Article 6: which services face the account rule?
Article 6 applies to providers of online social networking services and video-sharing platform services where the service poses a risk to the privacy, safety or security of a person below 15. The proposal treats that risk condition as met when the service has any one of five features:
- account holders can transmit content in real time to an indeterminate number of recipients, including livestreaming;
- account holders can contact or interact with people outside their pre-existing connections or subscriptions;
- a recommender system uses profiling;
- a recommender system suggests contacts or information not supplied by an existing connection or subscription; or
- features or interface design can foreseeably enable uninterrupted consumption, incentivise engagement, or send automated prompts to start or resume using the service.
Scope matters
A service is not brought within Article 6 merely because it is commonly called “social media”. The provider must fall within one of the two legal service categories and the service must have a listed risk feature. See scope and applicability.
Below age 13
On an Article 6 service, a child below 13 cannot have an account created for or attributed to them. Article 6’s limited-account derogation is not available below 13.
Article 7 creates a different and narrower arrangement. A video-sharing platform specifically designed for children below 13 may choose to let a guardian enable limited access through the guardian’s own account. It does not create an account for the child and does not apply to social networking services as a category.
Conditions for Article 7 access
The provider must expressly permit the access in its terms, specify the age range and publish an age-specific risk assessment. It must identify and block content or behaviour considered age-inappropriate or harmful for that range. Features must adjust to the child’s age.
Personalisation, recommender systems and searching other users’ content must be off and unavailable unless the provider’s assessment demonstrates that activation is in the child’s best interests and does not negatively affect privacy, safety or security.
The arrangement must also:
- use guardian tools or parental controls on the guardian’s account or device;
- activate guardian tools by default;
- rely on the guardian’s declaration of the child’s age;
- never enable access for a child below 3;
- allow the guardian to set a maximum daily duration of no more than one hour;
- allow supervision of displayed or recommended content, while respecting the child’s privacy and best interests;
- allow the guardian to approve, limit and remove contacts; and
- allow the guardian to suspend access at any time.
Article 7 does not force any provider to offer this route and creates no right of access where the service’s terms—or a higher lawful minimum age—do not permit it.
Ages 13 and 14: limited accounts
Article 6(2) allows—but does not require—a provider to let a guardian set up a limited account for a user in the 13–14 age group. This account is attributed to the minor, unlike Article 7 access through the guardian’s own account.
At minimum:
- Article 20 guardian tools must always be active;
- the guardian must be able to set a daily limit that cannot exceed one hour; and
- the guardian must be able to pre-approve new contacts and cap the number of contacts.
The provider must establish that the person creating the account holds parental responsibility and verify that the user has reached 13. Article 26 and the age-assurance rules govern those two separate checks.
Ages 15 to 17
From age 15, Article 6 does not prevent a person from creating or using an independent account. They remain a “minor” under the proposal until 18, so applicable safety-by-design requirements, child-friendly controls, reporting mechanisms and guardian tools continue.
Some provisions have their own age-specific wording. For example, Article 11 says specified safe defaults may be changed only where the minor is above 15, is clearly informed and explicitly consents. Reaching the Article 6 account age therefore does not switch off the rest of the protection framework.
The two guardian arrangements are not interchangeable
| Question | Article 6(2) limited account | Article 7 guardian-controlled access |
|---|---|---|
| Who is it for? | Users in the 13–14 age group | Children below 13, but never below 3 |
| Which services? | Qualifying social networking and video-sharing services under Article 6 | Only video-sharing services specifically designed for children below 13 |
| Whose account? | A limited account set up for the minor by the guardian | The guardian’s own account; no account is created or attributed to the child |
| Is the child the contracting party? | The proposal does not create Article 7’s exclusion | No—the guardian holds the account and contract |
| Daily limit | Guardian can set a limit, capped at one hour | Guardian can set a limit, capped at one hour |
| End point | Article 6 account restriction ends at 15 | Must end when the child reaches 13 |
Existing accounts
Article 6(4) would require affected providers, within six months after the Regulation starts to apply, to establish whether holders of existing accounts are below 15. Accounts established to belong to a person below 15—or where age cannot be established—would have to be disabled.
Article 32 supplies the method and qualifications:
- providers should use the age-verification solution specified through the EU Age Verification Scheme;
- verification is not required if the provider can establish with a high degree of confidence that the account holder has reached 15;
- providers subject to Article 8 and app stores do not have to assess age where they can establish with high confidence that the person is not a minor; and
- very large online platforms must submit a compliance plan explaining their approach to existing accounts, adult status and any reliance on the high-confidence exceptions.
How age verification connects to the rules
For Article 6, Article 29 would require providers to use a certified EU age-verification solution based on a third-party EU proof-of-age attestation. The proposal’s aim is to establish whether the person meets the threshold—not to disclose their identity to the service.
Articles 27 and 28 require accuracy, reliability, security, robustness, non-intrusiveness, privacy, data protection and non-discrimination. Age assurance must not identify, locate, track, target, advertise to or profile the recipient. The data must be limited to what is strictly necessary, and the proposal requires zero-knowledge proof.
Where account processing relies on consent, Article 6(5) says these rules operate in parallel with the national consent-age framework under GDPR Article 8.