ProposalSupporting material to the proposal
This view contains the explanatory memorandum and the Legislative Financial and Digital Statement. Read the proposed legislation.
EXPLANATORY MEMORANDUM
1 CONTEXT OF THE PROPOSAL
Reasons for and objectives of the proposal
Only half of children aged 9-16 across Europe say they feel safe online. The risks faced by minors online are real and urgent, and impact their health, development and wellbeing, such as for example reduced physical activity, increased risk of myopia and reduced sleep, depressive and anxious symptoms, decrease self-esteem, negative impact on learning and cognitive development, eating disorders, decreased empathy, loneliness and addictive behaviours. Minors online also face risks of cyberbullying, child sexual abuse and grooming.
The protection of minors online is a political priority of the Commission. In her 2025 State of the Union, Commission President Ursula von der Leyen announced that she will commission a panel of experts to advise her on the best approach for Europe on child safety online. After a process in the first half of 2026 involving a wide range of experts from different fields, as well as representatives from industry, parents and youth, the co-chairs of the Special panel presented their recommendations to the President in July 2026. The recommendations set out a clear path for enhancing the safety of minors online and ensuring the functioning of the Single Market. In particular, they recommend an EU-wide access restriction, harmonised safety-by-design rules as well as proportionate, privacy-preserving age assurance systems. Finally, they recommend covering digital services beyond social media platforms, including app stores, AI companions and some video games and video-sharing platforms offering risky features.
In October 2025, the Jutland Declaration signed by 25 Member States called for age verification and for a safer online environment for minors. In its conclusions of March 2026 and of October 2025, the European Council also stressed the importance of protecting minors online, including through a digital age of majority. In its report of November 2025 on the protection of minors online, the European Parliament called for a harmonised European digital age limit of 16 years for access to social media, video-sharing platforms and AI companions unless parents or guardians have authorised their children otherwise. It also called upon a harmonised European digital age limit of 13, under which no minor can access social media platforms. The European Parliament also recognised the need for additional legislation on age-appropriate design and safety by design. It further called for a European approach regarding age assurance ensuring legal certainty.
Across the European Union, Member States are discussing or proposing national legislation to enhance the safety of minors online. Italy, France, Norway, Greece, Austria, Poland and Belgium notified in 2025 and 2026 their draft legislation limiting access to certain digital services for minors under a certain age. Norway also notified its legislation in May 2026. In almost all other Member States, consultations are ongoing, drafts are discussed in national parliaments or have been announced by governments. Proposed national draft legislations differ in terms of scope, age limits and types of restrictions imposed, risking fragmenting the single market, reducing legal certainty and increasing compliance costs while providing an uneven level of protection for minors across the European Union.
The current online environment is not designed with minors in mind. While legislation already exists to create a safer online environment, no single legislation takes the children and their safety and empowerment as the starting point. Building on the key principles set out in Regulation (EU) 2022/2065 and Regulation (EU) 2024/1689, this proposal seeks to protect minors from risky digital services and AI systems, uphold the digital single market and maintain a coherent regulatory framework and enforcement structure for the protection of minors online.
The proposal recognises the risks that minors face on certain online social networking services and video-sharing platforms and therefore limits autonomous account creation on those specific platforms and systems by children below the age of 15 years. By providing one age across the European Union, it harmonises diverging national rules removing obstacles to the implementation of the Digital Single Market, ensuring legal certainty and a similar level of protection for all children in the European Union. This is combined with rules that recognise the role of parents and legal guardians in supporting the safe development of minors online, by creating accounts with limited functionalities for minors on from 13 years as well as rules to create an environment of safe services and systems for very young children with strict parental supervision and which takes into account their development. In line with the developmental approach recommended by the co-chairs of the Special Panel on Child Safety Online, minors below the age of 13 should not have access to harmful online social networking services and video-sharing platform services.
The proposal sets out clear safety by design requirements for online social networking services, video-sharing platform services, online games, AI companions and general conversational chatbots, and software application stores. Building on the recommendations of the co-chairs of the Special panel, it harmonises and extends those requirements ensuring legal certainty across the Digital Single Market and a high level of protection for minors across the digital environment, taking into account that business models are constantly changing in this dynamic field and loopholes must be avoided.
To underpin the access delay and the implementation of safety by design requirements, the proposal establishes a clear framework for age assurance with clear criteria and safeguards for the use and deployment of such systems. By enshrining requirements for the use of age assurance methods, the proposal ensures that the use of those methods will be proportionate, effective, reliable and privacy-preserving. It also provides for common criteria for age assurance ensuring the functioning of the Single Market.
A fast, effective and robust enforcement is critical to the protection of minors online and the functioning of the Single Market. The proposal therefore lays out an enforcement framework that relies on existing enforcement structures while providing for a an expedited enforcement procedure.
Consistency with existing policy provisions in the policy area
The proposal builds on the existing legislative framework for the protection of minors online ensuring the functioning of the Single Market. By building on Regulation (EU) 2022/2065 and Regulation (EU) 2024/1689, it provides continuity and coherence with the EU regulatory framework for digital services and AI systems while developing specific requirements for the protection of minors online taking into account their evolving capacities, safety and empowerment as a starting point.
This proposed Regulation is without prejudice to the Digital Services Act, and builds on the provisions laid down therein, notably on Article 28 regarding the obligation for certain providers of online platforms to take appropriate measures to ensure a high level of privacy, safety and security for minors. The proposed instrument, and in particular its provisions related to safety by design, set in “hard law” those specifications that the Commission has already included in the Guidelines on protection of minors under Regulation (EU) 2022/2065. In doing so it specifies the obligations set out in Article 28 of Regulation (EU) 2022/2065 where these concern safety by design and age assurance requirements. Therefore, ongoing cases related to these obligations under Regulation (EU) 2022/2065, in particular Article 28, remain unaffected. The proposed Regulation is also without prejudice to Regulation (EU) 2024/1689 and builds on its framework, notably on its comprehensive risk-based rules. The proposed Regulation is complementary and does not affect the prohibitions and other obligations and requirements for AI systems and general-purpose AI models already established in Regulation (EU) 2024/1689.
The Better Internet for Kids strategy (BIK+) supports the implementation of this legislative framework, notably Regulation (EU) 2022/2065. Under the BIK+, the EU co-funded network of Safer Internet Centres offers training sessions, helplines and hotlines and run awareness raising activities. They regularly consult children and young people on their needs and view on online safety. In February 2026, the Commission adopted the Action plan against cyberbullying to prevent cyberbullying, raise awareness and make it easier to report and ensure that victims receive adequate support. The proposal is consistent with those non-legislative actions, and builds upon them to give kids in Europe the best support when they use the online environment.
Consistency with other Union policies
The proposed Regulation introduces a horizontal framework for the protection of minors online. This Regulation is without prejudice to the rules laid down by other Union legal acts regulating other aspects of the provision of intermediary services in the internal market, in particular, the rules on audiovisual media services, consumer protection and product safety, and on the protection of personal data.
The proposal will be complemented by further actions which would be in full alignment with this Regulation, including the ongoing evaluation and upcoming review of the Audiovisual Media Services Directive that will additionally look at the protection of minors as viewers and will ensure that they are sufficiently protected when watching audiovisual content. Considering new threats and risks, it will examine whether further specification of the concept of harmful audiovisual content is needed, and what measures are necessary to ensure that minors do not encounter such content.
Furthermore, the upcoming Digital Fairness Act (“DFA”) aims at strengthening and making consumer protection law fit for purpose, also in the digital environment, in full alignment with the obligations in this Regulation. Consumer law plays an important role in ensuring that consumers, children in their consumer role included, are not exposed to unfair or misleading practices. The Unfair Commercial Practices Directive (“UCPD”) in particular acknowledges children as vulnerable consumers that need enhanced protection; it also bans a direct exhortation to children to buy advertised products or persuade their parents or other adults to buy those products for them. Furthermore, as part of the revision of the existing consumer protection law, the CPC Regulation will also be revised to strengthen the existing enforcement coordination system for national authorities and vest in the Commission direct investigation and enforcement powers in specific cases.
Additionally, the recent changes to Regulation (EU) 2024/1689 prohibiting AI systems generating child sexual abuse material, the on-going adoption of Regulation to prevent and combat child sexual abuse, together with the recently adopted Recast of the Child Sexual abuse directive, strengthens the EU framework against child sexual abuse and exploitation, both online and offline. They will improve prevention, investigation and support for victims.
The proposal is also fully consistent and further supports existing or upcoming initiatives to empower and support minors and ensure their well-being online, including the EU Strategy on the rights of the child8, the Commission Recommendation on developing and strengthening integrated child protection systems in the best interests of the child9, the Digital Education Action Plan (2021-2027)12, as well as the forthcoming 2030 Roadmap on the future of digital education and skills.
Child safety online is a global challenge requiring international cooperation. The proposal is consistent with the Union’s external policies, including the International Digital Strategy (2025) through which the EU expands and deepens its cooperation bilaterally, regionally and multilaterally. The proposal harmonises legislation EU-wide which will support the effectiveness of the EU’s external cooperation and global influence in child safety online.
2 LEGAL BASIS, SUBSIDIARITY AND PROPORTIONALITY
Legal basis
The legal basis for the proposal is Article 114 of the Treaty on the Functioning of the European Union, which provides for the establishment of measures to ensure the functioning of the Internal Market. This proposal aims to approximate rules with the objective to establish the functioning of the Internal Market and, in accordance with article 114(3), ensuring a high level of protection for the health and safety of children across the European Union considering new technological developments.
The main objective of this proposal is to put in place harmonised provisions to protect minors online. As Member States are discussing or adopting new measures to restrict access to certain online platforms considered risky for children under a specified age, the EU market risks becoming increasingly fragmented. This proposal therefore aims to ensure the proper functioning of the internal market, in particular, in relation to the provision of cross-border online social networking services, video-sharing platform services, software application stores, of AI companions and general conversational chatbots, and of online games. Such a harmonised approach also ensures an equally high level of protection for minors across the EU.
Furthermore, this proposal specifies and complements the relevant provisions of Regulation (EU) 2022/2065 as regards the protection of minors, and complements Regulation (EU) 2024/1689 as regards child-specific safety requirements for AI companions and general conversational chatbots. Since both Regulation (EU) 2022/2065 and Regulation (EU) 2024/1689 have Article 114 of the Treaty on the Functioning of the European Union as a legal basis, this proposal follows the same approach.
Subsidiarity (for non-exclusive competence)
Taking into account that digital services and AI systems are by their nature cross-border, the legislative efforts at national level mentioned above for delayed access of minors hamper the provision of digital services and systems cross-border, create legal uncertainty and obstacles to the implementation of the Single Market, high compliance costs and an unequal level of protection for minors across Europe.
