Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

LIBE-PR-746811 → A-9-2023-0364

From
LIBE-PR-746811 report parliamentary committee draft of 19 Apr 2023
To
A-9-2023-0364 Plenary report of 16 Nov 2023
Changes
95 changes to the text
Paragraphs
+421 added · −186 removed · 51 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse
Title (to)
on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 1 of 14: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

9 unchanged paragraphs

on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse

(COM(2022)0209 – C90174/2022 – 2022/0155(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

– having regard to the Commission proposal to Parliament and the Council (COM(2022)0209),

– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90174/2022),

– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

– having regard to the reasoned opinions submitted, within the framework of Protocol No 1 and 2 to the EU Treaties, by the Spanish Parliament, the Netherlands Senate, the Irish Houses of the Oireachtas, the French Senate and the Czech Chamber of Deputies,

– having regard to the opinion of the European Economic and Social Committee of 21 September 2022,

Changed– having regard to RulesRule 59 and 41 of its Rules of Procedure,

Changed– having regard to the reportopinions of the Committee on Civilthe Liberties,Internal JusticeMarket and HomeConsumer AffairsProtection, (A90000/2023),Committee on Budgets, Committee on Culture and Committee on Education and Women’s Rights and Gender Equality

Added– having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A9-0364/2023),

4 unchanged paragraphs

1. Adopts its position at first reading hereinafter set out;

2. Approves its statement annexed to this resolution, which will be published in the L series of the Official Journal of the European Union together with the final legislative act;

3. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

4. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Change 1

ChangedRecital 2:1: (2)(1) GivenInformation thesociety centralservices importancehave ofbecome relevantvery informationimportant societyfor services,communication, thoseexpression, aimsgathering canof onlyinformation beand achievedmany byother ensuringaspects thatof providerspresent-day offeringlife, suchincluding servicesfor inchildren. theHowever, Unionthese behaveservices responsiblyare andalso takeused reasonableby measuresperpetrators toof minimisechild thesexual riskabuse ofoffences. theirSuch servicesoffences, beingwhich misusedare forsubject theto purposeminimum ofrules childset sexualat abuse,Union thoselevel, providersare oftenvery beingserious incriminal aoffences uniquethat positionoften tocause preventlong-lasting andnegative combatconsequences suchon abuse.victims Theand measuresthat takenneed shouldto be effective, targeted, carefully balancedprevented and proportionate,combated soeffectively asin order to avoidprotect anychildren’s unduerights negativeand consequenceswell-being, foras thoseis whorequired useunder the services for lawfulCharter purposes,of inFundamental particularRights forof the exerciseEuropean ofUnion their(‘Charter’), fundamentaland rightsto protectedprotect undersociety Unionat law,large. thatUsers is,of thosesuch enshrinedservices offered in the Charter and recognisedUnion asshould generalbe principlesable ofto Uniontrust law,that andthe soservices asconcerned tocan avoidbe imposingused anysafely excessivein burdensa ontrusted theonline providersenvironment, ofespecially theby services.children.

Change 2

RemovedRecital 3: (3) Member States are increasingly introducing, or are considering introducing, national laws to prevent and combat online child sexual abuse, in particular by imposing requirements on providers of relevant information society services. In the light of the inherently cross-border nature of the internet and the service provision concerned, those national laws, which diverge, may have a direct negative effect on the internal market. To increase legal certainty, eliminate the resulting obstacles to the provision of the services and ensure a level playing field in the internal market, the necessary harmonised requirements should be laid down at Union level.

AddedRecital 2: (2) Given the central importance of relevant information society services, those aims can only be achieved by ensuring that providers offering such services in the Union behave responsibly and take reasonable measures to minimise the risk of their services being misused for the purpose of child sexual abuse, those providers often being in a unique position to prevent and combat such abuse. The measures taken should be effective, targeted, evidence-based, carefully balanced, and proportionate, and subject to constant review so as to avoid any undue negative consequences for those who use the services for lawful purposes, in particular for the exercise of their fundamental rights protected under Union law, that is, those enshrined in the Charter and recognised as general principles of Union law, and so as to avoid directly or indirectly imposing any excessive burdens on the providers of the services.

