Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

LIBE-PR-746811 → A-9-2023-0364

From
LIBE-PR-746811 report parliamentary committee draft of 19 Apr 2023
To
A-9-2023-0364 Plenary report of 16 Nov 2023
Changes
95 changes to the text
Paragraphs
+421 added · −186 removed · 51 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse
Title (to)
on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse

Changes that matter, 95

Changes to the text in document order — the ones the change notes describe. Cover page, renumbering and punctuation-only edits are left out (see “Every difference”); changes to citations and references stay in and are marked as formal in the notes.

Change 1

ChangedRecital 2:1: (2)(1) GivenInformation thesociety centralservices importancehave ofbecome relevantvery informationimportant societyfor services,communication, thoseexpression, aimsgathering canof onlyinformation beand achievedmany byother ensuringaspects thatof providerspresent-day offeringlife, suchincluding servicesfor inchildren. theHowever, Unionthese behaveservices responsiblyare andalso takeused reasonableby measuresperpetrators toof minimisechild thesexual riskabuse ofoffences. theirSuch servicesoffences, beingwhich misusedare forsubject theto purposeminimum ofrules childset sexualat abuse,Union thoselevel, providersare oftenvery beingserious incriminal aoffences uniquethat positionoften tocause preventlong-lasting andnegative combatconsequences suchon abuse.victims Theand measuresthat takenneed shouldto be effective, targeted, carefully balancedprevented and proportionate,combated soeffectively asin order to avoidprotect anychildren’s unduerights negativeand consequenceswell-being, foras thoseis whorequired useunder the services for lawfulCharter purposes,of inFundamental particularRights forof the exerciseEuropean ofUnion their(‘Charter’), fundamentaland rightsto protectedprotect undersociety Unionat law,large. thatUsers is,of thosesuch enshrinedservices offered in the Charter and recognisedUnion asshould generalbe principlesable ofto Uniontrust law,that andthe soservices asconcerned tocan avoidbe imposingused anysafely excessivein burdensa ontrusted theonline providersenvironment, ofespecially theby services.children.

Change 2

RemovedRecital 3: (3) Member States are increasingly introducing, or are considering introducing, national laws to prevent and combat online child sexual abuse, in particular by imposing requirements on providers of relevant information society services. In the light of the inherently cross-border nature of the internet and the service provision concerned, those national laws, which diverge, may have a direct negative effect on the internal market. To increase legal certainty, eliminate the resulting obstacles to the provision of the services and ensure a level playing field in the internal market, the necessary harmonised requirements should be laid down at Union level.

AddedRecital 2: (2) Given the central importance of relevant information society services, those aims can only be achieved by ensuring that providers offering such services in the Union behave responsibly and take reasonable measures to minimise the risk of their services being misused for the purpose of child sexual abuse, those providers often being in a unique position to prevent and combat such abuse. The measures taken should be effective, targeted, evidence-based, carefully balanced, and proportionate, and subject to constant review so as to avoid any undue negative consequences for those who use the services for lawful purposes, in particular for the exercise of their fundamental rights protected under Union law, that is, those enshrined in the Charter and recognised as general principles of Union law, and so as to avoid directly or indirectly imposing any excessive burdens on the providers of the services.

RemovedRecital 4: (4) Therefore, this Regulation should contribute to the proper functioning of the internal market by setting out clear, uniform and balanced rules to prevent and combat child sexual abuse in a manner that is effective, targeted and proportionate, and that respects the fundamental rights of all parties concerned. In view of the fast-changing nature of the services concerned and the technologies used to provide them, those rules should be laid down in technology-neutral and future-proof manner, so they encourage innovation and technological development to prevent and combat online child sexual abuse.

AddedRecital 3: (3) Member States are increasingly introducing, or are considering introducing, national laws to prevent and combat online child sexual abuse and more generally to protect children online, in particular by imposing requirements on providers of relevant information society services. In the light of the inherently cross-border nature of the internet and the service provision concerned, those national laws, which sometimes diverge, can have a direct negative effect on the internal market. To increase legal certainty, eliminate the resulting obstacles to the provision of the services and ensure a level playing field in the internal market, the necessary harmonised requirements should be laid down at Union level.

RemovedRecital 5: (5) In order to achieve the objectives of this Regulation, it should cover providers of services that have the potential to be misused for the purpose of online child sexual abuse. As they are increasingly misused for that purpose, those services should include publicly available interpersonal communications services, such as messaging services and web-based e-mail services, in so far as those service as publicly available. As services which enable direct interpersonal and interactive exchange of information merely as a minor ancillary feature that is intrinsically linked to another service, such as chat and similar functions as part of gaming, image-sharing and video-hosting are equally at risk of misuse, they should also be covered by this Regulation. Online search engines and any other artificial intelligence services should also be covered. However, given the inherent differences between the various relevant information society services covered by this Regulation and the related varying risks that those services are misused for the purpose of online child sexual abuse and varying ability of the providers concerned to prevent and combat such abuse, the obligations imposed on the providers of those services should be differentiated in an appropriate manner.

AddedRecital 4: (4) Therefore, this Regulation should contribute to the proper functioning of the internal market by setting out clear, uniform, effective, proportionate and carefully balanced rules to prevent and combat child sexual abuse in a manner that is effective, targeted and proportionate, and that respects the fundamental rights of all parties concerned. In view of the fast-changing nature of the services concerned and the technologies used to provide them, those rules should be laid down in technology-neutral and future-proof manner, so they stimulate innovation and technological development to prevent and combat online child sexual abuse.

Show 5 more lines

RemovedRecital 7: (7) This Regulation should be without prejudice to the rules resulting from other Union acts, in particular Directive 2011/93 of the European Parliament and of the Council38 , Directive 2000/31/EC of the European Parliament and of the Council39 and Regulation (EU) 2022/2065 of the European Parliament and of the Council40, Directive 2010/13/EU of the European Parliament and of the Council41 , Regulation (EU) 2016/679 of the European Parliament and of the Council42 , and Directive 2002/58/EC of the European Parliament and of the Council43 . / 40 Regulation (EU) 2022/2065 of the European Parliament and of the Council on a Single Market For Digital Services (Digital Services Act) and amending Directive 2000/31/EC (OJ L 277/1).

AddedCompromise amendment replacing Amendment(s): 310, 311

AddedRecital 5: (5) In order to achieve the objectives of this Regulation, it should cover providers of services that have the potential to be misused for the purpose of online child sexual abuse. As they are increasingly misused for that purpose, those services should include publicly available number-independent interpersonal communications services, such as messaging services and web-based e-mail services, in so far as those services as are publicly available. As services which enable direct interpersonal and interactive exchange of information merely as a minor ancillary feature that is intrinsically linked to another service, such as chat and similar functions as part of gaming online games, image-sharing and video-hosting are also at risk of misuse for the purpose of online child sexual abuse, they should also be covered by this Regulation. However, given the inherent differences between the various relevant information society services covered by this Regulation and the related varying risks that those services are misused for the purpose of online child sexual abuse and varying ability of the providers concerned to prevent and combat such abuse, the obligations imposed on the providers of those services should be differentiated in an appropriate manner without lowering child protection standards.

AddedRecital 6: (6) Online child sexual abuse can also involve the misuse of information society services offered in the Union by providers established in third countries. In order to ensure the effectiveness of the rules laid down in this Regulation and a level playing field within the internal market, those rules should apply to all providers, irrespective of their place of establishment or residence, that offer services in the Union, as evidenced by a substantial connection to the Union.

AddedRecital 7: (7) This Regulation should be without prejudice to the rules resulting from other Union acts, in particular Directive 2011/93 of the European Parliament and of the Council38 , Directive 2000/31/EC of the European Parliament and of the Council39 and Regulation (EU) 2022/2065 of the European Parliament and of the Council40, Directive 2010/13/EU of the European Parliament and of the Council41 , Regulation (EU) 2016/679 of the European Parliament and of the Council42 , and Directive 2002/58/EC of the European Parliament and of the Council43 .

Change 3

AddedRecital 9 a (new): (9a) Encryption, and especially end-to-end encryption, is an increasingly important tool to guarantee the security and confidentiality of the communications of all users, including children. Any restrictions or undermining of the end-to-end encryption can be used and abused by malicious third parties. Nothing in this Regulation should therefore be interpreted as prohibiting, weakening or undermining end-to-end encryption. Providers of information society services should under no circumstances be prevented from providing their services using the highest standards of encryption, considering that such encryption is essential for trust in and security of the digital services.

Change 4

ChangedRecital 11: (11) A substantial connection to the Union should be considered to exist where the relevant information society services has an establishment in the Union or, in its absence, where the number of recipients of the service in one or more Member States is significant in relation to its or their population, or on the basis of the targeting of activities towards one or more Member States. The targeting of activities towards one or more Member States should be determined on the basis of all relevant circumstances, including factors such as the use of a language or a currency generally used in that Member State, or the possibility of ordering products or services, or using a national top level domain. The targeting of activities towards a Member State could also be derived from the availability of a software application in the relevant national software application store, from the provision of local advertising or advertising in the language used in that Member State, or from the handling of customer relations such as by providing customer service in the language generally used in that Member State. A substantial connection should also be assumed where a service provider directs its activities to one or more Member State as set out in Article 17(1), point (c), of Regulation (EU) 1215/2012 of the European Parliament and of the Council44 . Mere technical accessibility of a website from the Union should not, on that ground alone, be considered as establishing a substantial connection to the Union.t…

Change 5

RemovedRecital 15: (15) Some of those providers of relevant information society services in scope of this Regulation may also be subject to an obligation to conduct a risk assessment under Regulation (EU) 2022/2065 with respect to information that they store and disseminate to the public. For the purposes of the present Regulation, and in order to ensure consistency and avoid duplication, those providers may draw on such a risk assessment and complement it with a more specific assessment of the risks of use of their services for the purpose of online child sexual abuse, as required by this Regulation.

AddedRecital 14: (14) With a view to minimising the risk that their services are misused for the dissemination of known or new child sexual abuse material or the solicitation of children, providers of hosting services and providers of publicly available number independent interpersonal communications services should assess such risk stemming, inter alia, from the design, functioning and use of their services that they offer in the Union. That risk assessment should be specific to the services they offer and proportionate to the risk considering its severity and probability. To guide their risk assessment, a non-exhaustive list of elements to be taken into account should be provided. To allow for a full consideration of the specific characteristics of the services they offer, providers should be allowed to take account of additional elements where relevant. As risks evolve over time, in function of developments such as those related to technology and the manners in which the services in question are offered and used, it is appropriate to ensure that the risk assessment is updated regularly and when needed for particular reasons.

RemovedRecital 16: (16) In order to prevent and combat online child sexual abuse effectively, providers of hosting services and providers of publicly available interpersonal communications services should take reasonable measures to mitigate the risk of their services being misused for such abuse, as identified through the risk assessment. Providers subject to an obligation to adopt mitigation measures pursuant to Regulation (EU) 2022/2065 may consider to which extent mitigation measures adopted to comply with that obligation. Mitigation measures may include designing their online interfaces or parts thereof with the highest level of privacy, safety and security for children by default or adopting standards for protection of children, or participating in codes of conduct for protecting children, targeted measures to protect the rights of the child, including functionalities enabling age assurance and age scoring, and age-appropriate parental control tools. Enabling flagging and/or notifying mechanisms and self-reporting functionalities may also serve to address the risk identified in the specific risk assessment pursuant to this Regulation, and to which extent further targeted mitigation measures may be required to comply with this Regulation.

AddedRecital 14 a (new): (14a) The obligation to conduct a risk assessment should apply, in any case, to very large online platforms and to those providers which are substantial, exposed to online child sexual abuse. Providers that qualify as small and micro enterprises as defined in Commission Recommendation 2003/361/EC should carry out a simplified risk assessment. Irrespective of their size or their substantially exposure to online child sexual abuse, providers of online games that operate number-independent interpersonal communications service within their games, platforms primarily used for the dissemination of pornographic content and providers offering services directly targeting children should carry out a risk assessment.

Change 6

ChangedRecital 17 a (new): (17a) Providers should also15: assess,(15) inSome aof separatethose sectionproviders of theirrelevant riskinformation assessment,society theservices voluntaryin usescope of specific technologies for the processing ofthis personalRegulation datamay andalso otherbe datasubject to the extent strictlyan necessaryobligation to detect online child sexualconduct abusea onrisk theirassessment servicesunder andRegulation report(EU) it2022/2065 andrespect to removeinformation onlinethat childthey sexualstore abuseand materialdisseminate fromto theirthe services.public. OnFor the basispurposes of this separated assessment, providers may request to the competentpresent CoordinatingRegulation, Authorityand thein needorder to continue, as part of their mitigation measures, using specific technologies forensure theconsistency processingand ofavoid personalunnecessary databurdens and other data forduplications, those purposes. Following this request ofproviders themay provider,draw theon competentsuch Coordinatinga Authorityrisk shouldassessment havefor the power topurpose requestof the competent judicial authorityrisk ofassessment theunder Memberthis StateRegulation thatand designatedcomplement it orwith anothera independentmore administrativespecific authorityassessment of that Member State to issue an order that authorizes the provider to maintain or implement mitigation measuresrisks thatof consistuse of using specifictheir technologiesservices for the processingpurpose of personal and other data to the extent strictly necessary to detect, report and remove online child sexual abuseabuse, onas theirrequired services.by this Regulation.

Change 7

RemovedRecital 18: (18) In order to ensure that the objectives of this Regulation are achieved, that flexibility should be subject to the need to comply with Union law and, in particular, the requirements of this Regulation on mitigation measures. Therefore, providers of hosting services and providers of publicly available interpersonal communications services should, when designing and implementing the mitigation measures, give importance not only to ensuring their effectiveness, but also to avoiding any undue negative consequences for other affected parties, notably for the exercise of users’ fundamental rights and therefore be the least intrusive as possible. In order to ensure proportionality, when determining which mitigation measures should reasonably be taken in a given situation, account should also be taken of the financial and technological capabilities and the size of the provider concerned. When selecting appropriate mitigation measures, providers should at least duly consider the possible measures listed in this Regulation, as well as, where appropriate, other measures such as those based on industry best practices, including as established through self-regulatory cooperation, and those contained in guidelines from the Commission. When no risk has been detected after a diligently conducted or updated risk assessment, providers should not be required to take any mitigation measures.

AddedRecital 16: (16) In order to prevent and combat online child sexual abuse effectively, providers of hosting services and providers of publicly available number-independent interpersonal communications services should take reasonable measures to mitigate the risk of their services being misused for such abuse, as identified through the risk assessment. Providers subject to an obligation to adopt mitigation measures pursuant to Regulation (EU) 2022/2065 may consider to which extent mitigation measures adopted to comply with that obligation, which may include targeted measures to protect the rights of the child, including age verification and parental control tools, may also serve to address the risk identified in the specific risk assessment pursuant to this Regulation, and to which extent further targeted mitigation measures may be required to comply with this Regulation.

RemovedRecital 20: (20) With a view to ensuring effective prevention and fight against online child sexual abuse, when the provider refuses to cooperate by putting in place the mitigating measures aimed to limit the risk of misuse of a certain service for the purpose of online child sexual abuse, the Coordinating Authorities designated by Member States under this Regulation should be empowered to request, as a measure of last resort, the issuance of detection orders. In order to avoid any undue interference with fundamental rights and to ensure proportionality, that power should be subject to a carefully balanced set of limits and safeguards. For instance, considering that child sexual abuse material tends to be disseminated through hosting services and publicly available interpersonal communications services, and that solicitation of children mostly takes place in publicly available interpersonal communications services, it should only be possible to address detection orders to providers of such services.

AddedRecital 17: (17) To allow for innovation and ensure proportionality and technological neutrality, no exhaustive list of the compulsory mitigation measures should be established. Instead, providers should be left a degree of flexibility to design and implement measures tailored to the risk identified and the characteristics of the services they provide and the manners in which those services are used. In particular, providers are free to design and implement, in accordance with Union law, measures based on their existing practices to detect and prevent, online child sexual abuse in their services. Mitigation measures should aim to contribute to prevent child sexual abuse from happening in the first place, and consequently detection orders should be issued only to providers that have failed to take all reasonable and proportionate mitigation measures to address the risk identified.

RemovedRecital 21: (21) Furthermore, as parts of those limits and safeguards, detection orders should only be issued after a diligent and objective assessment leading to the finding of a significant risk of the specific service concerned being misused for a given type of online child sexual abuse covered by this Regulation. For conducting such assessment a fluent dialogue must be established between the Coordinating Authority and the provider. In order to achieve that aim, it should be possible for the Coordinating Authority to request additional information to the EU Centre, the competent data protection authorities or another public authority or entities. One of the elements to be taken into account in this regard is the likelihood that the service is used to an appreciable extent, that is, beyond isolated and relatively rare instances, for such abuse. An appreciable extent may be understood as being where access to child sexual abuse material could spread rapidly and widely with a particularly wide reach or other means of amplification. The criteria should vary so as to account of the different characteristics of the various types of online child sexual abuse at stake and of the different characteristics of the services used to engage in such abuse, as well as the related different degree of intrusiveness of the measures to be taken to execute the detection order.

AddedRecital 17 a (new): (17a) top Online platforms primarily used for the dissemination of pornographic content and providers of online games falling under the scope of this Regulation should take additional technical and organisational measures to ensure safety and security by design and by default for children.

Show 10 more lines

RemovedRecital 23: (23) In addition, to avoid undue interference with fundamental rights and ensure proportionality, when it is established that those requirements have been met and a detection order is to be issued, it should still be ensured that the detection order is justified, proportionate or related to the specific service, users or group of users, targeted and limited in time so as to ensure that any such negative consequences for affected parties do not go beyond what is strictly necessary to effectively address the significant risk identified. This should concern, in particular, a limitation to an identifiable part or component of the service, such as specific types of channels of a publicly available interpersonal communications service, or to specific users or specific groups of users, to the extent that they can be taken in isolation for the purpose of detection, as well as the specification of the safeguards additional to the ones already expressly specified in this Regulation, such as independent auditing, the provision of additional information or access to data, or reinforced human oversight and review, and the further limitation of the duration of application of the detection order that the Coordinating Authority deems necessary. To avoid unreasonable or disproportionate outcomes, such requirements should be set after an objective and diligent assessment conducted on a case-by-case basis.

AddedRecital 18: (18) In order to ensure that the objectives of this Regulation are achieved, that flexibility should be subject to the need to comply with Union law and, in particular, the requirements of this Regulation on mitigation measures. Therefore, providers of hosting services and providers of publicly available number-independent interpersonal communications services should, when designing and implementing the mitigation measures, give importance not only to ensuring their effectiveness, but also to avoiding any undue negative consequences for other affected parties, notably for the exercise of users’ fundamental rights or if they disproportionately affect people experiencing intersectional discrimination, including on the basis of sex, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age, gender or sexual orientation. Particular care should be taken to assess the impact on girls, who are at a greater risk of being subject to child sexual abuse and gender-based violence. In order to ensure proportionality, when determining which mitigation measures should reasonably be taken in a given situation, account should also be taken of the ongoing effectiveness of the measures, the financial and technological capabilities and the size of the provider concerned. Therefore mitigation measures should always be the least intrusive option possible. When selecting …

RemovedRecital 26: (26) The measures taken by providers of hosting services and providers of publicly available interpersonal communications services to execute detection orders addressed to them should remain strictly limited to what is specified in this Regulation and in the detection orders issued in accordance with this Regulation. In order to ensure the effectiveness of those measures, allow for tailored solutions, remain technologically neutral, and avoid circumvention of the detection obligations, those measures should be taken regardless of the technologies used by the providers concerned in connection to the provision of their services. Therefore, this Regulation leaves to the provider concerned the choice of the technologies to be operated to comply effectively with detection orders and should not be understood as incentivising or disincentivising the use of any given technology, provided that the technologies and accompanying measures meet the requirements of this Regulation. When executing the detection order, providers should take all available safeguard measures to ensure that the technologies employed by them cannot be used by them or their employees for purposes other than compliance with this Regulation, nor by third parties, and thus to avoid undermining the security and confidentiality of the communications of users.

AddedRecital 18 a (new): (18a) Parental control features and functionalities should be limited to allowing allow parents, or guardians only to prevent children from accessing platforms or services that are inappropriate for their age or fall under an age-restriction applicable under national law, or to help prevent them from being exposed to content that is inappropriate. Those measures should be in accordance with Regulation (EU) 2016/679 and the Convention on the Rights of the Child, in particular General Comment 25 (2021) on children’s rights in relation to the digital environment, respect the integrity and safety of the device and not allow unauthorised access or control by third parties.

RemovedRecital 26 a (new): (26a) End-to-end encryption is an important tool to guarantee the security and confidentiality of the communications of users, including those of children. Any weakening of the end-to-end encryption could potentially be abused by malicious third parties. Nothing in this Regulation should therefore be interpreted as prohibiting or weakening end-to-end encryption. However, to the extent strictly necessary and proportionate to mitigate the risk of misuse of their services for the purpose of online child sexual abuse, providers should be authorised by the competent judicial authority or another independent administrative authority to process metadata that can detect suspicious patterns of behaviour without having access to the content of the encrypted communication.

AddedRecital 18 b (new): (18b) Providers should have to establish and operate an accessible, age-appropriate, child-friendly and user-friendly reporting mechanism that allows any user or entity to flag or notify them the presence of potential online child sexual abuse on their services, including self-generated material.

RemovedRecital 27: (27) In order to facilitate the providers’ compliance with the detection obligations, the EU Centre should make available to providers detection technologies that they may choose to use, on a free-of-charge basis, for the sole purpose of executing the detection orders addressed to them. The European Data Protection Board should be consulted on those technologies and the ways in which they should be best deployed to ensure compliance with applicable rules of Union law on the protection of personal data. The advice of the European Data Protection Board should be taken into account by the EU Centre when compiling the lists of available technologies and also by the Commission when preparing guidelines regarding the application of the detection obligations. The providers should not be limited to operate the technologies made available by the EU Centre or by others but they will always be allowed to use technologies that they developed themselves, as long as they meet the requirements of this Regulation.

AddedRecital 18 c (new): (18c) Providers that have identified a risk of use of their services for the purpose of the solicitation of children, should be able to take age verification measures. The implementation of technical procedures to verify the age of users is likely to result in the processing of personal data. Such processing is particularly sensitive in view of its purpose and is subject to Regulation (EU) 2016/679. Age verification systems should strictly comply with the principle of data minimization. In addition, the requirement to set up an age verification system for the legitimate purpose of protecting minors provided for in this Regulation does not justify a general obligation to identify oneself prior to consulting any site offering content. Being able, in principle, to benefit from online public communication services without having to identify oneself, or by using pseudonyms, contributes to the freedom to inform oneself and to the protection of users' privacy. This is an essential element in the exercise of these freedoms on the Internet. Providers should use systems that provide proof of age without revealing the identity of the user as foreseen in Regulation .../... amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity. Such services could, for example, be based on a trusted third-party organization, which would have to incorporate a double anonymity mechanism preventing the trusted third party from identifying the site or applica…

RemovedRecital 29: (29) Providers of hosting services and providers of publicly available interpersonal communications services are uniquely positioned to detect potential online child sexual abuse involving their services. The information that they may obtain when offering their services is often indispensable to effectively investigate and prosecute child sexual abuse offences. Therefore, upon obtaining actual knowledge or awareness on potential child sexual abuse on their services, they should act expeditiously to remove or to disable access to that content and to report it to the EU Centre in accordance with this Regulation. The removal or disabling of access should respect the fundamental rights of the recipients of the service, including the right to freedom of expression and of information. The provider can obtain such actual knowledge or awareness on potential child sexual abuse on their services, inter alia through its own-initiative investigations, through the execution of voluntary detection orders or detection orders, as well as through information flagged by users, self-reported by victims or organisations, such as hotlines, acting in the public interest against child sexual abuse, or through notifications done by the Coordinating authorities or by the EU Centre. Where such reasonable grounds exist, doubts about the potential victim’s age should not prevent those providers from submitting reports. Those reports should contain a minimum of information, as specified in this Regulatio…

AddedRecital 19: (19) In the light of their role as intermediaries facilitating access to software applications that may be misused for online child sexual abuse, providers of software application stores considered as gatekeepers under Regulation (EU) 2022/1925 should be made subject to obligations to take certain reasonable measures to assess and mitigate that risk, specifically preventing children from accessing the software applications in relation to which the provider of software application has explicity informed that it does not permit its use by children or when it has an age rating model in place. The providers should make that assessment in a diligent manner, making efforts that are reasonable under the given circumstances, having regard inter alia to the nature and extent of that risk as well as their financial and technological capabilities and size, and cooperating with the providers of the services offered through the software application where possible.

Change 8

ChangedRecital 30:20: (30)(20) ToWith ensurea thatview to ensuring effective prevention and fight against online child sexual abuseabuse, materialwhen isthe removedprovider asrefuses swiftlyto ascooperate possibleby afterputting itsin detection,place Coordinatingthe Authoritiesmitigating ofmeasures establishmentaimed shouldto havelimit the powerrisk toof requestmisuse competentof judiciala authoritiescertain orservice independentfor administrativethe authoritiespurpose toof issueonline achild removalsexual orderabuse, addressedthe toCoordinating providersAuthorities ofdesignated hostingby services.Member AsStates removalunder orthis disablingRegulation ofshould accessbe mayempowered affectto therequest, rightas ofa usersmeasure whoof havelast providedresort, the material concerned,issuance providersof shoulddetection informorders. suchIn usersorder ofto theavoid reasonsany forundue theinterference removal,with tofundamental enablerights themand to exercise their rightensure ofproportionality, redress,that subjectpower toshould exceptionsbe neededsubject to avoida interferingcarefully withbalanced activitiesset forof thelimits prevention,and detection,safeguards. investigationFor andinstance, prosecutionconsidering ofthat child sexual abuse offences. Removalmaterial orderstends shouldto be addressed,disseminated asthrough ahosting generalservices rule,and topublicly providersavailable ofnumber-independent relevantinterpersonal informationcommunications societyservices, servicesit actingshould asonly recipientbe ofpossible theto serviceaddress indetection accordanceorders withto Regulationproviders (EU)of 2022/2065.such services. As ana exception,matter whereof contentprinciple, isdetection storedorders orshould processedbe asaddressed partto ofthe anservice infrastructureprovider providedacting byas anothera providercontroller. ofHowever, ain relevantsome informationcircumstances, societydetermining service,whether thea removalservice orderprovider mayhas bethe directlyrole addressedof tocontroller itor whereprocessor thecan recipientprove ofparticularly challenging or addressing the servicecontroller cannotmay be identifieddetrimental despiteto reasonablean effortsongoing oninvestigation. theConsequently, partas ofan theexception, Coordinatingit Authority,should orbe wherepossible addressingto theaddress recipienta ofdetection order directly to the service mayprovider bethat detrimentalstores toor anotherwise ongoingprocesses investigation.the data.

Show 87 more changes

Change 9

AddedRecital 21: (21) Furthermore, as parts of those limits and safeguards, detection orders should only be issued by a judicial authority and only after a diligent and objective assessment leading to the finding of reasonable grounds of suspicion for a link, at least an indirect one, of the service concerned being misused by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication for child sexual abuse material. Reasonable grounds are those resulting from any information reliable and legally acquired that suggest that individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication might have a link, even an indirect or remote one, with child sexual abuse material. A link with child sexual abuse material should be deemed to exist where on the basis of objective evidence there is a reasonable suspicion that such material will be detected in the use of a service by a user. Where a channel is operated specifically for the purpose of distributing child sexual abuse material, the subscribers to that channel should be considered linked to child sexual abuse material. Conduct which is legal according to Directive 2011/92/EU or national law transposing it should not be deemed a reasonable ground of suspicion. In order to conduct such an assessment a fluent dialogue needs to be established between the Coordinating Authority and the provider. With the view at achiving that aim, it sho…

AddedRecital 21 a (new): (21a) The definition of child sexual abuse material provided in Article 2 has to be interpreted taking into account Directive 2011/93/EU. Therefore, personal communication between consenting peers as well as children over the age of sexual consent and their partners are out of the scope of the definition insofar those images does not involve any abuse or exploitation or payment or remuneration for pornographic performance and the images have not been disseminated without the consent of the parties involved. Likewise, images produced for medical or scientific purposes, strictly verifiable as such, should remain out of the scope of definition of child sexual abuse material.

