Field Notes

source

Virtual private networks and child protection EPRS

This EPRS briefing surveys the policy dispute over minors using VPNs to bypass age checks and other access controls. It records calls for restrictions or age limits on VPN access, alongside objections based on privacy, cybersecurity, access to information, and legitimate business use.

The briefing is evidence that VPN restriction is an active policy proposal, not that the EU has enacted a general prohibition. It also shows the likely escalation problem: an age gate that is easy to route around can generate political pressure to regulate a general-purpose privacy tool.

United Kingdom survey data collected after the Online Safety Act’s child-protection codes took effect complicates the spike narrative: children’s VPN use held stable at about 8%, and only 7% reported using a VPN to bypass an age check, with false birthdates and borrowed logins far more common. The Internet Matters Online Safety Act report offers this as a counterpoint to claims that age checks would drive children to VPNs, while cautioning that uptake needs monitoring as stronger verification rolls out. The DSIT-commissioned Children’s circumvention behaviours online study later confirmed the pattern at larger scale, and in July 2026 the UK government decided not to limit VPNs, moving the circumvention burden onto platforms — the escalation debate’s first concrete resolution in a major jurisdiction.

The preserved artifact is the January 2026 EPRS briefing. Its implications are developed in Age-verification circumvention services and VPN service legal risk.

Built on 1 source (1 external).

Working out connections…