Pubblicazioni
08.10.2026
Anteprima
EU KIDS Act: the European Commission proposes a graduated, age-based framework for minors’ access to social media
On 17 September 2026, the European Commission proposed the EU KIDS Act to introduce a gradual uptake of social media for children across the EU, stating that protecting children online is a priority and that concerns are growing about the risks children and teenagers face when using online platforms that are highly addictive and designed to grab their attention for as long as possible. The proposal applies to online services used by minors, including social media, video-sharing platforms, online games, and AI companions and chatbots, and builds on the work of the special panel of experts set up by President von der Leyen to develop a strong and practical European approach to keep children safe online.
Under the delayed-access strand, access to social media will be based on age: under 13, children will not be able to access social media services, although they can still use child-friendly video-sharing services through an account managed by a parent or guardian; from 13 to under 15, children will be able to use social media only through a mini account managed by a parent or guardian, with limited features and a time restriction of one hour per day; and from age 15 onwards, children will be able to open and manage their own social media account.
Under the safety-by-design strand, online services used by minors will have to offer stronger protection by default, including by limiting features that can encourage excessive use, such as infinite scroll, reward tricks and push notifications during sleeping hours, by prohibiting unsolicited contact from strangers, by ensuring that profiles for minors are private by default, and by offering easy ways to block or mute other users, while AI chatbots and companions must be turned off by default and will no longer be able to act in ways that make children emotionally dependent on them.
On age checks, online services and app stores will have to use tools to check users’ ages while protecting their privacy, for example through the EU age verification app, which does not retain identity documents or biometric data, and social media services and video-sharing platforms will be required to verify age when a new account is opened.
Finally, under the heading of increasing platforms’ responsibility, the EU KIDS Act will shift the burden of proof from regulators to platforms, so that providers of very large online platforms will have to show that their services are safe for children and designed with their wellbeing in mind; the proposal will now be examined by the European Parliament and the Council, who will negotiate and decide on the final text.
The 120-day time limit set by the Italian Data Protection Authority for imposing sanctions: The Supreme Court rules again, but the issue remains unresolved
In judgments Nos. 24861 and 24862, filed on August 31, 2026, the Supreme Court once again ruled on the time limits for proceedings before the IDPA.
Before dwelling upon the findings of the two mentioned rulings, it is worth to recall that the IDPA’s proceedings consist of two phases: a preliminary investigation phase, which may conclude with a decision of dismissal or the notification of a statement of objections (the “SOB”); following the latter, the proper sanctioning phase would follow, concluded by the final IDPA’s decision adopting the pecuniary administrative sanction and/or the other prescriptions of the authority.
A first point addressed by the two rulings concerns the twelve-month time limit within which the IDPA must normally decide on a complaint filed by an individual pursuant to Article 143 of the Privacy Code (D. Lgs. 196/2003) and 77 GDPR. The Court confirms that this time limit is not peremptory: exceeding it does not result in the IDPA losing its power to impose sanctions, because the complaint procedure is distinct and independent from the actual sanctioning procedure, the latter of which may also be initiated ex officio. Furthermore, a data subject whose complaint is not decided within the prescribed time frame is not left without recourse, as they may still bring the matter before an ordinary court.
The issue of the 120-day time limit revolves around an internal regulation adopted by the IDPA which sets forth that the Authority has 120 days from the finding (accertamento) of the violation to notify the alleged breach to the persons concerned who are resident in Italy (or 360 days if they are resident abroad).
Here are the takeaways of the August rulings on this matter which have been endorsed by the IDPA.
First of all, they confirm the preemptory nature of the 120-day time limit (which had already been asserted by previous case law of the same Court – i.e. ruling nos. 18583/2025, 984/2026 and 22791/2026).
Secondly, they point out that the 120-day period marks the end of the preliminary investigation phase and sets the deadline for serving the SOB, once the Authority has “made its mind up” as to the existence of an infringement to privacy laws.
Thirdly, once the SOB is served, only the five-year statute of limitations would remain applicable for the adoption of the final IDPA’s decision (the one which eventually imposes administrative pecuniary sanctions and/or prescriptions).
The debate on the interpretation of the mentioned rulings is ongoing as earlier case law of the same Cassation (rulings nos. 18583/2025, 984/2026) seemed to suggest that the 120-day time limit had to be intended for the issuance of the final sanctioning decision and started from the date the SOB was served.
The matter remains unsettled, pending a definitive clarification from the legislator or the Joint Sections of the Supreme Court.
Leggi il PDF