RemovedRecital 4: (4) Therefore, this Regulation should contribute to the proper functioning of the internal market by setting out clear, uniform and balanced rules to prevent and combat child sexual abuse in a manner that is effective, targeted and proportionate, and that respects the fundamental rights of all parties concerned. In view of the fast-changing nature of the services concerned and the technologies used to provide them, those rules should be laid down in technology-neutral and future-proof manner, so they encourage innovation and technological development to prevent and combat online child sexual abuse.

AddedRecital 3: (3) Member States are increasingly introducing, or are considering introducing, national laws to prevent and combat online child sexual abuse and more generally to protect children online, in particular by imposing requirements on providers of relevant information society services. In the light of the inherently cross-border nature of the internet and the service provision concerned, those national laws, which sometimes diverge, can have a direct negative effect on the internal market. To increase legal certainty, eliminate the resulting obstacles to the provision of the services and ensure a level playing field in the internal market, the necessary harmonised requirements should be laid down at Union level.

RemovedRecital 5: (5) In order to achieve the objectives of this Regulation, it should cover providers of services that have the potential to be misused for the purpose of online child sexual abuse. As they are increasingly misused for that purpose, those services should include publicly available interpersonal communications services, such as messaging services and web-based e-mail services, in so far as those service as publicly available. As services which enable direct interpersonal and interactive exchange of information merely as a minor ancillary feature that is intrinsically linked to another service, such as chat and similar functions as part of gaming, image-sharing and video-hosting are equally at risk of misuse, they should also be covered by this Regulation. Online search engines and any other artificial intelligence services should also be covered. However, given the inherent differences between the various relevant information society services covered by this Regulation and the related varying risks that those services are misused for the purpose of online child sexual abuse and varying ability of the providers concerned to prevent and combat such abuse, the obligations imposed on the providers of those services should be differentiated in an appropriate manner.

AddedRecital 4: (4) Therefore, this Regulation should contribute to the proper functioning of the internal market by setting out clear, uniform, effective, proportionate and carefully balanced rules to prevent and combat child sexual abuse in a manner that is effective, targeted and proportionate, and that respects the fundamental rights of all parties concerned. In view of the fast-changing nature of the services concerned and the technologies used to provide them, those rules should be laid down in technology-neutral and future-proof manner, so they stimulate innovation and technological development to prevent and combat online child sexual abuse.

RemovedRecital 7: (7) This Regulation should be without prejudice to the rules resulting from other Union acts, in particular Directive 2011/93 of the European Parliament and of the Council38 , Directive 2000/31/EC of the European Parliament and of the Council39 and Regulation (EU) 2022/2065 of the European Parliament and of the Council40, Directive 2010/13/EU of the European Parliament and of the Council41 , Regulation (EU) 2016/679 of the European Parliament and of the Council42 , and Directive 2002/58/EC of the European Parliament and of the Council43 . / 40 Regulation (EU) 2022/2065 of the European Parliament and of the Council on a Single Market For Digital Services (Digital Services Act) and amending Directive 2000/31/EC (OJ L 277/1).

AddedCompromise amendment replacing Amendment(s): 310, 311

AddedRecital 5: (5) In order to achieve the objectives of this Regulation, it should cover providers of services that have the potential to be misused for the purpose of online child sexual abuse. As they are increasingly misused for that purpose, those services should include publicly available number-independent interpersonal communications services, such as messaging services and web-based e-mail services, in so far as those services as are publicly available. As services which enable direct interpersonal and interactive exchange of information merely as a minor ancillary feature that is intrinsically linked to another service, such as chat and similar functions as part of gaming online games, image-sharing and video-hosting are also at risk of misuse for the purpose of online child sexual abuse, they should also be covered by this Regulation. However, given the inherent differences between the various relevant information society services covered by this Regulation and the related varying risks that those services are misused for the purpose of online child sexual abuse and varying ability of the providers concerned to prevent and combat such abuse, the obligations imposed on the providers of those services should be differentiated in an appropriate manner without lowering child protection standards.

AddedRecital 6: (6) Online child sexual abuse can also involve the misuse of information society services offered in the Union by providers established in third countries. In order to ensure the effectiveness of the rules laid down in this Regulation and a level playing field within the internal market, those rules should apply to all providers, irrespective of their place of establishment or residence, that offer services in the Union, as evidenced by a substantial connection to the Union.