AddedRecital 22: (22) It should be ensured that detection orders can be issued only after the Coordinating Authorities and the competent judicial authority having objectively and diligently assessed, identified and weighted, on a case-by-case basis, the likelihood and seriousness of any potential negative consequences for other parties affected, including the users of the service. With a view to avoiding the imposition of excessive burdens, the assessment should also take account of the financial and technological capabilities and size of the provider concerned.

AddedRecital 23: (23) In addition, to avoid undue interference with fundamental rights and ensure proportionality, when it is established that those requirements have been met and a detection order is to be issued, it should still be ensured that the detection order is limited in time so as to ensure that any such negative consequences for affected parties do not go beyond what is strictly necessary to effectively address the significant risk identified. This should concern, in particular, a limitation to individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication in respect of whom there are reasonable grounds of suspicion for a link, even an indirect one, with child sexual abuse material as defined in Article 2 as well as the specification of the safeguards additional to the ones already expressly specified in this Regulation, such as independent auditing, the provision of additional information or access to data, or reinforced human oversight and review, and the further limitation of the duration of application of the detection order that the Coordinating Authority deems necessary. To avoid unreasonable or disproportionate outcomes, such requirements should be set after an objective and diligent assessment conducted on a case-by-case basis.

AddedRecital 24: (24) The competent judicial authority, as applicable in accordance with the detailed procedural rules set by the relevant Member State, should be in a position to take a well-informed decision on requests for the issuance of detections orders. That is of particular importance to ensure the necessary fair balance of the fundamental rights at stake and a consistent approach. Therefore, a procedure should be provided for that allows the providers concerned, the EU Centre on Child Sexual Abuse established by this Regulation (‘EU Centre’) and, where so provided in this Regulation, the competent data protection authority designated under Regulation (EU) 2016/679 to provide their views on the measures in question. They should do so without undue delay, having regard to the important public policy objective at stake and the need to act without undue delay to protect children. In particular, data protections authorities should do their utmost to avoid extending the time period set out in Regulation (EU) 2016/679 for providing their opinions in response to a prior consultation. Furthermore, they should normally be able to provide their opinion well within that time period in situations where the European Data Protection Board has already issued guidelines regarding the technologies that a provider envisages deploying and operating to execute a detection order addressed to it under this Regulation.

AddedRecital 25: deleted

Show 6 more lines

AddedRecital 26: (26) The measures taken by providers of hosting services and providers of publicly available number-independent interpersonal communications services to execute detection orders addressed to them should remain strictly limited to what is specified in this Regulation and in the detection orders issued in accordance with this Regulation. In order to ensure the effectiveness of those measures, allow for tailored solutions, remain technologically neutral, and avoid circumvention of the detection obligations, those measures should be taken regardless of the technologies used by the providers concerned in connection to the provision of their services. Therefore, this Regulation leaves to the provider concerned the choice of the technologies to be operated to comply effectively with detection orders and should not be understood as incentivising or disincentivising the use of any given technology, provided that the technologies and accompanying measures meet the requirements of this Regulation. When executing the detection order, providers should take all available safeguard measures to ensure that the technologies employed by them cannot be used by them or their employees for purposes other than compliance with this Regulation, nor by third parties, and thus to avoid undermining the security and confidentiality of the communications of users, while ensuring the effective detection of child sexual abuse material and the balance of all the fundamental rights at stake. In that regard, …

AddedRecital 27: (27) In order to facilitate the providers’ compliance with the detection obligations, the EU Centre should make available to providers technologies that they may choose to use, on a free-of-charge basis, for the sole purpose of executing the detection orders addressed to them. The European Data Protection Board must be consulted on the use of those technologies and the ways in which they should be best deployed to ensure compliance with applicable rules of Union law on the protection of personal data. The advice of the European Data Protection Board should be taken into account by the EU Centre when compiling the lists of available technologies and also by the Commission when preparing guidelines regarding the application of the detection obligations. The providers should not be limited to operating the technologies made available by the EU Centre or by others but should always be allowed to use or technologies that they developed themselves, as long as they meet the requirements of this Regulation and other applicable Union law, such as Regulation (EU) 2016/679. Those technologies should be independently audited as regards their performance and reliability.

AddedRecital 27 a (new): (27a) Since the Commission consultations to the EDPB regarding several aspects of this Regulation will entail more work for the EDPB, its budget and staffing should be adapted accordingly. The situation of national authorities, who likewise will be regularly consulted by service providers, should also reflect their increased responsibilities.

AddedRecital 28: (28) With a view to constantly assess the performance of the detection technologies and ensure that they are sufficiently accurate and reliable, as well as to identify false positives and false negatives and avoid to the extent erroneous reporting to the EU Centre, providers should ensure adequate human oversight and, where necessary, human intervention, adapted to the type of detection technologies and the type of online child sexual abuse at issue. Such oversight should include regular assessment of the rates of false negatives and false positives generated by the technologies, based on an analysis of anonymised representative data samples. Providers should ensure that staff carrying out such task is adequately trained.

AddedRecital 29: (29) Providers of hosting services, and providers of publicly available number-independent interpersonal communications services are uniquely positioned to detect potential online child sexual abuse involving their services. The information that they may obtain when offering their services is often indispensable to effectively investigate and prosecute child sexual abuse offences. Therefore, upon obtaining actual knowledge on potential online child sexual abuse on their services, they should act expeditiously to remove or to disable access to that content and to report it to the EU Centre in accordance with this Regulation. The removal or disabling of access should respect the fundamental rights of the recipients of the service, including the right to freedom of expression and of information. / In the interest of effectiveness, it should be immaterial in which manner they obtain such awareness. Providers can obtain such actual knowledge on potential online child sexual abuse on their services, for example, through its own-initiative investigations, through the execution of detection orders, through notifications done by the Coordinating Authorities, as well as through information flagged by users, self-reported by victims or organisations, such as hotlines, acting in the public interest against child sexual abuse. To this end, it is important that providers, regardless of their size, have the obligation to put in place mechanisms that facilitate the flagging or notification o…

AddedRecital 30: (30) To ensure that online child sexual abuse material is removed as swiftly as possible after its detection and in order to stop or limit its dissemination, Coordinating Authorities of establishment should have the power to request competent judicial authorities to issue a removal order addressed to providers of hosting services. As removal or disabling of access may affect the right of users who have provided the material concerned, providers should, without undue delay, inform such users of the reasons for the removal, to enable them to exercise their right of redress, subject to exceptions, established for a limited time period, needed to avoid interfering with activities for the prevention, detection, investigation and prosecution of child sexual abuse offences. As a matter of principle, removal orders should be addressed to the service provider acting as a controller. However, in some circumstances, determining whether a service provider has the role of controller or processor can prove particularly challenging or addressing the controller could be detrimental to an ongoing investigation. Consequently, by way of derogation, it should be possible to address a removal order directly to the service provider that stores or otherwise processes the data.

Change 10

RemovedRecital 33: (33) In the interest of consistency, efficiency and effectiveness and to minimise the risk of circumvention, such blocking orders should be based on the list of Uniform Resource Identifiers, leading to specific items of verified child sexual abuse, compiled and provided centrally by the EU Centre on the basis of diligently verified submissions by the relevant authorities of the Member States. In order to avoid the taking of unjustified or disproportionate measures, especially those that would unduly affect the fundamental rights at stake, notably, in addition to the rights of the children, the users’ freedom of expression and information and the providers’ freedom to conduct a business, appropriate limits and safeguards should be provided for. In particular, it should be ensured that the burdens imposed on the providers of internet access services concerned are not unreasonable, that the need for and proportionality of the blocking orders is diligently assessed also after their issuance and that both the providers and the users affected have effective means of judicial as well as non-judicial redress.

AddedRecital 34: (34) Considering that acquiring, possessing, knowingly obtaining access and transmitting child sexual abuse material constitute criminal offences under Directive 2011/93/EU, it is necessary to exempt providers of relevant information society services from criminal liability when they are involved in such activities, including when carrying out voluntary own-initiative investigations, or taking other measures, insofar as their activities remain strictly limited to what is needed for the purpose of complying with their obligations under the Union law, including this Regulation and they act in good faith and in a diligent manner.

RemovedRecital 33 a (new): (33a) To prevent the dissemination of the known child sexual abuse material to users in the Union, online search engines and any other artificial intelligence systems should be subject to delisting orders. Coordinating Authorities should have the power to issue a delisting order addressed to the provider of online search engines or any other artificial intelligence systems under the jurisdiction of the Member State that designated them to take reasonable measures to delist a particular resource or resources indicating specific items of known child sexual abuse material.

AddedRecital 35: (35) Each act of dissemination of child sexual abuse material, including the non-consensual dissemination of self-generated material, is a criminal offence that affects the rights of the victims depicted, of whom the vast majority are girls. Repeated dissemination of child sexual abuse material constitutes a form of revictimization which could cause long-lasting negative consequences on the victim, and may reach extreme level in cases of so-called ‘highly traded’ material. Victims or their parents and guardians or legal representatives acting on their behalf should therefore have the right to obtain, upon request, from the EU Centre yet via the Coordinating Authorities, relevant information if known child sexual abuse material depicting them is reported by providers of hosting services or providers of publicly available number-independent interpersonal communications services in accordance with this Regulation. In dealing with such requests from cases of highly traded child sexual abuse material, particular care should be taken by the EU Centre and Coordinating Authorities to ensure the safeguarding of the victims concerned. For that purpose, staff dealing with such cases shall be specifically trained to interact with victims of serious abuse. / This information should be provided, within a reasonable period of time, in the language indicated by the victim, in a confidential, age-appropriate, accessible, understandable and gender-sensitive manner and tailored to the specific …

RemovedRecital 35: (35) Each act of dissemination of child sexual abuse material is a criminal offence that affects the rights of the victims depicted. Repeated dissemination of child sexual abuse material constitutes a form of revictimisation and may reach extreme level in cases of so-called 'highly traded' material. Victims should have the right to obtain, upon request, from the EU Centre yet via the Coordinating Authorities, relevant information if known child sexual abuse material depicting them is reported by providers of hosting services or providers of publicly available interpersonal communications services in accordance with this Regulation. In dealing with such requests from cases of highly traded child sexual abuse material, particular care should be taken by the EU Centre and Coordinating Authorities to ensure the safeguarding of the victims concerned.

AddedRecital 36: (36) Given the impact on the rights of victims depicted in such known child sexual abuse material and the typical ability of providers of hosting services to limit that impact by helping ensure that the material is no longer available on their services, those providers should assist victims or their parents and guardians or legal representatives who request the removal or disabling of access of the material in question in a timely manner, in order to minimise the impact that such offences have on the physical and mental health of the victim. That assistance should remain limited to what can reasonably be asked from the provider concerned under the given circumstances, having regard to factors such as the content and scope of the request, the steps needed to locate the items of known child sexual abuse material concerned and the means available to the provider. The assistance could consist, for example, of helping to locate the items, carrying out checks and removing or disabling access to the items. Considering that carrying out the activities needed to obtain such removal or disabling of access can be painful or even traumatic as well as complex, victims should also have the right to be assisted and receive adequate support by specifically trained staff of the EU Centre in this regard, via the Coordinating Authorities.

Show 4 more lines

RemovedRecital 36: (36) Given the impact on the rights of victims depicted in such known child sexual abuse material and the typical ability of providers of hosting services to limit that impact by helping ensure that the material is no longer available on their services, those providers should assist victims who request the removal or disabling of access of the material in question. Parents or guardians should have equal legal standing to exercise victim's rights when the victim is not able to do so due to age or other limitations. That assistance should remain limited to what can reasonably be asked from the provider concerned under the given circumstances, having regard to factors such as the content and scope of the request, the steps needed to locate the items of known child sexual abuse material concerned and the means available to the provider. The assistance could consist, for example, of helping to locate the items, carrying out checks and removing or disabling access to the items. Considering that carrying out the activities needed to obtain such removal or disabling of access can be painful or even traumatic as well as complex, victims should also have the right to be assisted by the EU Centre in this regard, via the Coordinating Authorities.

AddedRecital 37: (37) To ensure the efficient management of such victim support functions, victims should be informed about the existence of such functions and be allowed to contact and rely on the Coordinating Authority that is most accessible to them, which should channel all communications between victims and the EU Centre.

RemovedRecital 38: (38) For the purpose of facilitating the exercise of the victims’ right to information and of assistance and support for removal or disabling of access, victims should be allowed to indicate the relevant item or items of child sexual abuse material in respect of which they are seeking to obtain information or removal or disabling of access either by means of providing the image or images or the video or videos themselves, or by means of providing the Uniform Resource Identifiers leading to the specific item or items of child sexual abuse material, or by means of any other representation allowing for the unequivocal identification of the item or items in question.

AddedRecital 38 a (new): (38a) The Union budget should provide complementary funding to ensure a high level of support and protection for victims, including through sufficient resources in dedicated funding programmes, and through the promotion of innovative solutions to improve the quality and accessibility of the needed services. The relevant programmes under the next Multiannual Financial Framework should contain sufficient financial and human resources to ensure sufficient funding for an adequate Union contribution to the proper implementation.

Change 11

ChangedRecital 42: (42) Where relevant and convenient, subject to the choice of the provider of relevant information society services and the need to meet the applicable legal requirements in this respect, it should be possible for those providers to designate a single point of contact and a single legal representative for the purposes of Regulation (EU) 2022/20652022/2065, and this Regulation.

Change 12

RemovedRecital 48: (48) Given the need to ensure the effectiveness of the obligations imposed, Coordinating Authorities should be granted enforcement powers to address infringements of this Regulation. These powers should include the power to request the competent judicial authority or independent administrative authority of the Member State that designated them to temporarily restrict access of users of the service concerned by the infringement or, only where that is not technically feasible, to the online interface of the provider on which the infringement takes place. In light of the high level of interference with the rights of the users and the service providers that such a power entails, the latter should only be exercised when certain conditions are met. Those conditions should include the condition that the infringement results in the regular and structural facilitation of child sexual abuse offences, which should be understood as referring to a situation in which it is apparent from all available evidence that such facilitation has occurred on a large scale and over an extended period of time.

AddedRecital 44: (44) In order to provide clarity and enable effective, efficient and consistent coordination and cooperation both at national and at Union level, where a Member State designates more than one competent authority to apply and enforce this Regulation, it should designate one lead authority as the Coordinating Authority, whilst the designated authority should automatically be considered the Coordinating Authority where a Member State designates only one authority. For those reasons, the Coordinating Authority should act as the single contact point with regard to all matters related to the application of this Regulation, including issues related to prevention and combating child sexual abuse and assistance to victims, without prejudice to the enforcement powers of other national authorities.

RemovedRecital 49: (49) In order to verify that the rules of this Regulation, in particular those on mitigation measures and on the execution of voluntary detection orders, detection, removal, blocking or delisting orders that it issued, are effectively complied in practice, each Coordinating Authority should be able to carry out searches, using the relevant indicators provided by the EU Centre, to detect the dissemination of known or new child sexual abuse material through publicly available material in the hosting services of the providers concerned.

AddedRecital 47: (47) The Coordinating Authority, as well as other competent authorities, play a crucial role in ensuring the effectiveness of the rights and obligations laid down in this Regulation and the achievement of its objectives. Accordingly, it is necessary to ensure that those authorities have not only the necessary investigatory and enforcement powers, but also all necessary resources, including sufficient financial, human, technological and other resources to adequately carry out their tasks under this Regulation. In particular, given the variety of providers of relevant information society services and their use of advanced technology in offering their services, it is essential that the Coordinating Authority, as well as other competent authorities, are equipped with the necessary number of staff, including experts with specialised skills. The resources of Coordinating Authorities should be determined taking into account the size, complexity and potential societal impact of the providers of relevant information society services under the jurisdiction of the designating Member State, as well as the reach of their services across the Union.

Change 13

ChangedRecital 53:48: (53)(48) MemberGiven Statesthe shouldneed ensureto thatensure forthe infringementseffectiveness of the obligations laidimposed, downCoordinating inAuthorities thisshould Regulationbe theregranted areenforcement penaltiespowers whichto canaddress beinfringements of anthis administrativeRegulation. orThese penalpowers nature,should asinclude wellthe as,power whereto appropriate,request finingthe guidelinescompetent judicial authority of the Member State that aredesignated effective,them proportionateto andtemporarily dissuasive,restrict takingaccess intoof accountusers elementsof suchthe asservice concerned by the nature,infringement gravity,or, recurrenceonly andwhere durationthat ofis thenot infringement,technically infeasible, viewto the online interface of the publicprovider intereston pursued,which the scopeinfringement andtakes kindplace. In light of activitiesthe carriedhigh out,level asof wellinterference aswith the economic capacityrights of the providerusers and of relevantthe informationservice societyproviders servicesthat concerned.such Particularlya severepower penaltiesentails, the latter should only be imposedexercised onwhen thecertain providersconditions ofare relevantmet. informationThose societyconditions servicesshould ininclude the eventcondition that thosethe serviceinfringement providersresults systematicallyin orthe persistentlyregular failand tostructural complyfacilitation withof thechild obligationssexual setabuse outoffences, inwhich thisshould Regulation.be Memberunderstood Statesas shouldreferring ensureto thata thosesituation penaltiesin dowhich notit encourageis theapparent overfrom reportingall oravailable theevidence removalthat ofsuch materialfacilitation whichhas doesoccurred noton constitutea childlarge sexualscale abuseand material.over an extended period of time.

Change 14

AddedRecital 49: (49) In order to verify that the rules of this Regulation, in particular those on mitigation measures and on the execution of detection orders, removal, blocking orders that it issued, are effectively complied in practice, each Coordinating Authority should be able to carry out searches, using the relevant indicators provided by the EU Centre, to detect the dissemination of known or new child sexual abuse material through publicly available material in the hosting services of the providers concerned.

AddedRecital 50: (50) With a view to ensuring that providers of hosting services are aware of the misuse made of their services and to afford them an opportunity to take expeditious action to remove or disable access, Coordinating Authorities of establishment should be able to notify those providers of the presence of known child sexual abuse material on their services and requesting removal or disabling of access thereof. Such notifying activities should be clearly distinguished from the Coordinating Authorities’ powers under this Regulation to request the competent judicial authority of the Member State that designated them the issuance of removal orders.

AddedRecital 53: (53) Member States should ensure that for infringements of the obligations laid down in this Regulation there are penalties which can be of an administrative or criminal nature, as well as, where appropriate, fining guidelines, that are effective, proportionate and dissuasive, taking into account elements such as the nature, gravity, recurrence and duration of the infringement, in view of the public interest pursued, the scope and kind of activities carried out, as well as the economic capacity of the provider of relevant information society services concerned. Particularly severe penalties should be imposed in the event that the provider of relevant information society services in the event that those service providers concerned systematically or persistently fail to comply with the obligations set out in this Regulation. Member States should ensure that those penalties do not encourage the over reporting or the removal of material which does not constitute child sexual abuse material.

AddedRecital 55: (55) It is essential for the proper functioning of the system of mandatory detection and blocking of online child sexual abuse set up by this Regulation that the EU Centre receives, via the Coordinating Authorities, material identified as constituting child sexual abuse material or transcripts of conversations identified as constituting the solicitation of children, such as may have been found for example during criminal investigations, so that that material or conversations can serve as an accurate and reliable basis for the EU Centre to generate indicators of such abuses. In order to achieve that result, the identification should be made after a diligent assessment, conducted in the context of a procedure that guarantees a fair and objective outcome, either by the Coordinating Authorities themselves or by a court or another independent administrative authority than the Coordinating Authority which must be subject to judicial validation. Whilst the swift assessment, identification and submission of such material is important also in other contexts, it is crucial in connection to new child sexual abuse material and the solicitation of children reported under this Regulation, considering that this material can lead to the identification of ongoing or imminent abuse and the rescuing of victims. Therefore, specific time limits should be set in connection to such reporting.

AddedRecital 58: (58) In particular, in order to facilitate the cooperation needed for the proper functioning of the mechanisms set up by this Regulation, the EU Centre should establish and maintain the necessary secure information-sharing systems, such as, once available, the software provided by eu-LISA pursuant to Regulation1a (EU) 2023/969. When establishing and maintaining such systems, the EU Centre should cooperate with the European Union Agency for Law Enforcement Cooperation (‘Europol’) and national authorities to build on existing systems and best practices, where relevant. / 1a Regulation (EU) 2023/969 establishing a collaboration platform to support the functioning of joint investigation teams and amending Regulation (EU) 2018/1726

AddedRecital 59: (59) To support the implementation of this Regulation and contribute to the achievement of its objectives, the EU Centre should serve as a central facilitator, carrying out a range of specific tasks. The performance of those tasks requires strong guarantees of independence, in particular from law enforcement authorities, a governance structure ensuring the effective, efficient and coherent performance of its different tasks, legal personality to be able to interact effectively with all relevant stakeholders and an autonomous budget. Therefore, it should be established as a decentralised Union agency, and provided with the necessary human and financial resources to fulfil the objectives, tasks and responsibilities assigned to it under this Regulation, including expenditure related to the making available of technologies and the costs related to the analysis of data samples undertaken for micro, small and medium enterprises. It should be mainly financed by a contribution from the general budget of the Union, with the necessary appropriations drawn exclusively from unallocated margins under the relevant heading of the Multiannual Financial Framework and/or through the mobilisation of the relevant special instruments. In order to ensure that the Agency can respond flexibly to human resource needs, it is in particular appropriate that it has autonomy regarding the recruitment of contract agents.

Show 7 more lines

AddedRecital 59 a (new): (59a) Taking into consideration the central role of the EU Centre in the implementation of the Regulation and in view of the date of expiry of the interim Regulation on 3 August 2024, the EU Centre activities should start as soon as possible. The Commission should allocate an adequate level of resources for the quick establishment and initial operation of the EU Centre and provide commensurate assistance, including by seconding staff, to help the EU Centre reaching cruising speed in due time and no later than three years after the adoption of this Regulation.

AddedRecital 59 b (new): (59b) The arrangements concerning the seat of the EU Centre should be laid down in a headquarters agreement between the EU Centre and the host Member State. The headquarters agreement should stipulate the conditions of establishment of the seat and the advantages conferred by the Member State on the EU Centre and its staff. In line with point 9 of the Common Approach of 19 July 2012 on the location of the seats of decentralized agencies, the EU Centre should conclude a headquarters agreement with the host Member State in a timely manner before it starts its operational phase. In light of the case-law of the Court of Justice, the choice of the location of the seat should be made in accordance with the ordinary legislative procedure and should comply with the criteria laid down in this Regulation.

AddedRecital 59 c (new): (59c) The selection procedure for the location of the seat of the EU Centre should respect the following steps: (i) Parliament’s mandate for the interinstitutional negotiations would provide criteria for the selection of the host city; (ii) Parliament would negotiate those criteria with the Council; (iii) such criteria would constitute the basis for an inter-institutional call for applications made together by Parliament and Council; (iv) the candidates would be invited to joint hearings among Parliament and Council; (v) Parliament’s negotiating team would draw a short-list of candidates; (vi) such short-list would be negotiated against the Council’s short-list; (vii) before an agreement among co-legislators on the host city is reached; (viii) and before the plenary approves the outcome of the interinstitutional negotiations.

AddedRecital 60: (60) In the interest of legal certainty and effectiveness, the tasks of the EU Centre should be listed in a clear and comprehensive manner. With a view to ensuring the proper implementation of this Regulation, those tasks should relate in particular to the facilitation of the detection, reporting and blocking obligations imposed on providers of hosting services, providers of publicly available number-independent interpersonal communications services and providers of internet access services, The EU Centre should also be charged with certain other tasks, notably those relating to the implementation of the risk assessment and mitigation obligations of providers of relevant information society services, the removal of or disabling of access to child sexual abuse material by providers of hosting services, the provision of assistance to Coordinating Authorities, as well as proactively and on its own initiative conduct searches on publicly accessible content on hosting services for known child sexual abuse material. The EU Centre should facilitate the generation and sharing of knowledge, best practices and expertise related to online child sexual abuse, supporting the development of awareness-raising and prevention campaigns, educational and intervention programs, tools and materials in order to increase digital skills, while integrating a child rights perspective and ensuring a gender-sensitive and age-appropriate approach. The EU Centre should promote and ensure the appropriate s…

AddedRecital 61: (61) The EU Centre should provide reliable information on which activities can reasonably be considered to constitute online child sexual abuse, so as to enable the detection and blocking thereof in accordance with this Regulation. Given the nature of child sexual abuse material, that reliable information needs to be provided without sharing the material itself. Therefore, the EU Centre should generate accurate and reliable hashes and indicators, based on identified child sexual abuse material and solicitation of children submitted to it by Coordinating Authorities in accordance with the relevant provisions of this Regulation. These indicators should allow technologies to detect the dissemination of either the same material (known material) or of different child sexual abuse material (new material), or the solicitation of children, as applicable.

AddedRecital 62: (62) For the system established by this Regulation to function properly, the EU Centre should be charged with creating databases for known child sexual abuse material, new child sexual abuse material and solicitation of children and with maintaining, timely updating and operating those databases. For accountability purposes and to allow for corrections where needed, it should keep records of the submissions and the process used for the generation of the indicators.

AddedRecital 63: (63) For the purpose of ensuring the traceability of the reporting process and of any follow-up activity undertaken based on reporting, as well as of allowing for the provision of feedback on reporting to providers of hosting services and providers of publicly available number-independent interpersonal communications services, generating statistics concerning reports and the reliable and swift management and processing of reports, the EU Centre should create a dedicated database of such reports. To be able to fulfil the above purposes, that database should also contain relevant information relating to those reports, such as the indicators representing the material and ancillary tags, which can indicate, for example, the fact that a reported image or video is part of a series of images and videos depicting the same victim or victims.

Change 15

ChangedRecital 65: (65) In order to avoid erroneous reporting of online child sexual abuse under this Regulation and to allow law enforcement authorities to focus on their core investigatory tasks, reports should pass through the EU Centre and those reportsreport should be thoroughly assessed in a timely manner to ensure that a decision on the criminal relevance of the reported material is made as early as possible and to limit the retention of irrelevant data as far as possible. ReportsReport willshould be considered manifestly unfounded, where it is immediately evident, without any substantive legal or factual analysis, that the reported activities do not constitute online child sexual abuse. In those cases,cases the EU Centre should provide feedback to the reporting provider of hosting services or provider of publicly available number-independent interpersonal communications services in order to allow for improvements in the technologies and processes used and for other appropriate steps, such as reinstating material wrongly removed. Where the EU Centre considers that a report is not manifestly unfounded, it should forward the report to the competent law enforcement authority or authorities of the Member State likely to have jurisdiction to investigate or prosecute the potential child sexual abuse to which the report relates or to Europol in those cases where that competent law enforcement authority or those competent law enforcement authorities cannot be determined with sufficient certainty. Even in cases where the competent national law enfo…enforcement authority has been identified, the EU Centre sho…

Change 16

RemovedRecital 68: (68) Processing and storing certain personal data is necessary for the performance of the EU Centre’s tasks under this Regulation. In order to ensure that such personal data is adequately protected, the EU Centre should only process and store personal data if strictly necessary for the purposes detailed in this Regulation. It should do so in a secure and supervised manner and limit storage to what is strictly necessary for the performance of the relevant tasks and for a maximum retention period of 24 months.

AddedRecital 66: (66) With a view to contributing to the effective application of this Regulation and the protection of victims’ rights, the EU Centre should be able, upon request, to support victims and to assist Competent Authorities by conducting searches of hosting services for the dissemination of known child sexual abuse material that is publicly accessible, using the corresponding indicators. Where it identifies such material after having conducted such a search, the EU Centre should also be able to request the provider of the hosting service concerned to remove or disable access to the item or items in question, as soon as possible, given that the provider may not be aware of their presence and may be willing to do so on a voluntary basis. The EU Centre should be able to proactively, on its own initiative, analyse publicly accessible content for known child sexual abuse and to follow publicly accessible uniform resource locators.

RemovedRecital 70: (70) Longstanding Union support for both INHOPE and its member hotlines recognises that hotlines are in the frontline in the fight against online child sexual abuse. The EU Centre should leverage the network of hotlines, conclude, when necessary, memoranda of understanding with them, and encourage that they cooperate and coordinate effectively with the Coordinating Authorities, providers of relevant information society services and law enforcement authorities of the Member States. The hotlines’ expertise and experience is an invaluable source of information on the early identification of common threats and solutions, as well as on regional and national differences across the Union.

