Article 28 of the Digital Services Act, Regulation (EU) 2022/2065, is short. It has four paragraphs and it applies to every online platform accessible to minors in the Union, from a large social network to a small marketplace with a forum. Since July 2025 it also has a set of Commission guidelines that describe what compliance is expected to look like. This article sets out the article, the guidelines' main themes, and how a product team should read them, with the caveat that the guidelines are detailed and the reader should check the text where a point matters.
What Article 28 says
Article 28(1) requires providers of online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors on their service. That is the design duty.
Article 28(2) prohibits presenting advertisements on the platform based on profiling using the personal data of the recipient when the provider is aware with reasonable certainty that the recipient is a minor. That is the advertising ban.
Article 28(3) says that compliance with the article does not oblige a provider to process additional personal data to assess whether a recipient is a minor. That is the data minimisation guardrail: the article does not license mass age verification.
Article 28(4) lets the Commission, after consulting the European Board for Digital Services, issue guidelines on the measures in paragraph 1. The Commission published those guidelines on 14 July 2025.
The DSA has applied in full since 17 February 2024. Micro and small enterprises are exempt from most platform-specific duties under Article 19, including Article 28, unless they are designated as very large online platforms.
Who is "accessible to minors"
Recital 71 gives the working test. A platform is accessible to minors where its terms allow minors to use it, where it is directed at or predominantly used by minors, or where the provider is otherwise aware that some recipients are minors. A platform whose terms say 18 plus but that knows from its own data that teenagers use it is accessible to minors. The test is about reality, not the terms page.
The guidelines: main themes
The guidelines take a risk-based approach: the measures a platform should adopt depend on the risks it poses to minors, and the same list is not expected of every service. The main themes, as the Commission has described them, are set out below. Details vary and the reader should verify any specific point against the published text.
Age assurance. The guidelines distinguish age verification, age estimation and self-declaration. They indicate that age verification is appropriate where a platform poses high risks to minors, for instance where it provides content that national or Union law restricts to adults, such as pornography or gambling. Age estimation is treated as suitable for medium-risk cases. Self-declaration is not considered sufficient on its own where the risk is high. The Commission has also been developing an EU age verification app as a privacy-preserving reference method, piloted with several Member States in 2025.
Default settings. Minors' accounts should be private by default, so that their content, contacts and activity are not visible to people they have not accepted. Features that make a minor discoverable or contactable by strangers should be off by default, and features that expose location, such as location sharing, should be off.
Recommender systems. The guidelines ask that recommender systems used by minors give priority to explicit signals from the minor over engagement-based inference, allow the minor to see and reset what drives recommendations, and avoid feeding minors content that is harmful to their wellbeing. They also point to features known to prolong use, such as autoplay, streaks and night-time push notifications, as candidates for being off by default.
Contact, commercial practices and support. The guidelines address protection against unwanted contact, transparency about commercial content including features such as virtual currencies and loot boxes, the design of reporting and support tools that minors can actually use, and the provision of parental control tools that are transparent to the minor.
Governance. The guidelines expect the platform to assess the risks to minors from its own design, to document the measures chosen, and to review them.
Following the guidelines is not itself mandatory; Article 28(1) is. But the guidelines describe what the Commission and the national Digital Services Coordinators will look for, and a platform that departs from them should be able to explain why.
How it fits with the rest of the DSA
Article 25 already prohibits interface design that deceives or manipulates users, which overlaps with dark patterns aimed at minors. Article 27 requires transparency about the main parameters of recommender systems. For very large online platforms, Articles 34 and 35 require a systemic risk assessment that explicitly covers negative effects on the protection of minors, with mitigation measures such as age verification and parental control tools named in Article 35. Article 28 sits under those as the baseline every platform owes.
The GDPR continues to apply alongside. Article 8 GDPR sets the age of consent for information society services, and the age varies by Member State between 13 and 16. Article 28(3) DSA and Article 5(1)(c) GDPR point the same way: do not collect more data to prove age than the risk justifies. The age assurance comparison works through that trade-off.
A worked example
Skillbridge, a fictional company, runs a Union-wide platform where users share short tutorials and comment on each other's work. Its terms allow users from 14. That makes it accessible to minors, and it is above the small-enterprise threshold. The team reviews its product against the guidelines' themes. Accounts created by users who declare an age under 18 become private by default, with comments from non-followers off. The "people to follow" suggestions stop using inferred interests for those accounts and use only topics the user has chosen. Advertising for those accounts drops behavioural targeting entirely, which is the simplest way to comply with Article 28(2). The team decides against document-based age verification, recording that its content is not adult-restricted and that Article 28(3) counts against collecting identity data for a medium-risk service. It documents the assessment and sets a review date.
How Landfall helps
Landfall holds Article 28 as structured obligations with its paragraph citations, alongside the DSA's dark pattern, recommender transparency and systemic risk obligations, and maps them onto a project once the questionnaire establishes that a service is an online platform accessible to minors. The advertising prohibition fires as a separate item when a project declares behavioural advertising, and the age assurance answers decide which guideline-derived measures appear. Each generated item keeps its citation, so a reviewer can check it against the Regulation and the guidelines. Browse the obligations in the EU DSA explorer, and read the high-privacy defaults guide for the default settings the guidelines expect.