AddedRecital 7: (7) This Regulation should be without prejudice to the rules resulting from other Union acts, in particular Directive 2011/93 of the European Parliament and of the Council38 , Directive 2000/31/EC of the European Parliament and of the Council39 and Regulation (EU) 2022/2065 of the European Parliament and of the Council40, Directive 2010/13/EU of the European Parliament and of the Council41 , Regulation (EU) 2016/679 of the European Parliament and of the Council42 , and Directive 2002/58/EC of the European Parliament and of the Council43 .

Recital 8: (8) This Regulation should be considered lex specialis in relation to the generally applicable framework set out in Regulation (EU) 2022/2065 laying down harmonised rules on the provision of certain information society services in the internal market. The rules set out in Regulation (EU) 2022/2065 apply in respect of issues that are not or not fully addressed by this Regulation.

Change 3

AddedRecital 9 a (new): (9a) Encryption, and especially end-to-end encryption, is an increasingly important tool to guarantee the security and confidentiality of the communications of all users, including children. Any restrictions or undermining of the end-to-end encryption can be used and abused by malicious third parties. Nothing in this Regulation should therefore be interpreted as prohibiting, weakening or undermining end-to-end encryption. Providers of information society services should under no circumstances be prevented from providing their services using the highest standards of encryption, considering that such encryption is essential for trust in and security of the digital services.

Recital 10: (10) In the interest of clarity and consistency, the definitions provided for in this Regulation should, where possible and appropriate, be based on and aligned with the relevant definitions contained in other acts of Union law, such as Regulation (EU) 2022/2065.

Change 4

ChangedRecital 11: (11) A substantial connection to the Union should be considered to exist where the relevant information society services has an establishment in the Union or, in its absence, where the number of recipients of the service in one or more Member States is significant in relation to its or their population, or on the basis of the targeting of activities towards one or more Member States. The targeting of activities towards one or more Member States should be determined on the basis of all relevant circumstances, including factors such as the use of a language or a currency generally used in that Member State, or the possibility of ordering products or services, or using a national top level domain. The targeting of activities towards a Member State could also be derived from the availability of a software application in the relevant national software application store, from the provision of local advertising or advertising in the language used in that Member State, or from the handling of customer relations such as by providing customer service in the language generally used in that Member State. A substantial connection should also be assumed where a service provider directs its activities to one or more Member State as set out in Article 17(1), point (c), of Regulation (EU) 1215/2012 of the European Parliament and of the Council44 . Mere technical accessibility of a website from the Union should not, on that ground alone, be considered as establishing a substantial connection to the Union.t…

Change 5

RemovedRecital 15: (15) Some of those providers of relevant information society services in scope of this Regulation may also be subject to an obligation to conduct a risk assessment under Regulation (EU) 2022/2065 with respect to information that they store and disseminate to the public. For the purposes of the present Regulation, and in order to ensure consistency and avoid duplication, those providers may draw on such a risk assessment and complement it with a more specific assessment of the risks of use of their services for the purpose of online child sexual abuse, as required by this Regulation.

AddedRecital 14: (14) With a view to minimising the risk that their services are misused for the dissemination of known or new child sexual abuse material or the solicitation of children, providers of hosting services and providers of publicly available number independent interpersonal communications services should assess such risk stemming, inter alia, from the design, functioning and use of their services that they offer in the Union. That risk assessment should be specific to the services they offer and proportionate to the risk considering its severity and probability. To guide their risk assessment, a non-exhaustive list of elements to be taken into account should be provided. To allow for a full consideration of the specific characteristics of the services they offer, providers should be allowed to take account of additional elements where relevant. As risks evolve over time, in function of developments such as those related to technology and the manners in which the services in question are offered and used, it is appropriate to ensure that the risk assessment is updated regularly and when needed for particular reasons.