The potential consequences in the absence of immediate action also call for urgent action. Member States are already adopting their own legislation. In 2025 and 2026, several TRIS notifications (Italy, France, Norway, Greece, Poland, Austria, Belgium) were received on age restrictions for certain types of digital services. In almost all other Member States, consultations are ongoing, drafts are discussed in national parliaments or have been announced by governments. National laws differ in terms of scope, age limits and types of restrictions imposed. They propose different definitions or criteria for the types of digital services whose access is to be limited, different ages limits (from 13 to 16 years old), eventually dependent on parental consent. Some of the national legislations under discussion include additional obligations on safety by design. The proliferation of national legislations, with different legal obligations, significantly risks fragmenting the Single Market, reducing legal certainty and increasing compliance costs for providers of digital services while providing an uneven level of protection for minors across the European Union.
Harmonising the rules to protect minors and provide them with a safe online environment should be done at Union level, thereby providing predictability and certainty, reducing compliance costs across Europe and ensuring that all minors, no matter where they live are served by a high level of privacy, safety and security online.
Proportionality
The proposal aims to ensure a strong and coherent framework for the protection of minors online. It does so by introducing an EU-wide access restriction to social media+ for under 13-year-olds. The approach allows for the creation of parental accounts for children between 13 and 15 years. It provides for harmonised access to safe social networking services and video-sharing platforms as of 15 years old, combined with clear safety by design obligations and clear requirements and criteria for the use of age assurance.
The proposal takes the report of the co-chairs of the Special Panel on Child Safety as the starting point, which sets out clearly the risks that minors face online. Against that background, it puts in place a framework that tackles the risks on the services mentioned in the report, without disproportionately impacting fundamental rights (see section below).
Key features of the proposal limit the Regulation to what is strictly necessary to achieve the objectives of the proposal. In particular, the proposal sets out obligations on different types of digital services and systems, depending on the nature of the service or system to ensure that they are targeted and proportionate. This approach addresses the identified problems, while not overburdening providers unconcerned by such problems. The substantive obligations are limited to online social networking services, video-sharing platform services, online games, and providers of software application stores. Following a co-regulatory approach, they build on co-regulatory initiatives for the services in scope of this Regulation, including regarding software application stores and online games. As regards AI systems, the proposal is limited to AI companions and general conversational chatbots that may pose serious risks to health, safety and well-being of minors that are not covered by safety by design requirements specifically aimed to address those risks to minors under Regulation (EU) 2024/1689.
At the same time, small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope.
Exempted from scope because they are unlikely to pose harms to minors are not-for-profit online encyclopaedias, not-for-profit educational and scientific repositories, services and systems that are designed for purely educational purposes and operated within educational establishments or organisations, open-source software-developing and-sharing platforms, unless the platform itself constitutes an AI system in scope of this Regulation and Regulation (EU) 2024/1689, services and systems specifically developed and operated for the sole purpose of scientific research and development, and services and systems designed, developed and operated by public authorities and for exclusive use of said public authorities or on their behalf.
By establishing a clear framework, accompanied by cooperation between Member States, as well as by co-regulation, this proposal aims to enhance legal certainty, ensure the functioning of the Single Market and increase trust levels.
Choice of the instrument
Article 114 of the Treaty on the Functioning of the European Union gives the legislator the possibility to adopt regulations and directives.
The Commission has decided to put forward a proposal for a Regulation to ensure a consistent level of protection for minors throughout the Union and to prevent divergences hampering the free provision of the relevant services and systems within the internal market. This is necessary to provide legal certainty and transparency for economic operators and children and parents alike.
3 RESULTS OF EX-POST EVALUATIONS, STAKEHOLDER CONSULTATIONS AND IMPACT ASSESSMENTS
Stakeholder consultations
The proposal directly follows on the recommendations of the co-chairs of the Special Panel on Child Safety Online. As an independent process, the Special panel on child safety online examined risks and opportunities for children on digital services as well as the existing regulatory framework and its gaps. It gathered extensive data and expertise. This independent process brought together experts across the European Union from different fields, including health, child psychology and psychiatry, computer sciences, digital technology and media, social sciences and children’s rights. Representatives from youth groups, parents’ group and children’s rights organisations also participated in the meeting. Additional stakeholders provided input throughout the process such as the OHCHR, specialised think-tanks, industry representatives as well as the European Data Protection Board.
Youth was also consulted in preparation of this proposal. The President Youth Advisory Group discussed child safety and wellbeing online in its meeting of December 2026, bringing together the views of children from across all 27 EU Member States. The Group brings together more than 30 young representatives, one from each EU Member State’s National Youth Council, one from the European Youth Forum, and observers from candidate countries and potential candidates for EU accession. In December 2025, the Safer Internet Forum, which involved over 200 children, young people and representatives from civil society, industry and national authorities discussed the topic ‘Why age matters: Protecting and empowering youth in the digital age’. Better Internet for Kids Youth ambassadors and youth representatives from the child participation platforms were also actively included in the Special panel. Across the groups, youth representatives emphasised the responsibility of digital services in providing safe and age-appropriate services. They highlighted the need for requirements for safety by design, including age-appropriate defaults settings, recommender systems and interface design.
This consultative process is complemented by the Commission’s wider stakeholder engagement in the area of child safety online. This includes consultative processes undertook in the context of the implementation and enforcement of the Digital Services Act as well as the Better Internet for Kids Strategy and its network of Safer Internet Centres and Better Internet for Kids Youth Ambassadors. In the context of the adoption of the guidelines on the protection of minors under Regulation (EU) 2022/2065, a 2024 Call for Evidence, which received more than 170 feedbacks, and a 2025 public consultation, with more than 300 inputs, provided detailed information from a wide range of stakeholders including researchers, civil society, industry and public authorities on good practices and measures on online platforms to design a safe online service for kids. A majority of respondents shared positive view on the measures introduced by the Guidelines, which are largely codified by the present proposal. They also requested additional clarity on the legal nature of the guidelines, and on the situations under which age verification and age estimation are appropriate.
Between March and April 2026, the Commission conducted a Eurobarometer survey on the impact of excessive screen time and social media on young people’s mental health collecting data from more than 26,000 13-18 years old and more than 12,000 parents across all 27 Member States. The findings show that screen time is a major part of adolescent’s daily life, with major risks as nine in ten adolescents have encountered at least one harmful or distressing piece of content online in the past three months, with concerns also regarding interpersonal harms and cyberbullying. 54% of parents and 45% of 13-18 years old consider age delays to be an effective solution and 47% of parents and 48% of adolescents call for better implementation of existing rules by digital services.
Furthermore, the Commission is receiving additional evidence sources on a continuous basis from the European Board for Digital Services and the national Digital Services Coordinators who are responsible for supervising the smaller online platforms and ensuring they provide a safe environment for minors and who closely monitor this area on the ground.
Additional consultative processes where also conducted under related European initiatives, such as the Digital Fairness Act and the Audiovisual Media Services Directive. The consultation and call for evidence on the Digital Fairness Act was opened for 12 weeks on 17 July 2025, collecting extensive feedback from citizens, public authorities and other stakeholders, which collected relevant evidence on addictive design of digital products and deceptive or manipulative interface design, including the impact on such practices on minors. For instance, 5,000 children from the EU Children’s Participation Platform were consulted on digital fairness, under the EU Strategy on the rights of the child. Furthermore, on 10 February 2026 the Commission launched a public consultation for the assessment of the Impact of the audiovisual media services directive, collecting feedback from an equally wide range of stakeholders, including on the best ways to strengthen the protections for minors online. Both consultative processes provided relevant evidence for the purpose of this proposal.
Impact assessment
The most important elements of this proposal build on a rich body of evidence from very different sources, including Impact Assessments informing other, either already adopted or forthcoming, legislative initiatives.
Therefore, the proposed Regulation and its accompanying Staff Working Document (“SWD”) on the impacts of the proposal are underpinned by a solid evidence base.
First, the Special panel on Child Online Safety brought together over 60 experts from various fields including health, child psychology and psychiatry, computer and social science, as well as representatives from youth groups, parents’ groups and children’s rights organisations, and the co-chairs also met with the OHCHR, specialised think-tanks, industry and the European Data Protection Board.
Second, the dedicated analysis of impacts presented in the SWD builds on existing impacts assessments, including for the DSA, Digital Markets Act (“DMA”), AI Act, the proposal for a Regulation to prevent and combat child sexual abuse and the recast Directive on combating the sexual abuse and sexual exploitation of children and child sexual abuse material, as well as the upcoming Digital Fairness Act and the Audio-visual Media Services Directive (“AVMSD”).
Third, evidence and data are collected through implementation and enforcement of the DSA, notably 10 preliminary findings in relation to the protection of minors including on addictive design, safe accounts and age assurance, as well as studies, risk assessment reports and stakeholder engagement, in particular during the development of the guidelines on the protection of minors which involved a call for evidence, a public consultation, engagement with children and young people and meetings with the European Board for Digital Services. In this context, engagement with national authorities within the supervisory and enforcement framework of the DSA is ongoing. This provides valuable inputs from investigations and many Member States have conducted inquiries and consultations regarding their national draft laws on the protection of minors, such as Sweden and Germany.
Fourth, international engagement and cooperation further points to sources of evidence by public authorities as well as regulators. The Commission is closely cooperating with other regulators including from Australia and the UK that conduced impact assessments and studies, as well as Brazil and Japan.
Fifth, additional studies include a vast body of academic research, a Eurobarometer on the impact of excessive screen time and social media on young people’s mental health conducted in 2026 and a study procured by the Commission on the impacts of age assurance on fundamental rights and its economic costs.
The Commission prepared an accompanying analytical Staff Working Document, including (i) a problem definition, (ii) the explanation of the followed approach, and (iii) an assessment of impacts. The Staff Working Document builds on the report of the co-chairs of the Special panel, as well as evidence and data collected in the context of the Digital Services Act implementation and enforcement, and the preparation of impact assessments, notably for the Digital Fairness Act and the review of the Audiovisual Media Services Directive.
The Staff Working Document outlines the main social and economic impacts of the proposal. In terms of social impacts, the health of minors should be improved as both a direct and indirect impact of the proposal. By delaying access to certain specific services and providing safeguards for age-appropriate digital services, the online environment will become a safer place for minors, limiting the risks they encounter online and their impact on their cognitive development as well as their physical and mental health.
