Current status: European Commission proposal — not adopted EU law

Regulatory guide

Compliance, enforcement & implementation

The proposal would use several existing EU enforcement systems rather than one regulator or one penalty rule for every provider.

The applicable route depends on the service, the provider’s status and the obligation breached. “Fines up to 6%” is not a complete description.

Compliance plans and independent audits

Article 5 applies only to providers of online social-networking services and video-sharing platform services that are designated as very large online platforms under the Digital Services Act. It is not a licensing system, certification scheme or prior authorisation to operate.

A newly designated provider would notify the Commission of a detailed compliance plan within four months of its DSA designation. A provider already designated when the Regulation starts applying would have 30 days from that application date. The plan covers Chapters II–V.

The provider must commission and pay for an independent audit by auditors with relevant child-protection, medical, developmental, age-assurance, interface, recommender-system, data-protection and security expertise. The auditor sends a draft report to the provider, allows 15 days for comments, and sends the final report to both provider and Commission within two months after receiving the plan. The provider must publish a non-confidential summary without undue delay.

If the Commission decides that the plan has shortcomings, the provider has 30 days to submit a corrective-action plan. Each measure must have a reasonable implementation period of no more than 60 days, and the auditor verifies implementation.

No general compliance certificate

Article 5(8) says neither the final audit report nor Commission action—or inaction—on it or the plan constitutes a finding that the provider complies with Chapters II–V. Nor does it limit the Commission’s powers.

After the first notification, the provider reports annually through its DSA risk assessment, and KIDS Act compliance becomes part of its DSA independent audit. The Commission may adopt implementing acts on audit templates and methods.

Which authority would enforce which rules?

Article 34 connects each provider category to a principal framework. Separately, data-protection authorities supervise the personal-data processing needed to comply with the proposal, particularly Articles 27–29.

Principal proposed enforcement routes by provider and service category
Provider or servicePrincipal routeImportant qualification
Social networks and video-sharing platformsDSA Chapter IV: Digital Services Coordinators and, for designated very large online platforms, relevant Commission powers.Article 5 plans and audits apply only to designated VLOPs. GDPR authorities supervise relevant age-assurance data processing.
Software application storesDSA Chapter IV.Commission powers and the proposed fee depend on very-large-platform designation and the Article 36 conditions. GDPR supervision remains separate.
Video-gaming platformsDSA Chapter IV.Article 21 complaints and collective representation name gaming platforms. A standalone video game follows the next row instead.
Standalone video gamesA Member State-designated competent authority with DSA Article 51 powers enforces Article 15 and applicable Articles 8 and 18–22.The main-establishment Member State authority has exclusive power. Member States set penalties using the DSA Article 52 framework. Article 21 does not name standalone games.
AI companions and general conversational chatbotsAI Act Chapter IX, including the AI Office or national market-surveillance architecture as applicable.The proposal extends that framework to Chapters II–IV and gives the Commission relevant AI Act powers where the AI Act assigns it exclusive supervision.
Operating systemsNo general category-wide enforcement route is expressly assigned by Article 34.GDPR authorities supervise personal-data processing required by the proposal, including relevant Articles 27–29 duties.
Personal-data processing for complianceGDPR supervisory authorities.For infringements of Articles 27–29 data-protection obligations, Article 34(6) points to GDPR Article 83 fines up to the Article 83(5) amount.

Member States must ensure that their DSA and AI Act authorities are competent for the KIDS Act responsibilities assigned to them. The Commission, Digital Services Coordinators, market-surveillance authorities and consumer-protection authorities must cooperate; national decisions must not conflict with a Commission decision under the proposed Regulation.

Complaints and collective representation

Article 21 gives minors and guardians using the listed social networks, video-sharing services and video-gaming platforms—and users of covered AI systems—the right to mandate a qualifying non-profit body, organisation or association to exercise KIDS Act rights on a minor’s behalf.

Those users and qualifying bodies may lodge a complaint with the competent authority in the Member State where the recipient or user is located or established. Complaints concerning AI systems under the European AI Office’s exclusive competence may go to that Office. These rights sit alongside DSA Article 53 and the Representative Actions Directive; they are not a universal complaint route for every Article 2 category.

Monitoring and EU legal representatives

Article 22 would require Article 8 providers that are designated very large online platforms to monitor, test and evaluate their KIDS Act measures as part of their DSA risk assessment. The duty is tied to VLOP designation, not imposed identically on every provider.

