Lawyers at Pinsent Masons say that social-media platforms face significant challenges establishing parental responsibility under a European Commission proposal unveiled last week.
The EU Kids Act, announced by commission president Ursula von der Leyen, proposes a ban on social media for children under the age of 13.
From 13 until a child turns 15, there will be access only to ‘mini’ accounts set up and supervised by parents, with limited features and time restrictions.
In a note on the firm’s website, Pinsent Masons notes that the draft regulation defines a guardian as ‘a person holding parental responsibility under applicable national law’.
The firm adds, however, that the practicalities of verifying that status are less clear.
“The practical question is: how does a platform check the authority of the person claiming to be the guardian in accordance with the relevant national law?” says Lauro Fava (online-safety expert at Pinsent Masons).
He points out that the proposed regulation specifies that providers must be able to use signals of parental responsibility based on freely accessible official sources made available by member states.
“Until the commission issues more detailed rules on how parental responsibility should be checked, providers are also allowed and required to rely on a self-declaration by the guardian,” Fava states.
“The catch is that the provider is still required to make reasonable efforts to verify the information it obtains – including that a self-declaration is made by an adult exercising parental responsibility,” he adds.
The Pinsent Masons lawyer says that the challenges associated with establishing parental responsibility may prove even more difficult than age verification, given the need for platforms to navigate different national rules governing parental authority.
Parental authority can derive from the law, court decisions or binding agreements, he notes, and different aspects of parental authority can be governed differently.
On age assurance, the proposal takes what Fava describes as “a highly prescriptive approach”, containing detailed requirements to ensure that age-assurance systems are privacy-preserving.
“It goes as far as requiring age-assurance measures to be 'zero knowledge' proof, which rules out numerous mechanisms currently in use, and in some cases mandates the use of certified EU age-verification solutions,” he states.
“While these requirements assume the availability of EU age-verification solutions, the relevant framework is still under development and is intended to operate in tandem with the [EU’s] eIDAS digital-identity architecture,” Fava adds.
The lawyer says that the draft rules could also require providers to establish the age of existing users within six months of the legislation becoming applicable, with accounts being disabled where age cannot be verified.
Pinsent Masons notes that, rather than setting up a dedicated EU child-safety regulator, the proposal allocates enforcement responsibilities across existing frameworks – including the Digital Services Act, AI Act, and GDPR.
Fava says that, while this approach represents a deliberate policy choice to avoid creating a new regulator, it carries the risk of fragmented oversight.
The proposal now enters the EU legislative process, where member states and the European Parliament will consider amendments before negotiations on a final text begin.
Fava concludes that the process is likely to take many months and, potentially, years, despite political momentum behind stronger protections for children online, with debates over age verification, privacy, freedom of expression, and the appropriate level of restrictions for likely to prove contentious during negotiations.