In terms of economic impacts, the marginal costs introduced by this proposal are expected to remain relatively limited with regard to the implementation of most safety by design requirements as these were already present in the Guidelines on the Protection of Minors under article 28 of the Digital Services Act. The requirements to prepare compliance plans and to rely on audits are largely included already in the risk assessments and audit provisions in the Digital Services Act. They also concern providers with a very large user base (45 million monthly active users) which should limit the impact on SMEs since, in principle, they do not reach a scale in their user base equivalent to that of very large online platforms. The implementation of age assurance measures and parental control tools will lead to additional costs for digital services providers. It is not possible to conclusively determine the costs of these adjustments and their incidence, especially for the potentially large number of small and micro providers of online social networking services, video-sharing platform services and video games that were previously not subject to article 28 of the Digital Services Act. However, those costs are mitigated by the development of the EU Age verification solution, the expected increased development of the market for safe design solutions and the fact that similar requirements already exist in EU law and increasingly in third countries. It should also be considered that many digital services providers would likely face many of these costs repeatedly under national legislation, and thus benefit from harmonized rules.
Fundamental rights
The proposal aims at improving, promoting and supporting the respect of the rights of the child online, as enshrined in the Charter of Fundamental Rights of the European Union (“the Charter”). The objective of the access delay is to ensure the comprehensive rights of the child online, including their rights to protection necessary for their wellbeing, health and security, privacy, participation, express their views freely, in line with their age and maturity, taking their best interests as a primary consideration, ensuring their right to development and self-determination free from the risks and harms posed by certain online services and systems. While the services in scope of this Regulation pose significant risks to the health and security of children, they also allow children to express their views freely and to receive and impart ideas, as protected by Article 24(1) and Article 11(1) of the Charter. Therefore, the access delay is strictly limited to account creations on a very defined set of digital services and systems that use certain design features and make available certain functionalities to minors that are proven to be harmful to the health and safety of minors. This measure ensures that this limitation on the child’s right to freedom of expression remains proportionate and necessary to meet the objective of general interest as required by the Charter. Access to services that are safe, age-appropriate, designed for children and allow for the appropriate parental control and supervision should not be limited. Additionally, exceptions to the delay are provided to ensure access to information, educational materials and public services.
In line with the UN Committee on the Rights of the Child General comment 25, safety by design requirements are established to ensure the respect of the rights of the child online. Safe settings will provide additional privacy to children, while limited contacts with strangers will diminish risks of cyberbullying and grooming.
Parents and guardians also play an important role in the upbringing and development of their children, as recognised by Article 24(3) of the Charter of Fundamental Rights of the European Union. The respect for private and family life, home and communication is safeguarded by Article 7 of the Charter. Article 14(3) of the Charter ensures that the freedom to found educational establishments with due respect for democratic principles and the right of parents to ensure the education and teaching of their children in conformity with their religious, philosophical and pedagogical convictions shall be respected, in accordance with the national laws governing the exercise of such freedom and right, while ensuring the respect of other fundamental rights enshrined in the Charter, including Article 21 on non-discrimination and Article 24 on children’s rights, taking their best interests as a primary consideration.
In recognition of this important role of parents and guardians, the proposal mandates tools for guardians and provides the possibility for parents to set up accounts in a safe environment for 13-15 years old minors. Those tools must be provided in line with the evolving capacities of children, and in respect with their rights to privacy.
Equally, this Regulation ensures respect of children’s rights by strengthening their autonomy. The Regulation requires providers of digital services and systems in scope to provide easy to access and child friendly reporting systems. They must ensure that reports from minors and guardians are addressed as a priority. The Regulation also allows further control over minors’ settings. Furthermore, the proposal helps children in their digital education, literacy and support from parents, caregivers, teachers and educators by providing for Member States to develop national strategies to support the objectives of protecting children online.
Age assurance systems and the requirement to verify the age of users can potentially have important implications for the right to privacy, as well as freedom of expression, participation and non-discrimination of the users. The proposal establishes clear requirements for the deployment and use of age assurance systems as well as safeguards and transitional measures to limit the impact on these fundamental rights to what is strictly necessary to safeguard the health and safety of minors online. These criteria include a high level of accuracy, reliability, robustness, security, non-discrimination and non-intrusiveness. Following a risk-based approach and ensuring proportionality, age verification is only mandated for the implementation of the access delay and limited to new accounts and existing accounts only when the provider cannot tell with a high degree of confidence that the holder of the account is above the age threshold. By enshrining those criteria in law, the proposal provides for clear legal standards for the use and deployment of age assurance systems ensuring a high standard of data protection for their use. This will promote the deployment of an innovative market of age assurance solutions within the Digital Single Market respectful of fundamental rights.
4 BUDGETARY IMPLICATIONS
It is important that the Commission is sufficiently staffed to carry out the activities under this Regulation. This is especially important because, in exercising its tasks, the Commission will have to supervise some of the financially strongest and technologically most sophisticated companies in the world. Supervising these companies will require staff with highly skilled and specialised profiles. The Commission faces a high political risk if enforcement is under-resourced. Calls for quick action to protect European children online are growing, and making sure that the next generation is effectively protected requires adequate staffing – also to deliver on the fast-track enforcement that will be required by this Regulation.
In order to do so the Commission will rely on the supervisory fee as established in Article 43 of the Digital Services Act. Since this proposal is a specification of the Digital Services Act, its resourcing should equally be based on the same supervisory fee. Further details on the budgetary implications are set out in the LFDS.
5 OTHER ELEMENTS
Implementation plans and monitoring, evaluation and reporting arrangements
The proposal will be rigorously evaluated, notably in terms of the effectiveness of the access delay, the personal scope of the access delay and its proportionality and the safety by design requirements. This evaluation shall account for experience gained in the implementation of the proposal as well as technological, market and legal developments.
This will complement ongoing monitoring under the Digital Services Act.
Detailed explanation of the specific provisions of the proposal
Chapter I sets out general provisions, including the subject matter and scope of the Regulation (Articles 1 and 2) and the definitions of key terms used in the Regulation (Article 3). This sections also sets out anti-circumvention rules for providers in scope of this Regulation (Article 4) and obligations on identified providers to notify and undergo an independent audit of a compliance plan (Article 5).
Chapter II contains provisions on the delayed access of minors to social media, laying down that providers of services that have specific features and that constitute social networking services or video-sharing platforms services, or both, shall not allow minors below the age of 15 to create an autonomous account. Furthermore, providers of those services may allow guardians to set up accounts for minors above the age of 13 with limited age-appropriate features to access the service (Article 6). Where providers of video-sharing platform services can demonstrate that they are an age-appropriate service, they may allow guardians to exceptionally enable, access also to minors below 13 years by means of accounts that are created and supervised by the guardians themselves (Article 7).
Chapter III sets out provisions on safety by design applicable to providers of online social networking services, of video-sharing platform services, of AI companions, of general conversational chatbots and of online games.
Section 1 lays down general provisions applicable to providers of online social networking services, of video-sharing platform services, of AI companions, of general conversational chatbots, of online games, and of software application stores. This section specifies that the requirements laid out in this Chapter also apply to unregistered recipients of the service or users of the system, and that it is only possible to derogate from those requirements when it has been established that the recipient of the service or user of the system is an adult, making use of age assurance in accordance with Chapter V (Article 8).
Section 2 lays down provisions applicable to online social networking services and video-sharing platform services. In particular, those services are prohibited from designing, organising or operate their services in a manner that is intended, or can reasonably be foreseen, to encourage compulsive or excessive use of the service by minors and should put in place effective time-management tools which protects core sleep hours and school time of minors (Article 9). Those providers that use recommender systems are obliged to design the information suggested and the optimisation of their recommender systems to minors in way that ensures a high level of privacy, safety and security of minors (Article 10). Furthermore, those providers shall put in place appropriate and proportionate measures to ensure that settings are set by default to a high level of privacy, security and safety of minors which cannot be changed unless minors have explicitly consented to such changes. Those providers shall ensure that features or settings which have any actual or foreseeable negative effects on minors’ privacy, safety and security are not available to minors (Article 11). Those online social networking services and video-sharing platform services are also obliged to put measures in place that ensure a high level of privacy, safety and security of minors as regards contacts between minors and other recipients of the service (Article 12). Finally, the same providers shall ensure that, before an economic transaction takes place, it is transparent to the minor that this is an economic transaction, and that their still developing commercial literacy is not exploited by design, organisation or operation choices which may lead to excessive, impulsive or unwanted spending, which includes not exposing minors to variable reward systems (Article 13).
Section 3 lays down provisions applicable to AI companions and general conversational chatbots. In particular, this section obliges providers to implement safety by design provisions related to addictive design, safe settings and transparency of commercial transactions set out by Article 9, 11 and 13 of Section 2, as well as specific rules tailored to these systems (Article 14). These rules require providers of AI companions and of general conversational chatbots to put in place strong child-safety protections, including designing the systems so minors are not exposed to features that are likely to create emotional dependencies, preventing harmful interactions, and carrying out testing and post-market monitoring to identify and mitigate harms to minors’ safety, health, fundamental rights and well-being and development. Where such systems are deployed as a functionality of an online social networking services, of a video-sharing platform services, of an online game, the providers of those services should ensure that AI companions and general conversational chatbots are not automatically activated, that minors have the possibility to opt out of their used, where enabled, and are not encouraged to use them.
Section 4 lays down provisions applicable to online games. In particular, this section obliges providers to implement safety by design provisions related to addictive design and safe settings set out by Article 9, 11 and 12 of Section 2, as well as specific rules tailored to online games (Article 15). These rules include that online games shall implement safeguards to prevent the online games from being used to entice the minors to initiate contacts on other services which may pose a risk to their privacy, safety and security. Where providers of video gaming platforms allow recipients to create video games the provider shall put in place the necessary software and organisational to allow those video games to comply with the obligations set out in Article 15(1) and (2) and Articles 18 and 20.
Section 5 lays down provisions for age-appropriate access applicable to providers of software application stores. This section obliges those providers to put in place an age-rating system to establish the age-appropriateness of software applications and to assess the age of the recipient of the service through age assurance. Where a software application is not considered age-appropriate, the provider of the software application store shall not allow minors access to such software applications that are age-inappropriate (Article 16). Finally, this section encourages the drawing up of codes of conduct to contribute to the harmonised establishing and application of age-rating systems (Article 17).