AddedRecital 67: (67) Given its central position resulting from the performance of its primary tasks under this Regulation and the information and expertise it can gather in connection thereto, the EU Centre should also contribute to the achievement of the objectives of this Regulation by serving as a hub for knowledge, for best practices, expertise and research on matters related to the prevention and combating of online child sexual abuse. In this connection, the EU Centre should cooperate with relevant stakeholders from both within and outside the Union and allow Member States to benefit from the knowledge and expertise gathered, including best practices and lessons learned. Where the EU Centre makes technologies available for providers of hosting services and providers of number-independent communication services to install and operate in order to execute detection orders, it should also make publicly available relevant information, such as the detailed licensing conditions, including licensing fees, under which the EU Centre is permitted, or has obtained permission to make such technologies available. Such information should cover all details regarding the procurement of such technologies, as well as their development over time, where relevant.

RemovedRecital 71: (71) Considering Europol’s mandate and its experience in identifying competent national authorities in unclear situation and its database of criminal intelligence which can contribute to identifying links to investigations in other Member States, the EU Centre should cooperate closely with it, especially in order to ensure the swift identification of competent national law enforcement authorities in cases where that is not clear or where more than one Member State may be affected. The EU Centre, while being an independent entity, should maximise efficiency by sharing, where possible, support functions with Europol and information technology (IT) services.

AddedRecital 68: (68) Processing and storing certain personal data is necessary for the performance of the EU Centre’s tasks under this Regulation. In order to ensure that such personal data is adequately protected, the EU Centre should only process and store personal data if strictly necessary for the purposes detailed in this Regulation. It should do so in a secure and supervised manner and limit storage to what is strictly necessary for the performance of the relevant tasks.

Show 10 more lines

RemovedRecital 72: (72) The arrangements concerning the seat of the EU Centre should be laid down in a headquarters agreement between the EU Centre and the host Member State. The headquarters agreement should stipulate the conditions of establishment of the seat and the advantages conferred by the Member State on the EU Centre and its staff. In line with point 9 of the Common Approach of 19 July 2012 on the location of the seats of decentralised agencies, the EU Centre should conclude a headquarters agreement with the host Member State in a timely manner before it starts its operational phase. In light of the case-law of the Court of Justice, the choice of the location of the seat should be made in accordance with the ordinary legislative procedure and should comply with the criteria laid down in this Regulation.

AddedRecital 69: (69) In order to allow for the effective and efficient performance of its tasks, the EU Centre should closely cooperate with Coordinating Authorities, the Europol and relevant partner organisations, such as the US National Centre for Missing and Exploited Children or the International Association of Internet Hotlines (‘INHOPE’) network of hotlines for reporting child sexual abuse material, within the limits sets by this Regulation and other legal instruments regulating their respective activities. To facilitate such cooperation, the necessary arrangements should be made, including the designation of contact officers by Coordinating Authorities and the conclusion of publicly accessible memoranda of understanding with Europol and, where appropriate, with one or more of the relevant partner organisations.

RemovedRecital 74 a (new): (74a) One of the pillars of this Regulation is the assistance and support of victims of child sexual abuse. In order to better understand and address victims’ individual needs is essential to create a forum where victims’ organisations are heard and the EU Centre can learn from their experience, expertise and knowledge. The Victims' Consultative Forum will play a key role in advising the EU Centre in its approach to all victim-related issues.

AddedRecital 70: (70) Hotlines play a very important role in the fight against child sexual abuse online, namely with regard to the reporting, detection and rapid removal of child sexual abuse material. Helplines are also essential in providing support for children in need. Longstanding Union support for both INHOPE and its member hotlines recognises that hotlines are in the frontline in the fight against online child sexual abuse. The EU Centre should leverage the network of hotlines and encourage that they cooperate and coordinate effectively with the Coordinating Authorities, providers of relevant information society services and law enforcement authorities of the Member States. The hotlines’ expertise and experience is an invaluable source of information on the early identification of common threats and solutions, as well as on regional and national differences across the Union.

AddedRecital 72: deleted

AddedRecital 74: (74) In view of the need for technical expertise in order to perform its tasks, in particular the task of providing a list of technologies that can be used for detection, the EU Centre should have a Technology Committee composed of experts with advisory function. The Technology Committee may, in particular, provide expertise to support the work of the EU Centre, within the scope of its mandate, with respect to matters related to detection and prevention of online child sexual abuse, to support the EU Centre in contributing to a high level of technical standards, data protection and safeguards in detection technology.

AddedRecital 74 a (new): (74a) One of the pillars of this Regulation is the assistance and support of victims and survivors of child sexual abuse. In order to better understand and address victims’ individual needs is essential to create a forum where victims’ organizations are heard and the EU Center can learn from their experience, expertise and knowledge. The Victims’ Rights and Survivors Consultative Forum should play a key role in advising the EU Center in its approach to all victim-related issues. Its member should be appointed mainly among victims or their parents, guardians or legal representatives, as well as from representatives of organisations acting in the public interest against child sexual abuse and promoting victims’ and survivors’ rights, but could also include members from other organisations such as organisations promoting rights of children belonging to vulnerable groups, organisations promoting children's rights which includes children’s digital rights.

AddedRecital 75: (75) In the interest of transparency and accountability and to enable evaluation and, where necessary, adjustments, providers of hosting services, providers of publicly available number independent interpersonal communications services and providers of internet access services, Coordinating Authorities and the EU Centre should be required to collect, record and analyse gender- and age-disaggregated data and information, based on anonymised gathering of non-personal data and to publish in a machine-readable format annual reports on their activities under this Regulation. The Coordinating Authorities should cooperate with Europol and with law enforcement authorities and other relevant national authorities of the Member State that designated the Coordinating Authority in question in gathering that information.

AddedRecital 78: (78) Regulation (EU) 2021/1232 of the European Parliament and of the Council45 provides for a temporary solution in respect of the voluntary use of technologies by certain providers of publicly available interpersonal communications services for the purpose of combating online child sexual abuse. This Regulation, which provides for a clear and uniform long-term legal framework and establishes a mandatory regime for certain providers, should substitute the temporary and voluntary one. However, until the date of effective application of this Regulation and in order to secure that online child sexual abuse online can be effectively and lawfully combated without interruptions and that there is a smooth transition between the voluntary and the mandatory regime, Regulation (EU) 2021/1232 shall apply for a limited period of 9 months after the entry into force of this Regulation.

AddedRecital 82: (82) In order to allow all affected parties sufficient time to take the necessary measures to comply with this Regulation, and in particular the establishment of the EU Centre, provision should be made for an appropriate time period between the date of its entry into force and that of its application.

Change 17

RemovedArticle 1 – paragraph 1 – subparagraph 2 – point d a (new): (da) obligations on providers of online search engines and any other artificial intelligence systems to delist or disable specific items of child sexual abuse, or both;

AddedArticle 1 – paragraph 1 – subparagraph 1: This Regulation lays down uniform rules to address the misuse of relevant information society services for online child sexual abuse, in order to contribute to the proper functioning of the internal market and to create a safe, predictable and trusted online environment that facilitates innovation and in which fundamental rights enshrined in the Charter are effectively protected;

Change 18

ChangedArticle 1 – paragraph 31 – subparagraph 2 – point b: (b) Directiveobligations 2000/31/ECon providers of hosting services and Regulationproviders (EU)of 2022/2065;number-independent interpersonal communication services to detect and report online child sexual abuse;

Change 19

ChangedArticle 1 – paragraph 31 – subparagraph 2 – point d a (new): (da) Regulation(d (EU)a) .../...obligations on Artificialproviders Intelligenceof (Artificialonline Intelligencegames; Act).and

Change 20

AddedArticle 1 – paragraph 1 – subparagraph 2 – point e: (e) rules on the implementation and enforcement of this Regulation, including as regards the designation and functioning of the competent authorities of the Member States;

AddedArticle 1 – paragraph 1 – subparagraph 2 – point e a (new): (ea) rules on the establishment, functioning, cooperation, transparency and powers of the EU Centre For Child Protection on Child Sexual Abuse established in Article 40 (‘EU Centre’);

AddedArticle 1 – paragraph 2 a (new): 2a. This Regulation shall not apply to audio communications.

AddedArticle 1 – paragraph 3 – point b: (b) Directive 2000/31/EC and Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) and amending Directive 2000/31/EC];

AddedArticle 1 – paragraph 3 – point d a (new): (da) Directive (EU) 2022/2555 of the European Parliament and the Council of 14 December 2022 on measures for high common level of cybercecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 (NIS 2 Directive); and

AddedArticle 1 – paragraph 3 – point d b (new): (db) Regulation (EU) .../... on Artificial Intelligence (Artificial Intelligence Act);

Show 3 more lines

AddedArticle 1 – paragraph 3 a (new): 3a. Nothing in this Regulation shall be interpreted as prohibiting, weakening or undermining end-to-end encryption. Providers shall not in particular be prohibited to offer end-to-end encrypted services.

AddedArticle 1 – paragraph 3 b (new): 3b. Nothing in this Regulation shall undermine the prohibition of general monitoring under Union law or introduce general data retention obligations, or be interpreted in that way.

AddedArticle 1 – paragraph 4: 4. This Regulation limits the exercise of the rights and obligations provided for in 5(1) and (3) and Article 6(1) of Directive 2002/58/EC with the sole objective of enabling relevant information society services to use specific technologies for the processing of personal and other data to the extent strictly necessary to detect and report online child sexual abuse and remove child sexual abuse material from their services for the execution of the detection orders issued in accordance with Section 2 of Chapter 1 of this Regulation.

Change 21

ChangedArticle 2 – paragraph 1 – point c:b (c)a ‘software(new): application’(ba) means‘number-independent ainterpersonal digitalcommunications productservice’ ormeans an interpersonal communications service as defined in Article 2,(2), point 15,(7) of RegulationDirective (EU) 2022/1925;2018/1972;

Change 22

ChangedArticle 2 – paragraph 1 – point d:b (d)b ‘software(new): application(bb) store’‘number-independent meansinterpersonal acommunications service aswithin games’ means any service defined in Article 2,(2), point 14,(7) of RegulationDirective (EU) 2022/1925 [on contestable and fair markets in2018/1972 thewhich digitalis sectorpart (Digitalof Marketsa Act)];game;

Change 23

ChangedArticle 2 – paragraph 1 – point e ac: (new):(c) (ea)‘software “onlineapplication’ searchmeans engine”a meansdigital anproduct intermediaryor service as defined in Article 3,(2), point (j),(15), of Regulation (EU) 2022/2065;2022/1925;

Change 24

ChangedArticle 2 – paragraph 1 – point e bd: (new):(d) (eb)‘software ‘intermediaryapplication service’store’ means a service as defined in Article 3,(2), point (g),(14), of Regulation (EU) 2022/2065;2022/1925;

Change 25

RemovedArticle 2 – paragraph 1 – point e c (new): (ec) ‘artificial intelligence system’ (AI system) means software as defined in Article 3(1) of Regulation (EU) .../... on Artificial Intelligence (Artificial Intelligence Act);

AddedArticle 2 – paragraph 1 – point f – point ii: (ii) a number-independent interpersonal communications service;

Change 26

ChangedArticle 2 – paragraph 1 – point f – point iv a (new): (iv(iva) a)a annumber-independent onlineinterpersonal searchcommunication engine;service within online games.

Change 27

RemovedArticle 2 – paragraph 1 – point f – point iv b (new): (iv b) an artificial intelligence system.

Change 28

RemovedA “child user” is a “child” as defined in point (i) and a “user” as defined in point (h) thus this would be redundant.

Change 29

ChangedArticle 2 – paragraph 1 – point q a (new): (qa) ‘victim’ means: / Person residing in'victim' themeans Europeana Unionperson who being under 18 suffered child sexual abuse offences. For the purpose of exercising the victim’soffences rightsor/and recognisedwhose inchild thissexual Regulation,abuse parentsmaterial andis guardianshosted areor todisseminated bein consideredthe victims.Union;

Change 30

ChangedArticle 2 – paragraph 1 – point r: (r) ‘recommender system’ means the system as defined in Article 3,2, point (s),(o), of Regulation (EU) 2022/2065;

Change 31

ChangedArticle 2 – paragraph 1 – point t:s: (t)(s) ‘content moderation’data’ means the activities as defined in Article 3, point (t), oftexts, Regulationvideos (EU)and 2022/2065;images;

Change 32

ChangedArticle 2 – paragraph 1 – point v: (v)t: ‘terms(t) and‘content conditions’moderation’ means terms andthe conditionsactivities as defined in Article 3,2, point (u),(t), of Regulation (EU) 2022/2065;

Change 33

RemovedArticle 2 – paragraph 1 – point w a (new): (wa) ‘metadata‘ means data processed for the purposes of transmitting, distributing or exchanging content data; including data used to trace and identify the source and destination of a communication, data on the location and the date, time, duration and the type of communication;

AddedArticle 2 – paragraph 1 – point v: (v) ‘terms and conditions’ means terms and conditions as defined in Article 2, point (u), of Regulation (EU) 2022/2065;

Change 34

ChangedArticle 2 – paragraph 1 – point w ba (new): (wb)(wa) ‘hotline’ means an organisation officially recognised by its Member State of establishment that provides a mechanism, other than the reporting channels provided by law enforcement authorities, for receiving anonymous complaints from victims and the public about alleged online child sexual abuse online.abuse;

Change 35

RemovedArticle 3 – paragraph 1: 1. Providers of hosting services and providers of interpersonal communications services shall identify, analyse and assess, for each such service that they offer, the risk of use of the service for the purpose of online child sexual abuse. To that end, providers subject to an obligation to conduct a risk assessment under Regulation (EU) 2022/2065 may draw on that risk assessment and complement it with a more specific assessment of the risks of use of their services for the purpose of online child sexual abuse.

AddedArticle 2 – paragraph 1 – point w b (new): (wb) “help-line” means an organisation that provides services for children in need officially recognised by its Member State of establishment;

RemovedArticle 3 – paragraph 2 – point b – indent 3: — functionalities enabling age assurance and age scoring, without prejudice to other mechanisms that enable age-verification, with particular consideration to the impacts of such measures on fundamental rights;

AddedArticle 3 – paragraph 1: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall identify, analyse and assess for each such service that they offer, the significant risk stemming, inter alia, from the design, functioning and use of their services for the purpose of online child sexual abuse. That risk assessment shall be specific to the services they offer and proportionate to the risk considering its severity and probability. To that end, providers subject to an obligation to conduct a risk assessment under Regulation (EU) 2022/2065 may draw on that risk assessment and complement it with a more specific assessment of the risks of the use of their services for the purpose of online child sexual abuse.

RemovedArticle 3 – paragraph 2 – point b – indent 4: — functionalities enabling users to flag or notify online child sexual abuse to the provider through tools that are easily accessible and age-appropriate, including already available anonymous reporting channels as defined by Directive (EU) 2019/1937;

AddedArticle 3 – paragraph 1 a (new): 1a. Providers which are not substantially exposed to online child sexual abuse and which are not very large online platforms pursuant to Article 33 of Regulation (EU) 2022/2065 are exempted from these obligations provided for in this Article and Article 4. / A hosting service provider or a number-independent interpersonal communication service provider is substantially exposed to online child sexual abuse and therefore subject to the obligation to conduct a risk assessment in accordance with this Article: / (a) if it has received two removal orders in the previous 12 months; / (b) from the moment the provider becomes aware of any information indicating potential online child sexual abuse on its services and submits, in accordance with Article 12, a report to the EU Centre; or / (c) from the moment the provider is notified by the national competent authority or by the EU Centre, in accordance with Article 49, of the presence of one or more specific items of known child sexual abuse material on its services.

Show 4 more lines

RemovedArticle 3 – paragraph 2 – point b – indent 4a (new): — functionalities enabling age-appropriate parental controls;

AddedArticle 3 – paragraph 2 – point b – introductory part: (b) the existence and implementation by the provider of a policy and the availability and effectiveness of functionalities and protocols to prevent and address the risk referred to in paragraph 1, including through the following:

RemovedArticle 3 – paragraph 2 – point b – indent 4b (new): — functionalities enabling self-reporting.

AddedArticle 3 – paragraph 2 – point b – indent 2: – measures taken to enforce such prohibitions and restrictions and the amount of human and financial resources dedicated to address child sexual abuse material;

Change 36

ChangedArticle 3 – paragraph 2 – point b a (new): (ba)– theindent capacity,2 havinga regard(new): to– theinformation stateand ofawareness thecampaigns art,educating toand meaningfullywarning dealusers withof reportsthe andrisk notificationsof aboutonline child sexual abuse in a timely manner;abuse;

Change 37

ChangedArticle 3 – paragraph 2 – point c:b (c)– theindent manner3 ina which(new): users– usefunctionalities theenabling servicemeaningful and the negative impact thereofproportionate onage-appropriate thatparental risk;controls;

Change 38

RemovedArticle 3 – paragraph 2 – point d: (d) the manner in which the provider designed and operates the service, including the business model, governance, type of users targeted, and relevant systems and processes, and the negative impact thereof on that risk;

AddedArticle 3 – paragraph 2 – point b – indent 3 b (new): – functionalities, according to Article 12 (3), enabling users to flag or notify potential online child sexual abuse to the provider;

Change 39

ChangedArticle 3 – paragraph 2 – point eb – point i: (i)indent the3 extentc to(new): which– the servicecapacity isof usedthe orprovider, ishaving likelyregard to be used bythe childrenstate andof the extentart, to whichmeaningfully thedeal servicewith isthose targetingreports childand users;notifications in a timely manner;

Change 40

ChangedArticle 3 – paragraph 2 – point eb – pointindent iii3 d (new): – indentsystems 1and amechanisms (new):that —provide enablingchild- unsolicitedand contactuser-friendly forresources usersto and,ensure inthat particular,children forcan adultseek usershelp swiftly, including information on how to engagecontact andnational connecthotlines, withhelp-lines unknownor childnational users;law enforcement;

Change 41

ChangedArticle 3 – paragraph 2 – point e – point iiib – indent 2: — enabling users to establish contact with3 othere users(new): directly,– infunctionalities particularallowing onto servicesdetect directlysuspicious targetinglinks, childincluding usersthose orcoming throughfrom privatethe communications;darknet.

Change 42

RemovedArticle 3 – paragraph 2 – point e – point iii – indent 3: — enabling users to share content with other users, in particular through private communications.

AddedArticle 3 – paragraph 2 – point b – indent 4: deleted

RemovedArticle 3 – paragraph 2 – point e a (new): (ea) any other functionalities.

AddedArticle 3 – paragraph 2 – point d: (d) the manner in which the provider designed and operates the service, including the design of their recommender systems and any relevant algorithmic systems, the business model, governance, type of users targeted and relevant systems and processes, and the impact thereof on that risk;

RemovedArticle 3 – paragraph 2 a (new): 2a. The provider, where applicable, shall assess, in a separate section of its risk assessment, the voluntary use of specific technologies for the processing of personal and other data to the extent strictly necessary to detect, to report and to remove online child sexual abuse material from its services.

AddedArticle 3 – paragraph 2 – point e – point i: (i) the extent to which the service is used or is likely to be used by children and the extent to which the service is directly targeting children;

Show 50 more lines

RemovedArticle 3 – paragraph 3 – subparagraph 1: The provider may request the EU Centre to perform a test on data samples made available to the EU Centre to support the risk assessment. / Neither the request referred to in the first subparagraph or any subsequent analysis that the EU Centre may perform thereunder shall exempt the provider from carrying out its obligation to conduct the risk assessment in accordance with paragraphs 1 and 2 of this Article or to comply with any other obligation set out in this Regulation.

AddedArticle 3 – paragraph 2 – point e – point ii: (ii) where the service is used or is likely to be used by children or directly targeting children, the different age groups or likely age groups of children and the risk of solicitation of children in relation to those age groups;

RemovedArticle 3 – paragraph 3 – subparagraph 2: The costs incurred by the EU Centre for the performance of such an analysis shall be borne by the requesting provider. However, the EU Centre may bear those costs where the provider is a micro, small or medium-sized enterprise, provided the request is reasonably necessary to support the risk assessment.

AddedArticle 3 – paragraph 2 – point e – point iii – indent 1: – enabling users to search for other users, including through search engines external to the service and, in particular, for adult users to search for children;

RemovedArticle 3 – paragraph 4 – subparagraph 2 – point a: (a) for a service which is subject to a detection order issued in accordance with Article 7, the provider shall update the risk assessment at the latest four months before the expiry of the period of application of the detection order;

AddedArticle 3 – paragraph 2 – point e – point iii – indent 2: – enabling users to initiate unsolicited contact with other users, including children, directly, in particular through private communications;

RemovedArticle 4 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of interpersonal communications services shall put in place reasonable, proportionate, targeted and effective mitigation measures, tailored to their services and the risk identified pursuant to Article 3, with the aim of mitigating that risk. Such measures shall include some or all of the following:

AddedArticle 3 – paragraph 2 – point e – point iii – indent 3: – enabling users to share unsolicited with other users, in particular through private communications;

RemovedArticle 4 – paragraph 1 – point a: (a) adapting, through appropriate technical and operational measures and staffing, the provider’s content moderation or recommender systems, its decision-making processes, the operation or functionalities of the service, or the content or enforcement of its terms and conditions, including the speed, quality and effectiveness of processing notices and reports related to online child sexual abuse and, where appropriate, the expeditious removal of the content notified;

AddedArticle 3 – paragraph 2 – point e – point iii – indent 3 a (new): – Enabling users to indicate personal data in their usernames.

RemovedArticle 4 – paragraph 1 – point a a (new): (aa) adapting the design, features and functions of their services in order to ensure a high level of privacy, safety, and security by design and by default, in particular, for children;

AddedArticle 3 – paragraph 2 – point e a (new): (ea) When carrying out a risk assessment, the provider may take into account any other functionality in accordance with the state of the art to address child sexual abuse.

RemovedArticle 4 – paragraph 1 – point a b (new): (ab) enabling age-appropiate parental control tools;

AddedArticle 3 – paragraph 3 – subparagraph 1: The provider may request the EU Centre to perform an analysis of methodology for risk assessment, including, where appropriate, to perform a test on anonymized data samples made available to the EU Centre, to support the risk assessment.

RemovedArticle 4 – paragraph 1 – point c: (c) initiating or adjusting cooperation, in accordance with competition law, with other providers of hosting services or providers of interpersonal communication services, public authorities, hotlines, civil society organisations or, where applicable, entities awarded the status of trusted flaggers in accordance with Article 22 of Regulation (EU) 2022/2065 .

AddedArticle 3 – paragraph 3 – subparagraph 1 a (new): The provider may request the EU Centre to perform an analysis of methodology for risk assessment, including, where appropriate, to perform a test on anonymized data samples made available to the EU Centre, to support the risk assessment. / Neither the request referred to in the first subparagraph, nor the subsequent analysis that the EU Centre may perform thereunder, shall exempt the provider from its obligation to conduct the risk assessment in accordance with paragraphs 1 and 2 of this Article and to comply with any other obligations set out in this Regulation.

RemovedArticle 4 – paragraph 1 – point c a (new): (ca) reinforcing awareness-raising measures and adapting their online interface for increased user information, including child-appropriate information targeted to the risk identified;

AddedArticle 3 – paragraph 3 – subparagraph 2: The costs incurred by the EU Centre for the support of the risk assessment shall be borne by the requesting provider. However, the EU Centre may bear those costs where the provider is a micro, small or medium-sized enterprise. The EU Centre may reject the request where it is not reasonably necessary to support the risk assessment or does not comply with available budgetary resources. The EU Centre shall provide this support in a timely manner.

RemovedArticle 4 – paragraph 1 – point c b (new): (cb) enabling users to flag or notify online child sexual abuse to the provider through tools that are easily accessible and age-appropriate, including already anonymous reporting channels as defined by Directive (EU) 2019/1937;

AddedArticle 3 – paragraph 5: deleted

RemovedArticle 4 – paragraph 1 – point c c (new): (cc) enabling safe self-reporting capabilities;

AddedArticle 3 – paragraph 6: 6. The Commission in cooperation with Coordinating Authorities and the EU Centre, and after having consulted the European Data Protection Board and having conducted a public consultation, may issue guidelines on the application of paragraphs 1 to 5, having due regard in particular to relevant technological developments and to the manners in which the services covered by those provisions are offered and used.

RemovedArticle 4 – paragraph 1 – point c d (new): (cd) including clearly visible and identifiable age rating information;

AddedArticle 3 – paragraph 6 a (new): 6a. Providers that qualify as small and micro enterprises as defined in Commission Recommendation 2003/361/EC shall carry out a simplified risk assessment by [date of application of this Regulation + 6 months] or, where the provider did not offer the service in the Union by [date of application of this Regulation], by six months from the date at which the provider started offering the service in the Union. / The Commission shall be empowered to adopt delegated acts in accordance with Article 86 of this Regulation in order to provide practical support for micro and small enterprises for carrying out the simplified risk assessment

RemovedArticle 4 – paragraph 1 – point c e (new): (ce) developing awareness systems to alert the users of any potential infringement of this Regulation;

AddedArticle 3 – paragraph 6 b (new): 6b. Irrespective of their size or their substantial, exposure to online child sexual abuse, providers of online games that operate number-independent interpersonal communications service within their games, platforms primarily used for the dissemination of pornographic content and providers offering services directly targeting children shall carry out a risk assessment in accordance with Article 3(1) to (4).

RemovedArticle 4 – paragraph 1 – point c f (new): (cf) using any other measures in accordance with the current or future state of the art which are fit to mitigate the identified risk.

AddedArticle 4 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall put in place reasonable, proportionate, targeted and effective mitigation measures, tailored to their specific services and the risk identified pursuant to Article 3. The decision as to the choice of mitigation measures shall remain with the provider. Such measures shall include some or all of the following:

RemovedArticle 4 – paragraph 2 – point a: (a) effective in mitigating the identified risk, taking into account the characteristics of the service provided and the manner in which that service is used;

AddedArticle 4 – paragraph 1 – point a: (a) testing and adapting, through state of the art appropriate technical and operational measures and staffing, the provider’s content moderation or recommender systems, its decision-making processes, the operation or functionalities of the service, or the content or enforcement of its terms and conditions, including the speed, quality and effectiveness of processing notices and reports of alleged online child sexual abuse and, where appropriate, the expeditious removal of the child sexual abuse material;

RemovedArticle 4 – paragraph 2 – point b: (b) targeted and proportionate in relation to that risk, taking into account, in particular, the provider’s financial and technological capabilities and the number of users;

AddedArticle 4 – paragraph 1 – point a a (new): (aa) adapting the design, features and functions of their services in order to ensure the highest level of privacy, safety, and security by design and by default. / In particular, when the service is directly targeting children, providers shall include all of the following mitigation measures unless they are not technically feasible for the service: / i. limiting users, by default, to establish unsolicited contact with other users directly, in particular through private communications, by asking for user confirmation before allowing an unknown user to communicate and before displaying their communications; / ii. limiting users, by default, to directly share unsolicited content with other users directly, in particular through private communications; / iii. limiting users, by default, to directly share personal contact details with other users, such as phone numbers, home addresses and e-mail addresses, via pattern-based matching; / iv. providing meaningful and proportionate age-appropriate user-device-based parental control tools which allow parents or guardians to exercise appropriate control over children while respecting the fundamental rights and the confidentiality of communications of the child; / v. encouraging children, prior to registering for the service, to talk to consult their parents about how the service works and what parental controls tools are available; vi. providing readily accessible mechanisms for users to block or mute other users; / vii. providing human…

Removed"Seriousness" is an abstract and vague legal term. The risk has already been assessed and identified (risk assessment) by the providers.

AddedArticle 4 – paragraph 1 – point c: (c) initiating or adjusting cooperation, in accordance with competition law, with other providers of relevant information society services, public authorities, hotlines, helplines, civil society organisations or, where applicable, entities awarded the status of trusted flaggers in accordance with Article 22 of Regulation (EU) 2022/2065;

RemovedArticle 4 – paragraph 3: 3. Providers of interpersonal communications services that have identified, pursuant to the risk assessment conducted or updated in accordance with Article 3, a risk of use of their services for the purpose of the solicitation of children, shall take the necessary age assurance measures to reliably identify child users on their services, enabling them to take the mitigation measures.

