YOUR
Search

    17.06.2026

    Minors online: what businesses need to know


    For minors, the internet is home. It is where they find information, study, communicate and build a significant part of their social lives.

    But it is not always a safe place. It amplifies hate speech and disinformation, facilitates practices such as cyberbullying and the non-consensual sharing of sexual or explicit content, and can foster patterns of isolation or addiction. Artificial intelligence further exacerbates these risks: it enables the creation of deepfakes and AI-generated images without the consent of the person depicted; it allows the deployment of chatbots capable of influencing minors’ choices and behaviour; and it makes it possible to tailor content to the specific cognitive vulnerabilities of individual users.

    There is now widespread consensus on the need to protect minors online. How effective protection can be achieved, however, is far less clear.

    In Italy, as in the rest of Europe, the regulatory framework is fragmented and rapidly evolving, and many of the key issues remain unresolved.

     

    The regulatory framework

    Italy has no comprehensive regulatory framework specifically addressing minors in the digital environment.

    The legal framework is made up of various legislative instruments operating at different but complementary levels and often requiring a holistic interpretation.

    The main legislative instruments currently relevant are:

    • Regulation (EU) 2016/679 (“GDPR) and Legislative Decree No. 196/2003 (Italian Privacy Code), applicable to data controllers processing the personal data of minors;
    • Regulation (EU) 2022/2065 (“Digital Services Act” or “DSA”), the European Commission’s Guidelines adopted pursuant to Article 28(4) of the DSA, and Commission Recommendation (EU) 2026/1035 on establishing a common framework for EU-wide age verification technologies, applicable to providers of intermediary services;
    • Directive 2010/13/EU, as amended by Directive (EU) 2018/1808 (“Audiovisual Media Services Directive” or “AVMS Directive”), transposed in Italy by Legislative Decree No. 208/2021 (Consolidated Act on Audiovisual Media Services” or TUSMA), applicable to video-sharing platform providers;
    • Decree-Law No. 123/2023, converted into Law No. 159/2023 (Caivano Decree”) and AGCOM (Italian Communications Authority) Resolution No. 96/25/CONS, applicable to providers distributing pornographic content but increasingly serving as a technical benchmark for age verification; and

    • Law No. 132/2025 (Italian Artificial Intelligence Act”), which includes a provision specifically addressing minors’ use of artificial intelligence systems.

    In addition to the legislative instruments outlined above, two further initiatives deserve mention: the G7 Common Principles for a Safer and More Secure Digital Space for Minors, adopted by the G7 Digital and Technology Ministers in 2026, which establish a shared framework covering age verification, safety by design, protection from illegal content, parental control tools, digital literacy and risk management, and Bill No. 1136 (Bill 1136”), currently under consideration by the Italian Parliament, which introduces specific provisions governing minors’ access to social media and video-sharing platforms, as well as age verification and digital consent.

     

    Three key issues

    Beyond the existing legal framework, three issues currently lie at the heart of the political and regulatory debate at both national and European level.

     

    The ban on access to social media

    One of the issues currently dominating the debate on the protection of minors online concerns the introduction of a minimum age for accessing social media.

    In 2024, Australia introduced a ban on under-16s; France, Denmark and Spain are considering similar measures; in Italy, Bill 1136 proposes to prohibit minors under the age of 15 from opening accounts on social media (as well as on video-sharing platforms).

    These measures address genuine concerns. The risk, however, is that attention is focused exclusively on the age threshold for access, while neglecting the characteristics of the services once minors are granted access. A comparison with more mature regulatory models is instructive. The UK’s Age-Appropriate Design Code and the California Age-Appropriate Design Code Act do not merely set age limits, but impose requirements relating to responsible design, risk assessment and provider accountability. From this perspective, the protection of minors depends not only on who can access the service, but also on how the service is designed.

     

    The digital age of consent 

    Closely linked to the issue of minors’ access to social media is that of minors’ consent to the processing of their personal data.

    Article 8 of the GDPR sets the age at which a minor may validly consent at 16, while allowing Member States the option to set lower thresholds, which in any case must not be below 13. Italy has exercised this option, setting the age for a minor’s consent at 14.

    If approved in its current form, however, Bill 1136 would raise the age of consent for minors to 16.

    The issue is further complicated by the fact that age thresholds are not uniform even within the same legal system. The Italian Artificial Intelligence Act, for example, allows minors to access and use AI systems independently from the age of 14 onwards. Accordingly, an operator managing a service with social components and AI-based features may find itself applying different rules to the same user base.

     

     

    Service design and the functioning of algorithms

    The third aspect of the debate — and probably the most sensitive — concerns the design of digital services and the functioning of algorithmic systems.

    From this perspective, the regulatory debate is gradually shifting from content control to accountability for design choices that encourage compulsive use of services. These include infinite scroll, notifications deliberately designed to capture users’ attention, recommender systems optimised to maximise time spent on the platform, autoplay features, and intermittent reward mechanisms. The European Commission’s Guidelines adopted pursuant to Article 28(4) of the DSA expressly classify these techniques as incompatible with a high level of protection for minors. This is the principle of “safety by design”, which requires minors’ protection to be integrated from the service development stage, rather than addressed ex post on individual pieces of content.

    The scope of these obligations varies, however, depending on the type of service provided. Transparency obligations relating to recommender systems and the ban on profiling-based advertising apply to all online platform providers. The obligations to assess and mitigate systemic risks, on the other hand, are more stringent for very large online platforms (“VLOPs”) and very large online search engines (“VLOSEs”), which are required to carry out periodic risk assessments and adopt mitigation measures that are reasonable, proportionate and effective.

