technical, organisational, privacy and security requirements applicable;
b) the obligations applicable to operating systems as referred to in Article 29(6), including the requirements necessary to ensure the secure, privacy-preserving and interoperable sharing of age signals.
Article 31 – Obligations on Member States
1. Member States shall establish at least one privacy-preserving electronic means by which a guardian can obtain and present an attestation of parental responsibility in respect of a minor, for the purposes of Article 26(1), point (a), and of the exercise of the tools for guardians referred to in Article 20. Such means shall be:
a) be based on authentic sources established under national law;
b) be free of charge for the guardian;
c) not entail making any information on parental responsibility accessible to providers or to the public beyond the confirmation that parental responsibility exists.
2. Member States shall ensure that privacy-preserving electronic means referred to in paragraph 1 are effectively accessible to all citizens and guardians and minors residing in their territory, including persons with disabilities, persons with limited digital access or skills, and persons in vulnerable situations such as refugee and displaced families.
3. Member States shall provide for appropriate alternative procedures where parental responsibility cannot be demonstrated through standard civil status documentation.
4. Member States shall take the necessary measures to ensure the availability of means of obtaining a proof of age attestation to verify the minimum age set out in this Regulation.
5. Member States shall take the necessary measures to ensure the availability for citizens and residents, free of charge, of at least one EU age verification solution as certified in accordance with Article 29(3) to verify the age thresholds set out in this Regulation.
6. Member States shall ensure that public authorities can be accredited for the purposes of Article 29(3) and shall communicate to the Commission the names and addresses of the public authorities designated and accredited in their territory, as well as any subsequent changes thereto. The Commission shall make that information publicly available.
7. Member States shall notify to the Commission, without undue delay, the EU age verification solutions and EU proof of age attestations certified in accordance with Article 29(3), together with the corresponding certificate of conformity, as well as any subsequent suspension or withdrawal of a certificate. Once included in the lists referred to in Article 29(1) point (a) and (b), an EU age verification solution and EU proof of age attestations shall be recognised by all Member States for the purposes of this Regulation.
Article 32 – Existing accounts
1. For the purposes of establishing, in accordance with Article 6(4), whether an existing account belongs to a recipient below the age of 15 years, providers referred to in Article 6(1) shall rely on an age verification solution referred to in Article 30(2).
2. By way of derogation from paragraph 1 of this Article, providers referred to in that paragraph shall not be required to carry out age verification where they can establish, with a high degree of confidence, that the recipient of the service has reached the minimum age set out in Article 6.
3. By way of derogation from Article 8(1), providers falling within the scope of that Article and providers of software application stores shall not be required to assess the age of the recipient where they can establish, with a high degree of confidence that the recipient of the services is not a minor.
4. Providers of very large online platforms designated in accordance with Article 33 of Regulation (EU) 2022/2065 that fall within the scope of this Article, shall submit a plan to the competent authority specifying how they intend to comply with paragraph 1 and Article 8(1) and, in case they intend to rely on the exceptions laid down in paragraphs 2 and 3, how they intend to establish that the recipient of the service or the user of the system has reached the minimum age, in accordance with those paragraphs.
CHAPTER VI – MEASURES TO SUPPORT MINORS
Article 33 – National measures to prepare and support minors
1. Member States shall support the protection of minors by establishing national strategies to ensure that minors and their guardians have the following:
a) easy, free and confidential access at national level to channels through which minors can seek assistance in relation to the harms addressed by this Regulation, including unwanted contact and cyberbullying;
b) adequate information about the risks addressed by this Regulation and of the available means of protection, including by addressing digital literacy;
c) other information relevant to protect minors online.
2. Member States’ activities to support the protection of minors shall build on the experience and expertise of the Safer Internet Centres with their awareness raising activities, their helplines supporting children, guardians and educators, and their hotlines to report suspected illegal content.
3. Member States shall communicate the strategies referred to in paragraph 1 to the Commission by [same day as the date of entry into force plus 12 months].
4. The activities referred to in paragraph 1 may be supported by Union funding made available under the relevant Union programmes and instruments established under the multiannual financial framework.
5. The Commission shall facilitate the exchange of best practices between Member States, including on the development of digital literacy skills, and on the establishment and operation of national support channels and applications.
CHAPTER VII – COMPETENCES, SUPERVISION AND ENFORCEMENT
Article 34 – Competences, Supervision and Enforcement
1. For the purposes of the supervision and enforcement of obligations imposed by this Regulation on providers of online social networking services, of video-sharing platform services, of online games that are video gaming platforms, and of software application stores, Chapter IV of Regulation (EU) 2022/2065 shall apply and any references therein to the provider of intermediary services shall be construed to include the provider of services covered by this Regulation. Any references therein to compliance or non-compliance with the relevant provisions of Regulation (EU) 2022/2065 shall be deemed to include this Regulation.