Section 6 sets out additional general obligations on agency of minors and empowering tools for minors and guardians applicable to providers of social networking services, of video-sharing platforms services, of AI companions, of general conversational chatbots and of video gaming platforms and games. This section specifies that those providers are obliged to ensure that features, communication, information, user-control tools and mechanisms of the service, warnings, and any other information referred to in Chapter III are easily accessible to all minors and presented in a way that minors can understand. Providers of very large online platforms within the meaning of Article 33(1) of Regulation (EU) 2022/2065 are obliged to present such information in the in the official language(s) of the Member State(s) the service is provided in. Furthermore, providers of social networking services, of video-sharing platforms services, of AI companions, and of general conversational chatbots, and of video gaming platforms are obliged to provide tools enabling minors to control content, their settings and provide to feedback which should have a durable effect on content recommended (Article 18). This section also specifies that those providers are obliged to put in place child-friendly reporting mechanisms and support tools for minors (Article 19) as well as effective, easy to use tools for guardians. Moreover, this section obliges those providers of social networking services, of video-sharing platforms services, of AI companions, and of general conversational chatbots, and of online games to encourage the rollout of such tools and requires providers of very large online platform within the meaning of Article 33(1) of Regulation (EU) 2022/2065 to ensure that these tools for guardians are interoperable with tools for guardians provided by third parties, in accordance with conditions set out by Article 6 of Regulation (EU) 2022/1925 (Article 20). Finally, this section sets out that minors and guardians have the right to lodge a complaint with the competent authority against providers of social networking services, of video-sharing platforms services, of AI companions, and of general conversational chatbots, and of online games alleging an infringement to this Regulation, minors and guardians have the right to mandate a body, organisation or association to exercise the rights conferred by this Regulation on behalf of the minor or their guardian (Article 21).
Section 7 contains other provisions concerning due diligence for a safe environment online It sets out the monitoring obligations for very large online platforms (Article 22), provisions on drawing up codes of conduct (Article 23), and the obligation for services to have in place legal representatives (Article 24). Finally, it sets out that the Commission is empowered to adopt delegated acts to supplement the measures listed in this Chapter to ensure a high level of privacy, safety and security of minors on their service (Article 25).
Chapter IV contains the obligation to verify parental responsibility (Article 26).
Chapter V contains provisions concerning age assurance.
Section 1 sets out the general principles for age assurance. This section specifies that where providers in scope of Chapters II and III have to implement age assurance solutions, they shall provide a high level of accuracy, reliability, robustness, non-intrusiveness, privacy and non-discrimination, and that self-declaration is not sufficient for compliance with this Regulation (Article 27), it also sets out the specific rules for data protection in age assurance (Article 28).
Section 2 complements this with specific obligations for age assurance, setting out that for the purpose of compliance with Articles 5 and 6, providers should put in place age verification, and for the purpose of compliance with Chapter III they may use both age verification and other age assurance solutions under specific conditions (Article 29), complemented by an empowerment for the Commission to specify details set out in the age assurance Chapter (Article 30). Furthermore, this section requires Member States to take the necessary measures to ensure the availability of different means of obtaining a proof of age attestation to verify the minimum age and to make available at least one age verification solution (Article 31). Finally, this section contains measures on age verification for existing accounts (Article 32).
Chapter VI contains a provision on measures for the Member States to prepare and support minors as this Regulation becomes a reality (Article 33).
Chapter VII contains the provisions concerning the competences, supervision and enforcement of the provisions in this proposal that rely on the existing enforcement structures and frameworks under the Regulation (EU) 2022/2065 and Regulation (EU) 2024/1689 to avoid duplications and ensure consistency with the existing rules for intermediary services and AI systems (Article 34). Where the Commission initiates proceedings for services and systems within its exclusive competence, the Commission shall endeavour to adopt a final decision within 90 days and communicate the preliminary findings to the provider concerned within 30 days from the opening of proceedings (Article 35). Finally, it contains a provision on the financing of supervisory and enforcement activities by the Commission under this Regulation (Article 36) and provisions on the development of expertise and incident reaction mechanisms (Articles 37 and 38).
Chapter VIII contains the provisions on implementing and delegated acts (Articles 39 and 40) and Chapter IX contains the final provisions including on the review of the Regulation, inclusion of this Regulation in the Annex of the Representative Actions Directive (Article 41), and the entry into force and application (Articles 42 and 43).
2026/0286 (COD)
LEGISLATIVE FINANCIAL AND DIGITAL STATEMENT
- 1.FRAMEWORK OF THE PROPOSAL/INITIATIVE
- 1.1.Title of the proposal/initiative
- 1.2.Policy area(s) concerned
- 1.3.Objective(s)
- 1.3.1.General objective(s)
- 1.3.2.Specific objective(s)
- 1.3.3.Expected result(s) and impact
- 1.3.4.Indicators of performance
- 1.4.The proposal/initiative relates to:
- 1.5.Grounds for the proposal/initiative
- 1.5.1.Requirement(s) to be met in the short or long term including a detailed timeline for roll-out of the implementation of the initiative
- 1.5.2.Added value of EU involvement (it may result from different factors, e.g. coordination gains, legal certainty, greater effectiveness or complementarities). For the purposes of this section 'added value of EU involvement' is the value resulting from EU action, that is additional to the value that would have been otherwise created by Member States alone.
- 1.5.3.Lessons learned from similar experiences in the past
- 1.5.4.Compatibility with the multiannual financial framework and possible synergies with other appropriate instruments
- 1.5.5.Assessment of the different available financing options, including scope for redeployment
- 1.6.Duration of the proposal/initiative and of its financial impact
- 1.7.Method(s) of budget implementation planned
- 2.MANAGEMENT MEASURES
- 2.1.Monitoring and reporting rules
- 2.2.Management and control system(s)
- 2.2.1.Justification of the budget implementation method(s), the funding implementation mechanism(s), the payment modalities and the control strategy proposed
- 2.2.2.Information concerning the risks identified and the internal control system(s) set up to mitigate them
- 2.2.3.Estimation and justification of the cost-effectiveness of the controls (ratio between the control costs and the value of the related funds managed), and assessment of the expected levels of risk of error (at payment & at closure)
- 2.3.Measures to prevent fraud and irregularities
- 3.ESTIMATED FINANCIAL IMPACT OF THE PROPOSAL/INITIATIVE
- 3.1.Heading(s) of the multiannual financial framework and expenditure budget line(s) affected
- 3.2.Estimated financial impact of the proposal on appropriations
- 3.2.1.Summary of estimated impact on operational appropriations
- 3.2.1.1.Appropriations from voted budget
- 3.2.1.2.Appropriations from external assigned revenues
- 3.2.2.Estimated output funded from operational appropriations
- 3.2.3.Summary of estimated impact on administrative appropriations
- 3.2.3.1. Appropriations from voted budget
- 3.2.3.2.Appropriations from external assigned revenues
- 3.2.3.3.Total appropriations
- 3.2.4.Estimated requirements of human resources
- 3.2.4.1.Financed from voted budget
- 3.2.4.2.Financed from external assigned revenues
- 3.2.4.3.Total requirements of human resources
- 3.2.5.Overview of estimated impact on digital technology-related investments
- 3.2.6.Compatibility with the current multiannual financial framework
- 3.2.7.Third-party contributions
- 3.3.Estimated impact on revenue
- 4.Digital dimensions
- 4.1.Requirements of digital relevance
- 4.2.Data
- 4.3.Digital solutions
- 4.4.Interoperability assessment
- 4.5.Measures to support digital implementation
1 FRAMEWORK OF THE PROPOSAL/INITIATIVE
1.1 Title of the proposal/initiative
Child Online Safety and Rights Act (CARE)
1.2 Policy area(s) concerned
Policy area: Protecting minors online in the policy areas of communications networks, content and technology; public health; and internal market, industry, entrepreneurship and SMEs.
The budgetary impact concerns the new supervisory tasks entrusted to the Commission in relation to online social networking services, video-sharing platform services, software application stores as well as AI companions and general conversational chatbots within the Commission competence. Some limited impacts also arise from the new obligations on video games, although direct supervision lies with the Member State authorities.
1.3 Objective(s)
1.3.1 General objective(s)
This proposed Regulation follows up on the conclusions of the report by the Co-chairs of the Special Panel on Child Safety Online, which set out a clear path for how children in Europe can be better protected in the online environment.
As set out in the report, children spend an increasing amount of time online and, in doing so, are exposed to many different risks such as exposure to age-inappropriate content, cyberbullying, excessive time spent online, and unwanted contacts from strangers. These risks carry serious consequences for children’s mental health and well-being, with adolescents and children being a particularly vulnerable group.
The EU market risks becoming increasingly fragmented as Member States are planning or adopting new measures to restrict access to certain online platforms considered risky for children below a specified age – with differences in scope, age limit and proposed restrictions – thereby creating legal uncertainty, high compliance costs for businesses and an unequal level of protection for minors in a digital environment that knows no borders.
To ensure a safe and age-appropriate digital environment for minors and as also noted in the report by the Co-chairs of the Special Panel, age assurance is critical for effectively protecting minors online. Age assurance underpins both age restrictions and safety measures of children. However, the current legal framework around age assurance lacks clarity and its implementation is patchy.
Against this background, this proposed Regulation aims at ensuring a strong and coherent framework for the protection of minors online, taking the child and their empowerment and fundamental rights as a starting point.
1.3.2 Specific objective(s)
Taking into account the general objective to protect minors online, the proposal pursues the following specific objectives:
Delay minors’ access to to services with specific features that constitute social network services or video-sharing platforms. For these services, shall not allow minors below the age of 15 to create an account. Providers of those services may allow guardians to set up accounts for minors above the age of 13 with limited features to access the service. Where such providers can demonstrate that they are a child-friendly service, they may grant access also to minors below 13 years by means of accounts that are created and supervised by their guardian
Strengthen the protection of minors through safety-by-design requirements by clarifying the obligations of digital services and certain systems, so that risks to children are addressed in the design and functioning of those services and systems.
Ensure reliable and fundamental rights’ compliant age assurance mechanisms by establishing clear requirements and criteria for the use of age assurance systems to support both the access delay and the implementation of safety-by-design measures.
Ensure effective enforcement across the EU by establishing a robust and coherent regulatory and enforcement framework that enables timely and efficient implementation, making sure that minors are protected quickly and effectively in practice.
1.3.3 Expected result(s) and impact
Specify the effects which the proposal/initiative should have on the beneficiaries/groups targeted.
The proposal is expected to contribute to a safer online environment for children while also improving the functioning of the internal market. By clarifying and further harmonising child protection obligations across the Union, it should reduce regulatory fragmentation and provide a more predictable framework for cross-border service and system provision, in particular given the cross-border nature of the providers in scope of this Regulation.
In the short-term, for providers of affected services and systems, the proposal may increase internal compliance costs, require products redesigns and the implementation of additional safety measures – such as age assurance or guardian control tools – and could create certain barriers to entry for some providers. Over time, however, clearer legal obligations are expected to reduce costs, support more level competitive conditions, and facilitate supervision and enforcement by public authorities, with overall impacts expected to be neutral to slightly positive for public authorities.
