Below, we look at the access restrictions that have been proposed and the practical questions they pose for service providers.
Read more on this topic
Article 6 – delayed creation and use of accounts
The extent to which providers of social networking and video-sharing platform services could enable children under the age of 15 to access the service using their own account, would depend on whether the service could be said to pose a risk to the privacy, safety or security of children under that age.
The KIDS Act proposal sets out criteria by which that level of risk would be considered to apply.
Broadly, services are considered to pose a risk to the privacy, safety or security of under-15s if they do any of the following:
- allow real-time content transmission to an indeterminate number of recipients;
- allow stranger contact;
- provide recommendations based on profiling;
- suggest contacts or recommend content from non-contacts;
- have functionalities enabling uninterrupted content consumption, like autoplay, or encourage continued engagement.
This would appear to be an exhaustive list.
If any of those features are present, providers would have to stop under-15s from creating an account or otherwise accessing the service via an account set up for them.
There is, though, an exception to this that would allow the guardian of a child aged between 13 and 15 years old to set up accounts with limited features for their child.
These “limited accounts” must come with parental controls which are always activated, which can be used to set time limits on daily use, and which can be used to pre-approve contacts and limit the number of contacts the child is allowed to have. The parental controls required do not go to every feature which would qualify a service as posing a risk. For example, there is no mention of controls relating to recommendations based on profiling, although these are covered by the safety by design requirements.
Although guardians are given the ability to set limits on the daily time a child spends on a service, the KIDS Act proposal makes provision for daily limits, capped at one hour. This seems a more paternalistic regulatory approach – guardians are given autonomy, but only within very strict confines. Perhaps the intention is to enable guardians to say to persistent children that they can’t give them more time.
When enabling guardians to set up a limited account for their child, the provider is required to verify that the child is over 13 and to establish that the person opening the account has parental authority. The difficulties in establishing a child’s age have been widely discussed in recent years amidst a growing body of online safety regulation, but less so the difficulties in establishing parental responsibility. This task is complicated by the requirements of domestic law in EU member states. Member state family law rules on parental authority vary, and parental authority can emanate from different sources such as court decisions and contracts. Verifying parental responsibility may therefore prove more difficult than verifying age. The proposal provides limited detail on how that should be achieved in practice.
Within six months of the KIDS Act starting to apply, providers would need to establish the age of existing users. If they don’t – or can’t – they would need to disable those user accounts. An exemption applies if the provider can establish with a high degree of confidence that the user had reached the relevant threshold, potentially by reference to reliable information already held or, where sufficiently probative, the date on which the account was created. This proposal is ambitious and would lead to operational challenges.
Some platforms have already undertaken similar efforts, and many users refuse to engage with requests to prove their age. It seems likely that this measure would lead to many adult accounts being disabled at the end of the six months. In theory, providers might verify the age of long-standing users on the basis of them holding their account for at least 15 years. Platforms with “adult only” content are also likely to have already established that a user is over 18.
The KIDS Act proposal acknowledges the co-existence of age requirements under the GDPR, but it simply states that the requirements relating to limited accounts apply in parallel to those age requirements and it is unclear how the two work together. The age at which a child may consent independently to certain personal data processing under the GDPR varies between member states, whereas the KIDS Act would establish separate EU-wide age thresholds for account access and guardian controls. This would mean providers may need to distinguish between a guardian’s control over access and safety features and the child’s ability to exercise particular data protection choices.
Overall, one possible impact of the Article 6 proposals may be to encourage children to use a service in an unregistered, anonymous, or signed-out state.
It is also reasonable to question whether services should be statutorily labelled as posing a risk merely because one of the listed risk conditions features, without considering what mitigations the providers have put in place to address such risks.
Article 7 – guardian-controlled access for under-13s
Video-sharing platforms would have scope to “exceptionally” enable under-13s to access services they operate that are “specifically designed” for children in that age bracket. Providers would not be allowed to let such children set up their own accounts in order to obtain such access.
Instead, it appears the Commission envisages a form of account sharing, with access for under-13s enabled through profiles or restricted modes under the guardian’s own account, although the proposal doesn’t clearly specify the mode of access other than to say that it should be through the guardian’s account. This is referred to as guardian-controlled access. The proposal imagines under-13s only having “limited access” to the services, which providers could only enable if they meet a range of detailed conditions.
The conditions include that:
- the provider has undertaken and published an assessment of the impact of the service on minors, including an assessment of risks, and can demonstrate that measures are in place to mitigate against the risks identified;
- the provider publish a description of which content or behaviour on the platform is considered not age-appropriate or harmful to the privacy, safety and security of minors;
- tools are made available to guardians to control the child’s access;
- content blocks prevent under-13s accessing material that is not age-appropriate or which is harmful;
- the service operates with age-adjusted features and functionalities;
- personalisation, recommender systems and search are switched off unless in the child’s best interests.
In addition, the guardian must declare their child's age, with providers prohibited from enabling any access for children under the age of three. A one-hour-per-day use cap would also apply and guardians would have to be able to supervise and approve their child’s interactions. Guardian-controlled access under Article 7 would have to end when the child turns 13. At that point, the child might transition to an Article 6 limited account set up by the guardian, provided the relevant conditions are met.
This Article raises a number of questions, for providers and for law makers who will scrutinise the proposals.
For example, it is not clear what would constitute a service being “specifically designed” for under-13s or what makes access “exceptional”. It is also not clear how a platform would be able to prevent a guardian from simply giving a child access through their own account rather than set through sub-accounts or restricted modes.
In addition, while there is a general requirement that guardian-controlled access does not disproportionately restrict the minor’s privacy and supports the minor’s autonomy and agency, complying with some of the more prescriptive requirements of the KIDS Act would, we think, inevitably restrict minors’ privacy and their agency.
The parental controls that must be made available for guardian-controlled access are more extensive that those required for limited accounts for under-15s. They include the guardian’s ability to suspend the child’s access at any time, and to supervise content shown to the minor – notwithstanding the requirement to square this with the child’s right to privacy.
Similar to the provisions related to limited accounts for under-15s, the provider is required to establish that the guardian has parental responsibility. This seems less workable in a situation where the child can only access the service using the guardian’s own account. It is not clear how a provider would establish that the child is in fact the child that the guardian has parental responsibility over, where no account is created for that child.
It is positive to see recognition that different features may be appropriate for children in different age groups. The features can be enabled if they are in the best interests of the child, so providers will need to make sure that their best interests of the child assessments are up-to-date. A best interests assessment typically involves balancing the different rights of children, but in this case the proposal specifically states that the rights to privacy and safety should not be negatively affected at all.
The requirement to block recommender systems and search functionalities seems very limiting, and fails to recognise that pre-teens can be mature enough to search for content they are interested in. With search to be disabled, the proposal seems to envisage the parent pre-selecting content which the child can see.
Co-written by Julie Campana-Davies and Diana Azoitei of Pinsent Masons.