EU KIDS Act
PURPOSE: to ensure a high level of privacy, safety, and security of children (EU KIDS Act).
PROPOSED ACT: Regulation of the European Parliament and of the Council.
ROLE OF THE EUROPEAN PARLIAMENT: the European Parliament decides in accordance with the ordinary legislative procedure and on an equal footing with the Council.
BACKGROUND: children spend an increasing amount of time online and, in doing so, are exposed to many different risks such as exposure to age-inappropriate content, cyberbullying, excessive time spent online, and unwanted contacts from strangers. These risks carry serious consequences for childrens mental health and well-being, with adolescents and children being a particularly vulnerable group.
The EU market risks becoming increasingly fragmented as Member States are planning or adopting new measures to restrict access to certain online platforms considered risky for children below a specified age with differences in scope, age limit and proposed restrictions thereby creating legal uncertainty, high compliance costs for businesses and an unequal level of protection for minors in a digital environment that knows no borders.
To ensure a safe and age-appropriate digital environment for minors, age assurance is critical for effectively protecting minors online. Age assurance underpins both age restrictions and safety measures of children. However, the current legal framework around age assurance lacks clarity and its implementation is patchy.
CONTENT: against this background, this proposed Regulation aims at ensuring a strong and coherent framework for the protection of minors online, taking the child and their empowerment and fundamental rights as a starting point. This proposal therefore aims to ensure the proper functioning of the internal market, in particular, in relation to the provision of cross-border online social networking services, video-sharing platform services, software application stores, of AI companions and general conversational chatbots, and of online games. Such a harmonised approach also ensures an equally high level of protection for minors across the EU.
The proposal pursues the following specific objectives:
- delay minors access to services with specific features that constitute social network services or video-sharing platforms. These services shall not allow minors below the age of 15 to create an account. Providers of those services may allow guardians to set up accounts for minors above the age of 13 with limited features to access the service. Where such providers can demonstrate that they are a child-friendly service, they may grant access also to minors below 13 years by means of accounts that are created and supervised by their guardian;
- strengthen the protection of minors through safety-by-design requirements by clarifying the obligations of digital services and certain systems, so that risks to children are addressed in the design and functioning of those services and systems. This includes a ban on addictive features and profiling-based recommender feeds dragging minors into rabbit holes' of harmful content. It also includes prohibiting infinite scroll without stopping points, reward tricks, and push notifications during sleeping hours, as well as unsolicited contact from strangers. In addition, AI companions and chatbots must be turned off by default and cannot simulate interpersonal relationships in ways that create emotional dependency. Profiles for minors must be private by default, with geolocation, camera and microphone access turned off. Online services must also offer easy ways for minors to block and mute users, effective time-management tools, and safe recommender systems that minors can control, tune and reset;
- ensure reliable and fundamental rights compliant age assurance mechanisms by establishing clear requirements and criteria for the use of age assurance systems to support both the access delay and the implementation of safety-by-design measures. Online services and app stores may use the EU age verification app, which does not retain identity documents or biometric data, thereby meeting the highest privacy-preserving safeguards. In addition, providers of social media services and video-sharing platforms will be called to perform age verification when a user opens a new account. When it comes to existing accounts, providers should estimate the user's age based on reasonable proxies (e.g. account creation date, credit card details);
- ensure effective enforcement across the EU by establishing a robust and coherent regulatory and enforcement framework that enables timely and efficient implementation, making sure that minors are protected quickly and effectively in practice. The enforcement framework builds on the structures already in place under the Digital Services Act and the Artificial Intelligence Act, making use of established mechanisms and existing expertise. The proposal introduces expedited enforcement procedures against providers in case of noncompliance with the EU KIDS Act, where the Commission should conclude investigations within 90 days.