RemovedRecital 16: (16) In order to prevent and combat online child sexual abuse effectively, providers of hosting services and providers of publicly available interpersonal communications services should take reasonable measures to mitigate the risk of their services being misused for such abuse, as identified through the risk assessment. Providers subject to an obligation to adopt mitigation measures pursuant to Regulation (EU) 2022/2065 may consider to which extent mitigation measures adopted to comply with that obligation. Mitigation measures may include designing their online interfaces or parts thereof with the highest level of privacy, safety and security for children by default or adopting standards for protection of children, or participating in codes of conduct for protecting children, targeted measures to protect the rights of the child, including functionalities enabling age assurance and age scoring, and age-appropriate parental control tools. Enabling flagging and/or notifying mechanisms and self-reporting functionalities may also serve to address the risk identified in the specific risk assessment pursuant to this Regulation, and to which extent further targeted mitigation measures may be required to comply with this Regulation.

AddedRecital 14 a (new): (14a) The obligation to conduct a risk assessment should apply, in any case, to very large online platforms and to those providers which are substantial, exposed to online child sexual abuse. Providers that qualify as small and micro enterprises as defined in Commission Recommendation 2003/361/EC should carry out a simplified risk assessment. Irrespective of their size or their substantially exposure to online child sexual abuse, providers of online games that operate number-independent interpersonal communications service within their games, platforms primarily used for the dissemination of pornographic content and providers offering services directly targeting children should carry out a risk assessment.

Change 6

ChangedRecital 17 a (new): (17a) Providers should also15: assess,(15) inSome aof separatethose sectionproviders of theirrelevant riskinformation assessment,society theservices voluntaryin usescope of specific technologies for the processing ofthis personalRegulation datamay andalso otherbe datasubject to the extent strictlyan necessaryobligation to detect online child sexualconduct abusea onrisk theirassessment servicesunder andRegulation report(EU) it2022/2065 andrespect to removeinformation onlinethat childthey sexualstore abuseand materialdisseminate fromto theirthe services.public. OnFor the basispurposes of this separated assessment, providers may request to the competentpresent CoordinatingRegulation, Authorityand thein needorder to continue, as part of their mitigation measures, using specific technologies forensure theconsistency processingand ofavoid personalunnecessary databurdens and other data forduplications, those purposes. Following this request ofproviders themay provider,draw theon competentsuch Coordinatinga Authorityrisk shouldassessment havefor the power topurpose requestof the competent judicial authorityrisk ofassessment theunder Memberthis StateRegulation thatand designatedcomplement it orwith anothera independentmore administrativespecific authorityassessment of that Member State to issue an order that authorizes the provider to maintain or implement mitigation measuresrisks thatof consistuse of using specifictheir technologiesservices for the processingpurpose of personal and other data to the extent strictly necessary to detect, report and remove online child sexual abuseabuse, onas theirrequired services.by this Regulation.

Change 7

RemovedRecital 18: (18) In order to ensure that the objectives of this Regulation are achieved, that flexibility should be subject to the need to comply with Union law and, in particular, the requirements of this Regulation on mitigation measures. Therefore, providers of hosting services and providers of publicly available interpersonal communications services should, when designing and implementing the mitigation measures, give importance not only to ensuring their effectiveness, but also to avoiding any undue negative consequences for other affected parties, notably for the exercise of users’ fundamental rights and therefore be the least intrusive as possible. In order to ensure proportionality, when determining which mitigation measures should reasonably be taken in a given situation, account should also be taken of the financial and technological capabilities and the size of the provider concerned. When selecting appropriate mitigation measures, providers should at least duly consider the possible measures listed in this Regulation, as well as, where appropriate, other measures such as those based on industry best practices, including as established through self-regulatory cooperation, and those contained in guidelines from the Commission. When no risk has been detected after a diligently conducted or updated risk assessment, providers should not be required to take any mitigation measures.

AddedRecital 16: (16) In order to prevent and combat online child sexual abuse effectively, providers of hosting services and providers of publicly available number-independent interpersonal communications services should take reasonable measures to mitigate the risk of their services being misused for such abuse, as identified through the risk assessment. Providers subject to an obligation to adopt mitigation measures pursuant to Regulation (EU) 2022/2065 may consider to which extent mitigation measures adopted to comply with that obligation, which may include targeted measures to protect the rights of the child, including age verification and parental control tools, may also serve to address the risk identified in the specific risk assessment pursuant to this Regulation, and to which extent further targeted mitigation measures may be required to comply with this Regulation.

