For years, the European debate on children’s online protection has largely revolved around one central question: what content should platforms remove? Legislative initiatives have focused on illegal content, harmful material, age verification, parental controls and content moderation obligations. These remain essential components of digital governance, but they no longer address the principal source of risk in contemporary online environments.
Increasingly, the greatest influence exercised by digital platforms does not stem from the content they host but from the way they are designed. Online services shape users’ behaviour through interface architecture, recommender systems, default settings, personalised notifications and behavioural optimisation techniques that influence attention, choices and engagement. Children are particularly exposed to these mechanisms, not only because of their age but because digital environments are increasingly capable of identifying and exploiting behavioural vulnerabilities through continuous data collection and algorithmic personalisation.
European digital regulation is gradually recognising this transformation. Rather than focusing exclusively on regulating online conduct, it is progressively beginning to regulate digital architecture itself. This evolution reflects a broader regulatory philosophy that has emerged across several areas of European law and that may be described as regulation by design. Within this broader framework, the current debate on digital fairness suggests the emergence of a more specific principle of fair design, particularly relevant to the protection of children.
The forthcoming Digital Fairness Act may therefore represent more than another consumer protection instrument. It may become the legislative moment in which different regulatory developments converge into a common principle requiring providers to design digital environments consistently with users’ fundamental rights and, above all, children’s right to develop their autonomy in online spaces.
The emergence of regulation by design
The idea that law can regulate technology through design is not entirely new. More than twenty-five years ago, Lawrence Lessig famously argued that “code is law”, highlighting how software architecture determines the conditions under which individuals exercise their freedoms in cyberspace. Digital technologies do not merely facilitate human activity; they define the possibilities of action available to users. Depending on how software is designed, certain behaviours become easier, others more difficult, and some impossible altogether.
European legislation has progressively translated this intuition into concrete legal obligations.
The first systematic example appeared in Article 25 of the General Data Protection Regulation, introducing Data Protection by Design and by Default. Rather than relying exclusively on sanctions after unlawful processing has occurred, the GDPR requires controllers to integrate data protection safeguards directly into technological systems from the earliest stages of development. Privacy is no longer conceived solely as an external legal constraint but as a characteristic that products and services should incorporate by design.
The significance of this innovation extends well beyond data protection. It introduces a preventive regulatory technique based on anticipating foreseeable risks during product development instead of correcting them afterwards.
This logic has gradually expanded throughout European digital legislation.
The Digital Services Act introduces obligations concerning the design of online interfaces, requiring providers to enable traders to comply with consumer information and product safety rules. The AI Act adopts a lifecycle approach based on continuous risk assessment and mitigation, obliging providers of high-risk systems to identify and manage foreseeable risks before deployment. Cybersecurity legislation follows a similar rationale by requiring operators to adopt appropriate risk-management measures rather than merely reacting to cyber incidents. Even the Ecodesign Regulation demonstrates how legal requirements concerning environmental sustainability can be integrated directly into product development through performance obligations and the Digital Product Passport.
These instruments belong to different legal sectors and pursue different policy objectives. Nevertheless, they increasingly share the same regulatory method: compliance is embedded within technological design itself.
Regulation is therefore no longer directed exclusively at behaviour. It increasingly governs the characteristics of digital products and services before they reach users.
From digital asymmetries to children’s vulnerability
The implications of this regulatory evolution become particularly evident in relation to children’s online protection.
Traditionally, legal systems have associated children’s vulnerability primarily with age. Consequently, regulatory responses have focused on parental consent, age verification mechanisms and restrictions on access to specific digital services. Digital environments challenge this understanding.
Contemporary online platforms do not merely provide information or communication services. They actively construct the environment within which users make decisions. Behavioural data, profiling techniques and machine-learning systems continuously optimise interfaces to maximise engagement, data disclosure and commercial conversion. The result is a profound structural asymmetry between providers and users.
The European Consumer Organisation (BEUC) has described this phenomenon as digital asymmetry, identifying three interconnected dimensions. First, there is an architectural asymmetry because providers control the entire choice architecture of digital services. Secondly, there is a relational asymmetry, since consumers possess very limited bargaining power and can often only accept or abandon the service. Finally, there is a knowledge asymmetry, because providers accumulate detailed behavioural information while users remain largely unaware of how personalisation and algorithmic optimisation influence their decisions.
Children experience these asymmetries more intensely than adults. Their developmental characteristics make them particularly sensitive to persuasive technologies, while the adaptive nature of digital services enables platforms to personalise influence at an unprecedented scale. Children’s vulnerability therefore cannot be reduced to chronological age. It emerges from the interaction between cognitive development and sophisticated technological architectures specifically designed to predict and shape behaviour.
This observation fundamentally changes the legal problem. If digital risks originate from the architecture of digital environments, protecting children cannot depend exclusively on removing harmful content. It requires regulating the technological conditions through which behaviour itself is influenced.
