Ireland’s media regulator Coimisiún na Meán has opened its first formal investigation under the Online Safety Code, and the target is X.
The announcement was made on September 8, after the regulator’s supervision team raised concerns about X’s compliance with the rules regarding digital ID age verification and parental controls.
The Online Safety Code is a set of rules that designated video-sharing platforms must follow in Ireland to ensure what is considered the well-being of their users, and children in particular. It combines content restrictions with rules based on age, such as access to certain content and services.
The investigation concerns two main points: whether X properly prevents children from accessing content that is meant for adults only, and if the company provides sufficient parental control tools.
The first part of the inquiry is to establish if X appropriately ensures that children do not normally see “videos depicting pornography or extreme/gross and gratuitous violence or acts of cruelty.” Under the Online Safety Code, children are those under the age of 18.
The second part concerns parental controls on services that admit under-16s, and the probe is looking into four different areas: whether X provides these tools and puts them under the end-users’ control for video content “that may impair the physical, mental or moral development of children,” whether these tools meet the minimum requirements set by the Code, whether X alerts users to the existence of these controls, and whether new users are offered these controls when they sign up for the service.
The minimum requirements for parental controls that the Code sets include giving parents the ability to restrict their child’s ability to see content from unknown users, as well as restrict unknown users from seeing content uploaded by a child. Parents should also be able to filter videos and audiovisual advertising based on descriptive terms or metadata, and set limits on the time their child spends watching videos.
As for the age "assurance," the regulator’s Digital Services Commissioner John Evans said that “We have been clear that any age assurance measure based solely on self-declaration, is not sufficient.”
This means that simply entering a date of birth is not enough to satisfy the regulator, but the announcement does not go into what would be considered a valid age-assurance method. Usually, that means showing some form of ID or having your biometrics scanned, both privacy invasive practices.
X has not been fined in this investigation. The announcement concerns the opening of the investigation, and if wrongdoing is established, the maximum fine can be either €20 million or 10% of relevant annual revenue, whichever is greater.