AddedArticle 4 – paragraph 1 – point c a (new): (ca) informing and reminding users and non-users, such as parents, about the risks related to the use of their services, the nature of the service and the functionalities offered, what constitutes online child sexual abuse and what is typical offender behaviour;

RemovedArticle 4 – paragraph 4 a (new): 4a. On the basis of the separate risk assessment submitted in accordance zith Article 3 (2a), providers may request the Coordinating Authority of establishment to proceed in accordance with Article 5a based on the need of continuing, as part of their mitigation measures, to use specific technologies for the processing of personal and other data to the extent strictly necessary and proportionate to mitigate the risk of misuse of their services for the purpose of online child sexual abuse.

AddedArticle 4 – paragraph 1 – point c b (new): (cb) enabling users according to Article 12 to flag or notify potential online child sexual abuse to the provider;

RemovedArticle 5 – paragraph 1 – point b: (b) any mitigation measures both taken and requested pursuant to Article 4.

AddedArticle 4 – paragraph 1 – point c c (new): (cc) reinforcing awareness-raising measures and adapting their online interface for increased in order to give user and child-friendly information about the risk of online child sexual abuse on its services;

RemovedArticle 5 – paragraph 3 – subparagraph 1: Where necessary for that assessment, that Coordinating Authority may:

AddedArticle 4 – paragraph 1 – point c d (new): (cd) including clearly visible and identifiable information on the minimum age for using the service;

RemovedMoving Article 7.2 of the proposal here to reinforce the consultation and exchange of information between the provider and the coordinating authority prior to any decision pursuant to Article 7.

AddedArticle 4 – paragraph 1 – point c e (new): (ce) Setting up mechanisms to raise awareness among users of any potential infringement by them of this Regulation.

RemovedArticle 5 – paragraph 3 – subparagraph 1 – point a (new): (a) carry out the consultations with the provider that it may deem necessary to determine whether the requirements of Articles 3 and 4 have been met;

AddedArticle 4 – paragraph 2 – introductory part: 2. The mitigation measures shall meet all of the following requirements:

RemovedArticle 5 – paragraph 3 – subparagraph 1 – point b (new): (b) require further information and clarification from the provider within a reasonable time period set by that Coordinating Authority which shall not be longer than two weeks;

AddedArticle 4 – paragraph 2 – point a: (a) they shall be effective and proportionate in mitigating the identified risk, taking into account the characteristics of the service provided and the manner in which that service is used;

RemovedArticle 5 – paragraph 3 – subparagraph 1 – point c (new): (c) request the EU Centre, the competent data protection authorities, another public authority or relevant experts or entities to provide the necessary additional information.

AddedArticle 4 – paragraph 2 – point b: (b) they shall be targeted and proportionate in relation to that risk, the provider’s financial strength, technological and operational capabilities and the number of users and the amount of content that they provide;

Change 43

ChangedArticle 54 – paragraph 42 a– (new):point 4a.c: Where(c) thethey requirementsshall ofbe Articlesapplied 3in a diligent and 4non-discriminatory aremanner, met,having thedue Coordinatingregard, Authorityin shallall issuecircumstances, ato positivethe opinionwhichpotential shallconsequences beof takenthe intomitigation accountmeasures priorfor tothe anyexercise decisionof pursuantfundamental torights Articleof 7.all parties affected;

Change 44

RemovedArticle 5 – paragraph 5: 5. Providers shall, when transmitting the report in accordance with paragraph 1 or further information in accordance with paragraph 3 to the Coordinating Authority of establishment, transmit the report or further information also to the EU Centre.

AddedArticle 4 – paragraph 2 – point d: (d) they shall be introduced, reviewed in light of their effectiveness and adapted in accordance with the state of the art, discontinued or expanded, as appropriate, each time the risk assessment is conducted or updated pursuant to Article 3(4), as soon as possible and in any case within three months from the date referred to therein;

RemovedArticle 5 a (new): Article 5a / Voluntary detection order / 1. Following the request of the provider under Article 4(4a) the Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State to issue an order that authorizes the provider to maintain or implement mitigation measures that consist of using specific technologies for the processing of personal and other data to the extent strictly necessary to detect, report and remove online child sexual abuse on their services. / 2. Before submitting the request, that Coordinating Authority shall request and take into consideration the opinion of the competent data protection authority. / 3. Taking into account this opinion and the assessment submitted by the provider under Article 3(2a), the Coordinating Authority shall have the power to propose to the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State the terms of authorisation for the provider to take measures specified in Article 10 to detect online child sexual abuse on a specific service. / 4. The Coordinating Authority shall decide whether to proceed according to paragraph 3 no later than three months from the provider’s request.

AddedArticle 4 – paragraph 2 – point d a (new): (da) they shall respect the principles of data protection by design and by default, as well as of data minimisation; and

RemovedArticle 6 – paragraph 1 – point a: deleted

AddedArticle 4 – paragraph 2 – point d b (new): (db) they shall not restrict the possibility to use a service anonymously.

Change 45

ChangedArticle 64 – paragraph 1 – point3: b:3. (b)Providers takeof reasonableinterpersonal measurescommunications toservices preventthat childhave usersidentified, frompursuant accessingto the softwarerisk applicationsassessment inconducted relationor toupdated whichin theyaccordance havewith identifiedArticle a3, significanta risk of use of the servicetheir concernedservices for the purpose of the solicitation of children, may take the necessary and proportionate age verification measures to reliably identify children oron where:their services, enabling them to take the mitigation measures.

Change 46

RemovedArticle 6 – paragraph 1 – point b – point i (new): i) the developer of the software application has informed the software application store that its terms and conditions of use do not permit child users,

AddedArticle 4 – paragraph 3 a (new): 3a. When providers put forward age verification systems, they shall meet the following criteria: / (a) Protect the privacy of users and do not disclose or process data gathered for the purposes of age verification for any other purpose; / (b) Not collect any data other than the age of the user for the purposes of age verification; / (c) Not retain personal data on the age verification process after its completion; / (d) Be proportionate to the risks associated to the product or service that presents a risk of misuse for child sexual abuse; / (e) Provide appropriate remedies and redress mechanisms for users whose age is wrongly identified; / (f) Allow selective disclosure of attributes; / (g) Use zero-knowledge protocol; / (h) Allow users to use anonymous accounts; / (i) Not require the identification of each user of a service; / (j) Not retain personal data on the age verification process after its completion; / (k) Not require the processing of biometric data.

RemovedArticle 6 – paragraph 1 – point b – point ii (new): ii) the software application has an appropriate age rating model in place, or

AddedArticle 4 – paragraph 4: 4. Providers of hosting services and providers of number-independent interpersonal communications services shall clearly describe in their terms and conditions the mitigation measures that they have taken. That description shall not include information that may reduce the effectiveness of the mitigation measures.

RemovedArticle 6 – paragraph 1 – point b – point iii (new): iii) the developer of the software application has requested the software application store not to allow child users to download its software applications.

AddedArticle 4 – paragraph 5: 5. The Commission, in cooperation with Coordinating Authorities and the EU Centre and after having consulted the European Data Protection Board and having conducted a public consultation, may issue guidelines on the application of paragraphs 1, 2, 3 and 4, having due regard in particular to relevant technological developments and in the manners in which the services covered by those provisions are offered and used.

Show 29 more lines

RemovedArticle 6 – paragraph 1 – point c: (c) take the necessary age assurance measures to reliably identify child users on their services, enabling them to take the measures referred to in point (b).

AddedArticle 4 – paragraph 5 a (new): 5a. The Commission, in cooperation with Coordinating Authorities and the EU Centre and after having consulted the European Data Protection Board shall, by [date - 12 months from the date of entry into force of this Regulation], issue guidelines on how providers may implement age verification or age assessment measures on application of paragraph (3a), based on selective disclosure of attributes and zero-knowledge protocol.

RemovedArticle 6 a (new): Article 6a / Encrypted services and metadata processing / 1. Nothing in this Regulation shall be interpreted as prohibiting or weakening end-to-end encryption. / 2. On the basis of the risk assessment submitted and, where applicable, further information, the Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State to authorise a provider of hosting services or a provider of interpersonal communications services to process metadata to the extent strictly necessary and proportionate to mitigate the risk of misuse of their services for the purpose of online child sexual abuse. / When assessing whether to request the processing of metadata, the Coordinating Authority shall take into account any interference with the rights to privacy and data protection of the users of the service that such a processing entails and determine whether, in that case, the processing of metadata would be effective in mitigating the risk of use of the service for the purpose of child sexual abuse, and that it is strictly necessary and proportionate. / 3. Without prejudice to Regulation (EU) 2016/679, providers shall inform the users of such processing in their terms and conditions, including information on the possibility to submit complaints to the competent data processing authorities concerning the relevant processing and on the avenues for judic…

AddedArticle 4 a (new): Article4a / Mitigation measures for platforms primarily used for the dissemination of pornographic content / Where an online platform is primarily used for the dissemination of pornographic content, the platform shall take the necessary technical and organizational measures to ensure: / a. functionalities according to Article 12(3) enabling users to flag or notify potential online child sexual abuse; / b. adequate professional human content moderation to rapidly process notices of potential child sexual abuse material; / c. automatic mechanisms and interface design elements to inform users about external resources in the user’s region on preventing child sexual abuse, counselling by specialist helplines, victim support and educational resources by hotlines and child protection organizations; / d. automatic detection of searches for child sexual abuse material, warning and advice alerts displayed to users doing such searches, and flagging of the search and the user for human moderation; / e. functionalities enabling age verification that meet the criteria of Article 4a (new) of this Regulation.

RemovedArticle 7 – paragraph 1: 1. The Coordinating Authority of establishment shall have the power, when the requirements of Articles 3, 4, 5 or 5a have not been met, to request the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State to issue a detection order requiring a provider of hosting services or a provider of interpersonal communications services under the jurisdiction of that Member State to take the measures specified in Article 10 to detect online child sexual abuse on a specific service.

AddedArticle 4 b (new): Article4b / Mitigation measures for number-independent interpersonal communications service within games / Providers of online games that operate number-independent interpersonal communications service within their games, shall take all of the following mitigation measures in addition to the requirements referred to in Articles 3 and 4: / 1. prevent users from initiating unsolicited contact with other users; / 2. facilitate functionalities according to Article 12(3) enabling users to flag or notify potential online child sexual abuse / 3. provide technical measures and tools that allow users to manage their own privacy, visibility, reachability and safety and that are set to the most private and secure levels by default; / 4. provide tools in a prominent way on their platform that allow users or their guardians or legal representatives and potential victims to seek help from their local helpline.

RemovedArticle 7 – paragraph 2 – subparagraph 1: The Coordinating Authority of establishment shall request the issuance of the detection order and the competent judicial authority or independent administrative authority shall issue the detection order where it considers that the following conditions are met:

AddedArticle 5 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall transmit, by three months from the date referred to in Article 3(4), to the Coordinating Authority of establishment a report specifying the following:

RemovedFor clarity purposes, moving Article 7.4 here and adding a new point (b).

AddedArticle 5 – paragraph 1 – point a: (a) the process and the results of the risk assessment conducted or updated pursuant to Article 3;

RemovedArticle 7 – paragraph 2 – subparagraph 1 – point a (new): (a) there is evidence of a significant risk of the service being used for the purpose of online child sexual abuse, within the meaning of paragraphs 5, 6 and 7, as applicable;

AddedArticle 5 – paragraph 3 – subparagraph 1: Where necessary for that assessment, that Coordinating Authority may: / (a) carry out the consultations with the provider that it may deem necessary to determine whether the requirements of Articles 3 and 4 have been met; / (b) require further information and clarification from the provider within a reasonable time period set by that Coordinating Authority which shall not be longer than two weeks; / (c) request the EU Centre, the competent data protection authorities, another national public authority or relevant experts or entities to provide the necessary additional information.

RemovedArticle 7 – paragraph 2 – subparagraph 1 – point b (new): (b) mitigation measures put in place by the provider are not considered effective and proportionate to the risk of the misuse of the service offered or the service provider fails to conduct the risk assessment, the risk mitigation or the risk reporting obligations set out in this Regulation.

AddedArticle 5 – paragraph 3 – subparagraph 2: deleted

RemovedArticle 7 – paragraph 2 – subparagraph 1 a (new): The reasons for issuing the detection order shall outweigh negative consequences for the rights and legitimate interests of all parties affected, having regard in particular to the need to ensure a fair balance between the fundamental rights of those parties.

AddedArticle 5 – paragraph 4: 4. Without prejudice to Articles 7 and 27 to 29, where the Coordinating Authorithy of establishment considers that the requirements of Articles 3 and 4 have not been met, that Coordinating Authority shall have the power to address a reasoned decision to the provider requiring it to re-conduct or update the risk assessment or to take the necessary mitigation measures so as to ensure that Articles 3 and 4 are complied with, within a reasonable time period set by that Coordinating Authority. That time period shall not be longer than one month.

AddedArticle 5 – paragraph 4 a (new): 4a. The provider may, at any time, request the Coordinating Authority of establishment to review and, where appropriate, amend or revoke a decision as referred to in paragraph 4. The Coordinating Authority shall, within three months of receipt of the request, adopt a reasoned decision on the request based on objective factors and notify the provider of that decision.

AddedArticle 5 – paragraph 4 b (new): 4b. Where the requirements of Articles 3 and 4 are met, the Coordinating Authority shall issue a positive opinion, which shall be transmitted to the EU Centre and taken into account prior to any decision pursuant to Article 7.

AddedArticle 5 – paragraph 5: 5. The Coordinating Authority of establishment shall transmit the report referred to in paragraph 1 to the EU Centre, as well as any further information resulting from paragraph 3 and, where applicable, the positive opinion issued according to paragraph 4c.

AddedArticle 5 – paragraph 6: 6. Providers shall, upon request, transmit the report to the providers of software application stores, insofar as necessary for the compliance with the obligations set out in Article 6. Where necessary, they may remove confidential information from the reports.

AddedArticle 6 – paragraph 1 – introductory part: 1. Providers of software application stores considered as gatekeepers under the Regulation (EU) 2022/1925 shall, based on the information provided by the providers of software applications:

AddedArticle 6 – paragraph 1 – point a: (a) indicate that the provider of software application does not permit its use by children or that the software application has an age rating model in place;

AddedArticle 6 – paragraph 1 – point b: (b) when, according to Union law, parental consent is required for children to access the sofware application, make reasonable efforts to verify that the consent is given or authorised by the holder of parental responsibility over the child, taking into consideration the available technology.

AddedArticle 6 – paragraph 1 – point c: deleted

AddedArticle 6 – paragraph 2: 2. Providers of software application stores considered as gatekeepers under the Regulation (EU) 2022/1925 may, when the provider of software application has indicated to the provider of software application store that it does not permit its use by children, take additional measures to implement those restrictions on children, including reasonable measures to prevent children from accessing those software applications. When putting in place age verification systems, providers of software application stores shall meet the criteria set out in Article 4 (3a) of this Regulation.

AddedArticle 6 – paragraph 3: 3. Where software application stores take measures under this Article, those software application stores shall not be exempted from the obligations set out in this Regulation.

AddedArticle 6 – paragraph 4: 4. The Commission, in cooperation with Coordinating Authorities and the EU Centre and after having consulted the European Data Protection Board and after having conducted a public consultation, may issue guidelines on the application of paragraph 1 and 2 having due regard in particular to relevant technological developments and to the manners in which the services covered by that provision are offered and used.

AddedArticle 7 – paragraph 1: 1. The Coordinating Authority of establishment shall have the power, as a last resort after all the measures in Article 3, 4 and 5 have been exhausted, to request the competent judicial authority of the Member State that designated it to issue a detection order requiring a provider of hosting services or a provider of number-independent interpersonal communications services under the jurisdiction of that Member State to take the measures specified in Article 10 to detect child sexual abuse material on a specific service. / The detection order shall be targeted, specified and limited to individual users, a specific group of users, either as such or as subscribers to a specific channel of communication, in respect of whom there are reasonable grounds of suspicion for a link, even an indirect one, with child sexual abuse material as defined in Article 2. / Interpersonal communications to which end-to-end encryption is, has been or will be applied shall not be subject to the measures specified in Article 10. / Detection orders shall be addressed to the service provider acting as controller in accordance with Regulation (EU) 2016/679. By way of exception, the detection order may be directly addressed to the service provider that stores or otherwise processes the data on behalf of the controller, where: / (a) the controller cannot be identified despite reasonable efforts on the part of the issuing authority; or / (b) addressing the controller might be detrimental to an ongoing inve…

AddedArticle 7 – paragraph 2 – subparagraph 1: Based on a reasoned justification, the Coordinating Authority of establishment shall, request the issuance of the detection order and the competent judicial authority shall issue the detection order where it considers that all the following conditions are simultaneously met: / (a) there are reasonable grounds of suspicion on individual users, or on a specific group of users, either as such or as subscribers to a specific channel of communication, in respect of whom there is a link, even an indirect one, with child sexual abuse material as defined in Article 2. Reasonable grounds of suspicion are those resulting from any information reliable and legally acquired that suggest that individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication might have a link, even an indirect or remote one, with online child sexual abuse material. / (b) the mitigation measures put in place by the provider have insufficient material impact on limiting the identified risk or the service provider fails to to put in place reasonable and proportionate mitigation measures set out in this Regulation. / (c) issuing the detection order is necessary and proportionate and outweighs negative consequences for the rights and legitimate interests of all parties affected, having regard in particular to the need to ensure a fair balance between the fundamental rights of those parties, and without jeopardising the security of communications.

Change 47

RemovedIdea included in Article 5.3.

AddedArticle 7 – paragraph 3 – subparagraph 1 – introductory part: Where the Coordinating Authority of establishment takes the view that all the conditions of paragraph 2 have been met, it shall:

RemovedArticle 7 – paragraph 3 – subparagraph 1 – introductory part: Where the Coordinating Authority of establishment takes the preliminary view that the conditions of paragraph 2 have been met, it shall:

AddedArticle 7 – paragraph 3 – subparagraph 1 – point a: (a) establish a draft request to the competent judicial authority of the Member State that designated it for the issuance of a detection order, specifying the factual and legal grounds upon which the request is based and the duration of the order, as well as, the main elements of the content of the detection order it intends to request and the reasons for requesting it;

Change 48

ChangedArticle 7 – paragraph 3 – subparagraph 21 – introductory part: Where, having regard to the comments of the provider andpoint thed: opinion(d) ofinvite the EU Centre, that Coordinating Authority continues to be of theand viewin thatparticular theits conditionsTechnology ofCommittee, paragraphto 2provide haveits beenopinion met,on the provider shall do all of thedraft following,request, within a reasonable time period setof byfour thatweeks Coordinatingfrom Authority,the whichdate cannotof exceedreceiving fourthe weeks:draft request.

Change 49

RemovedArticle 7 – paragraph 3 – subparagraph 2 – point b: (b) where the draft implementation plan concerns an intended detection order concerning new child sexual abuse material or the solicitation of children other than the renewal of a previously issued detection order without any substantive changes, conduct a data protection impact assessment and a prior consultation procedure as referred to in Articles 35 and 36 of Regulation (EU) 2016/679, respectively, in relation to the measures set out in the implementation plan;

AddedArticle 7 – paragraph 3 – subparagraph 2 – introductory part: Where, having regard to the comments of the provider and the opinion of the EU Centre, that Coordinating Authority continues to be of the view that the conditions of paragraph 2 have been met and prior to requesting the competent judicial authority the issuance of the detection order, it shall request the provider to do all of the following, within a reasonable time period set by that Coordinating Authority, which cannot exceed four weeks:

RemovedJoint Opinion of the EDPB and the EDPS 04/2022 (point 104)

AddedArticle 7 – paragraph 3 – subparagraph 2 – point a: (a) draft an implementation plan setting out the measures it envisages taking to execute the intended detection order, including detailed information regarding the envisaged technologies and their technical feasibility and safeguards and if any, the negative impacts and safeguards on the rights of all parties involved. The provider may consult the EU Centre, and in particular its Technology Committee, to obtain support in identifying appropriate measures in this respect;

RemovedArticle 7 – paragraph 3 – subparagraph 3: Where, having regard to the implementation plan of the provider and the opinion of the data protection authority, that Coordinating Authority continues to be of the view that the conditions of paragraph 2 have met, it shall submit the request for the issuance of the detection, adjusted where appropriate, to the competent judicial authority or independent administrative authority. It shall attach the implementation plan of the provider and the opinions of the EU Centre and the data protection authority to that request.

AddedArticle 7 – paragraph 3 – subparagraph 2 – point b: (b) where the draft implementation plan concerns the use of any specific technology for the purpose of complying with an intended detection order concerning new child sexual abuse material other than the renewal of a previously issued detection order without any substantive changes, conduct a data protection impact assessment and a prior consultation procedure as referred to in Articles 35 and 36 of Regulation (EU) 2016/679, respectively, in relation to the measures set out in the implementation plan;

Show 14 more lines

RemovedArticle 7 – paragraph 4 – subparagraph 1: deleted / (deleted) / (deleted)

AddedArticle 7 – paragraph 3 – subparagraph 2 – point c: (c) where point (b) applies, or where the conditions of Articles 35 and 36 of Regulation (EU) 2016/679 are met, adjust the draft implementation plan, where necessary in view of the outcome of the data protection impact assessment and in order to take due account of the opinion of the data protection authority provided in response to the prior consultation;

RemovedMoved to Article 7.2.

AddedArticle 7 – paragraph 3 – subparagraph 2 – point d: (d) submit to that Coordinating Authority the implementation plan, where applicable attaching the opinion of the competent data protection authority and specifying how the implementation plan has been adjusted to take due account of the outcome of the data protection impact assessment and of that opinion.

RemovedArticle 7 – paragraph 4 – subparagraph 2 – introductory part: When assessing whether the conditions of paragraph 2 have been met, account shall be taken of all relevant facts and circumstances of the case at hand, in particular:

AddedArticle 7 – paragraph 3 – subparagraph 3: Where, having regard to the implementation plan of the provider and the opinion of the data protection authority and, where applicable, the opinion issued in accordance with article 5 (4c), that Coordinating Authority continues to be of the view that the conditions of paragraph 2 have been met, it shall submit the request for the issuance of the detection order, adjusted where appropriate, to the competent judicial authority. It shall attach the implementation plan of the provider and the opinions of the EU Centre and the data protection authority to that request.

RemovedArticle 7 – paragraph 4 – subparagraph 2 – point a: (a) the risk assessment conducted or updated and any mitigation measures taken by the provider pursuant to Articles 3 and 4;

AddedArticle 7 – paragraph 4: deleted / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted)

RemovedArticle 7 – paragraph 4 – subparagraph 2 – point b: (b) any additional information obtained pursuant to Article 5(3) and (4) where applicable;

AddedArticle 7 – paragraph 5 – introductory part: 5. As regards detection orders concerning the dissemination of known child sexual abuse material, the reasonable grounds of suspicion referred to in paragraph 2, point (a), shall be deemed to exist where the following conditions are met:

RemovedArticle 7 – paragraph 4 – subparagraph 2 – point d: (d) the opinions of the EU Centre and of the data protection authority submitted in accordance with paragraph 3 and, where applicable, the opinion of the Coordinating Authority issued in accordance with Article 5(4a).

AddedArticle 7 – paragraph 5 – point a: (a) the mitigation measures that the provider has taken, have insufficient material impact on limiting the systemic risk and the service is being used by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication, to an appreciable extent, for the dissemination of known child sexual abuse material;

RemovedArticle 7 – paragraph 4 – subparagraph 3: Where that Coordinating Authority substantially deviates from the opinion of the EU Centre or the data protection authorities, it shall inform the EU Centre or the data protection authorities and the Commission thereof, specifying the points at which it deviated and the main reasons for the deviation.

AddedArticle 7 – paragraph 5 – point b: (b) there is evidence of the service, having been used in the past 12 months by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication to an appreciable extent for the dissemination of known child sexual abuse material.

Change 50

ChangedArticle 7 – paragraph 56 – introductory part: 5.6. As regards detection orders concerning the dissemination of knownnew child sexual abuse material, the significantreasonable riskgrounds of suspicion referred to in paragraph 2 point (a) shall be deemed to exist where the following conditions are met:

Change 51

ChangedArticle 7 – paragraph 56 – point a: (a) despite the mitigation measures that the provider has takentaken, have insufficient material impact on limiting the systemic risk and the service is being used by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication, to an appreciable extentextent, for the dissemination of knownnew child sexual abuse material;

Change 52

ChangedArticle 7 – paragraph 6 – introductorypoint part:b: 6.(b) Asthere regardsis detectionevidence ordersof concerningthe service, having been used in the disseminationpast of12 newmonths childby sexualindividual abuseusers, material,or thea significantspecific riskgroup referredof tousers, ineither paragraphas 2such shallor beas deemedsubscribers to exista wherespecific channel of communication to an appreciable extent for the followingdissemination conditionsof arenew met:child sexual abuse material.

Change 53

RemovedArticle 7 – paragraph 7 – subparagraph 1 – introductory part: As regards detection orders concerning the solicitation of children, the significant risk referred to in paragraph 2 shall be deemed to exist where the following conditions are met:

AddedArticle 7 – paragraph 6 – point c: deleted / (deleted) / (deleted)

RemovedArticle 7 – paragraph 7 – subparagraph 2: The detection orders concerning the solicitation of children shall apply only to interpersonal communications between a child user and an adult.

AddedArticle 7 – paragraph 7: deleted / (deleted) / (deleted) / (deleted) / (deleted)

Change 54

ChangedArticle 7 – paragraph 8 – subparagraph 1: The Coordinating Authority of establishment when requesting the issuance of detection orders, and the competent judicial or independent administrative authority when issuing the detection order, shall,shall in accordance with Article 8 of Regulation (EU) 2022/2065,2022/2065 target and specify it in such a manner that the negative consequences referred to in paragraph 2 (c) remain limited to what is strictly necessary, justifiable and proportionate to effectively address the significant risk referred to in pointtarget (a)individual thereof,users, andor limita thespecific detectiongroup orderof tousers, aneither identifiableas partsuch or component of a service,as suchsubscribers asto a specific channel of communication or aas specificreferred groupto ofin userspoint identified(a) withthereof, particularitywhile fornot whichjeopardising the significant risk hassecurity beenof identified.communications.

Change 55

RemovedArticle 7 – paragraph 8 – subparagraph 3 – point a: (a) where that risk is limited to an identifiable part or component of a service, the required measures are only applied to an identifiable part or component of a service, such as a specific channel of communication or a specific group of users identified with particularity for which the significant risk has been identified, in respect of that part or component;

AddedArticle 7 – paragraph 8 – subparagraph 2: To that end, they shall take into account all relevant parameters, including the availability of sufficiently reliable detection technologies in that they limit to the maximum extent possible, in accordance with the state of the art, the rate of errors regarding the detection, and their suitability and effectiveness for achieving the objectives of this Regulation, as well as the impact of the measures on the rights of the users affected, and require the taking of the least intrusive measures, in accordance with Article 10, from among several equally effective measures.

RemovedArticle 9 – paragraph 2 – subparagraph 1: When the detection order becomes final, the competent judicial authority or independent administrative authority that issued the detection order shall, without undue delay, inform the Coordinating Authority of establishment thereof. The Coordinating Authority of establishment shall then, without undue delay, inform all other Coordinating Authorities through the system established in accordance with Article 39(2).

AddedArticle 7 – paragraph 8 – subparagraph 3 – point a: deleted

RemovedArticle 10 – paragraph 1: 1. Providers of hosting services and providers of interpersonal communication services that have received a detection order shall execute it by installing and operating available technologies to detect the dissemination of known or new child sexual abuse material or the solicitation of children, as applicable, using the corresponding indicators provided by the EU Centre in accordance with Article 46.

AddedArticle 7 – paragraph 8 – subparagraph 3 – point c: (c) subject to paragraph 9, the period of application remains limited to what is strictly necessary and proportionate;

Show 30 more lines

RemovedArticle 10 – paragraph 3 – point c: (c) in accordance with the state of the art and the least intrusive in terms of the impact on the users’ rights to private and family life, including the confidentiality of communication, and to protection of personal data;

AddedArticle 7 – paragraph 9 – subparagraph 1: The competent judicial authority shall specify in the detection order the period during which it applies, indicating the start date and the end date.

