Luxembourg: A ruling handed down by the Court of Justice on 16 June has handed national governments a powerful tool in their long fight to keep children away from online pornography, while leaving the thorniest privacy questions for another day. The judges held that member states may require age verification for users of pornographic websites, even when those sites are established in another EU country.
The decision cuts through a jurisdictional knot that had frustrated regulators for years. Under the country-of-origin principle that underpins the single market for digital services, a website based in one member state is normally supervised by that state alone, not by every country where its users happen to live. Adult-content platforms had leaned heavily on that principle, arguing that only their home regulator could impose obligations on them. The Court’s answer is that protecting minors can justify an exception, allowing a destination country to insist on age checks regardless of where the operator is incorporated.
For governments in France, Germany and beyond that have spent years drafting age-verification mandates only to see them challenged, the judgment is a vindication. It confirms that the push to wall off explicit material behind a proof-of-age barrier rests on solid European legal ground rather than wishful national legislation. The same ruling also touched a separate question, upholding the power of a member state to prohibit the rebroadcasting of information about certain roadside police checks, a reminder that the case ranged across the boundaries of the digital services framework.
The harder issue, largely deferred, is how age can be verified without turning every adult visitor into a surveilled subject. Privacy advocates warn that the most obvious methods, uploading identity documents or submitting to facial age estimation, create exactly the kind of sensitive data honeypot that data-protection law is supposed to discourage. The Court affirmed that states may require verification; it did not bless any particular technology, leaving regulators to reconcile child protection with the principle of data minimisation enshrined in EU privacy rules.
That unresolved tension guarantees the fight is far from over. Industry groups argue that crude age gates simply push minors toward unregulated platforms beyond European reach, while doing little to stop the determined teenager armed with a borrowed credential. Child-safety campaigners counter that the absence of any friction has been a policy failure, and that imperfect barriers still change behaviour at the margins.
What is now settled is the principle. National parliaments can legislate age checks for adult sites without fear that the single market will strike them down, and operators can no longer hide behind a foreign letterbox. The next battle, over which verification systems are proportionate and privacy-preserving, moves back to data-protection authorities and, in time, almost certainly back to Luxembourg.