RemovedRecital 20: (20) With a view to ensuring effective prevention and fight against online child sexual abuse, when the provider refuses to cooperate by putting in place the mitigating measures aimed to limit the risk of misuse of a certain service for the purpose of online child sexual abuse, the Coordinating Authorities designated by Member States under this Regulation should be empowered to request, as a measure of last resort, the issuance of detection orders. In order to avoid any undue interference with fundamental rights and to ensure proportionality, that power should be subject to a carefully balanced set of limits and safeguards. For instance, considering that child sexual abuse material tends to be disseminated through hosting services and publicly available interpersonal communications services, and that solicitation of children mostly takes place in publicly available interpersonal communications services, it should only be possible to address detection orders to providers of such services.

AddedRecital 17: (17) To allow for innovation and ensure proportionality and technological neutrality, no exhaustive list of the compulsory mitigation measures should be established. Instead, providers should be left a degree of flexibility to design and implement measures tailored to the risk identified and the characteristics of the services they provide and the manners in which those services are used. In particular, providers are free to design and implement, in accordance with Union law, measures based on their existing practices to detect and prevent, online child sexual abuse in their services. Mitigation measures should aim to contribute to prevent child sexual abuse from happening in the first place, and consequently detection orders should be issued only to providers that have failed to take all reasonable and proportionate mitigation measures to address the risk identified.

RemovedRecital 21: (21) Furthermore, as parts of those limits and safeguards, detection orders should only be issued after a diligent and objective assessment leading to the finding of a significant risk of the specific service concerned being misused for a given type of online child sexual abuse covered by this Regulation. For conducting such assessment a fluent dialogue must be established between the Coordinating Authority and the provider. In order to achieve that aim, it should be possible for the Coordinating Authority to request additional information to the EU Centre, the competent data protection authorities or another public authority or entities. One of the elements to be taken into account in this regard is the likelihood that the service is used to an appreciable extent, that is, beyond isolated and relatively rare instances, for such abuse. An appreciable extent may be understood as being where access to child sexual abuse material could spread rapidly and widely with a particularly wide reach or other means of amplification. The criteria should vary so as to account of the different characteristics of the various types of online child sexual abuse at stake and of the different characteristics of the services used to engage in such abuse, as well as the related different degree of intrusiveness of the measures to be taken to execute the detection order.

AddedRecital 17 a (new): (17a) top Online platforms primarily used for the dissemination of pornographic content and providers of online games falling under the scope of this Regulation should take additional technical and organisational measures to ensure safety and security by design and by default for children.

RemovedRecital 23: (23) In addition, to avoid undue interference with fundamental rights and ensure proportionality, when it is established that those requirements have been met and a detection order is to be issued, it should still be ensured that the detection order is justified, proportionate or related to the specific service, users or group of users, targeted and limited in time so as to ensure that any such negative consequences for affected parties do not go beyond what is strictly necessary to effectively address the significant risk identified. This should concern, in particular, a limitation to an identifiable part or component of the service, such as specific types of channels of a publicly available interpersonal communications service, or to specific users or specific groups of users, to the extent that they can be taken in isolation for the purpose of detection, as well as the specification of the safeguards additional to the ones already expressly specified in this Regulation, such as independent auditing, the provision of additional information or access to data, or reinforced human oversight and review, and the further limitation of the duration of application of the detection order that the Coordinating Authority deems necessary. To avoid unreasonable or disproportionate outcomes, such requirements should be set after an objective and diligent assessment conducted on a case-by-case basis.

AddedRecital 18: (18) In order to ensure that the objectives of this Regulation are achieved, that flexibility should be subject to the need to comply with Union law and, in particular, the requirements of this Regulation on mitigation measures. Therefore, providers of hosting services and providers of publicly available number-independent interpersonal communications services should, when designing and implementing the mitigation measures, give importance not only to ensuring their effectiveness, but also to avoiding any undue negative consequences for other affected parties, notably for the exercise of users’ fundamental rights or if they disproportionately affect people experiencing intersectional discrimination, including on the basis of sex, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age, gender or sexual orientation. Particular care should be taken to assess the impact on girls, who are at a greater risk of being subject to child sexual abuse and gender-based violence. In order to ensure proportionality, when determining which mitigation measures should reasonably be taken in a given situation, account should also be taken of the ongoing effectiveness of the measures, the financial and technological capabilities and the size of the provider concerned. Therefore mitigation measures should always be the least intrusive option possible. When selecting …