RemovedArticle 10 – paragraph 3 – point d a (new): (da) not able to weaken end-to-end encryption.

AddedArticle 7 – paragraph 9 – subparagraph 3: The period of application of detection orders concerning the dissemination of known or new child sexual abuse material shall be proportionate, taking all relevant factor into account, and not exceed 24 months and that of detection orders concerning the solicitation of children shall not exceed 12 months.

AddedArticle 7 – paragraph 9 a (new): 9a. Detections orders shall contain information about the right to appeal to a court of law according to the national legislation.

AddedArticle 8 – paragraph 1 – introductory part: 1. The competent judicial authority shall issue the detection orders referred to in Article 7 using the template set out in Annex I. Detection orders shall include:

AddedArticle 8 – paragraph 1 – point a: (a) information regarding the targeted and proportionate measures to be taken to execute the detection order, including, the individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication, in respect of whom there are reasonable grounds of suspicion for a link, even an indirect one, with child sexual abuse material, the indicators to be used and the safeguards to be provided for, including the reporting requirements set pursuant to Article 9(3) and, where applicable, any additional safeguards as referred to in Article 7(8);

AddedArticle 8 – paragraph 1 – point b: (b) identification details of the competent judicial authority issuing the detection order and authentication of the detection order by that judicial;

AddedArticle 8 – paragraph 1 – point e: (e) whether the detection order issued concerns the dissemination of known or new child sexual abuse material;

AddedArticle 8 – paragraph 1 – point g: (g) a detailed justification of reasons explaining why the detection order is issued and how is necessary, effective and proportionate;

AddedArticle 8 – paragraph 1 – point i: (i) the date, time stamp and electronic signature of the judicial issuing the detection order;

AddedArticle 8 – paragraph 2 – subparagraph 1: The competent judicial authority issuing the detection order shall address it to the main establishment of the provider or, where applicable, to its legal representative designated in accordance with Article 24.

AddedArticle 8 – paragraph 2 – subparagraph 2: The detection order shall be securely transmitted to the provider’s point of contact referred to in Article 23(1), to the Coordinating Authority of establishment and to the EU Centre, through the system established in accordance with Article 39(2).

AddedArticle 8 – paragraph 3: 3. If the provider cannot execute the detection order because it contains manifest errors or does not contain sufficient information for its execution, or it is manifestly unfounded, the provider shall, without undue delay, request the necessary correction or clarification to the Coordinating Authority of establishment, using the template set out in Annex II.

AddedArticle 9 – paragraph 1: 1. Providers of hosting services and providers of number-independent interpersonal communications services that have received a detection order, as well as users affected by the measures taken to execute it, shall have a right to information and effective redress. That right shall include the right to challenge the detection order before the courts of the Member State of the competent judicial authority that issued the detection order.

AddedArticle 9 – paragraph 2 – subparagraph 1: When the detection order becomes final, the competent judicial authority that issued the detection order shall, without undue delay, transmit a copy thereof to the Coordinating Authority of establishment. The Coordinating Authority of establishment shall then, without undue delay, transmit a copy thereof to all other Coordinating Authorities through the system established in accordance with Article 39(2).

AddedArticle 9 – paragraph 4 – subparagraph 1: In respect of the detection orders that the competent judicial authority issued at its request, the Coordinating Authority of establishment shall, where necessary and in any event following reception of the reports referred to in paragraph 3, assess whether any substantial changes to the grounds for issuing the detection orders occurred and, in particular, whether the conditions of Article 7(2) continue to be met. In that regard, it shall take account of additional mitigation measures that the provider may take to address the significant risk identified at the time of the issuance of the detection order.

AddedArticle 9 – paragraph 4 – subparagraph 2: That Coordinating Authority shall request to the competent judicial authority that issued the detection order the modification or revocation of such order, where necessary in the light of the outcome of that assessment. The provisions of this Section shall apply to such requests, mutatis mutandis.

AddedArticle 10 – paragraph 1: 1. Providers of hosting services and providers of number-independent interpersonal communication services that have received a detection order in accordance with to Article 7 shall execute it by installing and operating available, secure and privacy-friendly technologies to detect the dissemination of known or new child sexual abuse material, as applicable, using the corresponding indicators provided by the EU Centre in accordance with Article 46.

AddedArticle 10 – paragraph 2 a (new): 2a. The technologies relied on for the purpose of executing the detection order, regardless of whether they are provided by the EU Centre or procured or developped by the provider itself, shall be audited independently as regards their performance, reliability and security. The audit shall be made publicly available.

AddedArticle 10 – paragraph 3 – introductory part: 3. The technologies shall:

AddedArticle 10 – paragraph 3 – point a: (a) be effective in detecting the dissemination of known or new child sexual abuse material, as applicable;

AddedArticle 10 – paragraph 3 – point b: (b) not be able to permit the acquisition of knowledge of the content of the communications or any other information from the relevant communications than the information strictly necessary to detect, using the indicators referred to in paragraph 1, patterns pointing to the dissemination of known or new child sexual abuse material or the solicitation of children, as applicable;

AddedArticle 10 – paragraph 3 – point c: (c) be in accordance with the technological state of the art and the least intrusive in terms of the impact on the users’ rights to private and family life, including the confidentiality of communication, and to protection of personal data;

AddedArticle 10 – paragraph 3 – point d: (d) be sufficiently reliable, in that they limit to the maximum extent possible the rate of errors regarding the detection of online child sexual abuse, with special attention to avoid deviations and bias with proper testing and training of algorithms and models where applicable, and where such occasional errors occur, they are rectified without delay; and

AddedArticle 10 – paragraph 3 – point d a (new): (da) not apply to end-to-end encrypted communications.

AddedArticle 10 – paragraph 4 – point a: (a) take all the necessary measures to ensure that the technologies and indicators, as well as the processing of personal data and other data in connection thereto, are proportionate and limited to what is strcitly necessary for the sole purpose of detecting the dissemination of known or new child sexual abuse material, as applicable, insofar as strictly necessary to execute the detection orders addressed to them and, unless alleged child sexual abuse material has been confirmed as such, the data is erased immediately;

AddedArticle 10 – paragraph 4 – point b: (b) establish effective internal procedures to prevent and, where necessary, detect and remedy any misuse of the technologies, indicators and personal data and other data referred to in point (a), including unauthorised access to, and unauthorised transfers of, such personal data and other data;

AddedArticle 10 – paragraph 4 – point c: (c) ensure regular human oversight as necessary to ensure that the technologies operate in a sufficiently reliable manner and, where necessary, in particular when potential errors are detected, immediate human intervention;

AddedArticle 10 – paragraph 4 – point d: (d) establish and operate an accessible, age-appropriate and user- and child-friendly mechanism that allows users to submit to it, within a reasonable timeframe, complaints about alleged infringements of its obligations under this Section, as well as any decisions that the provider may have taken in relation to the use of the technologies, including the removal or disabling of access to material provided by users, blocking the users’ accounts or suspending or terminating the provision of the service to the users, and process such complaints in an objective, effective and timely manner;

Change 56

ChangedArticle 10 – paragraph 4 – point f a (new): (fa) ensure privacy by designdesing and by default and, where applicable, without hampering thesafety-by-desing integrityand ofby encryption.default.

Change 57

RemovedArticle 11 – paragraph 1: The Commission, in cooperation with the Coordinating Authorities and the EU Centre and after having conducted a public consultation and consulted the European Data Protection Board, may issue guidelines on the application of Articles 7 to 10, having due regard in particular to relevant technological developments and the manners in which the services covered by those provisions are offered and used.

AddedArticle 10 – paragraph 5 – subparagraph 1 – point a: (a) the fact that it operates technologies to detect child sexual abuse material to execute the detection order, the ways in which it operates those technologies and the impact on the confidentiality of users’ communications;

Change 58

ChangedArticle 1210 – paragraph 2 – subparagraph6: 1:6. Where thea provider submitsdetects apotential reportchild pursuantsexual abuse material through the measures taken to paragraphexecute 1,the detection order, it shall inform the userusers concerned without undue delay, after Europol or the national law enforcement authority of a Member State that received the report pursuant to Article 48 has confirmed that the information to the users would not interfere with activities for the prevention, detection, investigation and prosecution of child sexual abuse offences.

Change 59

RemovedArticle 12 – paragraph 2 – subparagraph 2: deleted

AddedArticle 11 – paragraph 1: The Commission, in cooperation with the Coordinating Authorities and the EU Centre and after having consulted the European Data Potection Board and having conducted a public consultation, may shall issue guidelines on the application of Articles 7 to 10, having due regard in particular to relevant technological developments and trends reported by law enforcement, hotlines and civil society and the manners in which the services covered by those provisions are offered and used.

AddedArticle 12 – paragraph 1: 1. Where a provider of hosting services or a provider of number-independent interpersonal communications services obtains actual knowlege in any manner other than through a removal order issued in accordance with this Regulation of any information indicating potential online child sexual abuse on its services, it shall promptly submit a report thereon to the EU Centre in accordance with Article 13 and providers of hosting services shall expeditiously remove or disable access to it, except where communicated otherwise under Article 48(6) point (b). It shall do so through the system established in accordance with Article 39(2).

AddedArticle 12 – paragraph 2 – subparagraph 1: Where the provider submits a report pursuant to paragraph 1, it shall inform the user concerned without undue delay, except where the EU Centre has communicated otherwise under Article 48(6) point (a), providing information on the main content of the report, on the manner in which the provider has become aware of the potential child sexual abuse concerned, on the follow-up given to the report insofar as such information is available to the provider and on the user’s possibilities of redress, including on the right to submit complaints to the Coordinating Authority in accordance with Article 34.

AddedArticle 12 – paragraph 2 – subparagraph 2: The provider shall inform the user concerned without undue delay, either after having received a communication from the EU Centre indicating that it considers the report to be unfounded as referred to in Article 48(2), or after the expiry of a time period of three months from the date of the report without having received a communication from the EU Centre indicating that the information is not to be provided as referred to in Article 48(6), point (a), whichever occurs first.

Change 60

ChangedArticle 12 – paragraph 3: 3. TheProviders providerof hosting services and providers of number-independent interpersonal communication services shall establish and operate an accessible,easy age-appropriateto access, age-appropriate, child-friendly and user-friendly mechanism that allows any users or entity to flag or notify tothem of the providerpresence potentialon onlinetheir childservice sexualof abusespecific onitems of information that the service,individual or entity considers to be potential online child sexual abuse, including self-reportingself-generated tools.material. Those mechanisms shall allow for the submission of notices by users or entities exclusively by electronic means and allow for anonymous reporting already available through anonymous reporting channels as defined by Directive (EU) 2019/1937.

Change 61

RemovedArticle 13 – paragraph 1 – point c: (c) all content data;

AddedArticle 12 – paragraph 3 a (new): 3a. The Commission, in cooperation with Coordinating Authorities and the EU Centre after having conducted a public consultation shall, by [six months from the date of entry into force of this Regulation], adopt implementing acts laying down the practical and operational arrangements for the design of a uniform identifiable notification mechanism referred to in paragraph 3, including for the design of a uniform easily recognisable icon in the user interface. Those implementing acts shall be adopted in accordance with the advisory procedure referred to in Article 87.

RemovedArticle 13 – paragraph 1 – point f: (f) metadata related to the potential online child sexual abuse;

AddedArticle 13 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall submit the report referred to in Article 12 using the template set out in Annex III. They shall make all the reasonable efforts to ensure the quality of the information submitted in order to facilitate the assessment and process by the EU Centre in accordance with Article 49(1). The report shall include:

RemovedArticle 14 – paragraph 1 – subparagraph 1 a (new): Removal orders shall be addressed to providers of relevant information society services acting as recipient of the service in accordance with Regulation (EU) 2022/2065. As an exception, where content is stored or processed as part of an infrastructure provided by another provider of a relevant information society service, the removal order may be directly addressed to it where: / –(a) the recipient of the service cannot be identified despite reasonable efforts on the part of the Coordinating Authority; or / –(b) addressing the recipient of the service might be detrimental to an ongoing investigation.

AddedArticle 13 – paragraph 1 – point c: (c) all content data being reported;

Show 2 more lines

RemovedArticle 14 – paragraph 2: 2. The provider shall execute the removal order as soon as possible and in any event within 24 hours of receipt thereof, unless the removal order indicates a shorter period.

AddedArticle 13 – paragraph 1 – point d: (d) all relevant available data other than content data related to the potential online child sexual abuse;

Change 62

ChangedArticle 1413 – paragraph 31 – point e: (e) anwhether exactthe Uniformpotential Resourceonline Identifierchild and,sexual whereabuse necessary,to additionaltheir informationknowledge forconcerns the identificationdissemination of theknown or new child sexual abuse material;material or the solicitation of children;

Change 63

RemovedArticle 15 – paragraph 2 – subparagraph 1: When the removal order becomes final, the competent judicial authority or independent administrative authority that issued the removal order shall, without undue delay, inform the Coordinating Authority of establishment thereof. The Coordinating Authority of establishment shall then, without undue delay, inform the EU Centre and all other Coordinating Authorities through the system established in accordance with Article 39(2).

AddedArticle 13 – paragraph 1 – point f: deleted

RemovedArticle 16 – paragraph 1: 1. The Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated it or an independent administrative authority of that Member State to issue a blocking order requiring a provider of internet access services under the jurisdiction of that Member State to take reasonable measures to prevent users from accessing known child sexual abuse material indicated by any Uniform Resource Identifiers on the list of Uniform Resource Identifiers included in the database of indicators, in accordance with Article 44(2), point (b) and provided by the EU Centre.

AddedArticle 13 – paragraph 1 – point f a (new): (fa) where applicable, an exact uniform resource locator and, where necessary, additional information for the identification of the potential child sexual abuse material;

RemovedArticle 16 – paragraph 2 – subparagraph 2 – point a: (a) verify that, in respect of all or a representative sample of the Uniform Resource Identifiers on the list referred to in paragraph 1, the conditions of Article 36(1), point (b), are met, including by carrying out checks to verify in cooperation with the EU Centre that the list is complete, accurate and up-to-date;

AddedArticle 13 – paragraph 1 – point g: (g) available information concerning the identity of any user involved in the potential online child sexual abuse;

Show 22 more lines

RemovedArticle 16 – paragraph 2 – subparagraph 2 – point b: (b) require the provider to submit, within a reasonable time period set by that Coordinating Authority, the necessary information, in particular regarding the accessing or attempting to access by users of the child sexual abuse material indicated by the Uniform Resource Identifier, regarding the provider’s policy to address the risk of dissemination of the child sexual abuse material and regarding the provider’s financial and technological capabilities and size;

AddedArticle 13 – paragraph 1 – point i a (new): (ia) where applicable, information on the reporting mechanism or on the specific technology that enabled the provider to become aware of the potential online child sexual abuse following measures taken to execute a detection order issued in accordance with Article 7;

RemovedArticle 16 – paragraph 2 – subparagraph 2 – point c: (c) request the EU Centre to provide the necessary information, in particular explanations and assurances regarding the accuracy of the Uniform Resource Identifier in indicating child sexual abuse material, regarding the quantity and nature of that material and regarding the verifications by the EU Centre and the audits referred to in Article 36(2) and Article 46(7), respectively;

AddedArticle 13 – paragraph 1 – point j: (j) whether the provider considers that the report involves an imminent threat to the live or safety of a child, or requires urgent action;

RemovedArticle 16 – paragraph 4 – subparagraph 1 – point a: (a) there is evidence of the service having been used during the past 12 months, to an appreciable extent, for accessing or attempting to access the child sexual abuse material indicated by the Uniform Resource Identifiers;

AddedArticle 14 – paragraph 1: 1. The Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated to issue a removal order requiring a provider of hosting services under the jurisdiction of the Member State that designated that Coordinating Authority to remove or disable access in all Member States of one or more specific items of material that, after a diligent assessment, the Coordinating Authority or the courts or other independent administrative authorities subject to judicial validation referred to in Article 36(1) identified as constituting child sexual abuse material. / Removal orders shall be addressed to the service provider acting as controller in accordance with Regulation (EU) 2016/679. By way of derogation, the removal order may be directly addressed to the service provider that stores or otherwise processes the data on behalf of the controller, where: / (a) the controller cannot be identified despite reasonable efforts on the part of the issuing authority; or / (b) addressing the controller might be detrimental to an ongoing investigation.

RemovedArticle 16 – paragraph 4 – subparagraph 1 – point c: (c) the Uniform Resource Identifiers indicate, in a sufficiently reliable manner, child sexual abuse material;

AddedArticle 14 – paragraph 1 a (new): 1a. Before issuing a removal order, the competent judicial authorities shall take all reasonable measures to ensure that executing the removal order does not interfere with activities for the investigation and prosecution of child sexual abuse offences.

RemovedArticle 17 – paragraph 1 – point a: (a) the reference to the list of Uniform Resource Identifiers, provided by the EU Centre, and the safeguards to be provided for, including the limits and safeguards specified pursuant to Article 16(5) and, where applicable, the reporting requirements set pursuant to Article 18(6);

AddedArticle 14 – paragraph 2: 2. The provider shall execute the removal order as soon as possible and in any event within 24 hours of receipt thereof, except where the removal order indicates a shorter period. For micro and small enterprises, the removal order shall allow additional time, proportionate to the size and the resources of the provider, but in any case no longer than 3 working days.

RemovedArticle 18 – paragraph 1: 1. Providers of internet access services that have received a blocking order, as well as users who provided or were prevented from accessing a specific item of material indicated by the Uniform Resource Identifiers in execution of such orders, shall have a right to effective redress. That right shall include the right to challenge the blocking order before the courts of the Member State of the competent judicial authority or independent administrative authority that issued the blocking order.

AddedArticle 14 – paragraph 3 – introductory part: 3. The competent judicial authority shall issue a removal order using the template set out in Annex IV. Removal orders shall include:

RemovedArticle 18 – paragraph 4 – introductory part: 4. Where a provider prevents users from accessing the Uniform Resource Identifiers pursuant to a blocking order issued in accordance with Article 17, it shall take reasonable measures to inform the users of the following:

AddedArticle 14 – paragraph 3 – point a: (a) identification details of the judicial issuing the removal order and authentication of the removal order by that authority;

RemovedArticle 18 – paragraph 5 – subparagraph 1: The provider and the users referred to in paragraph 1 shall be entitled to request the Coordinating Authority that requested the issuance of the blocking order to assess whether users are wrongly prevented from accessing a specific item of material indicated by Uniform Resource Identifiers pursuant to the blocking order. The provider shall also be entitled to request modification or revocation of the blocking order, where it considers it necessary due to substantial changes to the grounds for issuing the blocking orders that occurred after the issuance thereof, in particular substantial changes preventing the provider from taking the required reasonable measures to execute the blocking order,

AddedArticle 14 – paragraph 3 – point g: (g) a reference to Article 14 of this Regulation as the legal basis for the removal order;

RemovedArticle 18 a (new): Article 18a / Delisting orders / 1. The Coordinating Authority of establishment shall have the power to issue a delisting order addressed to the provider of online search engines or any other artificial intelligence systems under the jurisdiction of that Member State, to take reasonable measures to delist a particular resource or resources indicating specific items of known child sexual abuse material, when the conditions set out in paragraph 3 are met. / 2. Before issuing an order under paragraph 1, the Coordinating Authority of establishment shall inform the provider of its intention specifying the main elements of the content of the delisting order and the reasons to delist a particular resource or resources. It shall afford the provider the opportunity to comment on that information, within a reasonable time period set by that Authority. / 3. The Coordinating Authority of establishment shall issue a delisting order, where it considers that delisting is necessary to prevent the dissemination of child sexual abuse material to users in the Union, having regard to the need to protect the rights of the victims and to the existence and implementation by the provider of a policy to address the risk of such dissemination.

AddedArticle 14 – paragraph 3 – point h: (h) the date, time stamp and electronic signature of the judicial authority issuing the removal order;

RemovedArticle 18 b (new): Article 18b / Additional rules regarding delisting orders / 1. The Coordinating Authority shall issue delisting orders as referred to in Article 18a using the template set out in Annex X. Delisting orders shall include: / (a) the name of the provider and, where applicable, its legal representative; / (b) where known, the specific service in respect of which the delisting order is issued; / (c) all the necessary details to properly identify the affected resource or resources; / (d) the start date of the delisting; / (e) a sufficiently detailed statement of reasons explaining the delisting order; / (f) a reference to this Regulation as the legal basis for delisting; / (g) the date, time stamp and electronic signature of the Coordinating Authority issuing the delisting order; / (h) easily understandable information about the redress available, including information about redress to a court and about the time periods applicable to such redress. / 2. The Coordinating Authority that issues the delisting order shall address it to the main establishment of the provider or, where applicable, to its legal representative designated in accordance with Article 24. / 3. The Coordinating Authority shall transmit the delisting order to the provider’s point of contact referred to in Article 23(1), to the Coordinating Authority of establishment and to the EU Centre, through the system established in accordance with Article 39(2). / 4. The Coordinating Authority shall draft the delisting order …

AddedArticle 14 – paragraph 4 – subparagraph 1: The judicial authority issuing the removal order shall address it to the main establishment of the provider or, where applicable, to its legal representative designated in accordance with Article 24.

RemovedArticle 19 – paragraph 1: Providers of relevant information society services, shall not be liable for child sexual abuse offences solely because they carry out, in good faith, the necessary activities to comply with the requirements of this Regulation, in particular activities aimed at detecting, identifying, removing, disabling of access to, blocking, delisting from search results, or reporting online child sexual abuse in accordance with those requirements.

AddedArticle 14 – paragraph 8 a (new): 8a. Where Europol or the national competent law enforcement authorities or the EU Centre pursuant to Article 49(2), become aware of the presence of child sexual abuse material on a hosting service, they shall notify the competent Coordinating Authority of its exact uniform resource locator, and the Coordinating Authority shall request a removal order where the conditions of paragraph 1 and 1a are met.

Change 64

ChangedArticle 2015 – paragraph 11: –1. subparagraphProviders 1:of Victimshosting shallservices that have thereceived righta toremoval receive,order uponissued theirin request,accordance fromwith theArticle Coordinating14, Authorityas designatedwell byas the Member State where theyusers reside,who informationprovided regardingthe anymaterial, instancesshall wherehave the dissemination of known childright sexualto abusean materialeffective depictingredress. themThat isright reportedshall toinclude the EU Centre pursuantright to Article 12.challenge Personssuch witha disabilitiesremoval shallorder havebefore the rightcourts toof askthe andMember receiveState suchof anthe informationcompetent injudicial aauthority mannerthat accessibleissued tothe them.removal order.

Change 65

AddedArticle 15 – paragraph 2 – subparagraph 1: When the removal order becomes final, the competent judicial authority that issued the removal order shall, without undue delay, inform the Coordinating Authority of establishment thereof. The Coordinating Authority of establishment shall then, without undue delay, inform the EU Centre and all other Coordinating Authorities through the system established in accordance with Article 39(2).

AddedArticle 15 – paragraph 3 – point b: (b) the reasons for the removal or disabling, providing a copy of the removal order;

AddedArticle 15 – paragraph 4 – subparagraph 1: The Coordinating Authority of establishment may request, when requesting the judicial authority issuing the removal order, and after having consulted with relevant public authorities, that the provider is not to disclose any information regarding the removal of or disabling of access to the child sexual abuse material, where and to the extent necessary to avoid interfering with activities for the prevention, detection, investigation and prosecution of child sexual abuse offences.

AddedArticle 15 – paragraph 4 – subparagraph 2 – point a: (a) the judicial authority issuing the removal order shall set the time period not longer than necessary and not exceeding six weeks, during which the provider is not to disclose such information;

AddedArticle 15 – paragraph 4 – subparagraph 2 – point c: (c) that judicial authority shall inform the provider of its decision, specifying the applicable time period.

AddedArticle 15 – paragraph 4 – subparagraph 3: That judicial authority may decide to extend the time period referred to in the second subparagraph, point (a), by a further time period of maximum six weeks, where and to the extent the non-disclosure continues to be necessary. In that case, that judicial authority shall inform the provider of its decision, specifying the applicable time period. Article 14(3) shall apply to that decision.

Show 20 more lines

AddedArticle 16 – paragraph 1: 1. As a measure of last resort, when the known child sexual abuse material cannot be reasonable removed at source, the Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated it to issue a blocking order requiring a provider of internet access services under the jurisdiction of that Member State to take reasonable measures to prevent users from accessing known child sexual abuse material indicated by the exact uniform resource locators on the list of uniform resource locators included in the database of indicators, in accordance with Article 44(2), point (b) and provided by the EU Centre.

AddedArticle 16 – paragraph 2 – subparagraph 2 – point a: (a) verify that, the conditions of Article 36(1), point (b), are met, including by carrying out checks to verify in cooperation with the EU Centre that the list is complete, accurate and up-to-date;

AddedArticle 16 – paragraph 2 – subparagraph 2 – point b: (b) require the provider to submit, within a reasonable time period set by that Coordinating Authority, any necessary information, in particular regarding the apparent accessing or attempting to access by users of the child sexual abuse material indicated by the uniform resource locators;

AddedArticle 16 – paragraph 2 – subparagraph 2 – point c: (c) request the EU Centre to provide the necessary information, in particular explanations and assurances regarding the accuracy of the uniform resource locators in indicating known child sexual abuse material, regarding the quantity and nature of that material and regarding the verifications by the EU Centre and the audits referred to in Article 36(2) and Article 46(7), respectively;

AddedArticle 16 – paragraph 4 – subparagraph 1 – introductory part: The Coordinating Authority of establishment may request the issuance of the blocking order, and the competent judicial authority shall issue the blocking order, where it considers that all the following conditions are simultaneously met:

AddedArticle 16 – paragraph 4 – subparagraph 1 – point a: (a) the child sexual abuse material cannot reasonable be removed at source and the material is still online;

AddedArticle 16 – paragraph 4 – subparagraph 1 – point c: (c) the exact uniform resource locators indicate, in a sufficiently reliable manner, child sexual abuse material;

AddedArticle 16 – paragraph 4 – subparagraph 1 – point d: (d) the reasons for issuing the blocking order outweigh negative consequences for the rights and legitimate interests of all parties affected, having regard in particular to the need to ensure a fair balance between the fundamental rights of those parties, including the exercise of the users’ freedom of expression and information and the provider’s freedom to conduct a business;

AddedArticle 16 – paragraph 4 – subparagraph 1 – point d a (new): (da) it is technically feasible for the provider, without undermining web traffic encryption and without collateral blocking of access to lawful content accessible via other uniform resource locators.

AddedArticle 16 – paragraph 5 – introductory part: 5. The Coordinating Authority of establishment when requesting the issuance of blocking orders, and the competent judicial when issuing the blocking order, shall:

AddedArticle 16 – paragraph 6 – subparagraph 2: The period of application of blocking orders shall not exceed five years, but it can be renewed afterwards if necessary.

AddedArticle 16 – paragraph 7 – subparagraph 1: In respect of the blocking orders that the competent judicial authority issued at its request, the Coordinating Authority shall, where necessary and at least once every year, assess whether any substantial changes to the grounds for issuing the blocking orders occurred and, in particular, whether the conditions of paragraph 4 continue to be met.

AddedArticle 16 – paragraph 7 – subparagraph 2: That Coordinating Authority shall request to the competent judicial authority that issued the blocking order the modification or revocation of such order, where necessary in the light of the outcome of that assessment or to take account of justified requests or the reports referred to in Article 18(5) and (6), respectively. The provisions of this Section shall apply to such requests, mutatis mutandis.

AddedArticle 17 – paragraph 2: 2. The competent judicial authority issuing the blocking order shall address it to the main establishment of the provider or, where applicable, to its legal representative designated in accordance with Article 24.

AddedArticle 18 – paragraph 1: 1. Providers of internet access services that have received a blocking order, as well as users who provided or were prevented from accessing a specific item of material indicated by the uniform resource locators in execution of such orders, shall have a right to effective redress. That right shall include the right to challenge the blocking order before the courts of the Member State of the competent judicial authority that issued the blocking order.

AddedArticle 18 – paragraph 2 – subparagraph 1: When the blocking order becomes final, the competent judicial authority that issued the blocking order shall, without undue delay, transmit a copy thereof to the Coordinating Authority of establishment. The Coordinating Authority of establishment shall then, without undue delay, transmit a copy thereof to all other Coordinating Authorities through the system established in accordance with Article 39(2).

