lexiara

§2 SCOPE OF THE GUIDELINES

4. It is in the light of the aforementioned risks that the Union legislature enacted Article 28 of Regulation (EU) 2022/2065 of the European Parliament and the Council (6). Paragraph 1 of this provision obliges providers of online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors, on their service. Paragraph 2 of Article 28 of Regulation (EU) 2022/2065 prohibits providers of online platform from presenting advertisements on their interface based on profiling, as defined in Article 4, point (4), of Regulation (EU) 2016/679 (7), using personal data of the recipient of the service when they are aware with reasonable certainty that the recipient of the service is a minor. Paragraph 3 of Article 28 of Regulation (EU) 2022/2065 specifies that compliance with the obligations set out in this Article shall not oblige providers of online platforms accessible to minors to process additional personal data in order to assess whether the recipient of the service is a minor. Paragraph 4 of Article 28 of Regulation (EU) 2022/2065 provides that the Commission, after consulting the European Board for Digital Services (‘the Board’), may issue guidelines to assist providers of online platforms in the application of paragraph 1. 5. These guidelines describe the measures that the Commission considers that providers of online platforms accessible to minors should take to ensure a high level of privacy, safety and security for minors online, in accordance with Article 28(1) of Regulation (EU) 2022/2065. The obligation laid down in that provision is addressed to providers of online platforms whose services are accessible to minors (8). Recital 71 of that Regulation further clarifies that ‘[a]n online platform can be considered accessible to minors when its terms and conditions permit minors to use the service, when its service is directed at or predominantly used by minors, or where the provider is otherwise aware that some of the recipients of its service are minors’. 6. As regards the first scenario described in that recital, the Commission considers that a provider of an online platform cannot solely rely on a statement in its terms and conditions prohibiting access to minors, to argue that the platform is not accessible to them. If the provider of the online platform does not implement effective measures to prevent minors from accessing its service, it cannot claim that its online platform falls outside the scope of Article 28(1) of Regulation (EU) 2022/2065 based on that declaration. For example, providers of online platforms that host and disseminate adult content, such as online platforms disseminating pornographic content, and therefore restrict, in their terms and conditions, the use of their service to users over the age of 18 years old, will be considered accessible to minors within the meaning of Article 28(1) of Regulation (EU) 2022/2065 when no effective measures have been put in place to prevent minors from accessing their service. 7. As regards the third scenario, recital 71 of Regulation (EU) 2022/2065 clarifies that one example of a situation in which a provider of an online platform should be aware that some of the recipients of its service are minors is where that provider already processes the personal data of those recipients revealing their age for other purposes, such as during registration in the relevant service, and this reveals that some of those recipients are minors. Other examples of situations in which a provider can reasonably be expected to be aware that minors are amongst the recipients of its service include those in which the online platform is known to appeal to minors; the provider of the online platform offers similar services to those used by minors; the online platform is promoted to minors; the provider of the online platform has conducted or commissioned research that identifies minors as recipients of the services or where such identification results from an independent research. 8. Pursuant to Article 19 of Regulation (EU) 2022/2065, the obligation laid down in Article 28(1) of Regulation (EU) 2022/2065 does not apply to providers of online platforms that qualify as micro or small enterprises, except where their online platform has been designated by the Commission as a very large online platform in accordance with Article 33(4) of that Regulation (9). 9. Other provisions of Regulation (EU) 2022/2065 also aim at ensuring the protection of minors online (10). These include, among others, several provisions in Section 5 of Chapter III of Regulation (EU) 2022/2065, which imposes additional obligations on providers of very large online platforms (‘VLOPs’) and very large online search engines (‘VLOSEs’) (11). These guidelines do not aim to interpret those provisions and providers of VLOPs and VLOSEs should not expect that adopting the measures described below, either partially or in full, suffices to ensure compliance with their obligations under Section 5 of Chapter III of Regulation (EU) 2022/2065, as those providers may need to put in place additional measures which are not set out in these guidelines and which are necessary for them to comply with the obligations stemming from those provisions (12). 10. Article 28(1) of Regulation (EU) 2022/2065 should also be seen in the light of other Union legislation and non-binding instruments which aim to address the risks to which minors are exposed online (13). Those instruments also contribute to achieving the objective of ensuring a high level of privacy, safety and security of minors online, and thus complement the application of Article 28(1) of Regulation (EU) 2022/2065. These guidelines should not be understood as interpreting or pre-empting any obligations arising under those instruments or under Member State legislation. Supervision and enforcement of those instruments remain the sole responsibility of the competent authorities under those legal frameworks. In particular, as clarified in recital 10 of Regulation (EU) 2022/2065, that Regulation is without prejudice to other acts of Union law regulating the provision of information society services in general, regulating other aspects of the provision of intermediary services in the internal market or specifying and complementing the harmonised rules set out in Regulation (EU) 2022/2065, such as Directive 2010/13/EU, as well as Union law on consumer protection and on the protection of personal data, in particular Regulation (EU) 2016/679. 11. While these guidelines set out measures that aim at ensuring a high level of privacy, safety and security for minors online, providers of online platforms are encouraged to adopt those measures for the purposes of protecting all users, and not just minors. Creating a privacy preserving, safe and secure online environment for all users will inherently result in more privacy, safety and security for minors online, while adopting measures ensuring the respect of their specific rights and needs in line with Article 28 of Regulation (EU) 2022/2065. 12. By adopting these guidelines, the Commission declares that it will apply these guidelines to the cases described therein and thus impose a limit on the exercise of its discretion whenever applying Article 28(1) of Regulation (EU) 2022/2065. As such, these guidelines may therefore be considered a significant and meaningful benchmark on which the Commission will base itself when applying Article 28(1) of Regulation (EU) 2022/2065 and determining the compliance of providers of online platforms accessible to minors with that provision (14). The Digital Services Coordinators and competent national authorities may also draw inspiration from these guidelines when applying and interpreting Article 28(1) of Regulation (EU) 2022/2065. Nevertheless, adopting and implementing the measures set out in these guidelines, either partially or in full, shall not automatically entail compliance with that provision. 13. Any authoritative interpretation of Article 28(1) of Regulation (EU) 2022/2065 may only be given by the Court of Justice of the European Union, which amongst others has jurisdiction to give preliminary rulings concerning the validity and interpretation of EU acts, including Article 28(1) of Regulation (EU) 2022/2065. 14. Throughout the development of the guidelines the Commission has consulted with stakeholders (15), including with the Board and its working group on protection of minors. In accordance with Article 28(4) of Regulation (EU) 2022/2065, the Commission consulted the Board on a draft of these guidelines prior to their adoption on 2 July 2025. 15. The measures described in Sections 5 to 8 of these guidelines are not exhaustive. Other measures may also be deemed appropriate and proportionate to ensure a high level of privacy, safety and security for minors in accordance with Article 28(1) of Regulation (EU) 2022/2065, such as measures resulting from compliance with other pieces of Union legislation (16) or adherence to national guidance on the protection of minors or technical standards (17). In addition, new measures may be identified in the future that enable providers of online platforms accessible to minors to better comply with their obligation to ensure a high level of privacy, safety and security of minors on their service.

· All articles ·

Source: EUR-Lex (Cellar) · retrieved 2026-09-07