I have mixed feelings about this proposal. I hope it fails in its current form, but I do not oppose its core purpose.
There is a genuine need to protect children online. Large technology and gaming companies should not be allowed to profit from minors' personal data or use manipulative systems designed to encourage excessive engagement and spending. Microtransactions, loot-box mechanics, and other gambling-like features can be particularly troubling when directed at children. The industry has had plenty of time to address these problems voluntarily, so simply maintaining the status quo is not a responsible solution. Nor has the industry shown an appropriate response to itself.
At the same time, this proposal appears too broad, too vague, and too open to unintended consequences or abuse. Age verification is one of my biggest concerns. Before such systems are widely required, we need clear answers about what information will be collected, who will process it, how it will be protected, how long it will be retained, and what recourse users will have when that information is leaked or misused.
There may be ways to verify age while minimizing the amount of personal information disclosed, which would be a positive development. However, I am not convinced that the technology, legal safeguards, and accountability surrounding these systems are mature enough for deployment across such a broad range of mainstream services. A system created to protect children should not result in everyone surrendering more sensitive information to private companies or third-party verification providers.
GDPR is a useful comparison. It established worthwhile protections, including greater transparency and the right to request deletion of personal data. Those are meaningful benefits. However, exercising those rights can still place too much responsibility on individual users after their information has already been collected, shared, or otherwise processed. A technical method for requesting deletion does not necessarily provide a practical way to prevent abuse in the first place.
That is why I hope this proposal fails in its current form, but I do not want its failure to mean that the underlying issue is abandoned. Ideally, it would lead to a narrower, clearer, and more technically realistic proposal. Any replacement should be developed with substantial input from privacy and security experts, developers, parents, civil-liberties organizations, and the people who actually use and operate these services.
The EU has identified a real problem, and standing still is also harmful. However, recognizing the problem does not automatically make this particular solution the right one. We need protections that hold companies accountable without creating intrusive identification systems, placing sensitive information at greater risk, or unintentionally damaging legitimate online services.
But we cannot lose sight of the reason this legislation exists. As I type this, children are spending real money in real games on mechanics designed to imitate or encourage gambling and addictive behaviors. Companies are collecting information about how those children play, what attracts their attention, and what persuades them to spend, then using that knowledge to increase engagement and profit. That is the core problem.
This proposal may be too vague, too intrusive, and too poorly designed to solve it, but the failure of this bill cannot become an excuse for doing nothing. The EU has identified the right problem and produced the wrong solution. If this bill fails, it should be replaced with legislation that directly confronts the exploitation of children without requiring everyone to surrender even more personal information in the process.