AddedArticle 19 – paragraph 1: Providers of relevant information society services shall not be liable for child sexual abuse offences solely because they carry out, in good faith and in a diligent manner, the necessary activities to comply with the requirements of this Regulation, in particular activities aimed at detecting, identifying, removing, disabling of access to, blocking, or reporting online child sexual abuse in accordance with those requirements.

AddedArticle 20 – paragraph 1 – subparagraph 1: Victims shall have the right to receive, upon their request, from the Coordinating Authority designated by the Member State where they reside or a Coordinating Authority of their choice information regarding any instances where the dissemination of known child sexual abuse material depicting them is reported to the EU Centre pursuant to Article 12. The right to information shall cover both occasional information as well as periodic information on a weekly, monthly or yearly basis.

AddedArticle 20 – paragraph 1 – subparagraph 1: Persons residing in the Union shall have the right to receive, upon their request, from the Coordinating Authority designated by the Member State where they reside, information regarding any instances where the dissemination of known child sexual abuse material depicting them is reported to the EU Centre pursuant to Article 12. Victims shall have the right to ask and receive such an information in the language indicated by that person, in a confidential, age-appropriate, accessible, understandable and gender-sensitive manner. The information in question shall be provided, within a reasonable period of time.

AddedArticle 20 – paragraph 1 – subparagraph 1 a (new): For the purpose of this Regulation, parents and guardians or legal representatives shall be entitled to exercise the rights of victims on their behalf where the victim is under 18 years of age or legally incompetent.

Change 66

RemovedArticle 21 – paragraph 1: 1. Providers of relevant information society services shall provide reasonable assistance, on request, to persons residing in the Union that seek to have one or more specific items of known child sexual abuse material depicting them removed or to have access thereto disabled by the provider.

AddedArticle 20 – paragraph 1 a (new): 1a. Where victims indicate in their request the preference for a periodic information, the Coordinating Authority shall provide periodically the victim, with the information referred to in paragraph 3. Victims may terminate such a request for periodic information at any time by notifying the competent Coordinating Authority.

RemovedArticle 21 – paragraph 2 – subparagraph 1: To that end, victims shall have the right to receive, upon their request, from the Coordinating Authority designated by the Member State where the person resides, support from the EU Centre when they seek to have a provider remove or disable access to one or more specific items of known child sexual abuse material depicting them. Persons with disabilities shall have the right to ask and receive any information relating to such support in a manner accessible to them.

AddedArticle 20 – paragraph 2 – point b: (b) where applicable, the individual or entity formally assisting or representing the victim that is to receive the information on behalf of the person making the request;

RemovedArticle 21 – paragraph 3: deleted

AddedArticle 20 – paragraph 2 – point c: (c) sufficient elements to verify that the child sexual abuse material matches the identity of the victim making the request;

Show 32 more lines

RemovedArticle 22 – paragraph 1 – subparagraph 1 – introductory part: Providers of relevant information society services and providers of interpersonal communications services shall preserve the content data and other data processed in connection to the measures taken to comply with this Regulation and the personal data generated through such processing, only for one or more of the following purposes, as applicable:

AddedArticle 20 – paragraph 2 – point c a (new): (ca) an indication of whether the request is occasional or covers a certain time period.

RemovedArticle 23 – paragraph 1: 1. Providers of relevant information society services shall establish a single point of contact allowing for direct communication, by electronic means, with the Coordinating Authorities, other competent authorities of the Member States, the Commission and the EU Centre, for the application of this Regulation. The single point of contact shall allow for direct communication with the users of the service for issues related to this Regulation.

AddedArticle 20 – paragraph 3 a (new): 3a. Victims shall have the right to receive, upon their request, from the Coordinating Authority designated by the Member State where they reside or the Coordinating Authority of their choice information regarding vitims’ rights, support and assistance. The information shall be age-appropriate, accessible, understandable and gender-sensitive and shall include: / (a) the type of support they can obtain and from whom, including, where relevant, basic information about access to medical support, any specialist support, including emotional, psychological or social support, and alternative accommodation; / (b) the procedures for making complaints with regard to a criminal offence and their role in connection with such procedures; / (c) how and under what conditions they can obtain protection, including protection measures; / (d) how and under what conditions they can access legal advice, legal aid and any other sort of advice legal assistance; / (e) how and under what conditions they can access compensation; / (f) how and under what conditions they are entitled to interpretation and translation.

RemovedArticle 26 – paragraph 2 – point c: (c) are free from any undue external influence, whether direct or indirect;

AddedArticle 21 – paragraph 1: 1. Providers of hosting services shall provide reasonable assistance, on request, to victims that seek to have one or more specific items of known child sexual abuse material depicting them removed or to have access thereto disabled by the provider. That support shall be provided in a timely manner.

RemovedArticle 27 – paragraph 1 – point b: (b) the power to request the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State to carry out on-site inspections of any premises that those providers or the other persons referred to in point (a) use for purposes related to their trade, business, craft or profession, or to request other public authorities to do so, in order to examine, seize, take or obtain copies of information relating to a suspected infringement of this Regulation in any form, irrespective of the storage medium;

AddedArticle 21 – paragraph 2 – subparagraph 1: To that end, victims shall have the right to receive, upon their request, from the Coordinating Authority designated by the Member State where they resides or from the Coordinating Authority of their choice, support from the EU Centre when they seek to have a provider of hosting services remove or disable access to one or more specific items of known child sexual abuse material depicting them. Victims shall have the right to receive any information relating to such support in a confidential, easily understandable and accessible manner to them. The support shall be provided by staff specifically trained to interact with victims and be able to address the specific needs and vulnerabilities of victims.

AddedArticle 21 – paragraph 2 – subparagraph 2: That Coordinating Authority shall transmit the request to the EU Centre through the system established in accordance with Article 39(2) and shall communicate the results received from the EU Centre to the victim making the request.

AddedArticle 21 – paragraph 3: 3. The requests referred to in paragraphs 1 and 2 shall indicate the relevant item or items of child sexual abuse material and any other relevant information.

AddedArticle 21 – paragraph 4 – point d: (d) where necessary, informing the Coordinating Authority of establishment of the presence of that item or those items on the provider’s service, with a view to the issuance of a removal order pursuant to Article 14.

AddedArticle 22 – paragraph 1 – subparagraph 1 – point e: (e) esponding to requests issued by competent law enforcement authorities and judicial authorities in accordance with the applicable law, with a view to providing them with the necessary information for the prevention, detection, investigation or prosecution of child sexual abuse offences, insofar as the content data and other data relate to a report that the provider has submitted to the EU Centre pursuant to Article 12. All such requests shall be logged.

AddedArticle 22 – paragraph 1 – subparagraph 2: As regards the first subparagraph, point (a), the provider who uses its own detection may also preserve the fully anonymised information for the purpose of improving the effectiveness and accuracy of the technologies to detect online child sexual abuse for the execution of a detection order issued to it in accordance with Article 7. No personal data shall be retained for that purpose.

AddedArticle 22 – paragraph 2 – subparagraph 1: Providers shall securely preserve the information referred to in paragraph 1 for no longer than necessary for the applicable purpose and, in any event, no longer than 12 months from the date of the reporting or of the removal or disabling of access, whichever occurs first.

AddedArticle 22 – paragraph 2 – subparagraph 3: Providers shall ensure that the information referred to in paragraph 1 is preserved in a secure manner and that the preservation is subject to state of art appropriate technical and organisational measures. Those safeguards shall ensure, in particular, that the information can be accessed and processed only for the purpose for which it is preserved, that unauthorised access to and unauthorised transfers of such personal data and other data are prevented, that a high level of security is achieved, all access to the data is logged, and that the information is deleted upon the expiry of the applicable time periods for preservation. Providers shall regularly review those safeguards and adjust them where necessary.

AddedArticle 24 – paragraph 1: 1. Providers of relevant information society services which do not have their main establishment in the Union, but which offer services in the Union, shall designate, in writing, a natural or legal person as its legal representative in the Union.

AddedArticle 25 – paragraph 2 – subparagraph 1: Member States shall, by the date referred to in paragraph 1, designate one of the competent authorities as their Coordinating Authority for child sexual abuse issues (‘Coordinating Authority’). Where they designate only one competent authority, that competent authority shall be the Coordinating Authority

AddedArticle 25 – paragraph 2 – subparagraph 2: The Coordinating Authority shall be responsible for all matters related to the application and enforcement of this Regulation in the Member State concerned, unless that Member State has assigned certain specific tasks or sectors to other competent authorities.

AddedArticle 25 – paragraph 2 – subparagraph 3: The Coordinating Authority shall in any event be responsible for ensuring coordination at national level in respect of those matters including prevention and combating of child sexual abuse, issuing of recommendations and good practices on improving digital skills and competences, education and awareness raising campaigns and the organisation of regular training activities for officials dealing with cases which involve children. / The Coordinating Authority shall in any event be responsible for contributing to the effective, efficient and consistent application and enforcement of this Regulation throughout the Union

AddedArticle 25 – paragraph 5: 5. Each Member State shall ensure that a contact point is designated or established within the Coordinating Authority’s office to efficiently handle requests for clarification, feedback and other communications in relation to all matters related to the objectives application and enforcement of this Regulation in that Member State, including communication with trusted organisations providing assistance to victims, education and awareness raising. Member States shall make the information on the contact point widely accessible through gender-sensitive and age- appropriate online and offline awareness raising campaigns and communicate this information to the EU Centre. They shall keep that information updated.

AddedArticle 25 – paragraph 6: 6. Within two weeks after the designation of the Coordinating Authorities pursuant to paragraph 2, the EU Centre shall set up an online public register listing the Coordinating Authorities and their contact points. The EU Centre shall regularly publish any modification thereto.

AddedArticle 25 – paragraph 7 – point a: (a) provide certain information or technical expertise on matters covered by this Regulation, including knowledge and expertise on appropriate prevention techniques against child sexual abuse;

AddedArticle 25 – paragraph 7 – point a a (new): (aa) provide information and expertise on gender-sensitive and age-appropriate victim assistance and support and prevention of online child sexual abuse;

AddedArticle 25 – paragraph 7 – point b: (b) assist in assessing, in accordance with Article 5(2), the risk assessment conducted or updated or the mitigation measures taken by a provider of number-independent hosting or interpersonal communication services under the jurisdiction of the Member State that designated the requesting Coordinating Authority;

AddedArticle 25 – paragraph 8: 8. The EU Centre shall provide, without undue delay, such assistance free of charge and in accordance with its tasks and obligations under this Regulation and insofar as its resources and priorities allow.

AddedArticle 25 – paragraph 8 a (new): 8a. Coordinating Authorities shall, where necessary for the performance of their tasks under this Regulation and in order to promote the generation and sharing of knowledge and best practises in accordance with Article 43(6), cooperate with organisations and networks with expertise on matters related to the prevention and combating of online child sexual abuse, including civil society organisations and semi-public organisations and professional organisations of practitioners.

AddedArticle 26 – paragraph 1: 1. Member States shall ensure that the Coordinating Authorities that they designated perform their tasks under this Regulation in an objective, impartial, transparent and timely manner, while fully respecting the fundamental rights of all parties affected. They shall also ensure that their Coordinating Authorities perform their tasks with utmost respect and sensitivity towards victims and their legal representatives. Member States shall also ensure provide their Coordinating Authorities with all necessary resources, including sufficient technical, financial and human resources to efficiently carry out their tasks.

AddedArticle 26 – paragraph 2 – point e: deleted

AddedArticle 26 – paragraph 4: 4. The Coordinating Authorities shall ensure that relevant members of staff have the required qualifications, experience, integrity and technical skills to perform their duties.

AddedArticle 26 – paragraph 5: 5. Without prejudice to national or the Union law regulating whistleblower protection, the management and other staff of the Coordinating Authorities shall, in accordance with Union or national law, be subject to a duty of professional secrecy both during and after their term of office, with regard to any confidential information which has come to their knowledge in the course of the performance of their tasks. Member States shall ensure that the management and other staff are subject to rules guaranteeing that they can carry out their tasks in an objective, impartial and independent manner, in particular as regards their appointment, dismissal, remuneration and career prospects.

AddedArticle 27 – paragraph 1 – introductory part: 1. Coordinating Authorities shall have the following investigatory powers in respect of providers of relevant information society services under the jurisdiction of the Member State that designated them:

AddedArticle 27 – paragraph 1 – point b: (b) the power to carry out remote or on-site inspections of any premises that those providers or the other persons referred to in point (a) use for purposes related to their trade, business, craft or profession, or the power to request the competent judicial authority of the Member State that designated it to do so, in order to examine, seize, take or obtain copies of information relating to a suspected infringement of this Regulation in any form, irrespective of the storage medium;

Change 67

AddedArticle 28 – paragraph 1 – introductory part: 1. Coordinating Authorities shall have the following enforcement powers, in respect of providers of relevant information society services under the jurisdiction of the Member State that designated them:

AddedArticle 28 – paragraph 1 – point b: (b) the power to order specific measures to bring about the cessation of infringements of this Regulation and, where appropriate, to impose remedies proportionate to the infringement and necessary to bring the infringement effectively to an end;

Change 68

RemovedArticle 28 – paragraph 1 – point d: (d) the power to impose a periodic penalty payment in accordance with Article 35 to ensure that an infringement of this Regulation is terminated in compliance with an order issued pursuant to point (b) of this paragraph;

AddedArticle 28 – paragraph 1 – point e: (e) the power to adopt appropriate, reasonable, and proportionate interim measures to prevent serious harm.

RemovedArticle 28 – paragraph 1 – point e: (e) the power to adopt appropriate, reasonable, and proportionate interim measures to avoid the risk of serious harm.

Change 69

RemovedArticle 29 – title: Additional enforcement measures

AddedArticle 29 – paragraph 1 – introductory part: 1. Coordinating Authorities shall have the additional enforcement powers referred to in paragraph 2 in respect of providers of relevant information society services under the jurisdiction of the Member State that designated them, provided that:

RemovedArticle 29 – paragraph 1 – introductory part: 1. Coordinating Authorities shall have the power to request additional enforcement measures, in respect of providers of relevant information society services under the jurisdiction of the Member State that designated them, provided that:

Change 70

RemovedArticle 29 – paragraph 2 – introductory part: 2. Coordinating Authorities shall have the power to request to the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State the following additional enforcement measures:

AddedArticle 29 – paragraph 1 – point b: (b) an infringement of this Regulation persists; and

Change 71

ChangedArticle 29 – paragraph 2 – point b – introductory part: (b) request the competent judicial authority of the Member State that designated the Coordinating Authority to order the temporary restriction of access of users of the service concerned by the infringement or, only where that is not technically feasible, to the online interface of the provider on which the infringement takes place, where the Coordinating Authority considers that:

Change 72

RemovedArticle 30 – title: Common provisions on investigatory and enforcement measures

AddedArticle 29 – paragraph 2 – point b – point ii: (ii) the infringement persists and causes serious harm; and

AddedArticle 29 – paragraph 4 – subparagraph 2: The temporary restriction shall apply for a period of four weeks, subject to the possibility for the competent judicial authority to extend that period for further periods of the same lengths, subject to a maximum number of extensions set by that judicial authority.

AddedArticle 29 – paragraph 4 – subparagraph 3 – point a: (a) the provider has failed to take the necessary and proportionate measures to terminate the infringement;

AddedArticle 30 – paragraph 2: 2. Member States shall ensure that any exercise of the investigatory and enforcement powers referred to in Articles 27, 28 and 29 is subject to adequate safeguards laid down in the applicable national law to respect the fundamental rights of all parties affected. In particular, those measures shall be targeted and precise, and taken in accordance with the right to respect for private life and the rights of defence, including the rights to be heard and of access to the file, and subject to the right to an effective judicial remedy of all parties affected.

AddedArticle 31 – paragraph 1: Coordinating Authorities shall have the power to carry out searches on publicly accessible content on hosting services to detect the dissemination of known or new child sexual abuse material, using the indicators contained in the databases referred to in Article 44(1), points (a) and (b), where necessary to verify whether the providers of hosting services under the jurisdiction of the Member State that designated the Coordinating Authorities comply with their obligations under this Regulation.

Change 73

ChangedArticle 34 – paragraph 1: 1. Users and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf,behalf shall have the right to lodge a complaint alleging an infringement of this Regulation affecting them against providers of relevant information society services with the Coordinating Authority designated by the Member State whereof thehis useror residesher habitual residence, place of work or isplace established.of the alleged infringement.

Change 74

RemovedArticle 35 – paragraph 4: 4. Member States shall ensure that the maximum amount of a periodic penalty payment shall not exceed 5 % of the average daily global turnover of the provider or the other person referred to in Article 27 (1) (a) in the preceding financial year per day, calculated from the date specified in the decision concerned.

AddedArticle 34 – paragraph 1 a (new): 1 a. The Coordinating Authority with which the complaint has been lodged shall inform the complainant and the provider on the progress and the outcome of the complaint in accordance with national law.

RemovedArticle 35 – paragraph 4 a (new): 4a. Member States shall ensure that penalties imposed for the infringement of this Regulation do not encourage the over reporting or the removal of material which does not constitute child sexual abuse material.

AddedArticle 34 – paragraph 1 b (new): 1 b. Directive (EU) 2019/1937 of the European Parliament and of the Council shall apply to the reporting of breaches of this Regulation and the protection of persons reporting such breaches.

RemovedArticle 36 – paragraph 1 – subparagraph 1 – point b: (b) exact Uniform Resource Identifiers indicating specific items of material that Coordinating Authorities or that competent judicial authorities or other independent administrative authorities of a Member State have identified, after a diligent assessment, as constituting child sexual abuse material, hosted by providers of hosting services not offering services in the Union, that cannot be removed due to those providers’ refusal to remove or disable access thereto and to the lack of cooperation by the competent authorities of the third country having jurisdiction, for the EU Centre to compile the list of Uniform Resource Identifiers in accordance with Article 44(3).

AddedArticle 34 – paragraph 1 c (new): 1 c. The Coordinating Authority shall offer easy to use mechanism to anonymously submit information about infringements of this Regulation.

Show 80 more lines

RemovedArticle 36 – paragraph 1 – subparagraph 2: Member States shall take the necessary measures to ensure that the Coordinating Authorities that they designated receive, without undue delay, the material identified as child sexual abuse material, the transcripts of conversations identified as the solicitation of children, and the Uniform Resource Identifiers, identified by a competent judicial authority or other independent administrative authority than the Coordinating Authority, for submission to the EU Centre in accordance with the first subparagraph.

AddedArticle 34 – paragraph 2: 2. Coordinating Authorities shall provide age-appropriate and accessible mechanisms to submit a complaint under this Article and adopt an age-appropriate and gender-sensitive approach when handling complaints taking due account of the complainant’s age, maturity, views, needs and concerns. Coordinating Authorities shall diligently process the complaints.

RemovedArticle 36 – paragraph 3: 3. Member States shall ensure that, where their law enforcement authorities receive a report of the dissemination of new child sexual abuse material or of the solicitation of children forwarded to them by the EU Centre in accordance with Article 48(3), a diligent assessment is conducted in accordance with paragraph 1.

AddedArticle 34 – paragraph 3 – subparagraph 1: The Coordinating Authority receiving the complaint shall assess the complaint and, where appropriate, transmit it to the Coordinating Authority of establishment of the provider. In this case paragraph 1a shall apply to the Coordinating Authorty of establishment mutandis mutandis.

RemovedArticle 38 – paragraph 1 – subparagraph 1: Coordinating Authorities shall share best practice standards and guidance on the detection and removal of child sexual abuse material and may participate in joint investigations, which may be coordinated with the support of the EU Centre, of matters covered by this Regulation, concerning providers of relevant information society services that offer their services in several Member States.

AddedArticle 34 a (new): Article 34a / Judicial remedy and compensation / Users and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf shall have the right to seek, in accordance with Union and national law, judicial remedy, including the right to compensation for any damage or loss suffered due to an infringement of the obligations under this Regulation.

RemovedArticle 39 – paragraph 1: 1. Coordinating Authorities shall cooperate with each other, any other competent authorities of the Member State that designated the Coordinating Authority, the Commission, the EU Centre, Europol and other relevant Union agencies, including the European Union Agency for Cybersecurity (ENISA), to facilitate the performance of their respective tasks under this Regulation and ensure its effective, efficient and consistent application and enforcement.

AddedArticle 35 – paragraph 2: 2. Member States shall ensure that the maximum amount of penalties imposed for an infringement of this Regulation shall not exceed 6 % of the annual worldwide turnover of the preceding business year of the provider.

RemovedArticle 39 – paragraph 2: 2. The EU Centre shall establish and maintain one or more reliable and secure information sharing systems supporting communications between Coordinating Authorities, the Commission, the EU Centre, Europol, and other relevant Union agencies, including ENISA, and providers of relevant information society services.

AddedArticle 35 – paragraph 3: 3. Penalties for the supply of incorrect, incomplete or misleading information, failure to reply or rectify incorrect, incomplete or misleading information or to submit to an on-site inspection shall not exceed 1% of the annual worldwide turnover of the preceding business year of the provider or the other person referred to in Article 27.

RemovedArticle 39 – paragraph 3: 3. The Coordinating Authorities, the Commission, the EU Centre, Europol, other relevant Union agencies, including ENISA, and providers of relevant information society services shall use the information-sharing systems referred to in paragraph 2 for all relevant communications pursuant to this Regulation.

AddedArticle 35 – paragraph 4: 4. Member States shall ensure that the maximum amount of a periodic penalty payment shall not exceed 5 % of the average daily worldwide turnover of the provider or the other person referred to in point (a) of Article 27(1), point (a) in the preceding financial year per day, calculated from the date specified in the decision concerned.

RemovedArticle 40 – paragraph 2: 2. The EU Centre shall contribute to the achievement of the objective of this Regulation by supporting and facilitating the implementation of its provisions concerning the prevention, detection, reporting, removal or disabling of access to, blocking of online child sexual abuse or delisting a particular resource indicating specific items of child sexual abuse material. The EU Centre shall gather and share information and expertise and facilitate cooperation between relevant public and private parties in connection to the prevention and combating of child sexual abuse, in particular online. It shall promote and ensure the appropriate support and assistance to victims.

AddedArticle 36 – paragraph 1 – subparagraph 1 – point a: (a) specific items of material and transcripts of conversations that Coordinating Authorities or that the competent judicial authorities or other independent administrative authorities of a Member State subject to judicial validation have identified, after a diligent assessment, as constituting child sexual abuse material or the solicitation of children, as applicable, for the EU Centre to generate indicators in accordance with Article 44(3);

RemovedArticle 42 – paragraph 1: The seat of the EU Centre shall be... / The choice of the location of the seat of the EU Centre shall be made in accordance with the ordinary legislative procedure, based on the following criteria: / (a) it shall not affect the EU Centre’s execution of its tasks or the organisation of its governance structure; / (b) it shall ensure that the EU Centre is able to recruit the high-qualified and specialised staff it requires to perform the tasks provided by this Regulation; / (c) it shall ensure that it can be set up on site upon the entry into force of this Regulation; / (d) it shall ensure appropriate accessibility of the location, the existence of adequate education facilities for the children of staff members, appropriate access to the labour market, social security and medical care for both children and spouses; / (e) it shall ensure a balanced geographical distribution of EU institutions, bodies and agencies across the Union; / (f) it shall enable close cooperation with EU institutions, bodies and agencies; / (g) it shall ensure sustainability and digital security and connectivity with regards to physical and IT infrastructure and working conditions.

AddedArticle 36 – paragraph 1 – subparagraph 1 – point b: (b) exact uniform resource locators indicating specific items of material that Coordinating Authorities or that competent judicial authorities or other independent administrative authorities of a Member State subject to judicial validation have identified, after a diligent assessment, as constituting child sexual abuse material, hosted by providers of hosting services not offering services in the Union, that cannot be removed due to those providers’ refusal to remove or disable access thereto and to the lack of cooperation by the competent authorities of the third country having jurisdiction, for the EU Centre to compile the list of uniform resource locators in accordance with Article 44(3).

RemovedArticle 43 – paragraph 1 – point 4 – point d: (d) providing information, assistance and support to victims in accordance with Articles 20 and 21;

AddedArticle 36 – paragraph 1 – subparagraph 2: Member States shall take the necessary measures to ensure that the Coordinating Authorities that they designated receive in a secure manner, without undue delay, the material identified as child sexual abuse material, the transcripts of conversations identified as the solicitation of children, and the uniform resource locators, identified by a competent judicial authority or other independent administrative authority than the Coordinating Authority, for submission to the EU Centre in accordance with the first subparagraph.

RemovedArticle 43 – paragraph 1 – point 6 – point b a (new): (ba) supporting the development and dissemination of age appropriate educational tools in order to enhance digital literacy and to raise awareness among users;

AddedArticle 36 – paragraph 4: 4. They shall also ensure that, where the diligent assessment indicates that the material does not constitute child sexual abuse material or the solicitation of children, the Coordinating Authority is informed of that outcome and subsequently informs the EU Centre thereof, within the time periods specified in the first subparagraph. Member States shall establish effective procedures that such material, including any associated data, which does not constitute child sexual abuse material or solicitation of children, is deleted from the records and databases at the Coordinating Authority and the Member States law enforcement authorities.

RemovedArticle 44 – paragraph 1 – point a: (a) indicators to prevent and detect the dissemination of child sexual abuse material previously detected and identified as constituting child sexual abuse material in accordance with Article 36(1);

AddedArticle 37 – paragraph 4: 4. The Coordinating Authority of establishment shall, without undue delay and in any event not later than two months following receipt of the request or recommendation referred to in paragraph 1, communicate to the Coordinating Authority that sent the request, or the Commission, the outcome of its assessment of the suspected infringement, or that of any other competent authority pursuant to national law where relevant, and, where applicable, details of the investigatory or enforcement measures taken or envisaged in relation thereto to ensure compliance with this Regulation.

RemovedArticle 44 – paragraph 1 – point b: (b) indicators to prevent and detect the dissemination of child sexual abuse material not previously detected and identified as constituting child sexual abuse material in accordance with Article 36(1);

AddedArticle 38 – paragraph 1 – subparagraph 1: Coordinating Authorities may participate in joint investigations, which may be coordinated with the support of the EU Centre, of matters covered by this Regulation, concerning providers of relevant information society services that offer their services in several Member States. Those investigations shall also take place on the darkweb.

RemovedArticle 44 – paragraph 1 – point c: (c) indicators to prevent and detect the solicitation of children.

AddedArticle 39 – paragraph 1: 1. Coordinating Authorities shall cooperate with each other, any other competent authorities of the Member State that designated the Coordinating Authority, the Commission, the EU Centre, and other relevant Union agencies, including to facilitate the performance of their respective tasks under this Regulation and ensure its effective, efficient and consistent application and enforcement.

RemovedArticle 44 – paragraph 2 – point b: (b) as regards paragraph 1, point (a), the relevant indicators shall include a list of Uniform Resource Identifiers compiled by the EU Centre in accordance with paragraph 3;

AddedArticle 39 – paragraph 2: 2. The EU Centre shall establish and maintain one or more reliable and secure information sharing systems suject to highest state of art technical and organisational safeguards, such as the software provided by eu-LISA pursuant to Regulation (EU) 2023/969, supporting communications between Coordinating Authorities, the Commission, the EU Centre, other relevant Union agencies and providers of relevant information society services.

RemovedArticle 44 – paragraph 3 – subparagraph 2: The EU Centre shall compile the list of Uniform Resource Identifiers referred to in paragraph 2, point (b), solely on the basis of the Uniform Resource Identifiers submitted to it pursuant to Article 36(1), point (b).

AddedArticle 39 – paragraph 4 a (new): 4 a. The Coordinating Authorities shall share information, best practice standards and guidance on the prevention and combating of child sexual abuse and solicitation of children.

RemovedArticle 44 – paragraph 4: 4. The EU Centre shall keep records of the submissions and of the process applied to generate the indicators and compile the list referred to in the first and second subparagraphs. It shall keep those records for as long as the indicators, including the Uniform Resource Identifiers, to which they correspond are contained in the databases of indicators referred to in paragraph 1.

AddedChapter IV – title: IV EU CENTRE FOR CHILD PROTECTION

RemovedArticle 45 – paragraph 2 – point g: (g) relevant indicators, metadata, and ancillary tags associated with the reported potential child sexual abuse material.

