In the following article we are summarizing the regulatory approach set out in the European Commission’s proposal for an “EU Kids Act”.
In particular, the Regulation establishes in article 1:
(a) a harmonised minimum age for creating an account with online social networking services and video-sharing platform services;
(b) harmonised safety requirements for online social networking services, video-sharing platform services, video gaming platforms, and software application stores and harmonised safety requirements to protect minors online for video games, AI companions and general conversational chatbots;
(c) harmonised rules regarding age assurance online.
First, it is important to be aware of the differentiation between the establishment of an age threshold as laid down in a) for online social networking services and video-sharing platform services only and the concept of a safety-by-design approach applying to a broader range of digital services as laid down in b). Second, the regulation refers to minors in the sense of the UN Convention on the Rights of the Child, meaning any natural person under the age of 18. Nonetheless, while several of the suggested regulations shall affect all minors under the age of 18, some specific regulations affect minors under 13 years of age and some those between 13 and under 15 years of age. Thus, the regulation follows the developmental approach recommended by the co-chairs of the Special Panel on Child Safety Online which is also in line with the UN CRC principle of the evolving capacities of the child.
According to the Explanatory Memorandum the legal basis for the proposal is Article 114 of the Treaty on the Functioning of the European Union, which provides for the establishment of measures to ensure the functioning of the Internal Market. In the Memorandum the EC states the proposal’s “provisions related to safety by design, set in “hard law” the specifications” included in the DSA Art. 28 (4) Guidelines “where these concern safety by design and age assurance requirements”.
In scope of the proposal are online social networking services, video-sharing platform services, video gaming platforms, and software application stores and harmonised safety requirements to protect minors online for video games, AI companions and general conversational chatbots, despite their size or number of recipients, and deviant from DSA, Art 28 small and micro enterprises are not exempted, since they may equally provide harms to minors. An exemption from scope is foreseen for not-for-profit online encyclopaedias, not-for-profit educational and scientific repositories, services and systems that are designed for purely educational purposes and operated within educational establishments or organisations, open-source software-developing and-sharing platforms, unless the platform itself constitutes an AI system in scope of the proposal, because the afore-mentioned platforms are unlikely to pose harms to minors.
The proposal is following strictly a risk-based approach with Art. 6 on delayed creation and use of accounts being the centrepiece. Where online social networking services and video-sharing platform services pose a risk to the privacy, safety or security of a minor below the age of 15 they shall not allow such minors to create an account with that service or to access that service by means of an account. The following features are considered being risky: transmission of content in real-time to an indeterminate number of other recipients, contact, communication and interaction with other recipients through an account, recommender systems, functionalities enabling uninterrupted content consumption and incentivising such interactions or transmission of automated notifications designed to prompt the user to initiate or resume use of the service. Where providers of online social networking services and video-sharing platform services meet certain conditions, they may allow guardians to set up accounts for minors above the age of 13 years and below the age of 15 years with limited features. Conditions are that tools for guardians are activated, guardians are enabled to set a maximum limit on the amount of time in a day the service or system may be accessed through that account, which shall not exceed one hour per day, and guardians are enabled to pre-approve potential new contacts and to set a maximum limit on the number of other recipients or users in the account’s contacts. A further pre-condition is that measures are in place to establish whether the person creating the account is the holder of parental responsibility over that minor in accordance with Article 26 and verify that the recipient of the service has reached the age of 13 years in accordance with Article 28(1).
For already existing accounts article 32 of the proposal obliges social networking services and video-sharing platforms to rely on an age verification solution as referred to in Article 30(2). Nonetheless by way of derogation providers shall not be required to carry out age verification where they can establish, with a high degree of confidence, that the recipient of the service has reached the minimum age set out in Article 6.
For providers of video-sharing platform services whose service is specifically designed for minors and expressly permits, via terms and conditions, access by minors below the age of 13 years the proposed regulations foresee the option of guardian-controlled access for minors below the age of 13 in Art. 7. Conditions for that option are that the minor’s access shall take place exclusively through the guardian's own account and be controlled by means of the tools for guardians. Further the provider is obliged to carry out and publish an assessment of the impact of the service on minors within the specified age range, set out, in a clear and transparent manner which content or behaviour is considered as not age-appropriate or harmful to the privacy, safety and security of minors within the specified age range, to not grant access to such content to minors, to adapt available features and functionalities, and gradually adjust, to the age of the minor, and to turn off all personalisation features and recommender systems, and any functionality to search for content shared by other recipients of the service. Further conditions are to be met by the provider in order to ensure that the guardian-controlled access does not disproportionately restrict the minor’s privacy and does support the minor’s autonomy and agency, f.e. that such access shall not be enabled for a minor below the age of 3 years and that the guardian-controlled access shall be discontinued when the minor reaches the age of 13 years.
