Skip to main content
PrivacyEU Kids ActAge verificationBill C-34Brussels effect

Europe Just Published the Age-Verification Playbook. Canadian Privacy Teams Should Read It.

The EU Kids Act, proposed September 17, 2026, would make age checks the entry ticket to social media, games, and AI chatbots. For Canadian teams, it is a preview of where Bill C-34 is heading and what the Brussels effect will demand.

4 min read
ShareLinkedIn

Key takeaways

  • The EU Kids Act proposal (September 17, 2026) would phase social media access by age (no accounts under 13, supervised mini-accounts at 13-15, autonomous accounts at 15+), mandate age verification, and impose safety-by-design duties across social media, games, app stores, and AI chatbots.
  • It is not law and may not apply before 2028, but the architecture decisions it forces get locked in now, while vendors are chosen.
  • Canada’s Bill C-34 is heading the same direction with its proposed under-16 age gate. Treat the EU text as an early draft of your own homework: prove age without keeping identity, and ship safe defaults first.

On September 17, 2026, the European Commission published its proposed EU Kids Act. The EFF’s analysis calls it what it is: the largest attempt yet to make age verification a precondition for ordinary internet use. If your product reaches minors, this is your compliance future, and it is not a foreign story for Canadians.

What the Commission proposed

Phased access. No accounts under 13; supervised mini-accounts with parental control and limited features from 13 to 15 (reported outlines include a one-hour daily cap); autonomous accounts in a safe-by-design environment from 15.

Mandatory age verification through an EU age verification solution built on EU digital identity rules. The Commission says the app retains no identity documents or biometrics. The EFF flags the catch: providers that can tell with a “high degree of confidence” that a user is above the threshold need no re-verification. That vague standard is the battleground.

Safety by design. Social media, video platforms, online games, AI companions and chatbots, app stores: child-safe by default with limits on infinite scroll and reward tricks, no push notifications during sleeping hours, no unsolicited contact from strangers, private profiles by default. AI chatbots would be off by default and barred from fostering emotional dependence.

Not law yet. Parliament and Council must negotiate; Wilson Sonsini’s Data Advisor says the Act is unlikely to apply before 2028. Exemptions cover non-profit encyclopedias, scientific repositories, educational services, and open-source platforms, but not small businesses. The EFF notes the proposal skipped a full impact assessment.

The trend is law-like even before the text is law

Jurisdiction Age rule Status
Australia Under-16 social media ban (Online Safety Amendment Act 2024) In force since late 2025
France Under-15 social media ban Struck down before taking effect (August 2026); revised proposal underway
United Kingdom Announced under-16 ban Announced June 2026, intended early 2027; legislation not yet introduced
EU Phased: no accounts under 13, supervised 13-15, autonomous 15+ Proposal; negotiation ahead; unlikely before 2028
Canada Proposed under-16 age gate plus a Digital Safety Commission (Bill C-34) Proposal

France’s ban died on proportionality: blanket age bans lose in court, while risk-based, least-intrusive designs survive. Brussels and Ottawa are both moving toward the latter.

Why this is Canada’s homework too

The Brussels effect is doing what it always does. Michael Geist’s analysis this week notes Canada is negotiating a Digital Trade Agreement with the EU whose directives say the deal should “neither negotiate nor affect the EU’s personal data protection rules.” European law becomes the standard; Canada finds room around it. The EU AI Act already reaches Canadian providers whose systems are used in Europe. The Kids Act applies the same export to children’s safety, and Canadian companies serving EU users will comply with it whatever Parliament does.

Canada is building its own gate anyway. Bill C-34 carries a proposed under-16 age verification duty, a Digital Safety Commission, and 24-hour CSAM/NCII duties. I wrote in April about the paradox: prove you are 16, then destroy the verification data so the gate never becomes a registry. The EU version is bigger but structurally identical.

Architecture locks in before legislation does. Where age signals are collected, stored, kept, and seen is decided when vendors are selected. A proposal with a two-year runway is the best compliance gift you will get. Use it.

What privacy teams should do now

Map every place you collect age or identity signals. Sign-up, parental consent, ad targeting, support desk. Campaigners’ readings of the proposal say platforms would have to check all existing accounts, with accounts whose age cannot be established at risk. Know your backlog before anyone audits it.

Separate proof of age from proof of identity. Build age assurance that returns an attribute (“over 16”) and retains nothing else. Hold every vendor to that term, and verify it technically, not on a slide deck.

Ship safe defaults now. Private-by-default profiles, no stranger contact, recommender choice, notification quiet hours: defensible today under PIPEDA’s safeguards and Law 25’s privacy-by-default, whatever Ottawa or Brussels enact.

Document proportionality reasoning. France’s ban failed that test. Keep the record: the risk assessment, why an age gate is the least intrusive effective measure, the alternatives you rejected. This is the file the regulator will ask for.

Actionable takeaway: Pick one product surface where you serve EU users, or minors in Canada, and draw a one-page age-assurance data-flow map: what age signal you collect, where it is stored, how long it is kept, who can see it. Any “we’re not sure” is the first gap the EU Kids Act will ask about.

Related services

Practical consulting aligned to this article’s focus—program design, controls, and operational delivery.

Browse all services