AddedArticle 40 – paragraph 1: 1. A European Union Agency to prevent and combat child sexual abuse, the EU Centre for child protection, is established.

RemovedArticle 46 – paragraph 2: 2. The EU Centre shall give relevant information society services providers access to the databases of indicators referred to in Article 44, where and to the extent necessary for them to execute the voluntary detection orders, detection, blocking or delisting orders that they received in accordance with Articles 5a, 7, 16 or 18a. The EU Centre shall take measures to ensure that such access remains limited to what is strictly necessary for the period of application of the voluntary detection orders, detection, blocking or delisting orders concerned and that such access does not in any way endanger the proper operation of those databases and the accuracy and security of the data contained therein.

AddedArticle 40 – paragraph 2: 2. The EU Centre shall contribute to the achievement of the objectives of this Regulation by supporting and facilitating the implementation of its provisions concerning the detection, reporting, removal or disabling of access to, and blocking of online child sexual abuse. The EU Centre shall gather and share anonymised information, gender-, and age-disaggregated statistics, and expertise, educational materials and best practices and facilitate cooperation between relevant public and private parties in connection to the prevention and combating of child sexual abuse, in particular online. It shall promote and ensure the appropriate support and assistance to victims.

RemovedArticle 46 – paragraph 4: 4. The EU Centre shall give Europol and the competent law enforcement authorities of the Member States access to the databases of indicators referred to in Article 44 where and to the extent necessary for the performance of their tasks of investigating child sexual abuse offences.

AddedArticle 42 – paragraph 1: The seat of the EU Centre shall be [...]

RemovedArticle 46 – paragraph 5: 5. The EU Centre shall give Europol access to the databases of reports referred to in Article 45, where and to the extent necessary for the performance of its tasks of assisting investigations of child sexual abuse offences

AddedArticle 42 – paragraph 1 a (new): The choice of the location of the seat of the EU Centre shall be made in accordance with the ordinary legislative procedure, based on the following criteria: / a) it shall not affect the EU Centre’s execution of its tasks and powers, the organisation of its governance structure, the operation of its main organisation, or the main financing of its activities; / b) it shall ensure that the EU Centre is able to recruit the high-qualified and specialised staff it requires to perform the tasks provided by this Regulation; / c) it shall ensure that it can be set up on site upon the entry into force of this Regulation; / d) it shall ensure appropriate accessibility of the location, the existence of adequate education facilities for the children of staff members, appropriate access to the labour market, social security and medical care for both children and spouses; / e) it shall ensure a balanced geographical distribution of EU institutions, bodies and agencies across the Union; / f) it shall enable close cooperation with EU institutions, bodies and agencies but it shall be independent of any of the aforementioned; / g) it shall ensure sustainability and digital security and connectivity with regards to physical and IT infrastructure and working conditions.

RemovedArticle 46 – paragraph 6 – subparagraph 1: The EU Centre shall provide the access referred to in paragraphs 2, 3, 4 and 5 only upon the reception of a request, specifying the purpose of the request, the modalities of the requested access, and the degree of access needed to achieve that purpose. The requests for the access referred to in paragraph 2 shall also include a reference to the voluntary detection orders, detection, blocking or delisting orders, as applicable.

AddedArticle 43 – paragraph 1 – point 1 – point a: (a) supporting the Commission in the preparation of the guidelines referred to in Article 3(6), Article 4(5), Article 6(4) and Article 11, including by collecting and providing relevant gender-sensitive and age-apropiate information, expertise and best practices, taking into account advice, from the Technology Committee referred to in Article 66 and from the Victims’ Rights and Survivors Consultative Forum referred to in Article 66a new where applicable;

RemovedArticle 46 – paragraph 6 – subparagraph 2: The EU Centre shall diligently assess those requests and only grant access where it considers that the requested access is necessary for and proportionate to the specified purpose, and in accordance with Union law.

AddedArticle 43 – paragraph 1 – point 1 – point b: (b) upon request from a provider of relevant information services, providing an analysis of methodology for risk assessment or, where appropiate, performing a test on;

RemovedArticle 46 – paragraph 7: 7. The EU Centre shall regularly verify that the data contained in the databases referred to in Articles 44 and 45 is, in all respects, complete, accurate and up-to-date and continues to be necessary for the purposes of reporting, detection and blocking in accordance with this Regulation, as well as facilitating and monitoring of accurate detection technologies and processes. In particular, as regards the Uniform Resource Identifiers contained in the database referred to Article 44(1), point (a), the EU Centre shall, where necessary in cooperation with the Coordination Authorities, regularly verify that the conditions of Article 36(1), point (b), continue to be met. Those verifications shall include audits, where appropriate. Where necessary in view of those verifications, it shall immediately complement, adjust or delete the data.

AddedArticle 43 – paragraph 1 – point 2 – point c: (c) giving providers of hosting services and providers of number-independent, interpersonal communications services that received a detection order access to the relevant databases of indicators in accordance with Article 46;

RemovedArticle 46 – paragraph 8: 8. The EU Centre shall ensure that the data contained in the databases referred to in Articles 44 and 45 is stored in a secure manner and that the storage is subject to appropriate technical and organisational safeguards that ensure an effective supervision, especially in automated processing systems. Those safeguards shall ensure, in particular, that the data can be accessed and processed only by duly authorised persons for the purpose for which the person is authorised and that a high level of security is achieved. The EU Centre shall regularly review those safeguards and adjust them where necessary. It shall maintain a record of processing activities as established in Article 30 of Regulation (EU) 2016/679 which, upon request, shall be made available to the EU Centre’s data protection officer and to the European Data Protection Supervisor.

AddedArticle 43 – paragraph 1 – point 4 – point d: (d) providing information assistance and support to victims in accordance with Articles 20 and 21;

RemovedArticle 47 – paragraph 1 – point b: (b) the processing of the submissions by Coordinating Authorities, the generation of the indicators, the compilation of the list of Uniform Resource Identifiers and the record-keeping, referred to in Article 44(3);

AddedArticle 43 – paragraph 1 – point 4 a (new): (4 a) conduct searches on publicly accesible content on hosting services for known child sexual abuse material in accordance with Article 49.1(ba);

RemovedArticle 48 – paragraph 1: 1. The EU Centre shall expeditiously and accurately assess and process reports submitted by providers of hosting services and providers of interpersonal communications services in accordance with Article 12 to determine whether the reports are manifestly unfounded or not. To that end, providers of hosting services and providers of interpersonal communications services shall make all the reasonable efforts to ensure the quality of the information submitted in accordance with Article 13, in order to facilitate an expeditious and accurate assessment and process.

AddedArticle 43 – paragraph 1 – point 6 – introductory part: (6) facilitate the generation and sharing of knowledge and best practices, with other Union institutions, bodies, offices and agencies, Coordinating Authorities or other relevant authorities of the Member States to contribute to the achievement of the objective of this Regulation, by:

RemovedArticle 48 – paragraph 7: 7. The time periods referred to in paragraph 6, points (a) and (b), shall be those specified in the competent law enforcement authority’s request to the EU Centre, provided that they remain limited to what is necessary to avoid interference with the activities for the prevention, detection, investigation, and prosecution of child sexual abuse offences and does not exceed 18 months.

AddedArticle 43 – paragraph 1 – point 6 – point a: (a) collecting, recording, analysing and providing information, providing analysis based on anonymised and non-personal data gathering, including gender-, sex- and age-disaggregated data in accordance with Article 51;

RemovedArticle 49 – paragraph 1 – introductory part: 1. The EU Centre shall have the power to conduct targeted searches on hosting services for the dissemination of publicly accessible child sexual abuse material, using the relevant indicators from the database of indicators referred to in Article 44(1), points (a) and (b), in the following situations:

AddedArticle 43 – paragraph 1 – point 6 – point a a (new): (a a) providing assistance, expertise and coordination on matters regarding the prevention and combating of online child sexual abuse in order to support them when taking measures or formulating courses of action within their respective spheres of competence;

RemovedArticle 49 – paragraph 3: 3. Where so requested by a competent law enforcement authority of a Member State in order to avoid interfering with activities for the prevention, detection, investigation and prosecution of child sexual abuse offences, the EU Centre shall not proceed according to paragraph 2, for as long as necessary to avoid such interference but no longer than 18 months.

AddedArticle 43 – paragraph 1 – point 6 – point a b (new): (a b) supporting the development of age-appropiate and gender-sensitive awareness-raising and prevention campaings, educational and intervention programs, tools and materials, taking with a specific focus on vulnerable groups, in order to enhance digital literacy among users and to equip children and adults, including parents and educators, with adequate skills for detecting potential malicious behaviour online and to contribute to ensure safe use of the internet by children.

RemovedArticle 50 – paragraph 1 – subparagraph 3: Before including specific technologies on those lists, the EU Centre shall request the opinion of its Technology Committee and, upon request of the Commission, the opinion of the European Data Protection Board. The Technology Committee and the European Data Protection Board shall deliver their respective opinions within eight weeks. That period may be extended by a further six weeks where necessary, taking into account the complexity of the subject matter. The Technology Committee and the European Data Protection Board shall inform the EU Centre of any such extension within one month of receipt of the request for consultation, together with the reasons for the delay. Where the EU Centre substantially deviates from those opinions, it shall inform the Technology Committee or the European Data Protection Board and the Commission thereof, specifying the points where it deviated and the main reasons for that deviation.

AddedArticle 43 – paragraph 1 – point 6 – point a c (new): (a c) facilitating the drafting of recommendations and guidelines for providers on prevention and mitigation of child sexual abuse, in particular in the digital space and taking into account technological developments.

RemovedJoint Opinion of the EDPB and the EDPS 04/2022 (point 107 and 108)

AddedArticle 43 – paragraph 1 – point 6 – point b: (b) supporting the development and dissemination of research and expertise on those matters and on assistance and support to victims, taking into account the gender and age dimension and operating in a way that minimises risks to victims, specially children, including by: / i) serving as a hub of expertise to support evidence-based policy and by linking researchers to practitioners; / ii) acting on behalf of supporting victims in liaising with other relevant authorities of the Member States for reparations and all other victim support programmes; / iii) referring victims to the appropriate national child protection services and to pro bono legal support services; / iv) facilitating access to qualified health care support services, including mental health and psychological support; / v) supporting the collaboration of victim support services and elaborating best practices;

RemovedArticle 50 – paragraph 2 – point c: (c) information resulting from research or other activities conducted by Member States’ authorities, other Union institutions, bodies, offices and agencies, the competent authorities of third countries, international organisations, research centres, hotlines, and civil society organisations.

AddedArticle 43 – paragraph 1 – point 6 – point c a (new): (c a) create, maintain and operate the online European Child Protection Platform established by Article 54a.

RemovedArticle 50 – paragraph 5: 5. The EU Centre shall develop a communication strategy and promote dialogue and cooperation with civil society organisations, public authorities, and relevant information society services to raise public awareness of online child sexual abuse and measures to prevent and combat such abuse.

AddedArticle 44 – title: European Union Databases of hashes and indicators

RemovedArticle 51 – paragraph 3: 3. The EU Centre shall store the personal data referred to in paragraph 2 only where and for as long as strictly necessary for the applicable purposes listed in paragraph 2. The maximum retention period for the storage of those data shall not exceed 24 months. After that period, the EU Centre shall review the necessity of continued storage of that data and provide justification for another 24 months maximum prolonged retention.

AddedArticle 44 – paragraph 2 – point a: (a) relevant indicators, consisting of digital identifiers to be used to detect the dissemination of known or new child sexual abuse material or the solicitation of children, as applicable, on hosting services and number-independent interpersonal communications services, generated by the EU Centre in accordance with paragraph 3;

RemovedJoint Opinion of the EDPB and the EDPS 04/2022 (point 115)

AddedArticle 44 – paragraph 3 – subparagraph 1: The EU Centre shall generate the indicators referred to in paragraph 2, point (a), solely on the basis of the child sexual abuse material and the solicitation of children identified as such by the Coordinating Authorities or the courts or other independent authorities of the Member States subject to judicial validation, submitted to it by the Coordinating Authorities pursuant to Article 36(1), point (a).

RemovedArticle 51 – paragraph 4: 4. It shall ensure that the personal data is stored in a secure manner and that the storage is subject to appropriate technical and organisational safeguards that ensure an effective supervision, especially in automated processing systems. Those safeguards shall ensure, in particular, that the personal data can be accessed and processed only for the purpose for which it is stored, that a high level of security is achieved and that the personal data is deleted when no longer strictly necessary for the applicable purposes. It shall regularly review those safeguards and adjust them where necessary. It shall maintain a record of processing activities as established in Article 30 of Regulation (EU) 2016/679 which, upon request, would be made available to the EU Centre’s data protection officer and to the European Data Protection Supervisor.

AddedArticle 44 – paragraph 4 a (new): 4 a. The EU Centre shall ensure through all technical means available that the databases of indicators are secure and the content cannot be altered by any other actor.

RemovedJoint Opinion of the EDPB and the EDPS 04/2022 (point 116)

AddedArticle 45 – paragraph 1: 1. The EU Centre shall create, maintain and operate a database for the reports submitted to it by providers of hosting services and providers of number-independent interpersonal communications services in accordance with Article 12(1) and assessed and processed in accordance with Article 48.

RemovedArticle 53 – paragraph 2 – subparagraph 1: Europol shall provide the EU Centre with access to relevant information and information systems, where deemed strictly necessary for the performance of the EU Centre’s tasks. Any access to personal data processed in Europol’s information systems shall be granted only on a case-by-case basis, upon submission of an explicit request, which documents the specific purpose, and justification. Europol should be required to diligently assess those requests and only transmit personal data to the EU Centre where strictly necessary and proportionate to the required purpose. / The EU Centre shall provide Europol with access to relevant information and information systems where deemed strictly necessary for the performance of Europol’s tasks. That access and subsequent transmission of personal data obtained from the EU Centre’s information systems should only take place on a case-by-case basis, following a duly assessed request, via an available secure exchange communication tool.

AddedArticle 45 – paragraph 2 – point b: deleted

RemovedJoint Opinion of the EDPB and the EDPS 04/2022 (point 127-133)

AddedArticle 45 – paragraph 2 – subparagraph 1 (new): Where the EU Centre considered the report manifestly unfounded, all data shall be anonymized and in case of videos or images only a cryptographic hash value from the reported file, the reasons and the date and time of informing the provider in accordance with Article 48(2) shall be stored;

RemovedArticle 53 – paragraph 2 – subparagraph 2: Without prejudice to the responsibilities of the Executive Director, the EU Centre shall maximise efficiency by sharing, where possible, support functions with Europol and information technology services (IT).

AddedArticle 46 – paragraph 2: 2. The EU Centre shall give providers of hosting services, providers of interpersonal communications services and providers of internet access services access to the databases of indicators referred to in Article 44(1) points (a) and (b), where and to the extent necessary for them to execute the detection, blocking orders that they received in accordance with Articles 5a, 7, 16. The EU Centre shall take measures to ensure that such access remains limited to what is strictly necessary for the period of application of the detection, blocking orders concerned and that such access does not in any way endanger the proper operation of those databases and the accuracy and security of the data contained therein.

Change 75

ChangedArticle 5446 – paragraph 1: 1. Where necessary5: for5. theThe performanceEU ofCentre itsshall tasksgive underEuropol thisaccess Regulation,to the EU Centre may cooperatedatabases withof organisationsreports andwhich networksit withconsidered informationnot andunfounded expertiseas onreferred mattersto relatedin toArticle the45, preventionwhere and combatingto ofthe onlineextent childnecessary sexualfor abuse,the includingperformance civilof societyits organisationstasks actingof inassisting theinvestigations publicof interestchild andsexual semi-publicabuse organisations.offences.

Change 76

RemovedArticle 56 – paragraph 4: 4. Members of the Management Board and their alternates shall be appointed in the light of their knowledge in the field of combating child sexual abuse, taking into account expertise and profesional records. Member States shall appoint a representative of their Coordinating Authority, within four months of [date of entry into force of this Regulation]. All parties shall aim to achieve a balanced representation between men and women on the Management Board.

AddedArticle 46 – paragraph 6 – subparagraph 2: The EU Centre shall diligently assess those requests on a case-by-case basis and only grant access where it considers that the requested access is necessary for and proportionate to the specified purpose, and in accordance with the Union law. Where it considers that an access request by Europol is necessary and proportionate, it shall transmit the relevant data via an available secure exchange communication tool, such as the Secure Information Exchange Network Application (SIENA).

RemovedArticle 56 – paragraph 5: 5. The term of office for members and their alternates shall be four years. That term may be renewed only once for another four years term.

AddedArticle 46 – paragraph 8: 8. The EU Centre shall ensure that the data contained in the databases referred to in Articles 44 and 45 is stored in a secure manner and that the storage is subject to highest state of the art technical and organisational safeguards, that ensure an effective supervision. Those safeguards shall ensure, in particular, that the data can be accessed and processed only by duly authorised persons for the purpose for which the person is authorised and that a high level of security is achieved. The EU Centre shall regularly review those safeguards and adjust them where necessary.

AddedArticle 47 – paragraph 1 – point d: (d) the modalities of the access to the databases referred to in Articles 44 and 45 in accordance with Article 46(1) to (5), the content, processing and assessment of the requests in accordance with Article 46(6), procedural matters related to such requests and the necessary measures in accordance with Article 46(6);

AddedArticle 48 – paragraph 1: 1. The EU Centre shall expeditiously and accurately assess and process reports submitted by providers of hosting services and providers of number-independent, interpersonal communications services in accordance with Article 12 to determine whether the reports are unfounded or not.

Show 39 more lines

AddedArticle 48 – paragraph 2: 2. Where the EU Centre considers that the report is unfounded, it shall inform the provider that submitted the report, specifying the reasons why it considers the report to be unfounded.

AddedArticle 48 – paragraph 3 – subparagraph 1: Where, after a thorough legal and factual assessment, the EU Centre considers that a report is not unfounded, it shall forward the report, together with any additional relevant information available to it, to Europol and to the competent law enforcement authority or authorities of the Member State likely to have jurisdiction to investigate or prosecute the potential child sexual abuse to which the report relates.

AddedArticle 48 – paragraph 3 – subparagraph 2: Where that competent law enforcement authority or those competent law enforcement authorities cannot be determined with sufficient certainty by a thorough factual assessment, the EU Centre shall forward the report, together with any additional relevant information available to it, to Europol, for further analysis and subsequent referral by Europol to the competent law enforcement authority or authorities.

AddedArticle 48 – paragraph 7: 7. The time periods referred to in paragraph 6, points (a) and (b), shall be those specified in the competent law enforcement authority’s request to the EU Centre, provided that they remain limited to what is necessary and proportionate to safeguard the prevention, detection, investigation and prosecution of child sexual abuse offences in a specific case These time periods shall not in any case exceed 12 months.

AddedArticle 49 – paragraph 1 – introductory part: 1. The EU Centre shall have the power to conduct searches of publicly accessible content on hosting services for child sexual abuse material, using the relevant indicators from the database of indicators referred to in Article 44(1), points (a) and (b), in the following situations:

AddedArticle 49 – paragraph 1 – point b a (new): (b a) proactively on its own initiative for known child sexual abuse material. The European Data Protection Board shall issue guidelines regarding the compliance with Regulation (EU) 2016/679 of existing and future technologies that are used for this purpose.

AddedArticle 49 – paragraph 1 a (new): 1 a. The technologies used by the EU Centre to conduct the searches referred to in paragraph 1 shall comply with the requirements set out in Article 10 (3).

AddedArticle 49 – paragraph 2 – subparagraph 1: The EU Centre shall notify, after having conducted the searches referred to in paragraph 1 (a) and (b), providers of hosting services of the presence of one or more specific items of known child sexual abuse material on their services and request them to remove or disable access to that item or those items, for the providers’ voluntary consideration.

AddedArticle 49 – paragraph 2 – subparagraph 2 a (new): After having conducted the searches referred to in paragraph 1 (ba), the EU Centre shall notify the competent Coordinating Authority which shall request the provider to remove or disable access to that item or those items pursuant to Article 32 or request a removal order pursuant to Article 14.

AddedArticle 49 – paragraph 3: 3. Where it is necessary and proportionate to safeguard the prevention, detection, investigation and prosecution of child sexual abuse offences in a specific case and where requested by a competent law enforcement authority of a Member State, the EU Centre shall not proceed according to paragraph 2. This non-submission shall be in any case no longer than 12 months.

AddedArticle 50 – paragraph 1 – subparagraph 1: The EU Centre shall make available technologies that providers of hosting services and providers of number-independent interpersonal communications services may acquire, install and operate, free of charge, where relevant subject to reasonable licensing conditions, to execute detection orders in accordance with Article 10(1). The EU Centre shall make available tools, technologies and relevant best practices for the implementation of the mitigation measures referred to in Article 4 of this Regulation. The EU Centre shall make publicly available the relevant information related to the making available of these technologies or tools, including the names of the manufacturers of the technologies.

AddedArticle 50 – paragraph 1 – subparagraph 3: Before including specific technologies on those lists, the EU Centre shall request the opinions of its Technology Committee and Victims’ Rights and Survivors Consultative Forum, and through the European Commission, the opinion of the European Data Protection Board. The Technology Committee, the Victims’ Consultative Forum and the European Data Protection Board shall deliver their respective opinions within eight weeks. That period may be extended by a further six weeks where necessary, taking into account the complexity of the subject matter. The Technology Committee and the European Data Protection Board shall inform the EU Centre of any such extension within one month of receipt of the request for consultation, together with the reasons for the delay. Where the EU Centre substantially deviates from those opinions, it shall inform, where applicable, the Technology Committee, the Victims’ Rights and Survivors Consultative Forum, or the European Data Protection Board and the Commission thereof, specifying the points where it deviated and the main reasons for that deviation.

AddedArticle 50 – paragraph 2 – introductory part: 2. The EU Centre shall collect, record, aggregate, analyse and proactively make available relevant, objective, reliable and comparable information on matters related to the prevention and combating of child sexual abuse, in particular:

AddedArticle 50 – paragraph 2 – point c: (c) information resulting from research or other activities conducted by Member States’ authorities, other Union institutions, bodies, offices and agencies, the competent authorities of third countries, international organisations, research centres, hotlines, helplines and civil society organisations.

AddedArticle 50 – paragraph 2 – point c a (new): (c a) information obtained in the performance of its tasks under this Regulation concerning victim assistance and support.

AddedArticle 50 – paragraph 3: 3. Where necessary for the performance of its tasks under this Regulation, the EU Centre shall carry out, participate in or encourage research, surveys and studies, either on its own initiative or, where appropriate and compatible with its priorities and its annual work programme, at the request of the European Parliament, the Council or the Commission. The outcome of the research, surveys and studies referred to in this paragraph, including its analysis thereof, shall be made publicly available.

AddedArticle 50 – paragraph 3 a (new): 3 a. The EU Centre shall support Member States and the Coordinating Authorities in conducting research, taking into account age, gender, vulnerable groups and national specificities. The collected knowledge shall serve as a tool to elaborate prevention methods adapted and implemented by Coordinating Authorities in each Member State.

AddedArticle 50 – paragraph 4: 4. The EU Centre shall provide the information referred to in paragraph 2 and its opinions on matters related to the prevention and combating of online child sexual abuse to other Union institutions, bodies, offices and agencies, Coordinating Authorities, other competent authorities and other public authorities of the Member States, either on its own initiative or at request of the relevant authority. Where appropriate, the EU Centre shall make such information publicly available.

AddedArticle 50 – paragraph 5: 5. The EU Centre shall develop a communication strategy and promote dialogue and cooperation with civil society organisations, hotlines, helplines, public authorities, and relevant information society services to raise public awareness of online child sexual abuse and measures to prevent and combat such abuse. Communication campaigns shall be easily understandable and accessible to all children, their families and educators in formal and non-formal education in the Union, aiming to improve digital literacy and ensure a safe digital environment for children. Communication campaigns shall take into account the gender dimension of the crime and the contributions of the Victims’ Rights and Survivors Consultative Forum.

AddedArticle 50 – paragraph 5 a (new): 5 a. The EU Centre shall support the development of technologies to detect the dissemination of online child sexual material, having regard to the requirements of this Regulation and in particular those under Article 10(3), and make them, free and open source, available for relevant information society services. The EU Centre shall make publicly available the relevant information related to the support it provides, including the names of the manufacturers of the technologies.

AddedArticle 51 – paragraph 4: 4. It shall ensure that the personal data is stored in a secure manner and that the storage is subject to highest state of the art, technical and organisational safeguards. Security requirements for data security pursuant to Article 88 of Regulation (EU) 2018/1725, Article 32 of Regulation (EU) 767/2008, Article 16 of Regulation (EU) 1987/2006, Article 16 of Regulation (EU) 2018/1862 and Article 34 of Regulation (EU) 603/2013 shall apply accordingly. Those safeguards shall ensure, in particular, that the personal data can be accessed and processed only for the purpose for which it is stored, that a high level of security is achieved and that the personal data is deleted when no longer strictly necessary for the applicable purposes. It shall regularly review those safeguards and adjust them where necessary.

AddedArticle 51 a (new): Article51a / Logging / 1. The EU Centre shall provide for logs to be kept for at least the following processing operations, in relation to tasks performed under this Regulation: collection, alteration, consultation, disclosure including transfers, combination and erasure. / 2. The logs of consultation and disclosure shall make possible to establish the justification, date and time of such operations and, as far as possible, the identification of the person who consulted or disclosed the data, and the identity of the recipients of such data. / 3. The logs shall be used solely for verification of the lawfulness of processing, self-monitoring, ensuring the integrity and security of the personal data. / 4. The EU Centre shall make the logs available to the relevant data protection supervisory authority on request.

AddedArticle 52 – paragraph 4: 4. Costs that arise in connection with the designation of contact officers and the performance of their tasks shall be borne by the Coordinating Authority that designated them. Where contact officers are seconded to the EU Centre, the EU Centre shall cover the costs of office space in the building and adequate equipment for them to perform their duties.

AddedArticle 53 – paragraph 2 – subparagraph 1: Europol shall provide the EU Centre with (part. 1744 The Left) access to relevant information and information systems, where deemed strictly necessary for the performance of the EU Centre’s tasks and in accordance with the acts of Union law regulating that. Any access to personal data processed in Europol’s information systems shall be granted only on a case-by-case basis, upon submission of an explicit and justified request, which documents the specific purpose. Europol shall be required to diligently assess those requests and only transmit personal data to the EU Centre where strictly necessary and proportionate to the specified purpose. / The EU Centre shall provide Europol with access to relevant information where deemed strictly necessary for the performance of Europol’s tasks. Any access to personal data processed in the EU Centre’s information systems shall be granted only on a case-by-case basis, upon submission of an explicit and justified request, which documents the specific purpose. The EU Centre shall be required to diligently assess those requests and only transmit personal data to Europol where strictly necessary and proportionate to the specified purpose. / That access and subsequent transmission of personal data shall only take place via an available secure exchange communication tool, such as the Secure Information Exchange Network Application (SIENA).

AddedArticle 53 – paragraph 2 – subparagraph 2: deleted

AddedArticle 53 – paragraph 3: 3. The terms of cooperation and working arrangements shall be laid down in a publically accessible memorandum of understanding.

AddedArticle 54 – paragraph 1: 1. Where necessary for the performance of its tasks under this Regulation, the EU Centre shall cooperate with organisations and networks with information and expertise on matters related to the prevention and combating of online child sexual abuse, and victim support, including civil society organisations and semi-public organisations acting in the public interest, and professional organisations of practioners.

AddedArticle 54 – paragraph 2: 2. The EU Centre may conclude publically accessible memoranda of understanding with organisations referred to in paragraph 1, laying down the terms of cooperation.

AddedArticle 54 – paragraph 2 a (new): 2 a. The EU Centre shall cooperate with other organizations and bodies carrying out, in other jurisdictions, similar functions on matters related to the prevention and combating of online child sexual abuse and victim support, as well as in order to avoid potential duplication of reporting obligations for providers.

