EU KIDS Act: one age check will not satisfy EU and UK rules

Bratby Law Data Protection header card reading EU KIDS Act: one age check will not satisfy EU and UK rules

In short: The EU KIDS Act, which the European Commission proposed on 17 September 2026, would bar under-15s from social media accounts in the EU and require platforms to check age through a certified EU solution using zero-knowledge proof. The Online Safety Act 2023 sets an outcome standard instead, so a service with UK and EU users would need two age checks.

By Rob Bratby, Managing Partner, Bratby Law. Recognised in the Lexology Index as a Thought Leader for data privacy and protection. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms and data protection regulation, including Oftel and senior operator roles.

A social media service with teenage users in both London and Lisbon would have to check their ages in two different ways if the European Commission’s proposal becomes law. The EU would fix the minimum age at 15 and prescribe the technology used to check it. The UK sets a standard of effectiveness and leaves the provider to choose the method. The proposal is some way from law, but the methods Ofcom accepts today would not, on their own, meet the EU text at the point of sign-up.

The Commission adopted the proposal for a Regulation on the EU KIDS Act (COM(2026) 681 final) on 17 September 2026. The European Parliament has not yet referred it to a committee or appointed a rapporteur, according to its Legislative Observatory record. Commission President von der Leyen summarised the proposal in a speech in New York on 22 September 2026: “The KIDS Act says, no social media under 13. No personal accounts under 15.” Under Article 43 of the draft, the Regulation would apply six months after it enters into force.

What the EU KIDS Act would require at the account gate

Under Article 6(1) of the EU KIDS Act, a provider of an online social networking service or a video-sharing platform service would have to stop anyone under 15 from creating or using an account where the service poses a risk to minors. The draft lists five features that each create that risk: live streaming to an indeterminate audience, contact with people outside a user’s existing connections, a recommender system based on profiling, suggestions of contacts or content from outside those connections, and design that encourages uninterrupted use or prompts a return. Under Article 6(2), a provider could allow a parent or guardian to set up a limited account for a child aged 13 or 14.

At that gate, Article 29(2) would require the provider to “rely exclusively on an EU age verification solution using an EU proof of age attestation, provided by a third party”, certified against an EU scheme and entered on a Commission list. Under Article 29(3) a public authority would certify each solution, and a European Digital Identity Wallet (the digital identity app that Member States provide under Regulation (EU) No 910/2014) that meets the scheme would count as certified. The Commission has built the base for this in its EU age verification solution, and Article 31(5) would oblige each Member State to make at least one certified solution available free of charge.

Every age assurance method would also have to meet Article 28. An age assurance solution could not enable identification of the user or be used to “locate, track, target, advertise to or profile” anyone (Article 28(1)), and “Any age assurance measure shall be zero knowledge proof” (Article 28(3)). A zero-knowledge proof lets a user show that they are over an age threshold without the service learning their date of birth, name or anything else. Self-declaration would not count as age assurance at all (Article 3(5)(i)). Outside the account gate, for the general safety-by-design duties in Article 8(1) and the app store duties in Article 16(2) and (3), a provider could use other methods under Article 29(4), but only where it shows they meet Articles 27 and 28, including the zero-knowledge requirement.

Article 2(2) would apply these rules to providers wherever they are established, if they offer the service to users in the EU. A provider with no EU establishment would have to appoint a legal representative in a Member State (Article 24).

How the Online Safety Act 2023 regulates age checks in the UK

A provider of a user-to-user service likely to be accessed by children must use age verification or age estimation to prevent children from encountering primary priority content, unless it prohibits that content for all users (Online Safety Act 2023, section 12(3) to (5)). Primary priority content means pornography and content that encourages suicide, self-harm or eating disorders (section 61). Under section 12(6) the check must be “highly effective at correctly determining whether or not a particular user is a child”. These duties have applied since 25 July 2025.

The Act does not name a method. Ofcom’s guidance on highly effective age assurance for Part 3 services (24 April 2025) lists seven methods capable of meeting the standard: open banking, photo identification matching, facial age estimation, mobile network operator age checks, credit card checks, email-based age estimation and digital identity services, including wallets that store an age attribute. Ofcom judges a method against four criteria (technical accuracy, robustness, reliability and fairness) and has declined to set numerical thresholds. Self-declaration does not meet the standard. Ofcom opened an investigation into TikTok under section 12 on 16 July 2026, focused on whether its age inference models fail to identify a significant proportion of children.

The UK has no statutory minimum age for a social media account yet. Section 214A, inserted by the Children’s Wellbeing and Schools Act 2026 and in force since 29 April 2026, gives the Secretary of State power to make regulations that restrict children’s access to specified services or features. The Government has said it will use the power to stop under-16s holding social media accounts, a policy set out in detail in the post on the UK’s under-16 social media ban. No regulations had been laid by 18 September 2026, when the Government’s fact sheet said the first set would be laid before the end of the year and implemented in spring 2027. Ofcom has committed to report to Parliament by the end of October 2026 on how highly effective age checks could work to establish whether a user is over 16.