RemovedRecital 26: (26) The measures taken by providers of hosting services and providers of publicly available interpersonal communications services to execute detection orders addressed to them should remain strictly limited to what is specified in this Regulation and in the detection orders issued in accordance with this Regulation. In order to ensure the effectiveness of those measures, allow for tailored solutions, remain technologically neutral, and avoid circumvention of the detection obligations, those measures should be taken regardless of the technologies used by the providers concerned in connection to the provision of their services. Therefore, this Regulation leaves to the provider concerned the choice of the technologies to be operated to comply effectively with detection orders and should not be understood as incentivising or disincentivising the use of any given technology, provided that the technologies and accompanying measures meet the requirements of this Regulation. When executing the detection order, providers should take all available safeguard measures to ensure that the technologies employed by them cannot be used by them or their employees for purposes other than compliance with this Regulation, nor by third parties, and thus to avoid undermining the security and confidentiality of the communications of users.

AddedRecital 18 a (new): (18a) Parental control features and functionalities should be limited to allowing allow parents, or guardians only to prevent children from accessing platforms or services that are inappropriate for their age or fall under an age-restriction applicable under national law, or to help prevent them from being exposed to content that is inappropriate. Those measures should be in accordance with Regulation (EU) 2016/679 and the Convention on the Rights of the Child, in particular General Comment 25 (2021) on children’s rights in relation to the digital environment, respect the integrity and safety of the device and not allow unauthorised access or control by third parties.

RemovedRecital 26 a (new): (26a) End-to-end encryption is an important tool to guarantee the security and confidentiality of the communications of users, including those of children. Any weakening of the end-to-end encryption could potentially be abused by malicious third parties. Nothing in this Regulation should therefore be interpreted as prohibiting or weakening end-to-end encryption. However, to the extent strictly necessary and proportionate to mitigate the risk of misuse of their services for the purpose of online child sexual abuse, providers should be authorised by the competent judicial authority or another independent administrative authority to process metadata that can detect suspicious patterns of behaviour without having access to the content of the encrypted communication.

AddedRecital 18 b (new): (18b) Providers should have to establish and operate an accessible, age-appropriate, child-friendly and user-friendly reporting mechanism that allows any user or entity to flag or notify them the presence of potential online child sexual abuse on their services, including self-generated material.

RemovedRecital 27: (27) In order to facilitate the providers’ compliance with the detection obligations, the EU Centre should make available to providers detection technologies that they may choose to use, on a free-of-charge basis, for the sole purpose of executing the detection orders addressed to them. The European Data Protection Board should be consulted on those technologies and the ways in which they should be best deployed to ensure compliance with applicable rules of Union law on the protection of personal data. The advice of the European Data Protection Board should be taken into account by the EU Centre when compiling the lists of available technologies and also by the Commission when preparing guidelines regarding the application of the detection obligations. The providers should not be limited to operate the technologies made available by the EU Centre or by others but they will always be allowed to use technologies that they developed themselves, as long as they meet the requirements of this Regulation.

AddedRecital 18 c (new): (18c) Providers that have identified a risk of use of their services for the purpose of the solicitation of children, should be able to take age verification measures. The implementation of technical procedures to verify the age of users is likely to result in the processing of personal data. Such processing is particularly sensitive in view of its purpose and is subject to Regulation (EU) 2016/679. Age verification systems should strictly comply with the principle of data minimization. In addition, the requirement to set up an age verification system for the legitimate purpose of protecting minors provided for in this Regulation does not justify a general obligation to identify oneself prior to consulting any site offering content. Being able, in principle, to benefit from online public communication services without having to identify oneself, or by using pseudonyms, contributes to the freedom to inform oneself and to the protection of users' privacy. This is an essential element in the exercise of these freedoms on the Internet. Providers should use systems that provide proof of age without revealing the identity of the user as foreseen in Regulation .../... amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity. Such services could, for example, be based on a trusted third-party organization, which would have to incorporate a double anonymity mechanism preventing the trusted third party from identifying the site or applica…