The proposal is also expected to encourage innovation in child-safe design and age-appropriate digital services and systems, including privacy-preserving age assurance solutions. While costs will increase for age verification or alternative age assurance, synergies with wider Union digital infrastructure, notably the EU Digital Identity Wallet and the EU Age Verification Blueprint, may reduce implementation costs over time.
1.3.4 Indicators of performance
Specify the indicators for monitoring progress and achievements.
The following core indicators have been identified:
Limit access to high-risk digital services and systems: A range of surveys indicate that in the EU millions of minors under the age of 13 use social media and have their own accounts (1). For example, across six countries, 34% of 9–11-year-olds report having a social media profile (2). Against that background, the target would be to ensure that a substantial proportion of services apply effective access restrictions in line with the new requirements. The recent experience in Australia illustrates that such a societal change takes time and requires not only the effective compliance of providers, but also a shift with minors, parents, and society as a whole. Therefore, success will require effective enforcement, awareness raising in society, broad societal engagement, continuous monitoring and the recognition that behavioural change takes time.
Implement safety-by-design requirements: Currently, the online environment has not been designed with children in mind and does not cater for their evolving capabilities. Children face many risks online, which can have severe impacts on their well-being, development as well as their physical and mental health. Those risks are constantly evolving and, as children are early adopters of new technologies, they also remain the most vulnerable to its risks. Against this background, the target would be to ensure that the online environment becomes safer for minors through the implementation of safety-by-design measures. Success will require that safety of minors is built into products and services from the start, and throughout the lifecycle of a product or service, creating an overall shift-change amongst regulated services and systems that minors’ protection should be prioritised. This should be combined with effective enforcement and supervision.
Have in place fundamental rights’ compliant age assurance systems. Existing age requirements on online platforms are typically not developed based on children’s needs and hardly enforced. Most providers of digital services set out a minimum age to access or use their service in their terms and conditions (3). As noted by the OECD, the rationales behind the ages chosen by platforms derive from privacy and contract laws reasons rather than based on an assessment of safety or developmental appropriateness (4). The OECD further highlights that “very few of [the services that set a minimum age in their Terms of Service] implement age assurance in a systematic way” and that only 2 out of the 50 online services studied systematically require assure age for account creation (5). The only age check before account creation is typically self-declaration. It is widely recognised that self-declaration alone is not an effective age assurance measure, because many users do not reveal their true age (6, 7, 8). A range of surveys shows that minors routinely mis-state their age online (9). In practice, underage users can therefore easily access many age-restricted online services. In this context, the target is the broad take up of fundamental rights’ preserving age assurance. This can be achieved through action and real compliance from the services in scope of the Regulation, combined with effective supervision and enforcement, as well as continuous monitoring and evaluation especially concerning the impacts on fundamental rights.
Strengthen effective enforcement. Enforcement of Regulation (EU) 2022/2065 is running at full speed, including in the area of protection of minors. However, it still takes time before a final non-compliance decision is adopted. Against this background, where non-compliance is suspected, the target is that this is quickly tackled to ensure that minors are quickly served with effective action to protect them in the online environment.
1.4 The proposal/initiative relates to:
X a new action
¨ a new action following a pilot project / preparatory action10
X the extension of an existing action
¨ a merger or redirection of one or more actions towards another/a new action
10 As referred to in Article 58(2), point (a) or (b) of the Financial Regulation. ↑
1.5 Grounds for the proposal/initiative
1.5.1 Requirement(s) to be met in the short or long term including a detailed timeline for roll-out of the implementation of the initiative
The protection of minors online requires both immediate action to address urgent risks and structural measures to build a safer digital environment over time.
In the short-term, priority should be given to effective implementation and enforcement of the rules so that minors are effectively protected online – this will require substantial resources to make this a reality in practice. This should be combined with targeted support measures and awareness raising campaigns by Member States for minors, guardian and educators.
In the long-term, the objective is not only to respond to the risks, but to reshape the online environment so that the protection of minors because built-in rather than a corrective measure. This requires sustained investment in privacy-preserving age assurance solutions, strong digital literacy by Member States and the overall development of child-friendly services.
Six months after the entry into application of the Regulation, service providers will have to comply with the social media start date by establishing whether accounts belong to recipients below the minimum age and take measures to disable these. In order to ensure that existing accounts are brought into compliance with the minimum age obligations, providers of very large online platforms shall, before the expiry of the six month time period, submit to the competent authority a detailed implementation plan that corroborates the required high degree of confidence.
As of this date, platforms must also comply with safety-by-design obligations and, where necessary, employ age verification. At the same time, six months after entry into application, the Commission must be ready to enforce the new rules towards Very Large Online Platforms (VLOPs) and Search Engines (VLOSEs), and national Digital Services Coordinators towards smaller platforms and video games. The enforcement for the new requirements for AI companions and chatbots will take place under the existing supervisory and enforcement framework of the AI Act where the Commission is responsible for the AI companions and chatbots built on general-purpose AI models or integrated into VLOPs or VLOSEs.
Twelve months after entry into application, providers of services and systems in scope will have to enable parental accounts, comply with rules for AI companions and general conversational chatbots, implement various flanking measures, as well as follow a code of conduct for age rating if applicable to them. From this date onwards, i.e. twelve months after entry into application of the Regulation, the Commission must be ready to apply the new expedited enforcement regime (30 days for coming to preliminary findings, 90 days for coming to a final decision).
1.5.2 Added value of EU involvement (it may result from different factors, e.g. coordination gains, legal certainty, greater effectiveness or complementarities). For the purposes of this section 'added value of EU involvement' is the value resulting from EU action, that is additional to the value that would have been otherwise created by Member States alone.
EU action is justified by the cross-border nature of digital services and AI systems, fragmented national approaches regarding restricting minors’ access and the need to ensure a consistent level of protection for minors across the Union. Action at EU level can reduce regulatory divergence, increase legal certainty and reducing compliance costs for providers and users, improve enforcement, and ensure that minors are effectively protected throughout the EU.
1.5.3 Lessons learned from similar experiences in the past
Based on Regulation (EU) 2022/2065 there are the following lessons learnt:
Sufficient and stable resources are crucial. Experience under Regulation (EU) 2022/2065 shows that effective enforcement of rules towards the largest companies in the world requires high-skilled resources, technical capacity and sufficient staffing. This is particularly important when supervising and enforcing large cross-border digital services, and doing so in a highly litigious environment.
Resources should be permanent. Enforcement in the digital environment should rely on stable resources, to ensure long-term reliability and predictability. Risks on digital services evolve quickly, and platforms change their systems rapidly, while supervision must be continuous and circumvent the risk of revolving doors. Only through permanent resources can oversight be potent and credible overtime.
Swift enforcement is critical in the online environment, especially for minors. For digital services, harms can scale rapidly and delays can significantly reduce the effectiveness of intervention. Therefore, the enforcement framework must allow for timely action, including the ability to react quickly where serious risks emerge.
Credible enforcement strengthens compliance. Where authorities have the capacity and tools to act decisively, this creates incentives for providers to engage seriously and comply more proactively. Effective supervision is therefore about ensuring that the rules have practical impact.
1.5.4 Compatibility with the multiannual financial framework and possible synergies with other appropriate instruments
The initiative is compatible with the current Multiannual Financial Framework (MFF).
The initiative will draw on a supervisory fee to be paid by each provider of online social networking services, video-sharing platform services, and software application stores for which the Commission enjoys competence to supervise their compliance and that is designated as a very large online platform pursuant to Article 33 of Regulation (EU) 2022/2065, and AI companions, and general conversational chatbots that qualify as a very large online platform. The annual supervisory fee will be calculated based on Art. 43 of Regulation (EU) 2022/2065, which will however not be increased on a given provider of very large online platform or very large search engine for more than 0,03 % of its worldwide annual net income in the preceding financial year.
1.5.5 Assessment of the different available financing options, including scope for redeployment
The preferred financing option is a top up to the existing supervisory fee under the DSA. To this end, providers of online social networking services, of video-sharing platform services, and software application stores which fall under supervision by the European Commission and which are designated as Very Large Online Platform under Regulation (EU) 2022/2065, and AI companions and general conversational chatbots that qualify as a very large online platform will be charged an additional fee to the annual supervisory fee pursuant to Article 43 of Regulation (EU) 2022/2065.
For the purposes of enforcing the rules under this initiative, the Commission will rely partly on redeployment. However, carrying the considerable new supervisory tasks without risking to jeopardise existing enforcement work excludes full reliance on redeployment. See also section 4.1 of the annex.
Where enforcement relies on supervisory fees, it should be pointed out that there will be an inevitable gap between the upfront need for human resources and the financial contribution originating from the supervisory fee which will only become available after the Regulation has entered into force and the fee has been paid. This gap poses a critical risk for the correct implementation of the proposal, as the necessary resources would not be available when they are needed, i.e. from the moment of entry into force. The political and public expectations for effective supervision and enforcement to protect minors online are high, and the Commission will have to demonstrate convincingly that it is able to reign in harmful behaviour. It is therefore of the highest importance to minimise the risk from the gap between the upfront need for human resources and the financial contribution originating from the original fee and ensure that the Commission will have the adequate resources to enforce the proposal from the first day of entry into force.
1.6 Duration of the proposal/initiative and of its financial impact
¨ limited duration
- –¨ in effect from [DD/MM]YYYY to [DD/MM]YYYY
- –¨ financial impact from YYYY to YYYY for commitment appropriations and from YYYY to YYYY for payment appropriations.
X unlimited duration
- –Implementation with a start-up period from 2028 to unlimited,
- –followed by full-scale operation.
1.7 Method(s) of budget implementation planned11
X Direct management by the Commission
- –X by its departments, including by its staff in the Union delegations;
- –¨ by the executive agencies
¨ Shared management with the Member States
¨ Indirect management by entrusting budget implementation tasks to:
- –¨ third countries or the bodies they have designated
- –¨ international organisations and their agencies (to be specified)
- –¨ the European Investment Bank and the European Investment Fund
- –¨ bodies referred to in Articles 70 and 71 of the Financial Regulation
- –¨ public law bodies
- –¨ bodies governed by private law with a public service mission to the extent that they are provided with adequate financial guarantees
- –¨ bodies governed by the private law of a Member State that are entrusted with the implementation of a public-private partnership and that are provided with adequate financial guarantees
- –¨ bodies or persons entrusted with the implementation of specific actions in the common foreign and security policy pursuant to Title V of the Treaty on European Union, and identified in the relevant basic act
- –¨ bodies established in a Member State, governed by the private law of a Member State or Union law and eligible to be entrusted, in accordance with sector-specific rules, with the implementation of Union funds or budgetary guarantees, to the extent that such bodies are controlled by public law bodies or by bodies governed by private law with a public service mission, and are provided with adequate financial guarantees in the form of joint and several liability by the controlling bodies or equivalent financial guarantees and which may be, for each action, limited to the maximum amount of the Union support.