Under Article 24, covered social, video-sharing, game and AI providers without an EU establishment must designate a legal representative in a Member State where they offer the service or system. An existing DSA or AI Act representative may receive an extended mandate. The representative supports receipt of and compliance with enforcement decisions; designation does not remove the provider’s responsibility.

Commission proceedings and timing

For KIDS Act cases involving designated very large online platforms or AI systems under the Commission’s exclusive AI Act supervision, Article 35 says the Commission must endeavour to communicate preliminary findings within the bracketed proposal target of 30 working days after proceedings open and to adopt a final decision within 90 working days. These are proposed case-handling objectives, not deadlines for Parliament or Council to adopt the Regulation.

The provision imports the corresponding DSA and AI Act investigative and decision-making powers. It does not remove defence rights or make an opened proceeding proof of an infringement.

Penalties: several routes, not one number

  • DSA route: for providers in Article 34(1), DSA Chapter IV applies. Under the DSA, the Commission’s fines for a designated VLOP infringement can reach 6% of worldwide annual turnover, while Member States must set penalties within the DSA Article 52 limits for matters within their competence.
  • AI route: Article 34(2) expressly provides administrative fines under AI Act Article 99 not exceeding 6% of the provider undertaking’s worldwide annual turnover in the preceding financial year where it acted intentionally or negligently.
  • Standalone games: Member States set penalties for the provisions listed in Article 34(5), using the DSA Article 52 framework.
  • Age-assurance data rules: GDPR authorities may impose fines in line with GDPR Article 83, up to the amount in Article 83(5), for infringements of Articles 27–29 data-protection obligations.

The legal maximum is not an automatic fine. The responsible authority, infringement, competence rules and statutory criteria all matter.

Supervisory fees

Article 36 would require an annual fee from certain providers subject to Commission supervision: qualifying designated very large platforms and covered AI or gaming-platform providers where the Commission has competence. A fee is charged for each in-scope service or system and funds the Commission’s preceding-year KIDS Act supervisory costs, including the EU Age Verification Scheme.

The fee for each provider may not exceed 0.03% of its worldwide annual net income in the preceding financial year. The Commission would set the detailed method and payment arrangements by delegated act, applying the principles used for the DSA supervisory fee.

Member State support and implementation

Article 33 would require national strategies giving minors and guardians easy, free and confidential help channels, risk and protection information, and relevant digital-literacy support. Strategies must build on Safer Internet Centres, helplines and hotlines and be communicated to the Commission on the proposal’s relative timetable.

Article 31 separately requires Member States to make privacy-preserving parental-responsibility attestations, alternative procedures and at least one free certified EU age-verification solution available and accessible.

Expertise and incident response

The Commission and competent authorities would develop Union child-protection expertise, including for incidents. Article 38 provides for coordinated incident assessment, knowledge-sharing networks, a voluntary administrative rapid-response arrangement and minimum national preparedness. It complements rather than replaces the DSA crisis tools.

Delegated and implementing measures

The proposal leaves important technical detail to later measures. Delegated acts could update specified safety measures and set the supervisory-fee method; implementing acts could set Article 5 audit templates. Article 39 gives Parliament and Council scrutiny rights over delegated acts, while Article 40 establishes a Member State committee for implementing acts.

Voluntary EU codes of conduct under Article 23 may help demonstrate compliance but do not displace the legal duties. Article 25 also lets the Commission update a closed list of measures in response to emerging risks; it does not give a general power to rewrite every obligation.

When enforcement provisions would apply

Article 43 is still proposal text. If adopted as drafted, the Regulation would enter into force 20 days after Official Journal publication and generally apply six months after entry into force. Article 5 would apply from entry into force; Articles 33 and 35 would apply 12 months after entry into force. No calendar dates can yet be calculated because there is no adopted act or publication date.

See the legislative process and current status.

Sources and legal references

Primary sources used

EU KIDS Act proposal, COM(2026) 681 final

Articles 5, 21–25, 27–31, 33–40 and 43.

Digital Services Act

Chapter IV, including Articles 43, 49, 51–53 and 66–74.

AI Act — consolidated text

Chapter IX supervisory architecture and Article 99 penalties.

General Data Protection Regulation

Articles 51 and 83 for supervision and fines.