Dating apps

Age verification requirements for dating apps: EU

· 8 min read

Applies to
Dating and social discovery platforms offering services in the EU, above micro and small enterprise size
In force
DSA Article 28 since 17 February 2024; Commission guidelines since 14 July 2025
What to do
Run age assurance that does not collect more data than the age question needs, and treat your establishment state as the primary regulator

On 16 June 2026 the Grand Chamber of the Court of Justice told France it could not use its criminal code to force age checks onto a company established in the Czech Republic. In the same ruling it told France how it could.

That is the shape of age verification in the EU, and it is a different shape from the UK. There is no single European statute setting an age check requirement for dating apps. There is one horizontal duty that reaches every platform, a national patchwork currently aimed at pornography rather than dating, and a jurisdictional rule that decides which of the two can actually touch a given company. The jurisdictional rule is the part that just moved.

The one duty that reaches everyone

Article 28(1) of the Digital Services Act requires providers of online platforms "accessible to minors" to put in place appropriate and proportionate measures ensuring a high level of privacy, safety and security for minors on their service. A dating app is an online platform. The only question is whether it is accessible to minors — and answering that is the same fork the UK draws, arrived at from a different direction.

The Commission's guidelines on the protection of minors, published 14 July 2025 and now in the Official Journal, set out what the Commission expects. They apply to all online platforms accessible to minors except micro and small enterprises. They recommend age assurance that is "accurate, reliable, robust, non-intrusive, and non-discriminatory." And they split the methods by situation: age verification where access is being restricted to adult content such as pornography, to gambling, or where national rules set a minimum age for a category of service; age estimation in other cases, such as where terms and conditions set a minimum age below 18 because of identified risks to minors.

Two things about their status matter. Following them is voluntary and "does not automatically guarantee compliance." But the Commission has said it will use them to assess compliance with Article 28(1), and national regulators may draw on them in enforcement. In practice they are the standard.

Worth knowing where you are not: no dating service appears on the Commission's list of designated very large online platforms, last updated 24 July 2026. No dating app carries the systemic risk assessment duties, and none is supervised directly by the Commission. Supervision runs through the Digital Services Coordinator of the member state where the provider is established.

The constraint the UK does not have

Article 28(3) says something the Online Safety Act does not. Compliance with Article 28 shall not oblige providers to process additional personal data in order to assess whether a recipient of the service is a minor.

That single sentence reshapes the design problem. In the UK the instinct is to strengthen the check until it is defensible, and the data-protection question is handled afterwards by discarding what you no longer need. In the EU the data-minimisation constraint sits inside the age assurance obligation itself, not next to it. A check that satisfies a regulator by collecting more is not a better answer here; it is a worse one.

This is why the European answer trends toward device-based proofs rather than document uploads. The Commission has published an age verification blueprint — a white-label app, built on the same technical specifications as the European Digital Identity Wallets, that lets a person prove they are over a threshold without disclosing name, address or date of birth. An enhanced second version followed in October 2025. Under the EU Digital Identity Regulation, member states must make a wallet available, and the guidelines name the wallets and the blueprint as a reference standard for device-based age verification.

For a product team the implication is concrete. Build against a proof-of-age interface that returns a boolean, not against a document scanner. The interface is what the EU is standardising on.

Whose regulator can reach you

Under Article 3 of the e-Commerce Directive, an information society service is governed by the law of the member state where its provider is established. For years this country-of-origin principle was the reason a dating app incorporated in Ireland could largely ignore a French or Italian mandate.

The June 2026 judgment in joined cases C‑188/24 and C‑190/24, on references from the French Conseil d'État, redrew that line in both directions. The Court held that the coordinated field is broad — it covers general and abstract criminal legislation, and legislation pursuing public policy, security and safety objectives. It then held that member states are precluded "from applying a general and abstract obligation under criminal law, intended to prevent access by minors to pornographic content, to information society service providers established in other Member States."

But it did not stop there. The same operative part holds that the directive does not preclude a member state from adopting measures requiring "providers of a given service, established in other Member States, to establish a system for verifying the age of users of pornographic sites" — subject to the conditions in Article 3(4), and where those providers have not themselves taken the appropriate measures referred to in Article 28b of the Audiovisual Media Services Directive.

The distinction is procedural, and it is the whole ruling. A blanket national law applied to everyone cannot cross the border. A measure aimed at a named provider, after the establishment state has been asked to act and the Commission notified, can. Country of origin is now a procedure another regulator has to follow, not a wall.

The second holding in the same judgment deserves attention from anyone running a matching algorithm. Where an operator determines by algorithm, in its own interest, "under what conditions, how and in which order of priority" stored information is broadcast, it exercises control over that information and is not a hosting provider within Article 14(1). Curation is control, and control costs the immunity.

The national layer, and who it is currently aimed at

Two mandates are live and worth reading, neither of which targets dating.

France. ARCOM's technical référentiel, adopted under the SREN law of 21 May 2024, sets minimum technical requirements for age verification systems on sites distributing pornographic content, and ARCOM can pursue blocking and delisting against sites that fail. Its centrepiece is double anonymity: the site learns that the visitor is an adult but not who they are, while the verification provider learns who they are but not which site they are visiting. The CNIL reviewed and approved it.

Italy. AGCOM's delibera 96/25/CONS, adopted 8 April 2025 and published 12 May 2025, sets technical and procedural methods for establishing that a user is of age. Its scope is stated plainly and is the interesting part: it reaches operators of websites and video-sharing platforms distributing pornographic content in Italy whether they are established in Italy or in another member state.

A dating app is not on either target list. Both matter anyway, for two reasons. The technique they converge on — an independent third party attesting age without either side learning more — is the same technique Article 28(3) pushes toward, so it is what a European age check will look like whoever mandates it. And the pornographic content path is not hypothetical for dating, because what two matched users send each other is not governed by what a profile page contains.

The number that is not the access rule

Article 8 of the GDPR sets 16 as the age below which a child's consent to an information society service needs parental authorisation, and lets member states legislate any age down to 13. The resulting spread across the Union is real, and it is frequently confused with an access threshold.

It is not one. Article 8 governs when consent is a valid legal basis for processing, not who may use the service. A dating app's access rule comes from Article 28 of the DSA, from its own terms, and from whatever national measure is properly directed at it. Article 8 becomes relevant precisely when the access rule has already failed and a minor is inside.

What this looks like in practice

  • Identify your member state of establishment. That is your primary regulator, and your Digital Services Coordinator is the counterparty you will actually hear from.
  • Choose age assurance that collects nothing beyond the age answer. Article 28(3) makes over-collection a compliance problem, not a hedge against one.
  • Build against a proof-of-age interface with a wallet-shaped contract, so the EU Digital Identity Wallet and the Commission blueprint drop in without a rewrite.
  • Do not treat country of origin as a shield. After June 2026 it is a procedure another regulator can complete.
  • Assume the pornographic content duty reaches direct messages, and design moderation for the private surface, not only the public one.
  • Where terms set a minimum age, apply it with something stronger than a self-declared date of birth. The guidelines say a stated minimum is not an age assurance measure.

The EU has not written a dating app age check rule and probably will not. It has written a duty that applies whatever the product is, a data constraint that shapes how the duty may be met, and, as of June 2026, a route by which a regulator that is not yours can arrive anyway.

ProofAge for Dating Apps — Stop Fake Profiles Before They Kill Trust

ProofAge helps dating platforms reduce fake profiles, speed up review, and verify real users — without the heavy friction of enterprise KYC.

See how it works