A source-based guide for online platforms assessing the EU Digital Services Act duties on minors' privacy, safety, security, and profiling-based advertising.
Use it to separate binding Article 28 duties from the Commission's voluntary 2025 guideline measures, including age assurance and safer platform design.
Article 28 of the EU Digital Services Act requires an online platform to put appropriate and proportionate measures in place for a high level of minors' privacy, safety, and security. It also prohibits profiling-based advertising when the platform is aware with reasonable certainty that the recipient is a minor. Article 28 does not require extra personal-data processing solely to determine whether a recipient is a minor.
1
Section 1
What Article 28 requires for platforms accessible to minors
Determine the service's scope before selecting controls. Recital 71 says an online platform is when its terms allow minors to use it, it is directed at or predominantly used by minors, or the provider is otherwise aware that some recipients are minors. Record the terms, intended audience, actual use, and reliable age information already available to the provider.
Article 19 exempts qualifying micro and small enterprises from the DSA's additional online-platform obligations, including Article 28, unless they are designated as a very large online platform. After a provider loses micro or small enterprise status, the exemption continues for 12 months. Other DSA duties outside that section may still apply.
Article 28 sets an outcome and proportionality standard; it does not prescribe one control set for every service. The platform should connect each measure to the risks created by its purpose, design, size, and user base. The Commission's 2025 guidelines recommend specific measures, but following them is voluntary and does not by itself establish compliance.
Classify whether the service is an online platform and whether it is under the platform terms, audience, usage evidence, or age data already processed for another purpose.
Describe the minors-specific risks the service creates: unsolicited contact, harmful content exposure, addictive or excessive-use patterns, cyberbullying, harmful commercial practices, or access to adult-only products and content.
Map each control to a specific privacy, safety, or security risk for minors and explain why it is proportionate for the product's size, purpose, interface, and user base.
Keep the Article 28 record separate from broader DSA duties such as content moderation, statement-of-reasons reporting, marketplace traceability, and VLOP systemic-risk assessments.
Article 28 prohibits an online platform from presenting advertisements on its interface based on profiling, as defined by the GDPR, using the recipient's personal data when the provider is aware with reasonable certainty that the recipient is a minor. The Article 28 ban is limited to profiling-based advertising. Non-profiled advertising still requires assessment under the DSA and any other applicable consumer, privacy, advertising, or national child-protection rules.
The DSA does not define one universal signal for 'reasonable certainty.' A provider should document which information it already has, why that information reaches or does not reach the standard, and how its ad systems act on the result. Article 28 also says compliance does not oblige a platform to process additional personal data solely to assess whether a recipient is a minor.
Block profiling-based ad delivery for accounts, sessions, cohorts, or surfaces where the platform is aware with reasonable certainty that the recipient is a minor.
Document which existing signals support reasonable certainty, such as a declared date of birth, a child account, a parental setup, or other age information already processed, without assuming that any one signal is conclusive in every service.
Do not turn Article 28 into a general obligation to collect age from every user; record when age assurance is used because the risk profile or Commission guidelines support it.
Keep ad-system evidence: policy rules, targeting exclusions, delivery logs, campaign QA, advertiser controls, and tests showing minor profiles are excluded from profiling-based targeting.
Recommended minors-protection controls from the Commission guidelines
The Commission published its Article 28 guidelines on 14 July 2025. They are non-binding: implementation is voluntary, does not automatically establish compliance, and may inform Commission and national-regulator assessments. Use them as a control catalogue, then document why each selected or omitted measure fits the service's risks.
The official source recommendations cover privacy-by-default, safer recommender systems, user controls, limits on unwanted sharing of minors' content, safeguards against excessive-use features, harmful commercial-practice controls, and improved moderation, reporting, feedback, and parental-control tools.
Set minors' accounts or relevant sharing surfaces to private by default where the service exposes personal information, content, contact lists, or social interactions.
Tune recommender systems to reduce harmful-content exposure and content rabbit holes, including by giving more weight to explicit choices by children than to inferred behavioural signals where appropriate.
Give minors practical controls to block or mute users and avoid being added to groups without explicit consent where group or messaging features exist.
