Protecting minors in video games: what your studio must do today
Diego Navas Nicolás·4 August 2026·10 min read
More and more minors are playing video games from a very early age, and there they encounter third-party content, social interaction, algorithms, generative AI and reward structures that have a direct impact on their development, their privacy and their safety. The question that reaches the firm is always the same: what do I have to implement and from when. The short answer is that quite a lot is already mandatory, and that what is coming raises the bar.
Which rules apply to you
None of these rules is specific to video games, and that is precisely the difficulty: they have to be assembled. The ones that come into play are:
The General Data Protection Regulation (GDPR), especially Articles 8 and 25.
The Spanish Data Protection Act (Ley Orgánica 3/2018, LOPDGDD), which sets the age of consent in Spain.
The Digital Services Act (Regulation (EU) 2022/2065, DSA), if your game includes an online platform with third-party content.
The Artificial Intelligence Act (Regulation (EU) 2024/1689), if there is generative AI or recommender systems.
The Código de Conducta de Protección de la Infancia en Entornos Digitales (the Spanish code of conduct for protecting children in digital environments).
And, still going through Parliament, the Ley Orgánica para la protección de las personas menores de edad en entornos digitales (the Spanish organic law on the protection of minors in digital environments).
To this must be added the PEGI system, which is not a legal rule but a self-regulation code, although in practice it operates as the gateway to the stores and to distribution.
The three layers of the problem
Legally, protecting the space in which a minor interacts digitally requires acting on three layers, and neglecting one ruins the work done on the other two:
Personal data: what is collected, on what legal basis, for how long and for what purpose.
Accessible content: what they can see and who they can talk to.
Design architecture: how the product is built, what is enabled by default and which mechanics push towards a given behaviour.
The third is the most ignored and the one gaining the most weight in supervision.
Personal data: age, consent and design
When a minor uses a video game, it is not only the parental consent regime that applies, but also the obligations of privacy by design and by default under Article 25 of the GDPR. That provision requires the developer to adopt the measures needed to limit data processing, algorithmic profiling and advertising exposure.
On age it pays to be precise, because a lot of confusion circulates. Article 8 of the GDPR sets 16 as the general age at which a minor may give their own consent in information society services, but allows Member States to lower it to 13. Spain set it at 14 in the LOPDGDD. Below that age, consent from the holder of parental authority or guardianship is required.
This has two practical consequences that tend to surprise:
If your game is distributed in several countries of the Union, the age is not the same in all of them. A system built only for the Spanish threshold will fail in other markets.
Parental consent must be capable of being evidenced. A tick box saying "I declare I am over 14" is not a verification mechanism: it is a declaration by the minor themselves.
And above all, the question an inspector asks: what happens if the minor never touches a single setting. If by default the profile is public, the chat is open and advertising is personalised, privacy by default is not being complied with, however many options exist buried in a menu.
What the new Spanish law will bring
The Proyecto de Ley Orgánica para la protección de las personas menores de edad en entornos digitales (the draft Spanish organic law on the protection of minors in digital environments) was approved by the Council of Ministers in March 2025 and is still going through Parliament. It may still change, but its direction is clear and it is worth getting ready.
The points that most affect a video game studio are four:
The age of consent for data processing rises from 14 to 16. This is a significant change: a large part of the user base that can register on its own today will no longer be able to.
Effective age verification. The text insists that without real verification the protection is symbolic. Here lies the thorniest technical debate, because verifying age without collecting more personal data than necessary is an engineering problem, not just a legal one.
Parental controls by default and risk warnings.
A ban on loot boxes for minors. The text treats them as random-reward mechanisms comparable to gambling, with the risk that entails for vulnerable people. The ban is framed specifically in the context of video games, so companies will have to put in place effective systems preventing minors from accessing this type of reward.
That last measure is not an interface tweak. If your monetisation model rests on random rewards and a relevant share of your player base is underage, it affects your revenue line and it is worth modelling it in good time.
Accessible content: rating and moderation
The second layer is what the minor can see and who they can talk to. Here the risk rarely lies in the content the studio produces: it lies in what other users produce.
If your game allows player-generated content, chat, rooms or a user-to-user economy, you are operating something very similar to a platform, and the Digital Services Act comes into play with moderation obligations, notification mechanisms and, very relevantly, the ban on targeting profiling-based advertising at minors.