Comments
None
11 Details of budget implementation methods and references to the Financial Regulation may be found on the BUDGpedia site: https://myintracomm.ec.europa.eu/corp/budget/financial-rules/budget-implementation/Pages/implementation-methods.aspx. ↑
2 MANAGEMENT MEASURES
2.1 Monitoring and reporting rules
The proposal will be rigorously evaluated, notably in terms of the effectiveness of the access delay, the personal scope of the access delay and its proportionality and the safety by design requirements. This evaluation shall account for experience gained in the implementation of the proposal as well as technological, market and legal developments. The Commission will monitor the application of this Regulation and submit a report to the European Parliament and the Council by 31 August 2030.
Where appropriate, the report will be accompanied by a proposal to amend the Regulation. After this initial review, the Commission will submit a further report to the European Parliament and the Council every four years on progress towards achieving the Regulation's objectives.
This will complement ongoing monitoring under the Digital Services Act.
2.2 Management and control system(s)
2.2.1 Justification of the budget implementation method(s), the funding implementation mechanism(s), the payment modalities and the control strategy proposed
The Regulation establishes a safer online environment for children while also improving the functioning of the internal market. It sets out clear rules to limit minors’ access to digital services and systems that present the highest risks to them, strengthen the protection of minors through safety-by-design requirements, establishing clear requirements and criteria for the use of age assurance systems to support both the access delay and the implementation of safety-by-design measures, and putting in place effective enforcement across the EU by establishing a robust and coherent regulatory and enforcement framework
In order for the Commission to carry out the new responsibilities assigned to it, it is necessary to appropriately resource the Commission’s services. This is especially important because, in exercising its tasks, the Commission will have to supervise some of the financially strongest and technologically most sophisticated companies in the world, in a highly litigious environment. Supervising these companies will require staff with highly skilled and specialised profiles. The Commission faces a significant political risk if enforcement is under-resourced, especially because this instrument deals with the protection of minors as some of the most vulnerable members of society. Calls for quick action to protect European children online are growing, and making sure that the next generation is effectively protected requires adequate staffing, especially to enable the Commission to deliver on the fast-track enforcement that will be required by the new legislative instrument with a view to protecting children adequately and quickly.
The implementation and enforcement of the Regulation is estimated to require a total of 85 FTE. The proposed staffing levels are proportional to the volume and complexity of the new responsibilities and reflect the most cost-efficient option, avoiding duplication at national level.
In order to ensure these resources are available, the Commission will redeploy 45 FTE. Moreover, in order to complement the resource needs and fulfil the significant new supervisory tasks under this instrument, the Commission will require 40 FTE of new staff.
For financing the supervision of the rules under this instrument, the Commission will rely on a ‘top up’ to the existing supervisory fee under the Digital Services Act, which will have to be paid by those providers in scope of the new instrument that are designated as VLOP under the Digital Services Act.
Like the Digital Services Act, this legislative proposal meets the three cumulative requirements for relying on a fee:
- A service is being provided: The service concerns the supervision of activities, i.e. the supervision of the compliance of with the Regulation. Supervision has tangible compliance benefits for affected entities. For example, where providers can demonstrate that they are a child-friendly service, they may grant access also to minors below 13 years by means of accounts that are created and supervised by their guardian. The costs related to the provision of the service include the costs of IT tools, staff costs, and other administrative costs.
- The service is individually received by those who pay the contribution: The service provides direct benefits for the entities who are requested to pay the fee. By undergoing the supervision services provided for in the proposal, providers can reliably prove that they are offering a service that is safe for minors. The top-up to the DSA supervisory fee under this instrument will only be paid by those entities that are in scope of the new instrument and, by virtue of their designation as VLOPs or VLOSE under the DSA, fall under the Commission’s direct supervision.
- Proportionate fee level: As per established practice under the Digital Services Act, the level of the fee (and its top-up) will be established annually and will, in volume, be tailored to the individual supervised entity by use of a formula that takes into account the service’s number of users and may and is capped at a level of the service provider’s worldwide profit in the preceding financial year. The maximum top-up for the supervisory activities under this new instrument on a given provider of very large online platform or very large search engine is capped at 0,03 % of its worldwide annual net income in the preceding financial year.
As with the Digital Services Act, this instrument constitutes a case where the permanent nature of the revenue and the permanent nature of the tasks performed in exchange for the fee can be ensured. The DSA supervisory fee has been collected since 2024. So far, it amounted to between EUR 40 and 60 million annually, with slight variations explained by changes in the expected supervision costs for the following year. The pool of VLOPSEs (> 45 million monthly active users), has continued to grow rather than shrink as more services cross the user-number threshold. The underlying revenue base of the new fee can thus be considered stable, as services with > 45 million monthly active users are unlikely to rapidly lose user numbers and be removed from Commission supervision.
The permanent nature of the DSA fee, coupled with the permanence and significance of the Commission’s supervisory tasks regarding the safety and trustworthiness of online platforms including for safeguarding children online, renders the DSA and the current instrument a suitable example of an area in which the underlying fee could finance establishment plan posts.
2.2.2 Information concerning the risks identified and the internal control system(s) set up to mitigate them
The activities proposed in the Regulation involve the Commission and national authorities to carry out supervisory activities. The Commission will have to ensure that such activities are sufficiently staffed, and also that it is ready to prepare delegated and implementing acts, guidance documents, comitology secretariat, including monitoring against established KPIs and milestones. This would allow to promptly identify possible issues and risks in the execution of its activities.
Furthermore, for the revenues stemming from the supervisory fee, the Regulation will provide for regular reporting obligations for the Commission as regards the costs incurred and the revenues collected.
However, it should be pointed out that there will be an inevitable gap between the upfront need for human resources and the financial contribution originating from the supervisory fee which will only become available after the Regulation has entered into force and the fee paid.
This gap poses a critical risk for the correct implementation of this Regulation, as the necessary resources would not be available when they are needed, i.e. from the moment of entry into force. The political and public expectations for effective supervision and enforcement to achieve the objectives of this Regulation are high, and the Commission will have to demonstrate convincingly that it is able to reign in behaviour and impose changes where warranted.
It is therefore of the highest importance to minimise the risk from the gap between the upfront need for human resources and the financial contribution originating from the original fee and ensure that the Commission will have the adequate resources to enforce the new initiative from the first day of entry into force. Redeploying existing staff for parts of the supervisory activities under this new initiative is a key mitigation strategy in this regard.
2.2.3 Estimation and justification of the cost-effectiveness of the controls (ratio between the control costs and the value of the related funds managed), and assessment of the expected levels of risk of error (at payment & at closure)
The cost of controls for this initiative have been estimated at Commission level. The source of this information is the Commission’s internal management and control system. The costs were estimated based on the staff and resources dedicated to the activities foreseen as part of this initiative. The expected total costs for such controls can be relatively high due to the complexity of the activities proposed and the need for dedicated resources to mitigate execution risks. The control intensity will be adapted to the nature of the expenditure, the type of beneficiaries or contractors foreseen, the amount of financial resources concerned, and the level of risk.
2.3 Measures to prevent fraud and irregularities
The existing fraud prevention measures applicable to the Commission will cover the additional appropriations necessary for this Regulation. In addition, this Regulation will provide for regular reporting on the costs incurred and revenues collected from the supervisory fee and mechanisms to adjust the level of the fees to the costs incurred.
3 ESTIMATED FINANCIAL IMPACT OF THE PROPOSAL/INITIATIVE
The estimated impact on expenditure and staffing for 2028 and beyond is added for illustrative purposes only and does not pre-judge the next Multiannual Financial Framework. The source of financing and scope of Union financial commitment in the post-2027 period remain subject to the outcome of interinstitutional negotiations on the MFF 2028-2034 and thereafter shall be determined through the annual budgetary procedure. All appropriations and staffing allocations as of 2028 are indicative.
3.1 Heading(s) of the multiannual financial framework and expenditure budget line(s) affected
- Existing budget lines
In order of multiannual financial framework headings and budget lines.
Heading of multiannual financial framework | Budget line | Type of expenditure | Contribution | |||
Number | Diff./Non-diff.12 | from EFTA countries13 | from candidate countries and potential candidates14 | From other third countries | other assigned revenue | |
02 20 03 05 Digital Services Act (DSA) – Supervision of very large online platforms | Diff. | NO | NO | NO | YES | |
- New budget lines requested
In order of multiannual financial framework headings and budget lines.