Data protection law applies to the same checks. Since 5 February 2026, Article 25(1A) of the UK GDPR has required a UK data controller providing an information society service (broadly, an online service) likely to be accessed by children to take account of the higher protection children merit when designing its processing. Ofcom and the ICO published a joint statement on age assurance on 25 March 2026. The ICO fined Reddit £14.47 million in February 2026 for children’s privacy failures, finding self-declared age insufficient; Reddit has appealed to the First-tier Tribunal.

Where EU and UK age assurance rules differ

In the UK a provider may use any age check that achieves the required result; under the EU KIDS Act it would have to use a specified one. None of the methods on Ofcom’s list would meet Article 29(2) at the EU account gate unless delivered through a certified EU solution, however accurate the method is. On the text as drafted, an operator of a mobile network, for example, could serve that gate only by becoming a certified provider of EU proof of age attestations. The converse question is open: a certified EU wallet presenting an age attribute appears to fall within Ofcom’s digital identity category, but Ofcom has not said whether it would treat one as highly effective.

What the provider must do UK: Online Safety Act 2023 EU: KIDS Act (proposed)
Keep children below a minimum age off social media accountsNo minimum age in force; the Government intends 16 through section 214A regulations from spring 202715, with guardian-set limited accounts at 13 and 14 (Article 6)
Choose an age check methodAny method that is highly effective (section 12(6)); Ofcom lists sevenOnly a certified EU solution with a third-party proof of age attestation at the account gate (Article 29(2))
Protect the user’s data in the checkUK GDPR, including Article 25(1A) from 5 February 2026Zero-knowledge proof for every method; no identification, tracking or profiling (Article 28)
Treat self-declared ageNot capable of being highly effective (Ofcom guidance)Not age assurance at all (Article 3(5)(i))
Enforcement and penaltiesOfcom, and the ICO for data protection; fines up to the greater of £18 million or 10% of qualifying worldwide revenue (Schedule 13, paragraph 4)The Commission for very large platforms, national authorities for others, through the Digital Services Act enforcement chapter (Article 34); fines up to 6% of worldwide turnover (DSA Articles 52(3) and 74(1))
Comply from25 July 2025 for the children’s safety dutiesSix months after entry into force, once adopted (Article 43)

What a service with UK and EU users would have to do

A provider running age checks must first have a lawful basis for processing the data involved under Article 6 of each GDPR, and must carry out a data protection impact assessment under Article 35 where the processing is likely to result in a high risk to the rights and freedoms of the children concerned. Those conditions apply in both jurisdictions whichever method the provider picks.

On top of those conditions, a social media or video-sharing service with users in both markets would, if the proposal is adopted as drafted, run two account gates at two ages: 15 in the EU through a certified EU solution, and 16 in the UK once the section 214A regulations are made, through any method Ofcom accepts as highly effective. It would need a separate limited-account product for EU users aged 13 and 14. Within six months of the Regulation applying, it would have to establish the age of every existing EU account holder and disable accounts held by under-15s or by users whose age it cannot establish (Article 6(4)). Whether the Online Safety Act applies to a given service in the first place is a separate question, set out in the three tests of scope under the Online Safety Act. Where a product launch depends on the answer under both regimes, the regulatory perimeter and market entry page describes the advice Bratby Law gives.

Viewpoint

I read Article 29(2) as the provision in the EU KIDS Act that matters most to UK providers. The age thresholds will be argued over: the European Parliament’s November 2025 report, cited in the Commission’s explanatory memorandum, called for 16. The technology rule would be harder to change. Amending a Regulation takes the full legislative procedure unless the Regulation delegates the point to the Commission, whereas Ofcom can revise its guidance without new legislation. Ofcom’s over-16 assessment, due by the end of October 2026, is the next point at which the UK position could change.

Frequently asked questions

Does the EU KIDS Act apply to UK providers?

Yes, if adopted as proposed. Article 2(2) would apply it to providers of social media, video-sharing, online games, app stores and operating systems wherever they are established, where they offer the service to users in the EU. A provider with no EU establishment would have to appoint a legal representative in a Member State under Article 24.

When would the EU KIDS Act apply?

Not until the European Parliament and the Council agree a final text under the ordinary legislative procedure. The Commission proposed it on 17 September 2026 and the Parliament has not yet referred it to a committee. Article 43 of the draft would apply the Regulation six months after entry into force, with some provisions applying earlier or later.

Can facial age estimation satisfy both regimes?

In the UK, Ofcom lists facial age estimation as capable of being highly effective under section 12(6) of the Online Safety Act 2023. At the EU social media account gate it would not qualify, because Article 29(2) of the draft KIDS Act would accept only a certified EU solution. Elsewhere under the draft, a provider could use it only if it met Articles 27 and 28, including the zero-knowledge requirement.


For advice on age assurance under the Online Safety Act 2023 and the proposed EU KIDS Act, or on the data protection questions that age checks raise, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts