Dating apps

Fake profiles and banned users on dating apps: EU

· 9 min read

Applies to
Dating and social discovery platforms offering services in the EU
In force
Digital Services Act since 17 February 2024; GDPR Article 9 since 25 May 2018
What to do
Write the ban policy into your terms, give every removal a statement of reasons, and treat face matching against banned users as special-category processing

The only article of the Digital Services Act (DSA) about removing abusive users does not mention a permanent ban. Article 23, which has applied to online platforms since 17 February 2024, requires providers to suspend users who "frequently provide manifestly illegal content", and to do it "for a reasonable period of time and after having issued a prior warning."

Dating platforms sell the opposite promise. A scammer who is caught stays out; a person reported for harassment does not come back under a new email address. The DSA does not forbid that promise — it sets a floor, not a ceiling. But it regulates only half of it. The law has a great deal to say about how a platform decides to remove someone, and nothing to say about how it recognises that person on the way back in. That second half is governed by data protection law, and it is the harder one.

Two questions inside one ban

Every account removal on a dating platform contains two separate questions.

The first is the decision: is this account fake, fraudulent or abusive, and what happens to it. That is a content-moderation decision, and the DSA governs it in detail.

The second is the recognition: when someone signs up next week, is it the same person. That is an identification problem. It needs some signal that survives a new email, a new phone number and a new name — a document, a device, a face. The DSA is silent on it. The General Data Protection Regulation (GDPR) is not.

A dating app that answers only the first question has a fair process for removing people who then return within the hour. One that answers only the second has a blocklist without a lawful process behind it.

What the DSA asks of the decision

The rules sit in layers, and the layers matter because they apply to different sizes of business.

Every hosting service, of any size. Article 14 requires the terms and conditions to describe "any policies, procedures, measures and tools used for the purpose of content moderation, including algorithmic decision-making and human review", and Article 14(4) requires those restrictions to be enforced in a "diligent, objective and proportionate manner". Article 16 requires a notice mechanism that any individual can use to report illegal content — a fake profile used for fraud, for example — and a decision on each notice taken in a "timely, diligent, non-arbitrary and objective manner."

Article 17 is the one that reaches every ban. It requires a "clear and specific statement of reasons" to the affected user for any "suspension or termination of the recipient of the service's account", whether the ground is illegal content or incompatibility with the terms and conditions. Most fake profiles are removed on the second ground, so the statement of reasons is not limited to the fraud cases. It has to state the facts relied on, whether automated means were used, the contractual or legal ground, and the routes to redress.

Article 18 adds a duty most dating platforms will meet sooner or later. Where a provider becomes aware of information giving rise to a suspicion of a criminal offence "involving a threat to the life or safety of a person", it must promptly inform the law enforcement or judicial authorities of the member state concerned.

Online platforms above small-enterprise size. Article 20 requires an internal complaint-handling system, open for at least six months after the decision, against decisions to suspend or terminate an account. Complaint decisions must be taken "under the supervision of appropriately qualified staff, and not solely on the basis of automated means." Article 23 adds the suspension rule, with a case-by-case assessment that weighs the number of items, their proportion, the gravity of the misuse and, where it can be identified, intent. Article 23(4) requires the policy, with examples and the duration of suspension, to be set out in the terms. Article 24 then makes the platform report the number of Article 23 suspensions it imposed.

Recital 64 explains how the floor and the ceiling fit together. Article 23 is "without prejudice to the freedom by providers of online platforms to determine their terms and conditions and establish stricter measures", and the misuse rules "should not prevent providers of online platforms from taking other measures" against violations of their terms. A dating platform can write a permanent ban for romance fraud into its terms. What it cannot do is apply that ban without the warning, reasons and redress the DSA attaches to the decision.

Why recognising a returning user is the hard part

Once a platform decides to keep someone out, it needs a way to recognise them. Email addresses and phone numbers are cheap to replace, so the signal that actually works is the person: their identity document, or their face.