Heading of multiannual financial framework | Budget line | Type of expenditure | Contribution | |||
Number | Diff./Non-diff. | from EFTA countries | from candidate countries and potential candidates | from other third countries | other assigned revenue | |
12 Diff. = Differentiated appropriations / Non-diff. = Non-differentiated appropriations. ↑
13 EFTA: European Free Trade Association. ↑
14 Candidate countries and, where applicable, potential candidates from the Western Balkans. ↑
3.2 Estimated financial impact of the proposal on appropriations
3.2.1 Summary of estimated impact on operational appropriations
- –¨ The proposal/initiative does not require the use of operational appropriations
- –x The proposal/initiative requires the use of operational appropriations, as explained below
3.2.1.1 Appropriations from voted budget
3.2.1.2 Appropriations from external assigned revenues
EUR million (to three decimal places)
Heading of multiannual financial framework | Number |
DG CONNECT | Year | Year | Year | Year | Year | Year | Year | TOTAL MFF 2028-2034 | ||||||||||
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||||||||||||
Operational appropriations | ||||||||||||||||||
DSA fee | Commitments | (1a) | 7.700 | 5.700 | 5.700 | 5.700 | 5.700 | 5.700 | 5.700 | 41.900 | ||||||||
Payments | (2a) | 5.700 | 5.700 | 7.700 | 5.700 | 5.700 | 5.700 | 5.700 | 41.900 | |||||||||
Budget line | Commitments | (1b) | 0 | |||||||||||||||
Payments | (2b) | 0 | ||||||||||||||||
Appropriations of an administrative nature financed from the envelope of specific programmes15 | ||||||||||||||||||
Budget line | (3) | 0 | ||||||||||||||||
TOTAL appropriations | Commitments | =1a+1b+3 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | ||||||||
for DG CONNECT | Payments | =2a+2b+3 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | ||||||||
Year | Year | Year | Year | Year | Year | Year | TOTAL MFF 2028-2034 | |||||||||||
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||||||||||||
TOTAL operational appropriations | Commitments | (4) | 7.700 | 5.700 | 5.700 | 5.700 | 5.700 | 5.700 | 5.700 | 41.900 | ||||||||
Payments | (5) | 5.700 | 5.700 | 7.700 | 5.700 | 5.700 | 5.700 | 5.700 | 41.900 | |||||||||
TOTAL appropriations of an administrative nature financed from the envelope for specific programmes | (6) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||||||||
TOTAL appropriations under HEADING <….> | Commitments | =4+6 | 7.700 | 5.700 | 5.700 | 5.700 | 5.700 | 5.700 | 5.700 | 41.900 | ||||||||
of the multiannual financial framework | Payments | =5+6 | 5.700 | 5.700 | 7.700 | 5.700 | 5.700 | 5.700 | 5.700 | 41.900 | ||||||||
Heading of multiannual financial framework | 4 | ‘Administrative expenditure’16 |
EUR million (to three decimal places)
DG CONNECT | Year | Year | Year | Year | Year | Year | Year | TOTAL MFF 2028-2034 | |||
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | |||||
Ÿ Human resources | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 14.140 | |||
Ÿ Other administrative expenditure | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
TOTAL DG CONNECT | Appropriations | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 14.140 | ||
TOTAL appropriations under HEADING 4 of the multiannual financial framework | (Total commitments = Total payments) | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 14.140 | ||
EUR million (to three decimal places)
Year | Year | Year | Year | Year | Year | Year | TOTAL MFF 2028-2034 | ||
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | |||
TOTAL appropriations under HEADINGS 1 to 4 | Commitments | 9.720 | 7.720 | 7.720 | 7.720 | 7.720 | 7.720 | 7.720 | 56.040 |
of the multiannual financial framework | Payments | 7.720 | 7.720 | 9.720 | 7.720 | 7.720 | 7.720 | 7.720 | 56.040 |
15 Technical and/or administrative assistance and expenditure in support of the implementation of EU programmes and/or actions (former ‘BA’ lines), indirect research, direct research. ↑
16 The necessary appropriations should be determined using the annual average cost figures available on the appropriate BUDGpedia webpage. ↑
3.2.2 Estimated output funded from operational appropriations (not to be completed for decentralised agencies)
Commitment appropriations in EUR million (to three decimal places)
Indicate objectives and outputs ò | Year 2028 | Year 2029 | Year 2030 | Year 2031 | Enter as many years as necessary to show the duration of the impact (see Section1.6) | TOTAL | |||||||||||||
OUTPUTS | |||||||||||||||||||
Type17 | Average cost | No | Cost | No | Cost | No | Cost | No | Cost | No | Cost | No | Cost | No | Cost | Total No | Total cost | ||
SPECIFIC OBJECTIVE No 118… | |||||||||||||||||||
- Output | |||||||||||||||||||
- Output | |||||||||||||||||||
- Output | |||||||||||||||||||
Subtotal for specific objective No 1 | |||||||||||||||||||
SPECIFIC OBJECTIVE No 2 ... | |||||||||||||||||||
- Output | |||||||||||||||||||
Subtotal for specific objective No 2 | |||||||||||||||||||
TOTALS | |||||||||||||||||||
17 Outputs are products and services to be supplied (e.g. number of student exchanges financed, number of km of roads built, etc.). ↑
18 As described in Section 1.3.2. ‘Specific objective(s)’ ↑
3.2.3 Summary of estimated impact on administrative appropriations
- –¨ The proposal/initiative does not require the use of appropriations of an administrative nature
- –X The proposal/initiative requires the use of appropriations of an administrative nature, as explained below
3.2.3.1 Appropriations from voted budget
VOTED APPROPRIATIONS | Year | Year | Year | Year | Year | Year | Year | TOTAL 2028 - 2034 |
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||
HEADING 4 | ||||||||
Human resources | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 14.140 |
Other administrative expenditure | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 |
Subtotal HEADING 4 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 14.140 |
Outside HEADING 4 | ||||||||
Human resources | 0.525 | 0.525 | 0.525 | 0.525 | 0.525 | 0.525 | 0.525 | 3.675 |
Other expenditure of an administrative nature | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 |
Subtotal outside HEADING 4 | 0.525 | 0.525 | 0.525 | 0.525 | 0.525 | 0.525 | 0.525 | 3.675 |
TOTAL | 2.545 | 2.545 | 2.545 | 2.545 | 2.545 | 2.545 | 2.545 | 17.815 |
3.2.3.2 Appropriations from external assigned revenues
EXTERNAL ASSIGNED REVENUES | Year | Year | Year | Year | Year | Year | Year | TOTAL 2028 - 2034 | |||
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | |||||
HEADING 4 | |||||||||||
Human resources | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | |||
Other administrative expenditure | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | |||
Subtotal HEADING 4 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | |||
Outside HEADING 4 | |||||||||||
Human resources | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 71.228 | |||
Other expenditure of an administrative nature | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | |||
Subtotal outside HEADING 4 | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 71.228 | |||
TOTAL | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 10.175 | 71.228 | |||
3.2.3.3 Total appropriations
TOTALVOTED APPROPRIATIONS + EXTERNAL ASSIGNED REVENUES | Year | Year | Year | Year | Year | Year | Year | TOTAL 2028 - 2034 | |||
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | |||||
HEADING 4 | |||||||||||
Human resources | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 14.140 | |||
Other administrative expenditure | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | |||
Subtotal HEADING 4 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 2.020 | 14.140 | |||
Outside HEADING 4 | |||||||||||
Human resources | 10.700 | 10.700 | 10.700 | 10.700 | 10.700 | 10.700 | 10.700 | 74.903 | |||
Other expenditure of an administrative nature | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | |||
Subtotal outside HEADING 4 | 10.700 | 10.700 | 10.700 | 10.700 | 10.700 | 10.700 | 10.700 | 77.903 | |||
TOTAL | 12.720 | 12.720 | 12.720 | 12.720 | 12.720 | 12.720 | 12.720 | 89.043 | |||
The appropriations required for human resources and other expenditure of an administrative nature will be met in part by appropriations from the DG that are already assigned to management of the action and/or have been redeployed within the DG, together with any additional resources that will be paid by the DSA fee as external assigned revenue and limited recourse to the administrative budget.
3.2.4 Estimated requirements of human resources
- –¨ The proposal/initiative does not require the use of human resources
- –x The proposal/initiative requires the use of human resources, as explained below
3.2.4.1 Financed from voted budget
Estimate to be expressed in full-time equivalent units (FTEs)19
VOTED APPROPRIATIONS | Year | Year | Year | Year | Year | Year | Year | |
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||
Ÿ Establishment plan posts (officials and temporary staff) | ||||||||
20 01 02 01 (Headquarters and Commission’s Representation Offices) | 5 | 5 | 5 | 5 | 5 | 5 | 5 | |
20 01 02 03 (EU Delegations) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(Indirect research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(Direct research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (specify) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
• External staff (in FTEs) | ||||||||
20 02 01 (AC, END from the ‘global envelope’) | 10 | 10 | 10 | 10 | 10 | 10 | 10 | |
20 02 03 (AC, AL, END and JPD in the EU Delegations) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Admin. Support line |
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
[XX.01.YY.YY] |
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
(AC, END - Indirect research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(AC, END - Direct research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (specify) - Heading 4 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (AI Office) - Outside Heading 4 | 5 | 5 | 5 | 5 | 5 | 5 | 5 | |
TOTAL | 20 | 20 | 20 | 20 | 20 | 20 | 20 | |
19 Please specify below the table how many FTEs within the number indicated are already assigned to the management of the action and/or can be redeployed within your DG and what are your net needs. ↑
3.2.4.2 Financed from external assigned revenues
EXTERNAL ASSIGNED REVENUES | Year | Year | Year | Year | Year | Year | Year | |
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||
Ÿ Establishment plan posts (officials and temporary staff) | ||||||||
20 01 02 01 (Headquarters and Commission’s Representation Offices) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
20 01 02 03 (EU Delegations) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(Indirect research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(Direct research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (DSA fee) | 15 | 15 | 15 | 15 | 15 | 15 | 15 | |
• External staff (in full time equivalent units) | ||||||||
20 02 01 (AC, END from the ‘global envelope’) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
20 02 03 (AC, AL, END and JPD in the EU Delegations) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Admin. Support line |
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
[XX.01.YY.YY] |
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
(AC, END - Indirect research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(AC, END - Direct research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (specify) - Heading 4 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (DSA fee) - Outside Heading 4 | 50 | 50 | 50 | 50 | 50 | 50 | 50 | |
TOTAL | 65 | 65 | 65 | 65 | 65 | 65 | 65 | |
3.2.4.3 Total requirements of human resources
TOTAL VOTED APPROPRIATIONS + EXTERNAL ASSIGNED REVENUES | Year | Year | Year | Year | Year | Year | Year | |
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||
Ÿ Establishment plan posts (officials and temporary staff) | ||||||||
20 01 02 01 (Headquarters and Commission’s Representation Offices) | 5 | 5 | 5 | 5 | 5 | 5 | 5 | |
20 01 02 03 (EU Delegations) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(Indirect research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(Direct research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (DSA fee) | 15 | 15 | 15 | 15 | 15 | 15 | 15 | |
• External staff (in full time equivalent units) | ||||||||
20 02 01 (AC, END from the ‘global envelope’) | 10 | 10 | 10 | 10 | 10 | 10 | 10 | |
20 02 03 (AC, AL, END and JPD in the EU Delegations) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Admin. Support line |
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
[XX.01.YY.YY] |
| 0 | 0 | 0 | 0 | 0 | 0 | 0 |
(AC, END - Indirect research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
(AC, END - Direct research) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (specify) - Heading 4 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |
Other budget lines (ECF Digital window – administrative support line and DSA fee) - Outside Heading 4 | 55 | 55 | 55 | 55 | 55 | 55 | 55 | |
TOTAL | 85 | 85 | 85 | 85 | 85 | 85 | 85 | |
Possible internal redeployment within the Commission are for duly substantiated reasons insufficient. The proposal therefore requires additional human resources in DG CONNECT. The financing of these additional resources will be mainly the DSA fee as external assigned revenue, with limited recourse to the administrative budget.
