Somewhere in Europe right now, a 13-year-old is being harassed online for wearing a hijab, or for being Roma, or for being visibly disabled. She reports it. The platform logs it as “cyberbullying.” Case closed, box ticked, compliance achieved.
Nobody will ever know it happened to her because of who she is. Not the platform. Not the regulator. Not the European Commission. The system isn’t hiding this information — it was never built to collect it in the first place.
That is not a hypothetical gap in a hypothetical law. It is a precise, provable gap in one of the most ambitious pieces of digital regulation ever written: the EU Digital Services Act. I will admit a bias here: this text is my favorite. Not my favorite among laws — my favorite, full stop. It has held my attention longer and more completely than almost anything else I’ve read. And it’s exactly because I love it that I can’t let it be good when it could be better, or better when it could be the best version of itself — the version that actually does, in full, what it was written to do.
A law that already knows the answer
Here is the part almost no one — including, it seems, the people who wrote the implementing guidelines — has fully reckoned with.
Article 34 of the DSA requires the largest online platforms to assess the “systemic risks” their services pose. Buried inside that requirement is a single clause, Article 34(1)(b), that lists the fundamental rights platforms must protect. It names them side by side, in the same sentence: the right to non-discrimination (Article 21 of the EU Charter of Fundamental Rights) and the rights of the child (Article 24 of the Charter).
The law’s own drafters already understood that a child’s safety and a child’s right not to be discriminated against are not two separate problems. They wrote them into the same clause on purpose.
Then, in July 2025, the European Commission published its long-awaited guidelines on protecting minors online under Article 28 of the DSA — a genuinely serious document, built on consultations with more than 150 young people. It requires platforms to fight grooming, harmful content, addictive design, and cyberbullying.
It says almost nothing about who is being targeted.
Compliant, and still blind
This is the quiet mechanism by which discrimination against children disappears from the record.
A platform can run a textbook-compliant Article 28 risk assessment — document its cyberbullying mitigation, deploy age assurance, appoint a child-safety lead — and still have no idea whether Muslim, Jewish, Roma, or disabled children are being targeted at a higher rate than their peers. The data simply isn’t collected that way. “Harm to minors” is tracked as one undifferentiated category, even though the law that created the category already told us it has an identity dimension built in.
This isn’t a conspiracy theory about Big Tech. It’s a documented critique from inside the policy process itself. The Center for Democracy & Technology’s own formal response to the draft guidelines warned that the current ambiguities in the framework leave national regulators without clear benchmarks — meaning enforcement will fragment across member states, and fundamental rights protection will end up uneven depending on which country a platform happens to be regulated in.
When even the guidelines’ most engaged supporters are flagging that the enforcement categories don’t hold together, that’s not a fringe objection. That’s the system telling on itself.
Why this matters more than one more content-moderation complaint
I’ve made this argument before, in a different register. My formal complaint to the European Commission against X Corp. under Articles 34–35 of the DSA documented exactly this pattern: European anti-discrimination law exists in full, glossy, well-intentioned form — and the actual enforcement machinery underneath it cannot see the harm it was built to catch.
What’s different here is the subject. This isn’t an abstract argument about platform accountability. It’s about children who are being targeted for who they are, on services legally obligated to protect them, in a system that has no way of even noticing it’s happening.
You don’t need to belong to any particular community to find that unacceptable. That’s the point. This gap doesn’t discriminate — it fails every minority child equally, by failing to look for any of them specifically.
Why this doesn’t need a new law — just a better reading of the old one
Here is what should change your mind about whether this is fixable: it doesn’t require the European Parliament to reopen the DSA. It doesn’t need a new directive, a new treaty, or years of legislative negotiation. The obligation already exists, in binding law, in Article 34(1)(b). What’s missing is the operational instruction that tells platforms how to actually measure it.
Two concrete steps, both achievable through mechanisms the Commission and national regulators already use every day: first, the Commission should amend its Article 28 guidelines — using authority it already holds under Article 28(4) — to require that platforms disaggregate minor-safety risk data by protected characteristic: religion, ethnicity, disability, sexual orientation. This is a reporting-schema change, not a new obligation. Platforms are already collecting this data in aggregate. They would simply have to stop averaging away the pattern.
Second, the DSA’s existing “trusted flagger” mechanism — which lets specialist organizations get priority review for the content they flag — has no designated flagger anywhere in the EU focused specifically on discriminatory content targeting minors. That’s an open lane. Existing flaggers focus on child sexual abuse material or general child welfare. Nobody currently occupies the intersection. Someone should.
Neither of these ideas asks institutions to do something new. They ask institutions to finish doing what their own law already told them to do.
What I’m asking for
I’m not publishing this as a think-piece. I’m publishing it as the opening move in a campaign: to build a coalition of child-rights and anti-discrimination organizations around this specific, textually grounded argument; to establish the first working precedent for a discrimination-focused minors’ trusted flagger; and to put this question, formally, in front of the people who write these guidelines.
The European Commission spent a year listening to 150 young people before it wrote its rules on protecting children online. It should spend the next year listening to the ones its own rules still can’t see.
