Brussels, BELGIUM – The European Commission’s new Kids Act, introducing tiered age-based access restrictions for social media, games, AI chatbots, video-sharing platforms, and other online services, creates serious new privacy and security risks for children and adults alike, the Computer & Communications Industry Association (CCIA Europe) cautions.
While supporting effective protections for minors, CCIA Europe warns that the Commission cannot rely on privacy and security safeguards on paper alone without explaining how these age checks and parental controls will work in practice, particularly when many of the technologies mentioned remain unproven at the scale envisaged by the proposal.
The proposal also puts Europe’s long-standing principle of data minimisation to the test. Rather than a simple yes-or-no check, the Commission wants to set different rules across four distinct age brackets (under 3, 3-13, 13-15, and 15-18). So-called ‘parent-controlled’ and ‘parent-supervised’ accounts would require online services to verify family relationships.
The privacy implications do not stop with children. If platforms have to distinguish minors from adults, adults must also prove their age when signing up for platforms or services – making anonymous or pseudonymous use more difficult for all Europeans.
CCIA Europe stresses that any EU age-based restrictions should be grounded in a secure, privacy-preserving framework. Protecting children online should not require Europeans to surrender sensitive personal information to participate in digital life.
Beyond privacy, the Kids Act overlaps with recent and forthcoming EU rules – including the AI Act, Digital Services Act, Audiovisual Media Services Directive, and Digital Fairness Act – creating conflicting obligations, parallel enforcement tracks, and legal uncertainty. These conflicts urgently need to be addressed to ensure that legitimate and useful technologies, including AI, can continue to flourish and reach users in the EU.
The following can be attributed to Daniel Friedlaender, Senior Vice President and Head of CCIA Europe:
“Children deserve a safe internet, but promises of privacy and security are not enough. The Commission must answer a core question: how will it ensure these rules do not create an infrastructure that enables age tracking, identity linkability, or surveillance at scale?”
“If this system requires large amounts of sensitive information about children, adults, and family relationships, it will create serious risks for everyone. The Commission cannot treat these as mere implementation details when key technical, privacy, and security requirements are left to subsequent implementing and delegated acts.”
“Collecting age information, identity credentials, and data linking children with parents or guardians at this scale would undoubtedly create an attractive target for cybercriminals.”
“The Kids Act creates legal overlap and duplication that ultimately weaken protections for children and consumers. More regulatory complexity and confusion will only make it harder to keep young people safe.”