background image blur
background image
  • Blog
    >
  • News
    >
  • The EU Kids Act Has a Privacy Problem That Goes Well Beyond Age Verification

The EU Kids Act Has a Privacy Problem That Goes Well Beyond Age Verification

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 22 September, 2026
A Scandinavian mom teaches her young son to use a phone

Key Takeaways

  • EU’s proposal creates a three-tier system: no social media access for under-13s, restricted accounts under parental supervision for 13 to 15-year-olds, and safe-by-design autonomous accounts for 15 to 18-year-olds — with full unrestricted access reserved for adults only.
  • The EFF argues age gates undermine civil liberties, create barriers to internet entry that disproportionately affect marginalized groups, and build infrastructure that further entrenches big tech's power.
  • The proposal's safety-by-design pillar extends beyond social media to online games, AI companions, chatbots, and app stores, with app stores designated as the primary gatekeepers for age-appropriate access.
  • The EU Kids Act did not go through a full impact assessment process, which would normally require a systematic review of alternative policy options and stakeholder consultations.

What the EFF Is Objecting To

The EU Kids Act, announced by European Commission President Ursula von der Leyen at the State of the Union on September 16th, presents itself as a proportionate, risk-based approach to protecting minors online. The EFF's analysis, published September 21st, argues that its mechanisms will impose costs on everyone — and that several of those mechanisms are poorly designed even for the goal they are supposed to serve.

The proposal's first pillar creates phased access to social media and video-sharing platforms deemed risky — a threshold met simply by relying on personalized recommender systems or offering uninterrupted content consumption. That definition covers virtually all mainstream platforms. The access system requires no social media accounts for under-13s, restricted accounts under tight parental supervision for 13 to 15-year-olds, and autonomous accounts in a safe-by-design environment for 15 to 18-year-olds. 

Full unrestricted online access is reserved for adults. Teenagers aged 13 to 15 would need a parent to set up their accounts and verify that they are, in fact, a parent — adding a layer of verification on top of the age check already required of the child.

The EFF's core objection is that age gates, however they are designed, undermine civil liberties, reduce safety, and create barriers to internet entry — often at the expense of marginalized groups. The infrastructure they require also concentrates power: most companies facing compliance requirements will default to privacy-unfriendly age checks, and small and medium-sized enterprises will struggle to build compliant systems while large tech companies, already investing in similar measures, absorb the costs more easily. 

The proposal exempts not-for-profit encyclopaedias, scientific repositories, educational services, and open-source platforms, but contains no exemption for smaller businesses — which the EFF argues will simply accelerate the dominance of resource-laden tech companies.

Safety by Design, and Its Complications

The proposal's second pillar — safety by design — casts a wider net than social media. It applies to online games, AI companions, chatbots, and app stores, with varying requirements across each. Providers must make child-safe design the default, and can only relax from those requirements if they use age assurance to establish that a user is an adult. 

Rules on addictive features such as infinite scrolling, settings defaults, and recommender system controls are included. AI companions and chatbots would be required to design against emotional dependencies and harmful interactions for minors. App stores become the designated gatekeepers for age-appropriate access under a rating system.

The EFF raises a structural concern about this approach: deciding what is "safe" can easily become a question of what content people can access or share. Transplanting product-safety doctrines of conformity and risk control into speech regulation risks turning safety requirements into content requirements, particularly for very large online platforms required to submit compliance plans before rolling out new services.

The requirement also sits uneasily with the decentralized architecture of the Fediverse and similar open platforms, which don't have a central provider in a position to implement these controls.

The Process Problem

Beyond the substance of the proposal, the EFF flags a procedural concern: the EU Kids Act didn’t go through a full impact assessment process. Such a process would normally require a systematic check of alternative policy options, modeling of likely effects, and stakeholder consultations before a proposal reaches this stage. 

Its absence means the Commission hasn’t formally examined whether less rights-restrictive alternatives could achieve the same child protection goals, or what the broader effects on adult users and smaller platforms are likely to be.

The EFF's position isn’t that protecting children online is the wrong goal. It’s that the mechanisms chosen — mandatory age gates, privacy-intrusive verification, and a safety-by-design regime wide enough to cover app stores — will create a privacy minefield and intermingle the legitimate goal of curbing manipulative design with the more fundamental-rights-heavy question of who gets to access information online and on what terms.

The EFF is calling on EU lawmakers to pull back the most harmful provisions and ensure the new measures do not erode the fundamental rights of all users — including the children the law is meant to protect.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"