Cybersecurity Policy Report, Guidance on Minors’ Online Privacy Protections Offered by European Commission, (Jul 14, 2025)
By Tony Foley
The European Commission has finalized its guidelines on privacy, safety, and security protections for minors as required by article 28 of the European Union’s Digital Services Act (DSA).
The final guidelines, which outline a non-exhaustive list of measures that all platforms, except for small and micro enterprises, can implement to protect minors using a default approach guided by privacy-by-design, were subject to a request for feedback by the EC in May (CPR, May 13).
The guidelines represent a milestone in its efforts to boost online safety for children and young people, the EC said today in a news release. They include measures to protect children from online harms like grooming, harmful content, problematic and addictive behaviors, cyberbullying, and harmful commercial practices. Among the key recommendations included in the final guidelines, which may be downloaded from the news release, are the following:
Privacy by default: Setting minors’ accounts to private by default so that their personal information, data, and social media content is hidden from those they aren’t connected with to reduce the risk of unsolicited contact by strangers.
Recommender systems: Modifying platforms’ recommender systems to lower the risk of children encountering harmful content, including advising platforms to prioritize explicit signals from children over behavioral signals.
Blocking and muting: Empowering children to block and mute any user and ensuring they can’t be added to groups without their explicit consent.
Screenshots: Prohibiting accounts from downloading or taking screenshots of content posted by minors to prevent the unwanted distribution of sexualized or intimate content.
By-default features: Disabling by-default features that contribute to excessive use, like communications “streaks,” autoplay, or push notifications, among others.
Manipulative practices: Ensuring that children’s lack of commercial literacy is not exploited and that they aren’t exposed to commercial practices that may be manipulative, leading to unwanted spending and addictive behaviors.
Moderation and reporting tools: Introducing measures to improve moderation and reporting tools, requiring prompt feedback and minimum requirements for parental control tools.
The guidelines also recommend the use of effective age assurance methods, in particular to restrict access to adult content such as pornography and gambling or when national rules set a minimum age to access certain services, provided that the methods are accurate, reliable, robust, non-intrusive, and non-discriminatory.
The news release notes that the guidelines mirror the DSA in adopting a risk-based approach, recognizing that online platforms may pose different types of risks to minors depending on their nature, size, purpose, and user base. The guidelines specify that platforms should ensure that the measures they take do not disproportionately or unduly restrict children’s rights.
News: InternationalLegislation DataPrivacy