RemovedRecital 29: (29) Providers of hosting services and providers of publicly available interpersonal communications services are uniquely positioned to detect potential online child sexual abuse involving their services. The information that they may obtain when offering their services is often indispensable to effectively investigate and prosecute child sexual abuse offences. Therefore, upon obtaining actual knowledge or awareness on potential child sexual abuse on their services, they should act expeditiously to remove or to disable access to that content and to report it to the EU Centre in accordance with this Regulation. The removal or disabling of access should respect the fundamental rights of the recipients of the service, including the right to freedom of expression and of information. The provider can obtain such actual knowledge or awareness on potential child sexual abuse on their services, inter alia through its own-initiative investigations, through the execution of voluntary detection orders or detection orders, as well as through information flagged by users, self-reported by victims or organisations, such as hotlines, acting in the public interest against child sexual abuse, or through notifications done by the Coordinating authorities or by the EU Centre. Where such reasonable grounds exist, doubts about the potential victim’s age should not prevent those providers from submitting reports. Those reports should contain a minimum of information, as specified in this Regulatio…

AddedRecital 19: (19) In the light of their role as intermediaries facilitating access to software applications that may be misused for online child sexual abuse, providers of software application stores considered as gatekeepers under Regulation (EU) 2022/1925 should be made subject to obligations to take certain reasonable measures to assess and mitigate that risk, specifically preventing children from accessing the software applications in relation to which the provider of software application has explicity informed that it does not permit its use by children or when it has an age rating model in place. The providers should make that assessment in a diligent manner, making efforts that are reasonable under the given circumstances, having regard inter alia to the nature and extent of that risk as well as their financial and technological capabilities and size, and cooperating with the providers of the services offered through the software application where possible.

Change 8

ChangedRecital 30:20: (30)(20) ToWith ensurea thatview to ensuring effective prevention and fight against online child sexual abuseabuse, materialwhen isthe removedprovider asrefuses swiftlyto ascooperate possibleby afterputting itsin detection,place Coordinatingthe Authoritiesmitigating ofmeasures establishmentaimed shouldto havelimit the powerrisk toof requestmisuse competentof judiciala authoritiescertain orservice independentfor administrativethe authoritiespurpose toof issueonline achild removalsexual orderabuse, addressedthe toCoordinating providersAuthorities ofdesignated hostingby services.Member AsStates removalunder orthis disablingRegulation ofshould accessbe mayempowered affectto therequest, rightas ofa usersmeasure whoof havelast providedresort, the material concerned,issuance providersof shoulddetection informorders. suchIn usersorder ofto theavoid reasonsany forundue theinterference removal,with tofundamental enablerights themand to exercise their rightensure ofproportionality, redress,that subjectpower toshould exceptionsbe neededsubject to avoida interferingcarefully withbalanced activitiesset forof thelimits prevention,and detection,safeguards. investigationFor andinstance, prosecutionconsidering ofthat child sexual abuse offences. Removalmaterial orderstends shouldto be addressed,disseminated asthrough ahosting generalservices rule,and topublicly providersavailable ofnumber-independent relevantinterpersonal informationcommunications societyservices, servicesit actingshould asonly recipientbe ofpossible theto serviceaddress indetection accordanceorders withto Regulationproviders (EU)of 2022/2065.such services. As ana exception,matter whereof contentprinciple, isdetection storedorders orshould processedbe asaddressed partto ofthe anservice infrastructureprovider providedacting byas anothera providercontroller. ofHowever, ain relevantsome informationcircumstances, societydetermining service,whether thea removalservice orderprovider mayhas bethe directlyrole addressedof tocontroller itor whereprocessor thecan recipientprove ofparticularly challenging or addressing the servicecontroller cannotmay be identifieddetrimental despiteto reasonablean effortsongoing oninvestigation. theConsequently, partas ofan theexception, Coordinatingit Authority,should orbe wherepossible addressingto theaddress recipienta ofdetection order directly to the service mayprovider bethat detrimentalstores toor anotherwise ongoingprocesses investigation.the data.

