EU regulation

EU Digital Services Act and age assurance

The Digital Services Act does not order blanket age verification. It asks platforms accessible to minors to protect them proportionately, and the Commission's 2025 guidance points to age verification for higher risk services. Here's what it actually asks for.

At a glance

Law
Digital Services Act, Regulation (EU) 2022/2065
Key article
Article 28, protection of minors
Requirement
Proportionate measures for minors, not a blanket age-verification mandate
Data
Article 28(3): no duty to process extra personal data to check age
Guidance
Commission guidelines on protection of minors, 14 July 2025, voluntary
Blueprint
EU age-verification blueprint, 14 July 2025, built on the EUDI Wallet specs

What the DSA actually says

It is worth being precise here, because the DSA is often described as an age-verification law and it is not. Article 28(1) asks providers of online platforms accessible to minors to put in place appropriate and proportionate measures for a high level of privacy, safety and security for those minors. Article 28(2) bans profiling based advertising to users the platform knows with reasonable certainty are minors.

Article 28(3) is the part people miss. It says compliance should not oblige a platform to process additional personal data just to work out whether a user is a minor. So the DSA is risk based and proportionate, and it actively cautions against collecting more data to check age.

The 2025 guidelines

On 14 July 2025 the Commission published guidelines on the protection of minors under Article 28. They are soft law, so following them is voluntary and does not automatically prove compliance, but the Commission will use them when it assesses whether a platform meets Article 28(1).

The guidelines take a risk based line. They point to age verification for higher risk contexts, such as adult content and gambling or where national law sets a minimum age, and to age estimation in other cases. Whatever the method, it should be accurate, reliable, robust, non-intrusive and non-discriminatory.

The EU age-verification blueprint

On the same day the Commission released the first version of an EU age-verification blueprint. It is a white label, open source approach, and the detail that matters for us is that it is built on the same technical specifications as the EU Digital Identity Wallet. Denmark, France, Greece, Italy and Spain were the first to take it up.

That tells you the direction of travel. The Commission is steering age checks towards privacy preserving, wallet aligned proofs rather than document uploads and databases.

Where Tessio fits

Because Article 28(3) resists collecting extra personal data to check age, a proof that returns only an over-18 yes or no and stores nothing sits well with the DSA. Tessio does exactly that, from the EU Digital Identity Wallet.

It also uses the same standards as the Commission age-verification blueprint, so you are aligned with where EU age assurance is heading rather than betting on a document based tool that regulators are steering away from.

Frequently asked

Does the DSA require age verification?

No, there is no blanket age-verification mandate in the DSA. Article 28 asks for proportionate measures to protect minors, and Article 28(3) says you should not have to collect extra personal data just to check age. The Commission guidance recommends age verification for higher risk services like adult content and gambling.

What does Article 28 actually require?

Appropriate and proportionate measures for a high level of privacy, safety and security for minors on platforms accessible to them, no profiling based ads to known minors, and no obligation to process additional personal data to assess whether a user is a minor.

Is this the same as the EU age-verification app?

The Commission released an age-verification blueprint on 14 July 2025 that is built on the EU Digital Identity Wallet specifications. It is voluntary, and it points age checks towards the same privacy preserving, wallet aligned approach Tessio uses.

Primary sources

This is a plain language summary, not legal advice. Check your own duties against the primary sources and your regulator.

Put it into practice

Age verification API

Get ready with a wallet native check

Tessio proves someone is over 18 from their EU Digital Identity Wallet and stores no personal data. Access is invite only while we onboard design partners. Tell us what you're building.