The protection of minors in digital environments is the set of obligations that fall on platforms, video-sharing services and device manufacturers to limit minors’ access to certain content, features and data processing. On 17 September 2026 the European Commission adopted the proposal for an EU KIDS Act, which harmonises a minimum age for opening one’s own social media account. In Spain, the draft organic law on the same subject, before the Spanish Parliament since March 2025, lapsed when Parliament was dissolved on 6 October 2026. Neither text is binding today. What binds platforms today is Article 28 of the Digital Services Act.
If you need digital law advice for your business, request a free initial assessment.
The EU KIDS Act proposal bans an own account below the age of 13, allows a limited account opened by a parent or guardian between 13 and 15, and reserves the autonomous account for those aged 15 and over. Age verification must be certified and independent, with at least one free option in each Member State.
The planned method does not identify the user. It relies on zero-knowledge proofs, which show that someone is above an age without revealing who they are, and treats the European digital identity wallet as one of the valid routes. Platforms would have six months to verify existing accounts.
The text also names design practices and prohibits them. Endless autoplay, infinite scrolling, notifications designed to pull the minor back in, rewards for posting to mass audiences and streak mechanics. Recommender systems would have to be optimised for safety rather than engagement, and chatbots could not simulate human relationships that create emotional dependence. One caveat: it is a European Commission proposal and still has to be negotiated.
The European proposal reaches platforms and video services operating in the Union. The Spanish draft went further on a point that often goes unnoticed, because it also reached whoever manufactures the device.
| Criterion | EU KIDS Act proposal | Spanish draft organic law |
|---|---|---|
| Status | Proposal, 17 September 2026 | Lapsed with the dissolution of Parliament, 6 October 2026 |
| Who it covers | Platforms and video services | Platforms, audiovisual services and terminal equipment manufacturers |
| Product design | Bans addictive patterns, named one by one | Bans minors from random reward mechanisms |
| Personal data | Age verification without identifying the user | Raises the age of consent to data processing to 16 |
Article 4 of the draft organic law (in Spanish) required manufacturers of terminal equipment to inform users of the risks and to build in parental controls switched on by default at initial set-up. Article 5 barred minors from random reward mechanisms. The draft lapsed with the dissolution of Parliament, and the Government formed after the general election of 29 November 2026 will have to table it again if it wants it passed. It may take up this content or change it, so today it serves as a reference, not as an obligation.
The obligation in force is Article 28 of the Digital Services Act, which requires appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors. In July 2025 the Commission published guidelines that develop that article.
They are not binding and following them does not prove compliance, but they serve as a benchmark for assessing it. They recommend minors’ accounts that are private by default, recommender systems that reduce exposure to harmful content, and safeguards around virtual currencies and loot boxes. Much of what the September proposal turns into obligations was already there.
There is a Spanish nuance worth keeping in mind, which we develop in our analysis of the Digital Services Act. The European rule applies, but the national enforcement arm is arriving late, a pattern repeated across the rest of the digital regulatory framework.
The useful work today is the inventory. Which features minors can use, which data is collected from them, which spending or random reward mechanics exist, how the default settings behave and which age check is applied.
An example. A Galician company develops a video game with items that open at random and does not consider itself affected because it is not a social network. Article 5 of the Spanish draft would have reached it because of the random mechanic, and the European proposal singles out its streaks and its notifications. Neither text binds it today, and that is exactly why now is the time to look at it.
Neither of these two texts creates any obligation. The European proposal has not been adopted and the Spanish draft lapsed with the dissolution of Parliament in October 2026. Article 28 of the Digital Services Act does require proportionate measures to protect minors, and age assurance is one of the measures the Commission recommends in its 2025 guidelines for services with inappropriate content.
The Spanish draft organic law, which lapsed in October 2026, did cover manufacturers of terminal equipment. Its Article 4 required accessible warnings about risks and recommended usage time by age, and parental controls switched on by default at initial set-up. If a new draft takes it up again, it is the point most worth watching. The European proposal is aimed only at online services.
Neither text is binding yet, and that is exactly the window to work without pressure. Reviewing today which features reach minors, which data is collected and which random reward mechanics the product contains costs far less than rebuilding it once the rules are in force. At Innovatech we assess the service against Article 28 of the Digital Services Act, the European proposal and the lapsed Spanish draft, and deliver an inventory of points to fix, ranked by priority. The review is led by Marta Suárez-Mansilla, Spanish lawyer (abogada), Madrid Bar (ICAM) no. 108380. Write to us for a free initial assessment.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