Change 9

AddedRecital 21: (21) Furthermore, as parts of those limits and safeguards, detection orders should only be issued by a judicial authority and only after a diligent and objective assessment leading to the finding of reasonable grounds of suspicion for a link, at least an indirect one, of the service concerned being misused by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication for child sexual abuse material. Reasonable grounds are those resulting from any information reliable and legally acquired that suggest that individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication might have a link, even an indirect or remote one, with child sexual abuse material. A link with child sexual abuse material should be deemed to exist where on the basis of objective evidence there is a reasonable suspicion that such material will be detected in the use of a service by a user. Where a channel is operated specifically for the purpose of distributing child sexual abuse material, the subscribers to that channel should be considered linked to child sexual abuse material. Conduct which is legal according to Directive 2011/92/EU or national law transposing it should not be deemed a reasonable ground of suspicion. In order to conduct such an assessment a fluent dialogue needs to be established between the Coordinating Authority and the provider. With the view at achiving that aim, it sho…

AddedRecital 21 a (new): (21a) The definition of child sexual abuse material provided in Article 2 has to be interpreted taking into account Directive 2011/93/EU. Therefore, personal communication between consenting peers as well as children over the age of sexual consent and their partners are out of the scope of the definition insofar those images does not involve any abuse or exploitation or payment or remuneration for pornographic performance and the images have not been disseminated without the consent of the parties involved. Likewise, images produced for medical or scientific purposes, strictly verifiable as such, should remain out of the scope of definition of child sexual abuse material.

AddedRecital 22: (22) It should be ensured that detection orders can be issued only after the Coordinating Authorities and the competent judicial authority having objectively and diligently assessed, identified and weighted, on a case-by-case basis, the likelihood and seriousness of any potential negative consequences for other parties affected, including the users of the service. With a view to avoiding the imposition of excessive burdens, the assessment should also take account of the financial and technological capabilities and size of the provider concerned.

AddedRecital 23: (23) In addition, to avoid undue interference with fundamental rights and ensure proportionality, when it is established that those requirements have been met and a detection order is to be issued, it should still be ensured that the detection order is limited in time so as to ensure that any such negative consequences for affected parties do not go beyond what is strictly necessary to effectively address the significant risk identified. This should concern, in particular, a limitation to individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication in respect of whom there are reasonable grounds of suspicion for a link, even an indirect one, with child sexual abuse material as defined in Article 2 as well as the specification of the safeguards additional to the ones already expressly specified in this Regulation, such as independent auditing, the provision of additional information or access to data, or reinforced human oversight and review, and the further limitation of the duration of application of the detection order that the Coordinating Authority deems necessary. To avoid unreasonable or disproportionate outcomes, such requirements should be set after an objective and diligent assessment conducted on a case-by-case basis.

AddedRecital 24: (24) The competent judicial authority, as applicable in accordance with the detailed procedural rules set by the relevant Member State, should be in a position to take a well-informed decision on requests for the issuance of detections orders. That is of particular importance to ensure the necessary fair balance of the fundamental rights at stake and a consistent approach. Therefore, a procedure should be provided for that allows the providers concerned, the EU Centre on Child Sexual Abuse established by this Regulation (‘EU Centre’) and, where so provided in this Regulation, the competent data protection authority designated under Regulation (EU) 2016/679 to provide their views on the measures in question. They should do so without undue delay, having regard to the important public policy objective at stake and the need to act without undue delay to protect children. In particular, data protections authorities should do their utmost to avoid extending the time period set out in Regulation (EU) 2016/679 for providing their opinions in response to a prior consultation. Furthermore, they should normally be able to provide their opinion well within that time period in situations where the European Data Protection Board has already issued guidelines regarding the technologies that a provider envisages deploying and operating to execute a detection order addressed to it under this Regulation.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
25 September 2026

Cite as

European Parliament (2023). “Changes between LIBE-PR-746811 and A-9-2023-0364”. Text, 16 November 2023. from LIBE-PR-746811, to A-9-2023-0364. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1 (retrieved 25 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-11-16,
  author = {{European Parliament}},
  title = {{Changes between LIBE-PR-746811 and A-9-2023-0364}},
  year = {2023},
  date = {2023-11-16},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1}},
  url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1},
  urldate = {2026-09-25},
  publisher = {EU Parl Watch Research},
  note = {Text. from LIBE-PR-746811, to A-9-2023-0364. Data: European Parliament Open Data (CC BY 4.0)}
}