On 11 September 2026 the commission on Child and Youth Protection in the Digital World handed its final report to Family Minister Karin Prien. The report contains 56 recommendations, which the commission had first made public on 24 June 2026. Prien said the commission's work ends that day but that implementation of its recommendations "has long since begun." The report matters because it moves German platform regulation away from takedown deadlines, which was the NetzDG model, and toward design duties and age assurance.
The strongest case for a hard age floor
The case for a statutory minimum age deserves a fair statement. Self-declared birthdays have never worked. Voluntary platform measures have been slow. Parents are asked to police products built by some of the best-funded engineering teams in the world. A legal floor shifts the burden from individual families to the companies that profit from engagement, and it gives enforcers a clear line to apply. Prien has said that a statutory age limit of 13 is "in principle, the right way forward". The report also notes that several other countries are pursuing similar limits.
What the commission actually proposed
The commission did not propose a single answer. It set out two alternatives for social media:
- Option one: a statutory minimum age of 13, backed by effective age verification. For under-13s, only demonstrably child-safe, low-risk services would be permitted. Tiered protections would apply at 13–16 and 16–18. This is described on the ministry's recommendations page.
- Option two: no uniform age limit. Instead, a binding rule would restrict specific services or functions for certain age groups where a risk assessment shows particular danger. The report's examples are algorithmic feeds, open contact functions and livestreams.
The report also recommends safety-by-design defaults for minors' accounts and AI safety standards for youth-oriented services. Prien's own summary of the philosophy is that "platform providers must be structurally held accountable" and that services must be "designed safer ... from the start."
Why the legal frame is the DSA, not Berlin
NetzDG no longer exists as a standalone rulebook. As netzpolitik.org reported, the Digital Services Act took over from February 2024 and applies to all digital services, not only large social networks. The Bundesnetzagentur oversees it in Germany. That shapes what Berlin can do. A heise report on the commission's April status assessment noted that most regulatory authority sits at the European level, which limits German lawmakers' room to act. Prien says she will pursue a European solution but prepare national rules in parallel if Brussels stalls.
Brussels has already built part of the toolkit. The Commission's 14 July 2025 guidelines on minor protection under DSA Article 28 call for private accounts by default for minors. They also ask for modified recommender systems and for engagement features such as streaks and autoplay to be switched off by default. On age assurance they ask for methods that are "accurate, reliable, robust, non-intrusive, and non-discriminatory." The guidelines are voluntary, but they inform enforcement of Article 28(1). Option two is essentially a binding, age-banded version of that approach. Option one would sit awkwardly beside it, because a national access ban on a service the DSA treats as lawful invites a conflict with the single market.
Why function-based limits are the better bet
The deeper problem with a blanket floor is what enforcing it requires. Effective verification for every user means every adult must also prove their age to read, post or reply. That builds identity checks into the open internet. It also creates new data stores that attackers will target and pushes people toward whichever services verify least. The costs are certain, and the child-safety benefit depends on how well verification works. The Commission itself was reported to be skeptical that age verification works against jurisdictional limits.
The function-based route targets the mechanisms with the clearest link to harm. These are engagement-optimised feeds, contact from strangers and live broadcast to unknown audiences. It leaves lawful speech and information access intact for teenagers, who also have rights to expression and participation, which the commission itself puts at the starting point of its recommendations. It also rewards product redesign over blunt exclusion. Smaller services can comply by switching off a feature, where a compliance regime built on identity checks would favour incumbents that can afford one.
The hybrid is workable. Germany can adopt option two as its negotiating position in Brussels. It can define a short list of high-risk functions and require risk assessments to justify age-banded limits. It can then use the DSA's existing audit and enforcement machinery rather than creating a parallel national regime. Age assurance should be reserved for the functions where the risk assessment justifies it, and it should be privacy-preserving and proportionate, as the Commission's own guidelines require.
What to watch before year-end
Prien wants key points for legislation and an immediate action programme ready for the federal cabinet on 16 October 2026. Three tests will show whether Germany is choosing proportionality. The first is whether the draft names specific functions and evidence thresholds, or leaves "risk" undefined. The second is whether any age-verification mandate comes with data-minimisation rules. The third is whether Berlin brings its proposal to the Commission before legislating nationally. Germany spent years learning from NetzDG that national speech rules collide with European law and over-remove lawful content. The same discipline should apply to design duties.