Article 8 poses a general obligation on safety by design on all services named in Art. 1 b) without prejudice to the obligations as set out in Art. 6 and 7. Further, more specific obligations regarding safety by design are set out in the following articles, differentiated by the types of digital services.
In the scope of Articles 9 to 13 are online social networking services and of video-sharing platform services referring to minors – i.e. under 18 years olds – as users of such services with no further differentiation of age groups. The then following obligations in regard of “Addictive Design” (Art. 9), “Recommender Systems” (Art. 10), “Safe Settings” (Art. 11), “Contact and interaction safeguards” (Art. 12), and “Safety and security of economic transactions” (Art.13) are for the most part in line with the DSA Art 28 (4) Guidelines on the Protection of Minors. With the following nearly similar pretext “providers should at least …”, these five articles introduce a non-exhaustive list of measures to be taken or put in place by the providers of online social networking services and of video-sharing platform services.
With article 14 and 15 the proposal for an EU Kids Act goes beyond the DSA in addressing AI companions and online games which are not in the scope of DSA Art. 28 (1). Article 14 sets obligations for AI companions and general conversational chatbots referring to minors without any further differentiation by age, except for Art. 14, 1 (d) specifying that providers of AI companions and of general conversational chatbots shall ensure that access for minors below the age of 13 is only enabled and controlled by means of the tools for guardians. Importantly Art. 14, 2 also addresses AI companions and general conversational chatbots as functionalities in other types of services.
Article 15 sets obligations for providers of online games, again without further differentiation of age groups. But, Art. 15, 1 (d) specifies that providers ensure that access to such services for minors below the age of 13 years is only enabled and controlled by means of the tools for guardians.
Both afore-mentioned articles encompass addictive designs and those encouraging excessive use. Especially online game providers are obliged to prevent the game from being used to entice minors to initiate contacts on other services.
The age thresholds foreseen for online social networking sites and video-sharing platforms are not imposed on providers of online games. Therefore, an additional safety rope is established via the obligations for providers of software application stores in article 16. Those providers are obliged to put in place an age-rating system to allow to establish the age-appropriateness of software applications disseminated through their service and they shall not allow minors to access or purchase software applications that are inappropriate for their respective age.
The specific approaches on age thresholds and safety-by-design measures are accompanied by section VI of the proposal on general obligations on agency of minors and empowering tools for minors and guardians applying to all types of services. In line with the provisions of the DSA 28 (4) Guidelines, section 6.5.2 on user control and empowerment and section 7.1 on user reporting, feedback and complaints the articles 18 and 19 set out obligations on agency of minors and child-friendly reporting and support tools for minors. In addition, article 20 obliges providers to implement effective, accessible and user-friendly tools for guardians that are tailored to the age of the minor, taking due account of the minor’s gradual development, easy to use, access and activate for minors and guardians.
In order to ensure that the different age thresholds as laid down in articles 5 and 6 of the proposal and the age-gating obligations for providers of software application stores can have the intended effects the proposal includes Art. 26 on verification of parental responsibility setting out how providers shall use signals of the parental responsibility based on freely accessible official online databases or otherwise signals they may already be in possession of in view of the past engagements of the respective minor and adult with parental responsibility with their service. This results in an obligation to member states set out in article 31 to provide at least one privacy-preserving electronic means by which a guardian can obtain and present an attestation of parental responsibility in respect of a minor, free of charge for the guardian, effectively accessible to all citizens and guardians and minors residing in their territory, including groups in need of special support, f.e. migrants, etc.
Furthermore, the proposal includes a whole chapter on age assurance which is mainly in line with the provisions of the DSA 28 (4) Guidelines, section 6.1 Age Assurance.
Art. 27 sets general principles for age assurance which are a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination. Article 28 is dedicated especially to data protection in age assurance stating that age assurance solutions shall not enable the identification of the recipient nor locate, track, target, advertise to or profile recipients, and further comprising of the principle of data-minimization, state-of-the art technology and zero-knowledge proof and further technical and organisational measures.
Specific obligations in regard of age assurance solutions are set out in Art. 29. In order to verify whether the recipient of a service has reached the minimum age pursuant to the provisions of article 6 of the proposal, or, where applicable, whether the creation of a parental account is necessary, providers shall rely exclusively on an EU age verification solution using an EU proof of age attestation, provided by a third party, certified as conforming with the EU Age Verification Scheme. For compliance with the general obligation on safety by design as set out in article 8 and the specific obligations for providers of software application stores as set out in Article 16(2) and 16(3) age assurance solutions other than the EU age verification solutions may be used where those solutions meet the requirements laid down in Article 27 and Article 28 of the proposal.
Overall, the proposal aims at improving, promoting and supporting the respect of the rights of the child online, as enshrined in the Charter of Fundamental Rights of the European Union, esp. Art. 24 (1) and Art. 10 (1).