Face matching is where the GDPR changes the problem. Article 4(14) defines biometric data as personal data from "specific technical processing" of a person's physical characteristics "which allow or confirm the unique identification" of that person, "such as facial images". Article 9(1) then prohibits processing "biometric data for the purpose of uniquely identifying a natural person" unless one of the exceptions in Article 9(2) applies.

Recital 51 draws the line that matters for a dating app. Photographs are not special-category data by default; they are covered by the definition of biometric data "only when processed through a specific technical means allowing the unique identification or authentication of a natural person." A profile photo sitting on a server is ordinary personal data. The same photo turned into a face template and compared against a list of banned users is biometric data used to identify someone, and the Article 9 prohibition applies.

The exceptions in Article 9(2) are narrow. The one a private platform can realistically rely on is point (a), the user's "explicit consent" for a specified purpose. Point (g), substantial public interest, needs a basis in Union or member state law that is proportionate and provides "suitable and specific measures"; Article 23 of the DSA describes suspension, not identification methods, and does not mention biometrics at all. Article 35(3)(b) requires a data protection impact assessment before processing special categories "on a large scale".

One-to-one and one-to-many are different checks

EU law itself separates two things that are often sold under the same name. The AI Act defines biometric verification in Article 3(36) as "one-to-one verification" of identity against "previously provided biometric data", and biometric identification in Article 3(35) as establishing identity "by comparing biometric data of that individual to biometric data of individuals stored in a database." Its list of high-risk biometric systems in Annex III expressly excludes systems whose "sole purpose" is to confirm that a person "is the person he or she claims to be."

The distinction maps directly onto a dating platform's two checks. Matching a sign-up selfie to the photo on the same user's identity document is one-to-one: it answers whether this person is who their document says. Matching that selfie against every banned user is one-to-many: it answers whether this person is someone the platform has seen before. The first establishes that a profile is real. The second is what keeps a removed user out, and it is the check that carries the heavier legal weight.

A design that relies on the document rather than the face for the one-to-many step can avoid some of that weight. If the identity document is verified at sign-up, a banned user who returns has to present a different genuine document, which is far harder than a new email. The platform then compares document attributes it already holds, not face templates. Whether that is sufficient depends on the threat; it is a narrower data footprint, not a free one.

Where size changes the answer

Article 19 of the DSA exempts online platforms that qualify as micro or small enterprises from Section 3 of Chapter III, which contains Articles 20, 23 and 24. It does not exempt them from Articles 14, 16, 17 and 18, which apply to every hosting service. A two-person dating startup still owes a statement of reasons for every ban and still has to report threats to life or safety. It does not owe the formal complaint-handling system or the Article 23 suspension process.

The GDPR has no size threshold for Article 9. A small platform that runs face matching against a banned-user list carries exactly the same special-category obligations as a large one. The age-assurance side of the same sign-up flow — what the DSA asks of platforms accessible to minors — is covered separately in the first article on EU dating apps.

What this looks like in practice

  • Write the ban policy into the terms. List what leads to suspension and what leads to permanent removal, with examples and durations, as Article 23(4) asks.
  • Send a statement of reasons with every account removal, including removals for fake profiles under the terms. Say whether automated means were used.
  • Keep a human in the complaint loop. Article 20(6) rules out decisions taken solely by automated means.
  • Separate verification from identification in the design. Verify that a new profile is real with a one-to-one check; decide deliberately whether and how to run a one-to-many check against removed users.
  • If the returning-user check uses face templates, treat it as Article 9 processing: explicit consent for that specific purpose, a data protection impact assessment, and a retention period for the banned-user list.
  • Route threats to life or safety to the police of the member state concerned, as Article 18 requires, rather than only removing the account.

The DSA governs the decision to remove someone from a dating platform; the GDPR governs the act of recognising them when they come back.

Keep reading

ProofAge for Dating Apps — Stop Fake Profiles Before They Kill Trust

ProofAge helps dating platforms reduce fake profiles, speed up review, and verify real users — without the heavy friction of enterprise KYC.

See how it works