The measures that work are concrete:
Age-based content rating, with labels that also indicate the nature of the interactions between users, not just violence or language.
Reinforced chat moderation, capable of supervising effectively in several languages. Machine learning helps here, but it introduces its own analysis: an automated moderation system is a data processing operation and, depending on how it is built, may fall within the scope of the AI Act.
Visible reporting channels that get a response. A report button that leads nowhere is worse than not having one, because it creates an expectation that is not met.
Design architecture: where the real game is played
The third layer is the one changing the most. It is no longer only the data you process that is examined, but how the product is designed: which mechanics push players to stay connected, to spend or to interact.
This covers daily streaks that penalise stopping playing, rewards for session time, insistent notifications, countdown offers, the social pressure of leaderboards among friends and, of course, random rewards.
Not all of that is illegal, far from it. But when the recipient is a minor, the assessment changes, and the European framework points clearly to the fact that design that exploits the vulnerability of a protected group cannot be defended by saying the user accepted the terms.
The specific measures we recommend
With all of the above, this is what in practice we ask to review in a studio with underage players.
Advanced parental controls
Allowing parents, at a minimum, to:
Block and report specific users on their children's friends list, to keep precise control over who they interact with.
Restrict access to particular games or experiences they consider inappropriate, including social experiences with specific interaction features.
Disable direct messaging, inside and outside the video game. For under-13s the sensible approach is for it to be disabled across the board, not as an option.
Activity reports
Detailed reports allowing parents to know which experiences their child has taken part in over the past week. It is a simple measure to implement and delivers a lot of return, because it turns parental control into something usable rather than theoretical.
Moderation and rating
Improved chat moderation in several languages and age-based content rating that indicates the nature of the interactions between users, so that the youngest only access appropriate content.
Safety centres
Dedicated spaces offering guidance and resources for safe online interaction, with essential digital safety information for parents and users. Beyond their real usefulness, they are documentary evidence that the studio has taken active measures.
And first of all
Review the default settings. Before any new feature, check what is enabled for an account newly created by a minor who has not touched a single setting. That configuration, and not the privacy policy, is what says whether the product complies with privacy by default.
Frequently asked questions
▸From what age can a minor register in my video game on their own?NPC
In Spain, currently from the age of 14, under the Spanish Data Protection Act (Ley Orgánica 3/2018). Below that age, consent from the holder of parental authority or guardianship is required. Article 8 of the GDPR sets the general threshold at 16 and allows Member States to lower it to 13, so the age is not the same in every country of the Union.
▸Are loot boxes going to be banned in Spain?NPC
The draft Spanish organic law on the protection of minors in digital environments provides for banning them for minors, treating them as random-reward mechanisms comparable to gambling. The ban is framed specifically in the context of video games, so effective systems will have to be put in place to prevent minors from accessing that type of reward. The text is still going through Parliament.
▸Is a tick box asking for the user's age enough?NPC
No. A tick box in which the minor declares their own age is not a verification mechanism but a self-declaration. The draft law insists precisely that without effective age verification the protection is symbolic, and parental consent, where required, must be capable of being evidenced.
▸What does privacy by design and by default mean in a video game?NPC
That protective measures are built into the product from its conception and that the initial settings are the most protective ones. In practice it is checked by looking at what happens with a newly created account where no settings have been touched: if the profile is public, the chat is open and advertising is personalised, the requirement is not being met.
▸Can I show personalised advertising to underage players?NPC
No. The Digital Services Act prohibits targeting advertising based on profiling at minors on online platforms. This means separating advertising inventory by age and making sure that no external provider profiles those users.
▸My game has chat — does the Digital Services Act apply to me?NPC
It depends on how it is configured, but if it allows player-generated content, chat, rooms or a user-to-user economy, you are operating something very close to an online platform and it needs to be assessed. The most relevant obligations concern moderation, notification mechanisms and the ban on profiled advertising aimed at minors.
▸Is the PEGI system mandatory?NPC
PEGI is not a legal rule but an industry self-regulation code. In practice it operates as the gateway to the stores and to distribution, so its effect is very similar to that of a binding obligation, but it does not replace compliance with the GDPR, the Digital Services Act or the Spanish rules on the protection of minors.
At NN Agency we advise studios and platforms through ongoing legal counsel, including compliance on data and minors, and on contracts and terms of use. If your game has chat or player content, reviewing the default settings is where we start.
Facing something similar at your studio? The first consultation is free.