Dark patterns as evidence of a broader regulatory transformation
Current debates surrounding dark patterns illustrate this evolution particularly well. Traditionally, dark patterns have been analysed as individual unfair commercial practices or misleading interface techniques. The legal response has therefore concentrated on identifying specific prohibited behaviours.
However, this perspective risks underestimating the structural dimension of digital manipulation. Infinite scrolling, autoplay, emotionally framed notifications, privacy nudging, countdown timers, social pressure mechanisms and personalised recommender systems are not isolated design errors. They form part of integrated behavioural architectures whose objective is to maximise attention and engagement.
The European Parliament explicitly recognised this broader phenomenon in its Resolution on addictive design of online services. According to the Parliament, many online platforms intentionally exploit psychological vulnerabilities through interface design and real-time behavioural optimisation. The Resolution also acknowledges that digital vulnerability should no longer be restricted to traditionally protected groups because sophisticated behavioural architectures may affect virtually all consumers.
Significantly, the Parliament calls for the development of ethical digital products free from addictive and manipulative design, recommends stronger risk-assessment obligations for very large online platforms and even suggests introducing a digital “right not to be disturbed”, allowing users to deactivate attention-seeking features by default.
These proposals demonstrate an important conceptual shift. The objective is no longer simply prohibiting individual manipulative techniques. Instead, European institutions increasingly question whether the architecture of digital environments should itself comply with broader standards of fairness.
Fair design as the evolution of regulation by design
This is where the concept of fair design acquires particular significance. Fair design should not be understood merely as the absence of dark patterns. Such a negative definition would reduce it to another catalogue of prohibited practices. Instead, fair design represents the positive obligation to organise digital environments consistently with users’ rights, legitimate expectations and capacity for autonomous decision-making.
In this respect, fair design constitutes the natural evolution of regulation by design. If privacy can be protected through technological architecture, if cybersecurity can be incorporated into products through preventive risk management, and if environmental sustainability can become a characteristic of product development through ecodesign, fairness itself can equally become a design requirement.
The regulatory focus therefore shifts from individual interface elements to the architecture of digital environments as a whole.
For children, this perspective is particularly important. Harm does not arise exclusively because a single interface feature is misleading. Rather, it emerges from the cumulative interaction of recommender systems, engagement mechanisms, behavioural profiling, personalised notifications and default settings that continuously shape children’s attention and decision-making.
Accordingly, protecting children’s autonomy requires providers to anticipate foreseeable behavioural risks during product development.
Fair design therefore implies designing interfaces that minimise unnecessary friction, avoid exploitative recommender systems, ensure meaningful transparency adapted to children’s understanding, reduce addictive engagement mechanisms and refrain from exploiting developmental vulnerabilities for commercial purposes.
This approach is not paternalistic. It does not seek to eliminate children’s freedom of choice. On the contrary, it aims to preserve the conditions necessary for genuine self-determination within digital environments specifically engineered to influence behaviour.
The Digital Fairness Act and a new European regulatory paradigm
Against this background, the forthcoming Digital Fairness Act may become the missing piece of an increasingly coherent European regulatory framework.
Although the legislative proposal has not yet been published, institutional documents already indicate a clear direction. The Commission’s Fitness Check on EU Consumer Law emphasises that future consumer protection should increasingly operate by design and by default rather than relying exclusively on transparency obligations. The ongoing policy debate similarly focuses on addictive design, unfair personalisation, dark patterns and other manipulative commercial practices, with enhanced protection for children and other vulnerable users.
If this direction is confirmed, the Digital Fairness Act will not merely introduce additional prohibitions. Rather, it may consolidate an emerging constitutional principle of European digital law.
The GDPR, the Digital Services Act, the AI Act, cybersecurity legislation, consumer protection law and future digital fairness rules would no longer appear as fragmented regulatory instruments. Instead, they would become different expressions of a common legal methodology centred on embedding legal safeguards directly into digital architecture.
Children provide the clearest illustration of why this evolution matters. No amount of parental supervision, transparency notices or ex post enforcement can fully compensate for environments intentionally designed to maximise behavioural influence. Structural risks require structural obligations.
For this reason, the future of children’s online protection lies not simply in prohibiting dark patterns but in requiring providers to design digital environments that respect children’s rights from the outset.
Designing children’s rights
European digital regulation is entering a new phase. The first generation of digital rules sought to regulate online behaviour. The second focused on platform responsibilities and content moderation. A third generation now appears to be emerging, one in which the law increasingly regulates the architecture of digital services themselves.
Seen from this perspective, fair design is not simply another regulatory label. It represents the evolution of regulation by design into a broader principle capable of integrating data protection, consumer law, platform regulation, artificial intelligence and children’s rights within a common legal framework.
Whether the Digital Fairness Act ultimately codifies this principle remains to be seen. Yet the direction of travel is already visible. European digital law is progressively recognising that the most effective way to protect children is not merely to regulate what platforms remove after harm occurs, but to regulate how those platforms are designed before harm can occur.
The future of children’s digital rights will therefore depend less on content moderation than on digital architecture. And that may prove to be the most significant transformation of the European digital rulebook.