EU Digital Services Act Guidelines Raise the Bar for Safer Design for Minors
The European Commission is sharpening its approach to digital features that can keep children online longer than intended. Its Digital Services Act (DSA) guidance on protecting minors calls on platforms accessible to children to adopt safer defaults, including disabling features that contribute to excessive use by default for minors. The shift matters because it places product design, recommender systems and advertising practices alongside content moderation as core online-safety concerns. The Commission published its Guidelines on the protection of minors under the DSA on July 14, 2025. The guidance supports compliance assessments under Article 28 of the DSA through a risk-based, safety-by-design framework. It is not simply a statement against screen time. It sets out concrete measures intended to reduce risks to minors and frames privacy, safety and wellbeing as design priorities. For businesses that operate apps, marketplaces, communities or other online services in the EU, the practical question is no longer limited to whether harmful content is removed. Teams also need to understand whether interface choices, personalisation and notifications could amplify compulsive behaviour among underage users. What the DSA guidance changes The Commission identifies several features that may contribute to excessive use and says platforms should disable them by default for minors. Examples include messaging streaks, ephemeral content, read receipts, autoplay and push notifications. It also calls for the removal of persuasive, engagement-focused design elements where they create risks for children and young people. This is part of a wider DSA framework. The regulation already prohibits deceptive or manipulative interface practices, often described as dark patterns, and prohibits targeted advertising to children. The new guidance gives platforms a more detailed reference point for addressing risks to minors through product and account design. | DSA area | What the verified material establishes | Practical focus for platform teams | |---|---|---| | Minors protection guidance | Safety-by-design measures include disabling certain excessive-use features by default for minors. | Review autoplay, push prompts, streaks, read receipts and similar engagement loops. | | Advertising | The DSA prohibits targeted advertising to children. | Assess audience classification and ad-targeting workflows involving minors. | | Interface design | The DSA bans deceptive or dark-pattern practices. | Test whether consent, privacy and engagement flows are clear and age-appropriate. | | Enforcement | In February 2026, the Commission announced preliminary findings that TikTok's addictive-design features may breach the DSA. | Treat risk assessment, risk management and design decisions as enforceable issues. | The TikTok case is particularly significant as an enforcement signal, not because the guidance is limited to one company. On February 6, 2026, the Commission said its preliminary findings concerned whether TikTok's addictive-design features could breach DSA requirements relating to risk assessment, risk management and design decisions affecting minors. The related proceedings underline that so-called rabbit-hole effects and engagement-driven design can be treated as material risks under the regulation. What businesses should audit now The guidelines apply to platforms accessible to minors and use a risk-based approach. The DSA applies across the EU regardless of platform size, although the guidance has exclusions for micro and small enterprises in some circumstances. That distinction does not make a smaller service immune from scrutiny of its design choices. It does mean operators should assess their precise obligations and the relevance of the guidance to their service. A useful first review should cover the full user journey rather than a single feature. Teams can start by examining: - Engagement mechanics, including endless feeds, autoplay, notification prompts, streaks and reward loops. - Recommendation settings, particularly whether personalisation could repeatedly reinforce content or behaviour in ways that entrench use. - Minor account defaults, such as private-by-default settings and controls that are appropriate for younger users. - Advertising controls, to ensure targeted advertising is not shown to children. - Age and parental tools, including age-verification considerations and mechanisms that help parents or guardians manage a child's experience. The guidance also points toward non-personalised feeds where feasible. That does not mean every service must abandon recommendation technology. It does mean that design and product teams need to consider whether a feed's configuration creates risks for minors, and what safer alternatives or controls are appropriate. For app developers and website owners, this can affect roadmaps and operating costs. A platform may need separate settings for minor accounts, changes to notification infrastructure, revised advertising logic, stronger age-assurance processes and product testing that considers child safety. These are not merely legal-document updates. They can require changes to databases, account permissions, frontend interfaces and the systems that determine what users see. The most practical response is to connect legal requirements to specific product decisions. Document which features are available to minors, how defaults differ by age group, how advertising audiences are handled and who can change recommendation or notification settings. That record can make gaps visible before they become a redesign project. For companies that rely on major social platforms for marketing, the immediate impact is also worth monitoring. The DSA prohibition on targeted advertising to children limits how campaigns can reach younger audiences. Marketing teams should avoid assumptions that audience targeting methods available for adults can be used for minors, and should make sure campaign planning reflects the platform's applicable controls. Safer design is becoming a product requirement, not a late-stage compliance check. Businesses building consumer-facing services should address it during feature planning, especially where children are likely to access the service. If your product team needs to turn changing platform rules into workable account settings, user flows and backend controls, Scalevise's custom software development service can help identify the changes that reduce manual work while supporting safer customer experiences. A focused implementation plan can clarify which features need redesign, what data and permission logic must change, and how to deploy updates without disrupting essential workflows. Request a consultation to discuss your platform changes. Frequently Asked Questions What do the European Commission's DSA guidelines say about addictive features? The guidelines identify measures to reduce risks to minors, including disabling by default features that can contribute to excessive use, such as streaks, ephemeral content, read receipts, autoplay and push notifications. Does the DSA ban targeted advertising to children? Yes. The DSA prohibits targeted advertising to children, alongside broader protections for minors' privacy, safety and wellbeing. Are the DSA guidelines only relevant to large platforms? The DSA applies EU-wide regardless of platform size, while the guidance has exclusions for micro and small enterprises in some circumstances. Platforms accessible to minors should assess their specific obligations and risks. What did the Commission find in its TikTok case? On February 6, 2026, the Commission announced preliminary findings that TikTok's addictive-design features may breach DSA requirements related to risk assessment, risk management and design decisions affecting minors. Conclusion The Commission's minors-protection guidance makes clear that EU online-safety expectations now extend deeply into user experience and personalisation choices. Platforms accessible to children should review engagement features, advertising controls, account defaults and age-related safeguards as connected parts of product design. The TikTok preliminary findings show that these questions are moving from policy guidance into active enforcement. Top comments (0)
Comments
No comments yet. Start the discussion.