2. For the purposes of the supervision and enforcement of obligations imposed by this Regulation on providers of AI companions and of general conversational chatbots, Chapter IX of Regulation (EU) 2024/1689 shall apply, and any references therein to compliance or non-compliance with the relevant provisions of Regulation (EU) 2024/1689 shall be construed to include Chapters II, III and IV of this Regulation. Non-compliance with those obligations shall be subject to administrative fines under Article 99 of Regulation (EU) 2024/1689 not exceeding 6 % of the total worldwide annual turnover of the undertaking providing the AI companion or the general conversational chatbot in the preceding financial year where that provider has been found to have acted intentionally or negligently.
3. Member States shall ensure that authorities designated by them in accordance with Article 49 of Regulation (EU) 2022/2065 and Articles 70 and 74 of Regulation (EU) 2024/1689 are competent to supervise and enforce this Regulation in respect of providers of services or systems covered by this Regulation.
4. To the extent that powers are conferred on the Commission under Section 4 of Chapter IV of Regulation (EU) 2022/2065 and under Article 75a to 75d and Article 99 of Regulation (EU) 2024/1689, those powers shall also cover the supervision, investigation, enforcement and monitoring of compliance with this Regulation.
5. Member States shall ensure that a competent authority is responsible for the supervision of providers of online games that are video games and for the enforcement of Article 15 and applicable provisions in Articles 8 and 18 to 22. Such competent authority shall have the powers set out in Article 51 of Regulation (EU) 2022/2065. For the purpose of this paragraph, Member States shall lay down rules on penalties applicable to infringements of Article 15 and applicable provisions in Articles 8 and 18 to 22 as set out in Article 52 of Regulation (EU) 2022/2065. The competent authority of the Member State in which the main establishment of the provider of online games that are video games is located shall have exclusive powers to supervise and enforce this Regulation.
6. The supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 shall be competent to monitor the processing of personal data necessary to comply with this Regulation, and in particular Articles 27, 28 and 29 of this Regulation. For infringements of the data protection obligations laid down in those Articles, the data protection supervisory authorities may within their competence impose fines in line with Article 83 of Regulation (EU) 2016/679 and up to the amount referred to in Article 83(5) of that Regulation.
7. Member State authorities shall not take decisions which run counter to a decision adopted by the Commission under this Regulation. The Commission and the Member States, including Digital Services Coordinators, market surveillance authorities and national authorities responsible for the enforcement of consumer protection laws, shall work in close cooperation and coordination.
Article 35 – Expedited procedure
1. For the purposes of Section 4 of Chapter IV of Regulation (EU) 2022/2065 and Chapter IX of Regulation (EU) 2024/1689, where the obligations in this Regulation apply to providers of very large online platforms designated in accordance with Article 33 of Regulation (EU) 2022/2065 or to providers of AI systems under the exclusive supervision of the Commission in accordance with Regulation (EU) 2024/1689, the powers conferred upon the Commission under Chapter IV of Regulation (EU) 2022/2065 and Chapter IX of Regulation (EU) 2024/1689 shall be exercised in accordance with this Article.
2. Where the Commission initiates proceedings for infringement of this Regulation in accordance with Article 66 of Regulation (EU) 2022/2065 or Article 75a of Regulation (EU) 2024/1689 in view of the possible adoption of decisions pursuant to Articles 73 and 74 of Regulation (EU) 2022/2065 or Articles 75c of Regulation (EU) 2024/1689, the Commission shall endeavour to:
a) communicate its preliminary findings to the provider concerned within [30] working days from the opening of the proceedings pursuant to Article 66 of Regulation (EU) 2022/2065 or Article 75a of Regulation (EU) 2024/1689;
b) adopt a final decision within 90 working days from the opening of proceedings.
1. The Commission shall charge an annual supervisory fee on providers of very large online platforms designated in accordance with Article 33 of Regulation (EU) 2022/2065 which constitute, are embedded in or embed online social networking services, video-sharing platform services, or software application stores, and on providers of AI companions, general conversational chatbots, and video gaming platforms for which it enjoys the competence to supervise their compliance with Chapters II to V of this Regulation in accordance with Article 33 of this Regulation.
2. Each provider referred to in paragraph 1 shall be charged the annual supervisory fee for each service or system falling within the scope of this Regulation.
3. The overall amount of the annual supervisory fees pursuant to paragraph 1 shall cover the costs incurred by the Commission in the preceding calendar year in relation to its supervisory tasks under this Regulation vis-à-vis the providers referred to in paragraph 1, in particular costs related to human resources, including officials, the set-up, maintenance and operation of the EU Age Verification Scheme pursuant to Article 29, the exercise of supervisory and enforcement tasks pursuant to Article 34, and the development of expertise and capabilities pursuant to Article 37.