     

    Age verification

    Setting a minimum age for access to social media and for digital consent risks remaining a dead letter unless supported by truly reliable age verification mechanisms.

    From this perspective, Commission Recommendation (EU) 2026/1035 establishes a common framework for age verification technologies, based on an interoperable, privacy-respecting model utilising digital identities and advanced cryptographic protocols. The system — developed by the European Commission as an open-source solution and already being trialled in some Member States, including Italy — is based on zero-knowledge proofs: the user downloads an app, verifies their age using an electronic ID or a pre-installed banking app, and receives a digital credential that can be submitted to online platforms. The aim is to enable verification that a specific age threshold has been met without disclosing additional information about the user’s identity: the platform receives only a true/false response (e.g., “over 18: yes”), without access to the user’s name, date of birth or other personal data. Once certification is complete, the link between the user and the certificate provider is severed, preventing any tracking of online activities. In Italy, Bill 1136 provides for a verification system based on a national digital mini-wallet, which constitutes a national implementation of the European solution: not an alternative or parallel system, but a tailored application of the same technical blueprint made available by the Commission as open source, consistent with the requirements of the Recommendation and the implementation timetable set out therein.

     

    Obligations for businesses

    Against this background, while these issues remain unresolved and the regulatory framework continues to evolve, what should businesses providing information society services intended for, or otherwise accessible to, minors do?

    The answer depends on the nature of the service provided, as well as on the size of the business.

    Providers of online platforms (including social media providers and video-sharing platform providers) must not only comply with the ban on advertising based on the online profiling of minors, but also design their platforms so as to ensure an effective level of protection for minors. This entails, among other things, the adoption of protective default settings, configuring recommender systems that do not maximise user attention and engagement, eliminating features that encourage compulsive behaviour, and providing parental control tools. Furthermore, VLOPs and VLOSEs must identify, analyse and assess the systemic risks their services may pose to minors and adopt reasonable, proportionate and effective mitigation measures, which may include adjusting algorithmic systems, the introduction of age verification tools and specific content moderation measures.

    It is important to note that merely stating in the terms and conditions that a platform is intended for adults does not exempt providers from these obligations. Where effective measures are not implemented to prevent access by minors, the service is deemed to be accessible to minors.

    In addition to the obligations applicable to all online platform providers, providers of video-sharing platforms subject to Italian jurisdiction are also required, under TUSMA, to implement age verification systems for content that may impair the physical, mental or moral development of minors, as well as parental control tools. Providers of video-sharing platforms (and website operators) distributing pornographic content in Italy are also subject to a ban on access by under-18s to the pornographic content distributed, and are required to verify users’ age, in accordance with the procedures laid down by AGCOM.

    Furthermore, should Bill 1136 be enacted, social media providers and video-sharing platform providers would be subject to two additional obligations.

    The first concerns the prohibition on the creation of accounts for minors under the age of 15, rendering void any contracts already concluded with minors who have not yet reached that age at the time 

    the law enters into force. The second is the obligation to verify users’ ages via a national digital mini-wallet implementing the European age verification solution, again in accordance with procedures laid down by AGCOM.

    And what about those providers of information society services other than online platforms (such as e-commerce services) or entities that process personal data of minors? For these entities, there is currently no explicit obligation to verify age. Data protection law requires appropriate measures to ensure that a minor’s consent is valid, but it does not prescribe a specific age verification system nor define the technical means by which such verification must be carried out. In the absence of an express statutory obligation, however, it is advisable to carry out a risk assessment — similar in principle to that required under the Commission’s Guidelines for online platform providers — to determine whether, having regard to the nature of the service, the categories of personal data processed and the reasonably foreseeable presence of minors among users, age verification mechanisms compliant with the European technical solution or equivalent standards should be implemented.

    Raffaele Giarda joins ADVANT Nctm as new Partner
    ADVANT Nctm announces that Raffaele Giarda has joined the Firm as…
    Read more
    2025 annual report of the Italian Data Protection Authority: AI is accelerating, digital compliance must keep pace
    On 2 July 2026, at the Sala della Regina of Palazzo Montecitorio, the Italian…
    Read more
    AI Enters Trade Secret Protection
    On 10 June 2026, the Italian Council of Ministers approved two draft legislative…
    Read more
    Space Economy and Data Economy: the National Space Policy Strategic Document (DSPSN)
    The context and purpose of the National Space Policy Strategic Document…
    Read more
    Personal data governance in football clubs: data use as a strategic lever at the intersection of GDPR, security and value creation
    The football club as a data ecosystem (and as a media company) From a personal…
    Read more
    Tracking pixels in e-mails: the Data Protection Authority's new rules
    1. Introduction By Order No. 284 of 17 April 2026, published in the Official…
    Read more
    THE COMMISSION’S NEW GUIDELINES ON THE CLASSIFICATION OF HIGH-RISK AI SYSTEMS
    The context and structure of the Guidelines Regulation (EU) 2024/1689 (“AI…
    Read more
    WHY DID THE COURT OF ROME ANNUL THE DATA PROTECTION AUTHORITY’S ORDER ON OPENAI?
    Summary of the judgement On 18 March 2026, the Court of Rome annulled in its…
    Read more
    Cyber Resilience Act: the countdown has started
    With Regulation (EU) 2024/2847 (“Cyber Resilience Act” or “CRA”), the European…
    Read more