Where the relevant risk exists, prevent other accounts from downloading or taking screenshots of content posted by minors to reduce unwanted distribution of sexualised or intimate content and sexual extortion.
Review streaks, read receipts, autoplay, push notifications, ephemeral content, AI chatbots, virtual currencies, loot boxes, and similar interface patterns for excessive-use or harmful commercial-practice risks.
Recommender, interface, and VLOP controls that may overlap
Other DSA provisions may overlap with Article 28. Article 27 requires online platforms using recommender systems to explain the main parameters in plain and intelligible language and provide options to modify or influence them. For VLOPs and VLOSEs, Article 38 adds at least one recommender option that is not based on profiling.
For very large services, minors protection can also appear inside systemic-risk work. The DSA risk-assessment and mitigation provisions refer to children's rights, protection of minors, physical and mental well-being, recommender systems, advertising systems, interface design, content moderation, and internal documentation.
For all online platforms with recommender systems, keep terms-and-interface evidence showing the main recommender parameters and user controls.
For VLOPs and VLOSEs, keep evidence that each recommender system has at least one non-profiling option and that the option is available where recommendations are presented.
When minors are a material user group, test whether ranking, autoplay, notifications, chatbots, group suggestions, or ad selection can increase exposure to harmful content, unwanted contact, or excessive-use patterns.
For VLOP systemic-risk files, preserve supporting documents for risk assessments and connect minors-risk mitigations to design, recommender, advertising, moderation, staffing, and governance changes.
An Article 28 file should show why the service is or is not , what the provider knew, which risks it identified, which controls it selected, and why those controls are proportionate. It should also distinguish a decision not to collect more age data under Article 28(3) from a decision to use age assurance because the service's risks or another applicable rule supports it.
The record should let design, advertising, trust and safety, data science, policy, legal, privacy, and compliance teams test the same scope and control claims.
Does DSA Article 28 require every online platform to verify every user's age?
No. Article 28 requires appropriate and proportionate minors-protection measures and restricts profiling-based ads to minors when the platform is aware with reasonable certainty that the recipient is a minor. It also says compliance does not oblige platforms to process additional personal data to assess whether a recipient is a minor.
When do the Commission's DSA minors guidelines recommend age assurance?
The voluntary guidelines recommend age assurance that is accurate, reliable, robust, non-intrusive, and non-discriminatory. They recommend age verification for access to adult content such as pornography and gambling and where national rules set a minimum age for specified services. They recommend age estimation in other cases, including where terms set a minimum age below 18 because of identified risks to minors. The correct method still depends on the service, risk, and other applicable law.
Are micro and small online-platform providers exempt from DSA Article 28?
A provider that qualifies as a micro or small enterprise is exempt from the DSA section containing Article 28 unless the service has been designated as a very large online platform. If the provider later loses that enterprise status, the exemption continues for 12 months. This exception does not remove DSA duties that sit outside the additional online-platform section or obligations under other law.
Service-scope memo: online-platform classification, whether the service is , and whether any micro or small enterprise exclusion is being relied on.
Risk evidence: usage by minors, complaint and report trends, content or contact risks, harmful commercial-practice risks, recommender tests, ad-delivery tests, and interface-pattern review.
Control register: private-default settings, blocking and muting controls, group-add consent, reporting and feedback tools, parental controls, recommender changes, excessive-use safeguards, and commercial-practice safeguards actually implemented.
Age-assurance rationale: when age verification, age estimation, or no additional age check is used, tied to the specific risk and Article 28's data-minimisation limit.
Advertising evidence: profiling-based targeting blocks for known minors, special-category targeting controls under Article 26, campaign QA results, and incident handling for misdelivery.
Governance record: owner, decision date, product surfaces covered, source citations, test results, residual issues, and reassessment triggers such as a new feature, audience change, national age rule, or revised Commission guidance.
Build an official source DSA minors-protection review
Sorena can help structure Article 28 scope, targeted-ad restrictions, recommender controls, guideline recommendations, and age-assurance rationale into a reusable evidence record.
Commission guidelines hub stating that DSA guidelines are non-binding recommendations whose voluntary implementation does not automatically establish compliance.