Digital Age of Majority Law 2023 (France)

The information provided by IFTAS is for general guidance and informational purposes only. It does not constitute legal advice and should not be relied upon as such. IFTAS is not a law firm and does not offer legal services. For advice on legal or regulatory matters, please consult a qualified professional.

Background

France’s framework governing youth social media access, anchored in Loi No. 2023-566 (majorité numérique/digital age of majority) alongside broader provisions in Loi No. 2004-575 (LCEN) and Loi No. 2024-449 (SREN), establishes 15 as the digital age of majority. Under this framework, children under the age of 15 are prohibited from creating or maintaining social media accounts without explicit parental authorisation.

The legislation empowers Arcom (Autorité de régulation de la communication audiovisuelle et numérique), France’s digital and audiovisual media regulator, to enforce compliance, establish technical guidelines for age assurance, and mandate content removals.

The law sets out rules and obligations for online platforms, including:

  • Restricting registration for persons under 15 unless parental consent is verified.
  • Requiring platforms to display notices regarding screen time, online safety, and cyberbullying.
  • Operating responsive account-reporting and complaint-handling tools for illegal content.
  • Enforcing prompt takedowns of illegal material, including cyberbullying, child sexual abuse material (CSAM), and terrorist content.

Under the framework, a social media service is defined as any online public communication service allowing users to create accounts and interact, post, or share content with other users. Social Web services generally meet this defintion.

Excluded Categories

In alignment with EU standards, such as the Digital Services Act, French legislation generally excludes or exempts:

  • Purely private messaging services with no public profile or broadcast component.
  • Online encyclopaedias and collaborative knowledge bases operated on a non-commercial basis.
  • Open-source software development platforms and repositories (such as Codeberg or GitLab).
  • Educational and health portals designed solely for communication between institutions and students or patients.
  • Internal business communication tools used exclusively for enterprise networking.

Scale, Proportionality, and “Small Services”

French administrative law and EU governance frameworks operate under strict principles of proportionality. Regulatory supervision distinguishes between commercial entities with high impact and small community-run nodes.

Very Large Online Platforms (VLOPs) – The regulator will focus on platforms exceeding 45 million monthly active accounts in the EU (for instance, TikTok, Instagram, Snapchat, X, and YouTube).

Small and Volunteer-Run Services – Community-hosted, decentral, or non-commercial services with limited French account holders are considered extremely low risk for active regulatory enforcement.

Arcom’s enforcement priority remains squarely aimed at commercial platforms using algorithmic engagement feeds and commercial monetisation. Regulators lack the administrative bandwidth or technical mandate to aggressively target small, non-profit nodes, provided those nodes maintain basic good-faith moderation.

Minimum Age Enforcement (from September 1, 2026)

  • The law sets a minimum age of 15 for social media accounts.
  • Applies to all social media services, including federated platforms like Mastodon.
  • A small instance is still expected to:
    • Have reasonable age-assurance processes (these do not have to be intrusive or expensive, but some mechanism is needed).
    • Deny accounts to persons under 15.
    • Take reasonable steps to close accounts if underage use is identified.

Removal of Harmful Content

Arcom and French judicial authorities possess statutory powers to issue content removal notices. Social Web admins must be aware of key operational requirements:

  • CSAM and terrorist content must be removed immediately upon identification or receipt of an official notice.
  • Cyberbullying and Harassment reports involving minors must be triaged and actioned promptly.
  • Services must provide a functioning mechanism allowing people to report illegal content, harassment, or underage account creation.

Transparency & Record-keeping

While small services are exempt from formal annual reporting requirements levied on commercial tech companies, admins should maintain basic operational logs. Keep simple records of moderation actions taken, account suspensions, and account reports processed. Keep documentation of any official takedown requests received from law enforcement or Arcom. Maintaining simple audit records demonstrates good-faith compliance in the unlikely event of an inquiry.

Liability and Responsibility

Under French and EU law, the legal entity or individual hosting the server is treated as the service provider (“hébergeur”). Administrators are generally protected under host liability shields (régime de responsabilité atténuée) as long as they act expeditiously to remove or disable access to illegal material once they have actual knowledge of it. Federation across domains does not alter local liability; each instance administrator remains responsible for the content hosted on and served directly from their local domain.

Practical Steps for Fediverse Providers Offering Service in France

If your instance hosts accounts located in France or operates within the EU, follow these lightweight compliance steps:

Update Your Terms of Service / Community Rules:

  • Clearly state that account holders must be 15 years of age or older (or have verifiable parental authorisation) to create an account.
  • Prohibit illegal material, online harassment, cyberbullying, CSAM, and terrorist content.
  • Provide clear contact details or a dedicated email address (such as [email protected]) for regulatory or legal notices.

Establish Registration Controls:

  • Enable the self-declared age option if available.
  • If concerned about automated sign-ups or regulatory exposure, set registrations to “Approval Required” or “Invite Only.” This effectively gates new account creation and simplifies age-assurance compliance.

Maintain Reporting Workflows:

  • Ensure native platform reporting features are enabled and routed to active moderators.
  • Establish an internal process for reviewing and acting on account reports within a reasonable timeframe.

Prepare for Takedown Requests:

  • Monitor your administrative contact email regularly.
  • Action legitimate takedown notices from law enforcement or Arcom promptly, and keep a log of the action taken.

Avoid Over-Collecting Personal Data:

  • Do not request government IDs, passport photos, or credit cards for age verification. Over-collecting personal data violates EU GDPR principles of data minimisation.

If you receive any takedown or other communication from Arcom or French judicial processes, we may be able to help you find local resources, contact us.


IFTAS

Nonprofit trust and safety support for volunteer social web content moderators

49 posts
355 followers

Community Responses

IFTAS is a non-profit organisation committed to advocating for independent, sovereign technology, empowering and supporting the people who keep decentralised social platforms safe, fair, and inclusive..