Artifact GuideEU DSA

DSA Article 28 Minors Protection

A source-based guide for online platforms assessing the EU Digital Services Act duties on minors' privacy, safety, security, and profiling-based advertising.

Use it to separate binding Article 28 duties from the Commission's voluntary 2025 guideline measures, including age assurance and safer platform design.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Article 28 of the EU Digital Services Act requires an online platform to put appropriate and proportionate measures in place for a high level of minors' privacy, safety, and security. It also prohibits profiling-based advertising when the platform is aware with reasonable certainty that the recipient is a minor. Article 28 does not require extra personal-data processing solely to determine whether a recipient is a minor.

Section 1

What Article 28 requires for platforms accessible to minors

Determine the service's scope before selecting controls. Recital 71 says an online platform is when its terms allow minors to use it, it is directed at or predominantly used by minors, or the provider is otherwise aware that some recipients are minors. Record the terms, intended audience, actual use, and reliable age information already available to the provider.

Article 19 exempts qualifying micro and small enterprises from the DSA's additional online-platform obligations, including Article 28, unless they are designated as a very large online platform. After a provider loses micro or small enterprise status, the exemption continues for 12 months. Other DSA duties outside that section may still apply.

Article 28 sets an outcome and proportionality standard; it does not prescribe one control set for every service. The platform should connect each measure to the risks created by its purpose, design, size, and user base. The Commission's 2025 guidelines recommend specific measures, but following them is voluntary and does not by itself establish compliance.

  • Classify whether the service is an online platform and whether it is under the platform terms, audience, usage evidence, or age data already processed for another purpose.
  • Describe the minors-specific risks the service creates: unsolicited contact, harmful content exposure, addictive or excessive-use patterns, cyberbullying, harmful commercial practices, or access to adult-only products and content.
  • Map each control to a specific privacy, safety, or security risk for minors and explain why it is proportionate for the product's size, purpose, interface, and user base.
  • Keep the Article 28 record separate from broader DSA duties such as content moderation, statement-of-reasons reporting, marketplace traceability, and VLOP systemic-risk assessments.
Section 2

Targeted advertising and age-data boundaries

Article 28 prohibits an online platform from presenting advertisements on its interface based on profiling, as defined by the GDPR, using the recipient's personal data when the provider is aware with reasonable certainty that the recipient is a minor. The Article 28 ban is limited to profiling-based advertising. Non-profiled advertising still requires assessment under the DSA and any other applicable consumer, privacy, advertising, or national child-protection rules.

The DSA does not define one universal signal for 'reasonable certainty.' A provider should document which information it already has, why that information reaches or does not reach the standard, and how its ad systems act on the result. Article 28 also says compliance does not oblige a platform to process additional personal data solely to assess whether a recipient is a minor.

  • Block profiling-based ad delivery for accounts, sessions, cohorts, or surfaces where the platform is aware with reasonable certainty that the recipient is a minor.
  • Document which existing signals support reasonable certainty, such as a declared date of birth, a child account, a parental setup, or other age information already processed, without assuming that any one signal is conclusive in every service.
  • Do not turn Article 28 into a general obligation to collect age from every user; record when age assurance is used because the risk profile or Commission guidelines support it.
  • Keep ad-system evidence: policy rules, targeting exclusions, delivery logs, campaign QA, advertiser controls, and tests showing minor profiles are excluded from profiling-based targeting.
Section 4

Recommender, interface, and VLOP controls that may overlap

Other DSA provisions may overlap with Article 28. Article 27 requires online platforms using recommender systems to explain the main parameters in plain and intelligible language and provide options to modify or influence them. For VLOPs and VLOSEs, Article 38 adds at least one recommender option that is not based on profiling.

For very large services, minors protection can also appear inside systemic-risk work. The DSA risk-assessment and mitigation provisions refer to children's rights, protection of minors, physical and mental well-being, recommender systems, advertising systems, interface design, content moderation, and internal documentation.

  • For all online platforms with recommender systems, keep terms-and-interface evidence showing the main recommender parameters and user controls.
  • For VLOPs and VLOSEs, keep evidence that each recommender system has at least one non-profiling option and that the option is available where recommendations are presented.
  • When minors are a material user group, test whether ranking, autoplay, notifications, chatbots, group suggestions, or ad selection can increase exposure to harmful content, unwanted contact, or excessive-use patterns.
  • For VLOP systemic-risk files, preserve supporting documents for risk assessments and connect minors-risk mitigations to design, recommender, advertising, moderation, staffing, and governance changes.
Section 5

Evidence checklist for a minors-protection review

An Article 28 file should show why the service is or is not , what the provider knew, which risks it identified, which controls it selected, and why those controls are proportionate. It should also distinguish a decision not to collect more age data under Article 28(3) from a decision to use age assurance because the service's risks or another applicable rule supports it.

The record should let design, advertising, trust and safety, data science, policy, legal, privacy, and compliance teams test the same scope and control claims.

Does DSA Article 28 require every online platform to verify every user's age?

No. Article 28 requires appropriate and proportionate minors-protection measures and restricts profiling-based ads to minors when the platform is aware with reasonable certainty that the recipient is a minor. It also says compliance does not oblige platforms to process additional personal data to assess whether a recipient is a minor.

When do the Commission's DSA minors guidelines recommend age assurance?

The voluntary guidelines recommend age assurance that is accurate, reliable, robust, non-intrusive, and non-discriminatory. They recommend age verification for access to adult content such as pornography and gambling and where national rules set a minimum age for specified services. They recommend age estimation in other cases, including where terms set a minimum age below 18 because of identified risks to minors. The correct method still depends on the service, risk, and other applicable law.

Are micro and small online-platform providers exempt from DSA Article 28?

A provider that qualifies as a micro or small enterprise is exempt from the DSA section containing Article 28 unless the service has been designated as a very large online platform. If the provider later loses that enterprise status, the exemption continues for 12 months. This exception does not remove DSA duties that sit outside the additional online-platform section or obligations under other law.

  • Service-scope memo: online-platform classification, whether the service is , and whether any micro or small enterprise exclusion is being relied on.
  • Risk evidence: usage by minors, complaint and report trends, content or contact risks, harmful commercial-practice risks, recommender tests, ad-delivery tests, and interface-pattern review.
  • Control register: private-default settings, blocking and muting controls, group-add consent, reporting and feedback tools, parental controls, recommender changes, excessive-use safeguards, and commercial-practice safeguards actually implemented.
  • Age-assurance rationale: when age verification, age estimation, or no additional age check is used, tied to the specific risk and Article 28's data-minimisation limit.
  • Advertising evidence: profiling-based targeting blocks for known minors, special-category targeting controls under Article 26, campaign QA results, and incident handling for misdelivery.
  • Governance record: owner, decision date, product surfaces covered, source citations, test results, residual issues, and reassessment triggers such as a new feature, audience change, national age rule, or revised Commission guidance.
Primary sources

References and citations

Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.