AddedArticle 54 a (new): Article 54a / Establishment of an online European Child Protection Platform / 1. The EU Centre shall create, maintain and operate an online platform for the presentation of information about Member States hotlines and helplines ('Child Protection Platform'). That platform may also be used for the promotion of awareness-raising and prevention campaigns. The platform shall be accessible 24 hours a day and seven days a week in all Union languages and shall be child-friendly, age-appropriate and accessible. / 2. Providers of hosting services and providers of number-independent interpersonal communications services shall, where relevant in order to fulfil their tasks as laid down in Article 4 paragraph 1 point (cc) of this Regulation, make reference to the Platform.

AddedArticle 55 – paragraph 1 – point d a (new): (d a) a Victims’ Rights and Survivors Consultative Forum which shall exercise the tasks set out in Article 66a.

AddedArticle 55 – paragraph 1 – point d b (new): (d b) a Fundamental Rights Officer, which shall exercise the tasks set out in Art. 66b.

AddedArticle 55 – paragraph 1 – subparagraph 1 (new): When appointing the members that compose these bodies, all parties involved shall aim for an appropiate gender representation.

AddedArticle 56 – paragraph 1: 1. The Management Board shall be composed of one representative from each Member State, one representatives of the Commission, one independent representative designated by the European Parliament, all as members with voting rights.

AddedArticle 56 – paragraph 2 – subparagraph 1: deleted

AddedArticle 56 – paragraph 2 – subparagraph 1 a (new): One member of the Victims’ Rights and Survivors Consultative Forum as established in Art. 66a shall attend the meetings of the Management Board as an observer, without the right to vote. / The Technological Committee shall designate a representative to attend the meetings of the Management Board as an observer on matters related to technologies.

AddedArticle 56 – paragraph 3: 3. Each member of the Management Board shall have an alternate. The alternate shall represent the member in their absence.

AddedArticle 56 – paragraph 4: 4. Members of the Management Board and their alternates shall be appointed in the light of their knowledge in the field of preventing and combating child sexual abuse and victim support, taking into account their expertise and professional records. Member States shall appoint a representative of their Coordinating Authority, within four months of [date of entry into force of this Regulation]. All parties represented in the Management Board shall make efforts to limit turnover of their representatives, in order to ensure continuity of its work. All parties shall ensure that gender balance between men and women is achieved on the Management Board.

AddedArticle 56 – paragraph 5: 5. The term of office for members and their alternates shall be four years. That term may be renewed only once.

Change 77

RemovedArticle 57 – paragraph 1 – point a a (new): (aa) adopt the draft Single Programming Document and transmit it for their opinions to the European Parliament, the Council and the Commission;

AddedArticle 57 – paragraph 1 – point a: deleted

Change 78

ChangedArticle 57 – paragraph 1 – point a ba (new): (ab) adopt, by 30 November of(a eacha) year,adopt the draft Single Programming Document, and transmit it forDocument informationreferred to the European Parliament, the Councilin andArticle the66d Commissionbefore byits 31submission Januaryto the following year, as well as any other updated versionCommission offor theits document;opinion;

Change 79

RemovedArticle 57 – paragraph 1 – point a c (new): (ac) adopt the annual budget of the EU Centre and exercise other tasks in respect of the EU Centre's budget;

AddedArticle 57 – paragraph 1 – point a b (new): (ab) adopt, having requested the opinion of the Commission and the European Parliament, the Agency’s Single Programming Document by a majority of two-thirds of the members entitled to vote in accordance with Article 56 for the following year, as well as any other updated version of the document;

Change 80

ChangedArticle 57 – paragraph 1 – point a dc (new): (ad) assess and(ac) adopt a consolidated annual activity report on the EU Centre's activities, includingby ana overviewmajority of the fulfilmenttwo-thirds of its tasks and send it, by 1 Julythe eachmembers year,entitled to thevote, Europeanthe Parliament,annual thebudget Council,of the CommissionEU Centre and theexercise Courtother oftasks Auditorsin andrespect makeof the consolidated annual activityEU reportCentre's public;budget;

Change 81

AddedArticle 57 – paragraph 1 – point a d (new): (ad) assess and adopt, by a majority of two-thirds of the members entitled to vote, a consolidated annual activity report on the EU Centre's activities, including an overview of the fulfilment of its tasks and send it, by 1 July each year, to the European Parliament, the Council, the Commission and the Court of Auditors and make the consolidated annual activity report public;

Change 82

ChangedArticle 57 – paragraph 1 – point a h (new): (ah) appoint the Executive Director and remove him or herhim/her from office, in accordance with Article 65;

Change 83

ChangedArticle 57 – paragraph 1 – point a i (new): (ai) appoint an Accounting Officer, who may be the Commission's Accounting Officer, subject to the Staff Regulations and the Conditions of Employment of other servants, who shall be totally independent in the performance of hishis/her orthe herOfficer’s duties;

Change 84

ChangedArticle 57 – paragraph 1 – point a l (new): (al) appoint a Data Protection Officer;Officer in accordance with Regulation (EU) 2018/1725;

Change 85

ChangedArticle 57 – paragraph 1 – point f:c: (f)(c) appointadopt rules for the prevention and management of conflicts of interest in respect of its members, as well as for the members of the TechnologyTechnological Committee, the Victims’ Rights and Survivors Consultative Forum and of any other advisory group it may establish;establish and publish annually on its website the declaration of interests of the members of the Management Board;

Change 86

AddedArticle 57 – paragraph 1 – point d: deleted

AddedArticle 57 – paragraph 1 – point f: (f) appoint the members of the Technology Committee, of the Victims’ Consultative Forum and of any other advisory group it may establish;

AddedArticle 57 – paragraph 1 – point f a (new): (fa) designate the Fundamental Rights Officer referred to in Article 66b;

AddedArticle 57 – paragraph 1 – point h a (new): (h a) consult the Victims’ Rights and Survivors Consultative Forum as regards the obligations referred to in points (aa) and (h) of this Article.

AddedArticle 57 – paragraph 1 – point h b (new): (hb) authorise the conclusion of memoranda of understanding referred to in Article 53(3) and Article 54(2).

AddedArticle 57 – paragraph 1 a (new): 1a. With respect to the powers referred to in paragraph 2, 1 points (af) and (ag) of this Article, the Management Board shall adopt, in accordance with Article 110(2) of the Staff Regulations, a decision based on Article 2(1) of the Staff Regulations and Article 6 of the Conditions of Employment, delegating relevant appointing authority powers to the Executive Director. The Executive Director shall be authorised to sub-delegate those powers.

Show 2 more lines

AddedArticle 57 – paragraph 1 b (new): 1b. In exceptional circumstances, the Management Board may decide to temporarily suspend the delegation of the appointing authority powers to the Executive Director and any sub-delegation by the latter and exercise them itself or delegate them to one of its members or to a staff member other than the Executive Director.

AddedArticle 58 – paragraph 1 – subparagraph 2: The Deputy Chairperson shall automatically replace the Chairperson when necessary.

Change 87

RemovedArticle 59 – paragraph 4 a (new): 4a. The Management Board may invite the members of the Victims’ Consultative Forum as observers on matters related to a specific item on the Management Board’s agenda.

AddedArticle 60 – paragraph 2: 2. Each member, including the Chairperson and the Deputy Chairperson, shall have one vote. In the absence of a member, the alternate member shall be entitled to exercise the right to vote.

Change 88

ChangedArticle 61 – paragraph 1 – subparagraph 1: The Executive Board shall be gender-balanced and composed of the Chairperson and the Deputy Chairperson of the Management Board, three other members appointed by the Management Board from among its members with the right to vote andvote, two representatives of the Commission and the independent representative of the European Parliament to the Management Board. The Chairperson of the Management Board shall also be the Chairperson of the Executive Board. All parties shall ensure that gender balance between men and women is achieved on the Executive Board.

Change 89

AddedArticle 61 – paragraph 1 – subparagraph 2: The Executive Director shall participate in meetings of the Executive Board without the right to vote. The Executive Board may invite other observers to attend its meetings.

Change 90

ChangedArticle 62 – paragraph 2 – point p a (new): (pa)(p a) decide on matters provided for in the financial rules adopted pursuant to Article 68 that are not reserved to the Management Board by this Regulation;

Change 91

ChangedArticle 62 – paragraph 2 – point p b (new): (pb)(p ensureb) adequatewithout follow-upprejudice to the findingsresponsibilities andof recommendationsthe stemmingExecutive fromDirector, theas internalset orout externalin auditArticle reports64, monitor and evaluations,supervise asthe wellimplementation asof fromthe investigationsdecisions of OLAFthe andManagement Board, with a view to reinforcing supervision of EPPO;administrative and budgetary management.

Change 92

RemovedArticle 62 – paragraph 2 – point p c (new): (pc) without prejudice to the responsibilities of the Executive Director, as set out in Article 64, monitor and supervise the implementation of the decisions of the Management Board, with a view to reinforcing supervision of administrative and budgetary management.

AddedArticle 62 – paragraph 3: deleted

Change 93

ChangedArticle 64 – paragraph 1 a (new): 1a.1 a. Without prejudice to the powers of the Commission, of the Management Board and of the Executive Board, the Executive Director shall be independent in the performance of his or herthe duties and shall neither seek nor take instructions from any government nor from any other body.

Change 94

RemovedArticle 64 – paragraph 4 – point p a (new): (pa) authorise the conclusion of memoranda of understanding referred to in Article 53(3) and Article 54(2).

AddedArticle 64 – paragraph 2: 2. The Executive Director shall report to the European Parliament on the performance of the Executive Director’s duties when invited to do so. The Council may invite the Executive Director to report on the performance of the Executive Director’s duties.

RemovedArticle 65 – paragraph 2: 2. The Executive Director shall be appointed by the Management Board, from a list of candidates proposed by the Commission, following an open and transparent selection procedure.

AddedArticle 64 – paragraph 4 – point d: (d) preparing the Single Programming Document and submitting it to the Management Board after consulting the Commission;

AddedArticle 64 – paragraph 4 – point e: (e) implementing the Single Programming Document and reporting to the Management Board on its implementation;

AddedArticle 64 – paragraph 4 – point e a (new): (e a) implementing gender mainstreaming and gender budgeting in all areas, including drafting a gender action plan (GAP);

Show 7 more lines

AddedArticle 64 – paragraph 4 – point f: (f) preparing the Consolidated Annual Activity Report (CAAR) on the EU Centre’s activities including the activities of the Technology Committee and the Victims’ Rights and Survivors Consultative Forum and presenting it to the Management Board for assessment and adoption;

AddedArticle 64 – paragraph 4 – point g: (g) preparing an action plan following-up conclusions of internal or external audit reports and evaluations, as well as investigations by the European Anti-Fraud Office (OLAF) and by the European Public Prosecutor’s Office (EPPO) and reporting on progress twice a year to the Commission, the European Parliament and regularly to the Management Board and the Executive Board;

AddedArticle 64 – paragraph 4 – point i: (i) preparing an anti-fraud strategy, an efficiency gains and synergies strategy, a strategy for cooperation with third countries and/or international organisations and a strategy for the organisational management and internal control systems for the EU Centre and presenting them to the Management Board for approval;

AddedArticle 64 – paragraph 4 – point m: (m) implementing the annual work programme of the EU Centre under the control of the Management Board;

AddedArticle 64 – paragraph 4 – point p a (new): (pa) authorise the conclusion of memoranda of understanding, others than the referred to in Article 53(3) and Article 54(2), after having informed the Management Board.

AddedArticle 64 – paragraph 5: 5. Where exceptional circumstances so require, the Executive Director may decide to locate one or more staff in another Member State for the purpose of carrying out the EU Centre’s tasks in an a more efficient, effective and coherent manner according to the principles of good governance. Before deciding to establish a local office, the Executive Director shall obtain the prior consent of the Commission, the Management Board and the Member State concerned. The decision shall be based on an appropriate cost-benefit analysis that demonstrates in particular the added value of such decision and specify the scope of the activities to be carried out at the local office in a manner that avoids unnecessary costs and duplication of administrative functions of the EU Centre. A headquarters agreement with the Member State(s) concerned may be concluded.

AddedArticle 65 – paragraph 2: 2. The Executive Director shall be appointed by the Management Board, from a list of candidates proposed by the Commission, following an open and transparent selection procedure. / Before appointment, the candidates proposed by the Commission shall be invited to make a statement before the competent committee or committees of the European Parliament and answer questions put by its or their members. / Following such statements, the European Parliament shall adopt an opinion setting out its views and may indicate a preferred candidate. / The Management Board shall appoint by common accord with the European Parliament the Executive Director.

Change 95

RemovedArticle 66 a (new): Article 66a / Establishment and tasks of the Victims’ Consultative Forum / 1. The EU Centre shall establish a Consultative Forum to assist it by providing it with independent advice on victims related matters. The Consultative Forum will act upon request of the Management Board or the Executive Director. / 2. The Consultative Forum shall consist of a maximum of fifteen members. Members of the Consultative Forum shall be appointed from victims of child sexual abuse and exploitation, both online and offline, as well as from representatives of organisations acting in the public interest against child sexual abuse and promoting victims’ rights. They shall be appointed by the Management Board following the publication of a call for expression of interest in the Official Journal of the European Union. / 3. The mandates of members of the Consultative Forum shall be four years. Those mandates shall be renewable once. / 4. The Consultative Forum shall: / a) provide the Management Board and the Executive Director with advice on matters related to victims; / b) contribute to the EU Centre communication strategy referred to in Article 50(5); / c) provide its opinion on the technologies used to detect online child sexual abuse regarding their relevance to the conditions in which child sexual abuse is committed; / d) maintain an open dialogue with the Management Board and the Executive Director on all matters related to victims, particularly on the protection of victims’ rights.

AddedArticle 66 – paragraph 1: 1. The Technology Committee shall consist of technical experts on all matters related to the technologies relevant for the purposes of this Regulation appointed by the Management Board in view of their excellence and their independence, ensuring that gender balance is respected, following the publication of a call for expressions of interest in the Official Journal of the European Union.

RemovedArticle 69 – paragraph 4: 4. The EU Centre’s expenditure shall include staff remuneration, administrative and infrastructure expenses, and operating costs, including the operating costs of the Technology Committee, the Victims’ Consultative Forum and of any other advisory group it may establish.

AddedArticle 66 – paragraph 4: 4. When a member no longer meets the criteria of independence, he or she shall inform the Management Board. Alternatively, the Management Board may declare, on a proposal of at least one third of its members or of the Commission, a lack of independence and revoke the appointment of the person concerned. The Management Board shall appoint a new member for the remaining term of office in accordance with the procedure for ordinary members.

RemovedArticle 77 – paragraph 2: 2. The processing of personal data by the EU Centre shall be subject to Regulation (EU) 2018/1725. The Management Board shall, within six months of the date of its first meeting, establish measures for the application of that Regulation by the EU Centre, including those concerning the appointment of a Data Protection Officer of the EU Centre. Those measures shall be established after consultation with the European Data Protection Supervisor.

AddedArticle 66 – paragraph 5: 5. The mandates of members of the Technology Committee shall be four years. Those mandates shall be renewable once. On the expiry of their term of office, members shall remain in office until they are replaced or until their appointments are renewed. If a member resigns before the expiry of his or her term of office, the member shall be replaced for the remainder of the term by a member appointed by the Management Board.

Show 38 more lines

RemovedArticle 83 – paragraph 3 – point b: (b) the number of submissions of child sexual abuse material and solicitation of children referred to in Article 36(1), broken down by Member State that designated the submitting Coordinating Authorities, and, in the case of child sexual abuse material, the number of indicators generated on the basis thereof and the number of Uniform Resource Identifiers included in the list of Uniform Resource Identifiers in accordance with Article 44(3);

AddedArticle 66 – paragraph 6 – point c a (new): (c a) introduce a regular reviewing and reporting process to assess and share expertise on the most recent technological innovations and developments related to detection technology.

AddedArticle 66 a (new): Article66a / Establishment and tasks of the Victims’ Rights and Survivors Consultative Forum / 1. The EU Centre shall establish a Consultative Forum to assist it by providing it with independent advice on victims related matters. The Consultative Forum shall act upon request of the Management Board or the Executive Director. / 2. The Consultative Forum shall consist of a maximum of fifteen members. Members of the Consultative Forum will be appointed among victims of child sexual abuse and exploitation, both online and offline, as well as from representatives of organisations acting in the public interest against child sexual abuse and representing and promoting victims’ and survivors’ rights. They shall be appointed in view of their personal experience if applicable, expertise and scope of work by the Management Board following the publication of a call for expression of interest in the Official Journal of the European Union. / 3. Procedures concerning the appointment of the members of the Consultative Forum and its operation shall be specified in the rules of procedure of the Management Board and shall be made public. / 4. The members of the Consultative Forum shall be independent and shall act in the public interest. The list of members of the Committee shall be made public and shall be updated by the EU Centre on its website. / 5. When a member no longer meets the criteria of independence, he or she shall inform the Management Board. Alternatively, the Management Board may…

AddedArticle 66 b (new): Article 66b / Fundamental Rights Officer / 1. The Management Board shall, upon a proposal of a list of three candidates made by the Executive Director, designate a Fundamental Rights Officer. The Fundamental Rights Officer may be a member of the existing staff of the EU Centre who received special training in fundamental rights law and practice. / 2. The Fundamental Rights Officer shall perform the following tasks: / (a) contribute to the EU Centre's fundamental rights strategy and the corresponding action plan, including by issuing recommendations for improving them; / (b) monitore the EU Centre's compliance with fundamental rights, including by conducting investigations into any of its activities; / (c) promote the EU Centre's respect of fundamental rights in the performance of its tasks; / (d) advise the EU Centre where he or she deems it necessary or where requested on any activity of the EU Centre without impeding or delaying those activities; / (e) provide non-binding opinions on working arrangements; / (g) inform the Executive Director about possible violations of fundamental rights during activities of the EU Centre; / (h) performe any other tasks, where provided for by this Regulation. / 3. The EU Centre shall ensure that the Fundamental Rights Officer does not receive any instructions regarding the exercise of his or her tasks and is able to act autonomously. The Fundamental Rights Officer shall have sufficient and adequate resources at his or her disposal necessary…

AddedArticle 66 c (new): Article 66c / Budget / 1. Estimates of all revenue and expenditure for the EU Centre shall be prepared each financial year, which shall correspond to the calendar year, and shall be shown in the EU Centre’s budget, which shall be balanced in terms of revenue and of expenditure. / 2. Without prejudice to other resources, the EU Centre’s revenue shall comprise a contribution from the Union entered in the general budget of the Union. / 3. The EU Centre may benefit from Union funding in the form of delegation agreements or ad hoc grants in accordance with its financial rules referred to in Article 68 and with the provisions of the relevant instruments supporting the policies of the Union. / 4. The EU Centre’s expenditure shall include staff remuneration, administrative and infrastructure expenses, and operating costs, including the operating costs of the Technology Commitee, the Victims’ Rights and Survivors Consultative Forum and of any other advisory group it may establish for serving its purposes. / 5. Budgetary commitments for actions relating to large-scale projects extending over more than one financial year may be broken down into several annual instalments. / 6. The budget shall comply with the principle of gender mainstreaming and practise of gender budgeting shall be implemented.

AddedArticle 66 d (new): Article 66d / Single Programming Document / 1. By 30 November of each year, the Management Board shall adopt a draft single programming document containing multi-annual and annual programmingas well as all the documents listed in Article 32 of Commission Delegated Regulation (EU) 2019/715, based on a draft put forward by the Executive Director, after consulting the Technology Committee and the Victims’ Rights and Survivors Consultative Forum , taking into account the opinion of the Commission, and in relation to multiannual programming after consulting the European Parliament. If the Management Board decides not to take into account elements of the opinion of the Commission or of the Technology Committee or the Victims’ Rights and Survivors Consultative Forum, it shall provide a thorough justification therefor. The obligation to provide a thorough justification shall also apply to the elements raised by the European Parliament when it is consulted. / The Management Board shall forward the draft Single Programming Document to the European Parliament, the Council and the Commission by 31 January of the following year. The Single Programming Document shall become definitive after final adoption of the general budget and if necessary shall be adjusted accordingly. / 2. The annual work programme shall comprise detailed objectives and expected results including performance indicators. It shall also contain a description of the actions to be financed and an indication of the financi…

AddedArticle 67 – paragraph 1: 1. Each year the Executive Director shall draw up a draft statement of estimates of the EU Centre’s revenue and expenditure for the following financial year, including an establishment plan, a gender impact analysis and shall use gender mainstreaming and gender budgeting and send it to the Management Board.

AddedArticle 67 – paragraph 2: 2. The Management Board shall, on the basis of the draft statement of estimates, adopt a provisional draft estimate of the EU Centre’s revenue and expenditure for the following financial year and shall send it to the Commission by 31 January each year.

AddedArticle 67 – paragraph 3: 3. The Management Board shall send the final draft estimate of the EU Centre’s revenue and expenditure, which shall include a draft establishment plan, to the European Parliament, the Council and the Commission by 31 March each year.

AddedArticle 67 – paragraph 8: 8. The EU Centre’s budget shall be adopted by the Management Board by a majority of two-thirds of members entitled to vote. It shall become final following the final adoption of the general budget of the Union. Where necessary, it shall be adjusted accordingly.

AddedArticle 68 – paragraph 1: The financial rules applicable to the EU Centre shall be adopted by the Management Board after consultation with the Commission. They shall not depart from Delegated Regulation (EU) 2019/71552 unless such a departure is specifically required for the operation of the EU Centre and the Commission has given its prior consent.

AddedArticle 69: deleted / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted)

AddedArticle 71 – paragraph 3: 3. The EU Centre staff, in particular those working in areas related to detection, reporting and removal of online child sexual abuse, shall have access to appropriate counselling and support services, meeting any other possible physical or socio-psychological needs.

AddedArticle 83 – paragraph 1 – introductory part: 1. Providers of hosting services, providers of number-independent interpersonal communications services and providers of internet access services shall collect data on the following topics and make that information available to the EU Centre upon request:

AddedArticle 83 – paragraph 1 – point a – indent 2: – the error rates of the technologies deployed to detect child sexual abuse material, including the rates of false positives and negatives and confirmed positives and negatives, and measures taken to prevent or remedy any errors;

AddedArticle 83 – paragraph 1 – point b: (b) the number of removal orders issued to the provider in accordance with Article 14 and the average time, upon the moment the provider receives the order, needed for removing or disabling access to the item or items of child sexual abuse material in question;

AddedArticle 83 – paragraph 1 – point c: (c) the total number of items of child sexual abuse material when possible gender-and age-disaggregated that the provider removed or to which it disabled access, broken down by whether the items were removed or access thereto was disabled pursuant to a removal order or to a notice submitted by a Competent Authority, the EU Centre or a third party or at the provider’s own initiative;

AddedArticle 83 – paragraph 2 – point b: (b) the most important and recurrent risks of online child sexual abuse, as reported by providers of hosting services and providers of number-independent interpersonal communications services in accordance with Article 3 and 5 or identified through other information available to the Coordinating Authority;

AddedArticle 83 – paragraph 2 – point c: (c) a list of the providers of hosting services and providers of number independent interpersonal communications services to which the Coordinating Authority addressed a detection order in accordance with Article 7;

AddedArticle 83 – paragraph 2 – point d: (d) the number of detection orders issued in accordance with Article 7, broken down by provider and by type of child sexual abuse material, and the number of instances in which the provider invoked Article 8(3);

AddedArticle 83 – paragraph 2 – point f: (f) the number of removal orders issued in accordance with Article 14, broken down by provider, the time needed to remove or disable access to the item or items of child sexual abuse material concerned, including the time it took the Coordinating Authority to process the order, and the number of instances in which the provider invoked Article 14(5) and (6);

AddedArticle 83 – paragraph 2 – point i a (new): (ia) the measures taken regarding prevention and victim assistance programmes.

AddedArticle 83 – paragraph 3 – introductory part: 3. The EU Centre shall collect data and generate statistics on the detection, reporting, removal of or disabling of access to online child sexual abuse under this Regulation. The data shall include:

AddedArticle 83 – paragraph 3 – point c: (c) the total number of reports submitted to the EU Centre in accordance with Article 12, broken down by provider of hosting services and provider of number independent interpersonal communications services that submitted the report and by Member State the competent authority of which the EU Centre forwarded the reports to in accordance with Article 48(3);

AddedArticle 83 – paragraph 3 – point c a (new): (ca) the total number of reports forwarded to Europol in accordance with Article 48(3), and the total number of access requests received from Europol under Article 46(4) and 46(5), including the number of those requests granted and refused by the EU Centre;

AddedArticle 83 – paragraph 3 – point e: (e) the number of reports that the EU Centre considered unfounded, as referred to in Article 48(2);

AddedArticle 83 – paragraph 3 – point j: (j) the number of victims of online child sexual abuse assisted by the EU Centre pursuant to Article 21(2), and the number of these victims that requested to receive such assistance in a manner accessible to them due to disabilities.

AddedArticle 83 – paragraph 4: 4. The providers of hosting services, providers of number-independent interpersonal communications services and providers of internet access services, the Coordinating Authorities and the EU Centre shall ensure that the data referred to in paragraphs 1, 2 and 3, respectively, is stored no longer than is necessary for the transparency reporting referred to in Article 84. The data stored shall not contain any personal data.

AddedArticle 83 – paragraph 5: 5. They shall ensure that the data is stored in a secure manner and that the storage is subject to appropriate technical and organisational safeguards. Those safeguards shall ensure, in particular, that the data can be accessed and processed only for the purpose for which it is stored, that a high level of security is achieved and that the information is deleted when no longer necessary for that purpose. All access to this data shall be logged. They shall regularly review those safeguards and adjust them where necessary.

AddedArticle 84 – paragraph 1: 1. Each provider of relevant information society services shall draw up an annual report on its activities under this Regulation. That report shall compile the information referred to in Article 83(1). The providers shall, by 1 March of every year subsequent to the year to which the report relates, make the report available to the public in an structured commonly used and machine-readable format and communicate it to the Coordinating Authority of establishment, the Commission and the EU Centre.

AddedArticle 86 – paragraph 2: 2. The power to adopt delegated acts referred to in Articles 3, 8, 13, 14, 17, 47 and 84 shall be conferred on the Commission for a period of 5 years from [date of adoption of the Regulation]. The Commission shall draw up a report in respect of the delegation of power not later than 9 months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than 3 months before the end of each period.

AddedArticle 87 – paragraph 1: 1. For the purposes of the adoption of the implementing acts referred to in Article 39(4) and in Article 12(3a), the Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.

AddedArticle 87 – paragraph 2: 2. Where reference is made to this Article, Article 4 of Regulation (EU) No 182/2011 shall apply.

AddedArticle 87 a (new): Article 87a / Representative actions / The following is added to Annex I of Directive (EU) 2020/1828 on Representative actions for the protection of the collective interests of consumers: / “Regulation xxxx/xxxx of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse”

AddedArticle 88 – paragraph 1 a (new): Article 10, second subparagraph, of Regulation (EU) 2021/1232 is deleted.

AddedArticle 88 – paragraph 1: Regulation (EU) 2021/1232 is repealed from 9 months after the entry into force of this Regulation.

AddedArticle 88 a (new): Article 88a / Review / Within three years from the entry into force of the Regulation, the Commission shall submit a report to the European Parliament and to the Council on the necessity and feasibility of including the solicitation of children in the scope of the detection orders, taking into account in particular the reliability and accuracy of the state of art of the detection technologies. The Commission shall take into account the opinions of the EU Centre, in particular of its Technology Committee and the Victims’ Rights and Survivors Consultative Forum, and the opinion of the European Data Protection Board. / Where appropriate, the report shall be accompanied by legislative proposals. / Member States shall provide the Commission with the information necessary for the drafting of the report.

AddedArticle 89 – paragraph 2: It shall apply after its entry into force. However, Articles 7 to 18, Articles 20 to 21 and Chapter IV shall apply from 9 months after the entry into force of this Regulation.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
25 September 2026

Cite as

European Parliament (2023). “Changes between LIBE-PR-746811 and A-9-2023-0364”. Text, 16 November 2023. from LIBE-PR-746811, to A-9-2023-0364. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364 (retrieved 25 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-11-16,
  author = {{European Parliament}},
  title = {{Changes between LIBE-PR-746811 and A-9-2023-0364}},
  year = {2023},
  date = {2023-11-16},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364}},
  url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364},
  urldate = {2026-09-25},
  publisher = {EU Parl Watch Research},
  note = {Text. from LIBE-PR-746811, to A-9-2023-0364. Data: European Parliament Open Data (CC BY 4.0)}
}