Article content
In briefShow moreShow lessThe draft proposed private-by-default settings, controls for recommender systems and contact functions, and age assurance.
- The draft proposed private-by-default settings, controls for recommender systems and contact functions, and age assurance.
- It also addressed reporting and governance for platforms accessible to minors.
- The document was under consultation and was not final binding guidance or an amendment to the GDPR.
Status of the draft
The Commission published draft guidelines for platforms accessible to minors under the Digital Services Act. The guidelines were intended to clarify practical approaches to safety and privacy for children and young people. Because the document was a consultation draft, its contents had to be described as proposed practice rather than completed binding law or final guidance.
Private-by-default settings
One central proposal was private-by-default settings. This could reduce unwanted exposure and make it harder for strangers to contact minors without safeguards. The proposal had to be considered alongside each service’s features and risks. It was not a general licence to collect additional information, and it did not change the rules governing personal-data processing.
Recommender systems
The draft also addressed recommender systems. Platforms were expected to consider how recommendations affect minors and which controls could reduce harmful or unwanted content. The proposal connected product design more closely with risk management. It had to be understood within the DSA framework, not as a separate new statute applying in the same way to every digital service.
Contact and age assurance
Contact functions and age assurance were further topics. Platforms might need measures limiting unwanted contact while designing age checks proportionately and with privacy safeguards. The draft did not establish that one particular technical method was mandatory. Age assurance therefore needed to be assessed against necessity, risk and data minimisation rather than treated as an automatic requirement to identify every user.
Reporting and governance
The proposals included reporting and governance. This points towards clear internal responsibilities, documented assessments and processes for handling incidents or concerns involving minors. Such arrangements can make compliance more reviewable, but the precise legal effect depended on the final guidance and on which DSA obligations applied to the particular service.
Norway and scope
The document was EU guidance under development. It did not amend the GDPR and did not complete Norway’s implementation of the DSA. Norwegian platforms nevertheless needed to assess whether services reaching EU users fell within the DSA’s territorial scope. EEA incorporation and national implementation had to remain distinct from the EU process and from the binding status of the regulation itself.
Sources
European Commission: “Draft guidelines on protection of minors online,” 13 May 2025.
European Commission: “The Digital Services Act – policy overview.”
For discussion
How can platforms test private defaults and age assurance without collecting more personal data than their risk assessment justifies?

