There are ways. Placing regulatory burdens or legal liabilities on anyone running a social media instance would quickly make Mastadon untenable. Something as simple as manditory age verification might be enough.
My first thought is that people running Mastodon wouldn't qualify as data controllers, but I am no expert in GDPR laws.