The staff required to implement the proposal (in FTEs):
Internally redeployed | Exceptional additional staff | ||||
Within the implementing DGs* | Exceptionally, from the Commission redeployment pool after orientation from the CMB** | To be financed from Heading 7*** / Research | To be financed from BA line | To be financed from fees | |
Establishment plan posts | 5 | 15 | |||
External staff (CA, SNEs, INT) | 35 (already financed under the DSA fee) 5 (AI Office) | 10 | 15 | ||
Total | 45 | 10 | 30 | ||
The scale, significance and required speed of new supervisory tasks entrusted to the European Commission exceeds what can be covered by existing human resources and internal redeployments within the Commission.
Compared to the existing enforcement frameworks under the Digital Services Act and the AI Act, this instrument places a number of new supervisory tasks in the hands of the Commission – chief among them the enforcement of the delayed access of minors to social networking services and video-sharing platform services but also important elements such as the supervision of safety-by-design requirements to be implemented by providers of online social network services, of video-sharing platform services as well as of AI companions and general conversational chatbots, where these falls under Commission supervision.
The enforcement of these new rules is of exceptionally high social significance as they are designed to safeguard some of the most vulnerable members of society: Children. The underlying evidence shows the significant developmental and health risks to which children are exposed online. These risks necessitate the new rules and make their enforcement a task of utmost societal significance. The political and public expectations, including from Member States, for effective supervision and enforcement to protect minors online are high, and the Commission will have to demonstrate convincingly that it is able to reign in harmful behaviour.
Because of the heightened risk that children face online, this instrument foresees a fast-track enforcement path, which requires the Commission to adopt preliminary findings within 30 working days and a final decision within 90 working days. These enforcement timelines are unprecedented. The Commission will be required to enforce the new rules of this instrument not just in an expedited fashion, but also towards the largest and most well-resourced companies in the world in a highly litigious environment.
Taken together, these factors render it impossible to rely purely on existing human resources and internal redeployments.
The requested additional staff would lead to increase the authorised staffing levels under the DSA by 30 FTEs (15 permanent and 15 non-permanent), financed from the DSA fee (external assigned revenue). Additionally, 10 FTE of non-permanent staff would be redeployed within the Commission to reinforce the staffing levels of the AI Office.
Description of tasks to be carried out by:
Officials and temporary staff |
|
External staff |
|
3.2.5 Overview of estimated impact on digital technology-related investments
Compulsory: the best estimate of the digital technology-related investments entailed by the proposal/initiative should be included in the table below.
Exceptionally, when required for the implementation of the proposal/initiative, the appropriations under Heading 4 should be presented in the designated line.
The appropriations under Headings 1-3 should be reflected as “Policy IT expenditure on operational programmes”. This expenditure refers to the operational budget to be used to re-use/ buy/ develop IT platforms/ tools directly linked to the implementation of the initiative and their associated investments (e.g. licences, studies, data storage etc). The information provided in this table should be consistent with details presented under Section 4 “Digital dimensions”.
TOTAL Digital and IT appropriations | Year | Year | Year | Year | Year | Year | Year | TOTAL MFF 2028 - 2034 |
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||
HEADING 4 | ||||||||
IT expenditure (corporate) | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
Subtotal HEADING 4 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
Outside HEADING 4 | ||||||||
Policy IT expenditure on operational programmes | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
Subtotal outside HEADING 4 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
TOTAL | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
3.2.6 Compatibility with the current multiannual financial framework
The proposal/initiative:
- –¨ can be fully financed through redeployment within the relevant heading of the multiannual financial framework (MFF)
- –¨ requires use of the unallocated margin under the relevant heading of the MFF and/or use of the special instruments as defined in the MFF Regulation
- –¨ requires a revision of the MFF
3.2.7 Third-party contributions
The proposal/initiative:
- –x does not provide for co-financing by third parties
- –¨ provides for the co-financing by third parties estimated below:
Appropriations in EUR million (to three decimal places)
Year | Year | Year | Year | Year | Year | Year | Total | |
2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | ||
Specify the co-financing body | ||||||||
TOTAL appropriations co-financed |
3.3. Estimated impact on revenue
- –¨ The proposal/initiative has no financial impact on revenue.
- –x The proposal/initiative has the following financial impact:
- –¨ on own resources
- –x on other revenue (assigned)
- –¨ please indicate, if the revenue is assigned to expenditure lines
EUR million (to three decimal places)
Budget revenue line: | Appropriations available for the current financial year | Impact of the proposal/initiative20 | ||||||
Year 2028 | Year 2029 | Year 2030 | Year 2031 | Year 2032 | Year 2033 | Year 2034 | ||
02 20 03 05 | 17.875 | 15.875 | 15.875 | 15.875 | 15.875 | 15.875 | 15.875 | |
For assigned revenue, specify the budget expenditure line(s) affected.
02 20 03 05 Digital Services Act (DSA) – Supervision of very large online platforms Other remarks (e.g. method/formula used for calculating the impact on revenue or any other information).
20 In the case of traditional own resources (customs duties, sugar levies), the amounts indicated must be net amounts, i.e. gross amounts after deduction of 10 % for collection costs, as proposed in COM(2025)574. ↑
4 Digital dimensions
To comply with this Regulation, providers of digital services and systems in scope must determine the age of recipients of the service or the user of the system in compliance with the requirements established in Chapter V. Notably, the implementation of the ‘access delay’ requires providers of social networking services and video-sharing platforms to put in place robust and effective EU age verification solutions, which are based on the EU age verification blueprint, made available by the Commission. Member States and/or private entities can take this up as a self-standing app or as part of a digital wallet. This solution is user-friendly, secure and fully privacy preserving. For the purposes of implementing safety-by-design obligations, age assurance solutions, other than EU age verification, may also be used to comply with the Regulation, provided that they live up to certain criteria. In order to make this work in practice, it is important that there are age verification and age assurance solutions in place that provide a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection and non-discrimination. Commercial solutions are already on the market to determine the age of a recipient of the service, and provided that they provide an sufficient level of protection they may be used in accordance with the provisions of this Regulation.
Furthermore, following the Commission Recommendation (EU) 2026/1035, the Commission is developing an EU Age Verification Scheme, which consists of the requirements concerning the trust model, governance and the requirements to be fulfilled by providers of the proof of age attestation and age verification solutions. Entities should meet the requirements of the EU Age Verification Scheme before their solutions and proof of age attestation providers respectively can be added to EU trusted solutions list. Similarly, the proof of age attestation providers should meet the requirements of the EU Age Verification Scheme before they are added on the EU trusted proof of age attestation providers list. The EU Age Verification Scheme will need its maintenance and operations to be supported in the medium and long term.
4.1 Requirements of digital relevance
It is against this background that the following requirements are established in the Regulation: Requirement 1 (R1): providers of services subject to access delay are required to propose to recipients of their services and users of the systems to prove their age with EU age verification solutions using an EU proof of age attestation or other solutions as referred to in paragraph 2(a) and 2(b) of Article 24 of the present Regulation. Requirement 2 (R2): providers subject to the safety-by-design obligations and providers of software application stores may use age assurance solutions other than EU age verification solutions provided that they provide a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination. Requirement 3 (R3): the European Commission shall adopt implementing acts covering the existing specifications and the operation of the EU Age Verification Scheme, and a list of issuers of EU proof of age attestations and a list of EU age verification solutions. As mentioned above, for the purposes of R1 and R2, the Commission has already established the EU Age Verification Blueprint, which now requires uptake by Member States or private companies. For the purposes of R3, the Commission is already establishing the EU Age Verification Scheme as well as the two lists. For the purposes of information sharing between responsible authorities, AGORA will be used which is a secure information sharing system to support communications between the Digital Services Coordinators (DSCs) in the Member States, the Commission and the European Board for Digital Services (composed of the DSC). The Commission, the DSCs and the Board use AGORA for all communications related to enforcement of the DSA. This system is already established and will now also be used for the purposes of this Regulation, which would potentially require further onboarding of authorities onto the system, although such additional onboarding is likely limited since relevant authorities are mostly already onboarded. Therefore, this will not further be touched upon in this Legislative Financial and Digital Statement. The same applies regarding the supervision and enforcement of the AI companions and chatbots which will rely on the structures, enforcement framework and information exchange system that is already set up under the AI Act. |
4.2 Data
The EU age verification solution is a privacy-preserving, data-minimising, non-traceable, unlinkable and double-blind solution designed to keep to an absolute necessary minimum the processing of personal data. In many cases a person’s age can be verified based on existing data available to the issuer of the proof of age attestation. Producing the proof of age attestations involves processing personal data of persons who need to prove their age to online services. This data processing is done separately from the person’s access to such online services. The online service itself receives no personal information about the user as a result of the age verification process, except the proof that the person is over the required age. This data processing is fully privacy-preserving and uses the latest technology to ensure full compliance with data protection standards. The technology is regularly updated to maintain its secure and privacy-preserving nature. https://commission.europa.eu/strategy-and-policy/priorities-2019-2024/europe-fit-digital-age/european-data-strategy_en |
4.3 Digital solutions
The EU Age Verification Scheme is a set of open-source technical requirements that can be used to publish a stand-alone mobile age verification application. It is available to both Member States and private actors to develop an age verification solution. The solution allows individuals to prove to digital services and systems requiring age verification that they are old enough without sharing their identity, exact age, date of birth, or other personal information. This digital solution supports the digital requirements R1 and R2 and is indirectly linked to R3, by outputting proofs of age attestations, proving that individuals are (or are not) above a certain age. |
4.4 Interoperability assessment
The European Age verification solution is technically interoperable with the European Digital Identity Wallets as specified in Regulation (EU) 910//2014 setting out the European Digital Identity Framework. The proof of age attestation will be issued as an electronic attestation of attributes as set out in Article 3 (44) of Regulation (EU) 910/2014. This ensures that age verification solutions and their proof of age attestation providers will provide the (potential) recipients of the service with proof of age attestations that can be used across digital services and across Member States. The core specificities of the age verification solutions therefore allow for a seamless interoperability across digital services for potential recipients of digital services to prove their age. |
4.5 Measures to support digital implementation
As mentioned in Section 4.1 the Commission is already well-underway to support the digital implementation of this Regulation, through the publication of the EU blueprint and the ongoing work on the EU Age Verification Scheme. This should allow that the infrastructure and system is in place at the time of entry into application. To ensure public uptake, but to also allow for constant public feedback and updating, the European Commission published the technical requirements needed to build EU Age Verification solutions. The project is open source and all the information is available publicly at the website ageverification.dev. This website and its associated IT test infrastructure will need ongoing maintenance and operations. Furthermore, the ongoing work on the EU Age Verification Scheme, should make the work on the implementing acts to underpin this work straightforward, as it will be based on existing practice. Awareness raising campaigns around the time of entry into force will be crucial, not only to support wide public uptake, but also to mitigate concerns related to privacy and usability. |
