Which app stores are in scope?
Article 3 imports the Digital Markets Act definition of “software application store”: a type of online intermediation service focused on software applications as the intermediated product or service. For the proposed KIDS Act, the category is treated as an online platform.
Article 2 applies to providers offering the service to people established or located in the EU, regardless of where the provider is established, where the store is accessible to minors. Coverage depends on the definition and facts, so this page does not declare any named commercial service definitively in scope.
General safety-by-design duty
Article 8 includes software application stores. They must ensure a high level of privacy, safety and security for minors, apply the relevant Chapter III requirements by default and depart from them only after compliant age assurance establishes that the user is an adult.
The dedicated operative rules are in Article 16. Articles 18–20 do not generally name app stores, and Article 25’s list of measures that may be updated by delegated act does not include Article 16.
A mandatory age-rating system
Each store provider must establish an age-rating system capable of determining the age-appropriateness of every software application offered through the store. The system must take due account of children’s evolving capacities.
The provider must publish a clear, accessible description of the methodology, criteria and sources used. Article 16 does not prescribe a named commercial rating scheme; Article 17 instead envisages an EU code-of-conduct process for harmonisation.
Access and purchase restrictions
The store must not let a child access or purchase an application that its rating system finds inappropriate for that child’s age. That store-level duty does not replace the separate Article 6 account restrictions that may apply inside a social-network or video-sharing app.
If the store becomes aware that an application is subject to—or primarily consists of content subject to—a higher minimum age under EU law or compatible national law, it must block access or purchase below that higher age in the Member State or States concerned.
Age assessment and guardian controls
To implement those restrictions, the store must assess the user’s age under Chapter V. Article 29(4) allows a method other than the certified EU Article 6 verification route if the store can demonstrate that the method meets Article 27’s quality requirements and Article 28’s privacy rules.
For children below 13, Article 16 says access must be enabled and controlled through Article 20 guardian tools. This reference does not make the full general provider scope of Articles 18–20 apply to stores.
Under Article 32(3), the store need not assess age where it can establish with a high degree of confidence that the person is not a minor.
Privacy and stored age signals
App-store age assurance must be accurate, reliable, secure, robust, non-intrusive, privacy-preserving and non-discriminatory. It must not identify, locate, track, target, advertise to or profile the user, and it must minimise and separate personal data.
Article 28(4) allows the store to keep at account level only the minimum age signal showing that a threshold was met, solely to avoid repeated age assurance. Users must have a free electronic mechanism to challenge an incorrect result.
See age assurance & age verification for the full framework.
EU age-verification solutions in stores
Article 16(6) requires a store to allow a certified EU age-verification solution using a certified EU proof-of-age attestation to be offered in the store. This is distinct from saying that every app-store age decision must use one particular EU app.
Article 17 codes of conduct
The Commission would facilitate EU-level codes involving stores, games, developers, content providers, rating-system providers, child and guardian organisations, civil society and authorities. The codes should:
- support mutual recognition and consistent application of ratings across Member States;
- define criteria for violent, sexual, gambling and self-harm content, in-app purchases, contact risks and addictive design;
- provide free, impartial and financially independent redress for content providers disputing a rating;
- use prominent, recognisable labels and descriptions before access or purchase; and
- include regular independent monitoring, performance indicators and updates.
Interaction with online games
A game distributed through a store would be rated and access-controlled at store level under Article 16. The game provider may separately face Article 15 duties. Article 17 is intended to align methodologies for both stores and games while preserving those distinct obligations.
Read the online-games guide for game design, contact, guardian and enforcement rules.
What this means for app developers
The direct Article 16 duties fall on the store provider. But every offered application must receive a rating, and Article 17 envisages developers and content providers participating in common methodologies. The proposed code must also provide them a free independent route to challenge rating disputes.
The proposal does not, through Article 16 alone, transfer the store’s age-assessment duty to every developer. An app provider may of course have separate duties where the app itself is an in-scope social service, game or AI system.
Anti-circumvention
Article 4 applies to app-store providers. They must not use contractual, commercial, technical, behavioural or interface measures to undermine their duties, or knowingly and intentionally act to circumvent them.
Enforcement
Article 34 applies the Digital Services Act enforcement framework to software application stores. Data-protection authorities supervise processing needed for Articles 27–29 and may use the GDPR penalty framework for infringements of those data rules.
Where a store is designated a very large online platform, the Commission’s relevant DSA powers also extend to the proposal. Article 35 sets an expedited-proceedings objective for Commission cases, while Article 36 allows an annual supervisory fee for in-scope very large platforms, including software application stores, subject to its conditions and cap.
The enforcement route therefore depends on the provider’s status and the provision breached; a single universal penalty description would be inaccurate. See compliance, enforcement and implementation.