4. For the purpose of establishing the annual supervisory fee for the tasks pursuant to paragraph 3, the annual supervisory fee for each of the providers referred to in paragraph 1 shall not exceed 0,03 % of its worldwide annual net income in the preceding financial year.
5. For the purpose of the application of this Article, the Commission shall apply rules and principles laid down in Article 43 of Regulation (EU) 2022/2065.
6. The Commission shall adopt delegated acts, in accordance with Article X, laying down the detailed methodology and procedures for:
a) the determination of the estimated costs referred to in paragraph 3;
b) the determination of the individual annual supervisory fees referred to in paragraph 1;
c) the determination of the maximum overall limit defined in paragraph 4; and
d) the detailed arrangements necessary to make payments. When adopting those delegated acts, the Commission shall respect the principles set out in paragraph 5 of this Article.
Article 37 – Development of expertise and capabilities
The Commission, in cooperation with the competent authorities pursuant to Article 34, shall develop Union expertise and capabilities in the area of protection of minors, including, where appropriate, through the secondment of Member States’ personnel. Such development of expertise and capabilities shall especially be developed in the area of incidents affecting the protection of minors.
Article 38 – Incidents reaction mechanisms
1. The Commission, in cooperation with the competent authorities pursuant to Article 33, shall coordinate the assessment of incidents affecting the protection of minors across the Union in relation to services and systems in scope, and be able to rely on the expertise and resources of such authorities. Member States shall cooperate with the Commission in setting up efficient knowledge sharing networks with other authorities and relevant third parties.
2. The Commission shall establish a voluntary administrative arrangement with competent authorities setting out procedures to facilitate a rapid response in the event of an incident affecting the protection of minors in the Union or in significant parts of it. Member States shall establish minimum preparedness levels for national authorities to ensure regular communications channels between relevant national authorities and third parties, and map existing incident reaction protocols at national level and where relevant establish new ones. The incident reaction mechanism shall complement the existing crisis tools under Regulation (EU) 2022/2065 and inform their potential activation.
CHAPTER VIII-IMPLEMENTING AND DELEGATED ACTS
Article 39 – Exercise of the delegation
1. The power to adopt delegated acts is conferred upon the Commission subject to the conditions laid down in this Article.
2. The delegation of power referred to in Articles 2(5), 6(6), 7(6), 20(7), 25(1), 26(3), 30(3) and 36(6) shall be conferred on the Commission for a period of five years from [same day as date of entry into force]. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.
3. The delegation of power referred to in Articles 2(5), 6(6), 7(6), 20(7), 25(1), 26(3), 30(3) and 36(6) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.
4. Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.
5. As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.
6. A delegated act adopted pursuant to Articles Articles 2(5), 6(6), 7(6), 20(7), 25(1), 26(3), 30(3) and 36(6) shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of two months of notification of that act to the European Parliament and to the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.
Article 40 – Committee procedure
1. The Commission shall be assisted by a committee (‘the Child Safety Committee’). That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.
2. Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.
3. Where the opinion of the committee is to be obtained by written procedure, that procedure shall be terminated without result when, within the time limit for delivery of the opinion, the chair of the committee so decides or a simple majority of committee members so request.
CHAPTER IX-FINAL PROVISIONS
Article 41 – Amendment to Directive (EU) 2020/1828
In Annex I to Directive (EU) 2020/1828, the following point is added: [final name of the act].
1. The Commission shall review the application of this Regulation and shall report to the European Parliament and to the Council by [31 August 2030]. Taking into account the experience gained in the application of this Regulation, as well as technological, market and legal developments, the Commission shall evaluate in particular:
a) the contribution of this Regulation to the deepening and efficient functioning of the internal market and to ensuring a high level of protection for minors online in the European Union;
b) the effectiveness of the application of Articles 6 and 7;
c) the personal scope of the provisions in Chapters II and III;
d) the impact of this Regulation on the respect for the right to freedom of expression and information.
2. The report referred to in paragraph 1 shall be accompanied, where appropriate, by a proposal for amendment of this Regulation.
3. In addition, the Commission shall submit a report to the European Parliament and the Council every four years after the report referred to in paragraph 1 on the progress towards achieving the objectives of this Regulation.
Article 43 – Entry into force and application
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. This Regulation shall apply from [same day as entry into force plus 6 months]. However, Article 5 shall apply from [same day as entry into force] and Articles 33 and 35 shall apply from [same day as entry into force plus 12 months]. This Regulation shall be binding in its entirety and directly applicable in the Member States in accordance with the Treaties. Done at Brussels, For the European Parliament For the Council The President The President