Source: OJ L 277, 27/10/2022, p. 1–102

Current language: EN

Article 28 Online protection of minors


Summary What does Article 28 of the DSA regulation say?

This article places specific obligations on providers of online platforms that are accessible to minors, requiring them to ensure a high level of privacy, safety, and security for those users.

It also introduces a targeted restriction on advertising, prohibiting profiling-based ads when the platform is aware that the recipient is a minor.

Notably, the article includes a safeguard to prevent the rules from becoming self-defeating: platforms cannot be forced to collect more personal data just to determine whether a user is a minor.

The Commission retains the ability to issue guidance to help platforms apply these protections in practice.

Important points:

  • Providers of online platforms accessible to minors must put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security for those users.
  • Do not present profiling-based advertisements to any recipient of the service when you are aware with reasonable certainty that they are a minor.
  • Compliance with this article does not require you to process additional personal data solely to assess whether a recipient is a minor.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Providers of online platforms accessible to minors shall put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors, on their service.

    1. Providers of online platform shall not present advertisements on their interface based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679 using personal data of the recipient of the service when they are aware with reasonable certainty that the recipient of the service is a minor.

    1. Compliance with the obligations set out in this Article shall not oblige providers of online platforms to process additional personal data in order to assess whether the recipient of the service is a minor.

    1. The Commission, after consulting the Board, may issue guidelines to assist providers of online platforms in the application of paragraph 1.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod