Skip to content
EU DSAArticle 28minorsrecommender systemsage assurance

DSA Article 28: Protecting Minors on Online Platforms

The four paragraphs of Art. 28, who counts as accessible to minors, and the Commission's July 2025 guidelines on age assurance, defaults and recommenders.

Landfall ยท Published 5 September 2026

Article 28 of the Digital Services Act, Regulation (EU) 2022/2065, is short. It has four paragraphs and it applies to every online platform accessible to minors in the Union, from a large social network to a small marketplace with a forum. Since July 2025 it also has a set of Commission guidelines that describe what compliance is expected to look like. This article sets out the article, the guidelines' main themes, and how a product team should read them, with the caveat that the guidelines are detailed and the reader should check the text where a point matters.

What Article 28 says

Article 28(1) requires providers of online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors on their service. That is the design duty.

Article 28(2) prohibits presenting advertisements on the platform based on profiling using the personal data of the recipient when the provider is aware with reasonable certainty that the recipient is a minor. That is the advertising ban.

Article 28(3) says that compliance with the article does not oblige a provider to process additional personal data to assess whether a recipient is a minor. That is the data minimisation guardrail: the article does not license mass age verification.

Article 28(4) lets the Commission, after consulting the European Board for Digital Services, issue guidelines on the measures in paragraph 1. The Commission published those guidelines on 14 July 2025.

The DSA has applied in full since 17 February 2024. Micro and small enterprises are exempt from most platform-specific duties under Article 19, including Article 28, unless they are designated as very large online platforms.

Who is "accessible to minors"

Recital 71 gives the working test. A platform is accessible to minors where its terms allow minors to use it, where it is directed at or predominantly used by minors, or where the provider is otherwise aware that some recipients are minors. A platform whose terms say 18 plus but that knows from its own data that teenagers use it is accessible to minors. The test is about reality, not the terms page.

The guidelines: main themes

The guidelines take a risk-based approach: the measures a platform should adopt depend on the risks it poses to minors, and the same list is not expected of every service. The main themes, as the Commission has described them, are set out below. Details vary and the reader should verify any specific point against the published text.

Age assurance. The guidelines distinguish age verification, age estimation and self-declaration. They indicate that age verification is appropriate where a platform poses high risks to minors, for instance where it provides content that national or Union law restricts to adults, such as pornography or gambling. Age estimation is treated as suitable for medium-risk cases. Self-declaration is not considered sufficient on its own where the risk is high. The Commission has also been developing an EU age verification app as a privacy-preserving reference method, piloted with several Member States in 2025.

Default settings. Minors' accounts should be private by default, so that their content, contacts and activity are not visible to people they have not accepted. Features that make a minor discoverable or contactable by strangers should be off by default, and features that expose location, such as location sharing, should be off.

Recommender systems. The guidelines ask that recommender systems used by minors give priority to explicit signals from the minor over engagement-based inference, allow the minor to see and reset what drives recommendations, and avoid feeding minors content that is harmful to their wellbeing. They also point to features known to prolong use, such as autoplay, streaks and night-time push notifications, as candidates for being off by default.

Contact, commercial practices and support. The guidelines address protection against unwanted contact, transparency about commercial content including features such as virtual currencies and loot boxes, the design of reporting and support tools that minors can actually use, and the provision of parental control tools that are transparent to the minor.

Governance. The guidelines expect the platform to assess the risks to minors from its own design, to document the measures chosen, and to review them.

Following the guidelines is not itself mandatory; Article 28(1) is. But the guidelines describe what the Commission and the national Digital Services Coordinators will look for, and a platform that departs from them should be able to explain why.

How it fits with the rest of the DSA

Article 25 already prohibits interface design that deceives or manipulates users, which overlaps with dark patterns aimed at minors. Article 27 requires transparency about the main parameters of recommender systems. For very large online platforms, Articles 34 and 35 require a systemic risk assessment that explicitly covers negative effects on the protection of minors, with mitigation measures such as age verification and parental control tools named in Article 35. Article 28 sits under those as the baseline every platform owes.

The GDPR continues to apply alongside. Article 8 GDPR sets the age of consent for information society services, and the age varies by Member State between 13 and 16. Article 28(3) DSA and Article 5(1)(c) GDPR point the same way: do not collect more data to prove age than the risk justifies. The age assurance comparison works through that trade-off.

A worked example

Skillbridge, a fictional company, runs a Union-wide platform where users share short tutorials and comment on each other's work. Its terms allow users from 14. That makes it accessible to minors, and it is above the small-enterprise threshold. The team reviews its product against the guidelines' themes. Accounts created by users who declare an age under 18 become private by default, with comments from non-followers off. The "people to follow" suggestions stop using inferred interests for those accounts and use only topics the user has chosen. Advertising for those accounts drops behavioural targeting entirely, which is the simplest way to comply with Article 28(2). The team decides against document-based age verification, recording that its content is not adult-restricted and that Article 28(3) counts against collecting identity data for a medium-risk service. It documents the assessment and sets a review date.

How Landfall helps

Landfall holds Article 28 as structured obligations with its paragraph citations, alongside the DSA's dark pattern, recommender transparency and systemic risk obligations, and maps them onto a project once the questionnaire establishes that a service is an online platform accessible to minors. The advertising prohibition fires as a separate item when a project declares behavioural advertising, and the age assurance answers decide which guideline-derived measures appear. Each generated item keeps its citation, so a reviewer can check it against the Regulation and the guidelines. Browse the obligations in the EU DSA explorer, and read the high-privacy defaults guide for the default settings the guidelines expect.

Explore the underlying obligations

This article is grounded in the obligations Landfall maps from source legal text. Browse them yourself:

Questions this article answers

Which platforms does Article 28 apply to?
Providers of online platforms accessible to minors. Recital 71 explains that a platform is accessible to minors where its terms allow minors to use it, where it is directed at or predominantly used by minors, or where the provider is otherwise aware that some recipients are minors. Micro and small enterprises are exempt unless designated as very large.
Does Article 28 require age verification?
No. Article 28(1) asks for appropriate and proportionate measures, and Article 28(3) says compliance does not oblige a provider to process additional personal data to assess whether a user is a minor. The Commission's guidelines indicate verification where the risk is high and estimation where it is medium.
Can a platform show targeted ads to minors?
Article 28(2) prohibits advertising based on profiling using personal data where the provider is aware with reasonable certainty that the recipient is a minor. Contextual advertising that does not profile the user is not caught by that paragraph.
Are the Commission's guidelines binding?
No. Article 28(1) is binding; the guidelines published in July 2025 describe the measures the Commission and the Digital Services Coordinators expect. A platform that departs from them should be able to explain why. Check the published text for the details of any specific measure.

Sources

For informational purposes only. This guide is summary-level, informational writing โ€” not legal advice, not a risk score, and not regulatory approval. It does not create an attorney-client relationship. Always consult qualified legal counsel for compliance decisions about your specific product.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations