EU VPN bans and restrictions

The EU KIDS Act's Silence on VPNs Is the Right Call, but the Gap Will Not Stay Quiet

The Commission's 17 September child-safety proposal targets platform conduct, not VPNs. Parliament should keep it that way and write that choice into the text.

EU KIDS Act at a glance People of Internet Research · EU 15 Independent account age Minimum age to open an unsupervise… 1 hour Daily cap, ages 13-15 Usage limit on supervised mini acc… 6 months Deadline to purge accounts Existing under-15 accounts must be… peopleofinternet.com
EU KIDS Act at a glance People of Internet Research · EU 15 Independent account age 1 hour Daily cap, ages 13-15 6 months Deadline to purge accounts peopleofinternet.com

Key Takeaways

A proposal that regulates platforms, not tunnels

On 17 September 2026 the European Commission proposed the EU KIDS Act, COM(2026) 681. It would bar children under 13 from social media. It would also set 15 as the age for opening an independent account. Children aged 13 to 15 would get supervised "mini accounts" capped at one hour a day. According to the Commission's announcement, platforms would have to restrict infinite scroll, reward mechanics and overnight push notifications. They would also have to block unsolicited contact from strangers. The EU's age verification app, which the Commission says does not retain identity documents or biometric data, is held up as the privacy-preserving way to check age.

The anti-circumvention rule in Article 4 is aimed at provider-side conduct. That means non-neutral design choices and nudging minors toward secondary accounts. The Commission's announcement page does not mention circumvention or VPNs, and neither did the text of the proposal we reviewed. The Commission has said it is not planning a VPN crackdown. Even so, the political question is open: what happens when a 14-year-old simply routes around an age gate?

The strongest case for worrying about VPNs

Regulators have a fair point. A law that sets a minimum age is only as strong as its weakest bypass. A January 2026 European Parliamentary Research Service briefing records "a significant surge" in VPN use to bypass age verification in countries that have mandated it. It also notes that some stakeholders propose restricting VPN access to users above the digital age of majority. If minors can switch jurisdictions with one tap, the argument runs, the Act's protections are cosmetic.

That concern explains why Executive Vice-President Henna Virkkunen was asked about VPNs at the press conference for the age verification app. As Euronews reported in its May fact-check, she said no technology is foolproof. She later told Finnish broadcaster Talousaamu that the aim was to make safeguards harder to bypass, not to prohibit VPNs. Her office said there is "absolutely no crackdown on VPNs."

Why targeting VPNs would be the wrong fix

The case against VPN restrictions is stronger, for four reasons.

The risk is in the drafting gap

Silence in the text is not the same as a commitment. The Parliament's own research service has already put VPN-provider age checks on the table as an idea. The Commission has so far offered only verbal reassurance that it will not follow that path.

The proposal will now be examined by Parliament and the Council. Amendments that quietly widen "circumvention" beyond provider conduct are the likely route to a VPN obligation. A rule against "facilitating circumvention" could be read to cover VPN providers. That is exactly how a measure framed as child safety turns into a general-purpose access control.

The sensible line is to keep Article 4 limited to what platforms do. Providers should not design interfaces that steer minors to second accounts. They should not treat a VPN connection as proof of adulthood. They should apply stricter defaults where signals suggest a minor is present, such as device-level age signals, account history and behavioural indicators, without collecting more identity data.

What lawmakers should do

First, Parliament should add a recital or operative clause stating that nothing in the regulation obliges VPN providers, or other general-purpose privacy tools, to verify users' ages or to block users. That would turn the Commission's spokesperson's assurance into law.

Second, the co-legislators should commission the missing impact assessment. It should include measured evidence on how often minors actually bypass age checks and what that bypass costs in harm reduction. The EPRS briefing documents surges in VPN downloads, but downloads are not a measure of child harm.

Third, platform liability should be tied to outcomes and good-faith design rather than perfect prevention. Under the proposal's enforcement structure, which borrows the Digital Services Act's fining framework, a provider could face penalties for leakage it cannot technically stop. Proportionality means judging whether a platform took reasonable steps, not whether any teenager anywhere found a workaround.

The EU can protect children without turning privacy tools into suspects. The Commission has so far kept VPNs out of its text. Parliament should write that restraint into the final law.

Sources & Citations

  1. European Commission: EU KIDS Act announcement (17 Sep 2026)
  2. European Parliament EPRS: Virtual private networks and the protection of children online (Jan 2026)
  3. EFF: EU Kids Act Won't Keep the Internet Accountable and Trustworthy
  4. Euronews fact-check: Is the EU about to restrict the use of VPNs?
  5. PPC Land: EU KIDS Act sets 6-month deadline to disable existing under-15 accounts