Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
LIBE-PR-746811 → A-9-2023-0364
- From
- LIBE-PR-746811 report parliamentary committee draft of 19 Apr 2023
- To
- A-9-2023-0364 Plenary report of 16 Nov 2023
- Changes
- 95 changes to the text
- Paragraphs
- +421 added · −186 removed · 51 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 4 of 14: Paragraphs 181–240
AddedArticle 3 – paragraph 2 – point e – point iii – indent 3: – enabling users to share unsolicited with other users, in particular through private communications;
RemovedArticle 4 – paragraph 1 – point a: (a) adapting, through appropriate technical and operational measures and staffing, the provider’s content moderation or recommender systems, its decision-making processes, the operation or functionalities of the service, or the content or enforcement of its terms and conditions, including the speed, quality and effectiveness of processing notices and reports related to online child sexual abuse and, where appropriate, the expeditious removal of the content notified;
AddedArticle 3 – paragraph 2 – point e – point iii – indent 3 a (new): – Enabling users to indicate personal data in their usernames.
RemovedArticle 4 – paragraph 1 – point a a (new): (aa) adapting the design, features and functions of their services in order to ensure a high level of privacy, safety, and security by design and by default, in particular, for children;
AddedArticle 3 – paragraph 2 – point e a (new): (ea) When carrying out a risk assessment, the provider may take into account any other functionality in accordance with the state of the art to address child sexual abuse.
RemovedArticle 4 – paragraph 1 – point a b (new): (ab) enabling age-appropiate parental control tools;
AddedArticle 3 – paragraph 3 – subparagraph 1: The provider may request the EU Centre to perform an analysis of methodology for risk assessment, including, where appropriate, to perform a test on anonymized data samples made available to the EU Centre, to support the risk assessment.
RemovedArticle 4 – paragraph 1 – point c: (c) initiating or adjusting cooperation, in accordance with competition law, with other providers of hosting services or providers of interpersonal communication services, public authorities, hotlines, civil society organisations or, where applicable, entities awarded the status of trusted flaggers in accordance with Article 22 of Regulation (EU) 2022/2065 .
AddedArticle 3 – paragraph 3 – subparagraph 1 a (new): The provider may request the EU Centre to perform an analysis of methodology for risk assessment, including, where appropriate, to perform a test on anonymized data samples made available to the EU Centre, to support the risk assessment. / Neither the request referred to in the first subparagraph, nor the subsequent analysis that the EU Centre may perform thereunder, shall exempt the provider from its obligation to conduct the risk assessment in accordance with paragraphs 1 and 2 of this Article and to comply with any other obligations set out in this Regulation.
RemovedArticle 4 – paragraph 1 – point c a (new): (ca) reinforcing awareness-raising measures and adapting their online interface for increased user information, including child-appropriate information targeted to the risk identified;
AddedArticle 3 – paragraph 3 – subparagraph 2: The costs incurred by the EU Centre for the support of the risk assessment shall be borne by the requesting provider. However, the EU Centre may bear those costs where the provider is a micro, small or medium-sized enterprise. The EU Centre may reject the request where it is not reasonably necessary to support the risk assessment or does not comply with available budgetary resources. The EU Centre shall provide this support in a timely manner.
RemovedArticle 4 – paragraph 1 – point c b (new): (cb) enabling users to flag or notify online child sexual abuse to the provider through tools that are easily accessible and age-appropriate, including already anonymous reporting channels as defined by Directive (EU) 2019/1937;
AddedArticle 3 – paragraph 5: deleted
RemovedArticle 4 – paragraph 1 – point c c (new): (cc) enabling safe self-reporting capabilities;
AddedArticle 3 – paragraph 6: 6. The Commission in cooperation with Coordinating Authorities and the EU Centre, and after having consulted the European Data Protection Board and having conducted a public consultation, may issue guidelines on the application of paragraphs 1 to 5, having due regard in particular to relevant technological developments and to the manners in which the services covered by those provisions are offered and used.
RemovedArticle 4 – paragraph 1 – point c d (new): (cd) including clearly visible and identifiable age rating information;
AddedArticle 3 – paragraph 6 a (new): 6a. Providers that qualify as small and micro enterprises as defined in Commission Recommendation 2003/361/EC shall carry out a simplified risk assessment by [date of application of this Regulation + 6 months] or, where the provider did not offer the service in the Union by [date of application of this Regulation], by six months from the date at which the provider started offering the service in the Union. / The Commission shall be empowered to adopt delegated acts in accordance with Article 86 of this Regulation in order to provide practical support for micro and small enterprises for carrying out the simplified risk assessment
RemovedArticle 4 – paragraph 1 – point c e (new): (ce) developing awareness systems to alert the users of any potential infringement of this Regulation;
AddedArticle 3 – paragraph 6 b (new): 6b. Irrespective of their size or their substantial, exposure to online child sexual abuse, providers of online games that operate number-independent interpersonal communications service within their games, platforms primarily used for the dissemination of pornographic content and providers offering services directly targeting children shall carry out a risk assessment in accordance with Article 3(1) to (4).
RemovedArticle 4 – paragraph 1 – point c f (new): (cf) using any other measures in accordance with the current or future state of the art which are fit to mitigate the identified risk.
AddedArticle 4 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall put in place reasonable, proportionate, targeted and effective mitigation measures, tailored to their specific services and the risk identified pursuant to Article 3. The decision as to the choice of mitigation measures shall remain with the provider. Such measures shall include some or all of the following:
RemovedArticle 4 – paragraph 2 – point a: (a) effective in mitigating the identified risk, taking into account the characteristics of the service provided and the manner in which that service is used;
AddedArticle 4 – paragraph 1 – point a: (a) testing and adapting, through state of the art appropriate technical and operational measures and staffing, the provider’s content moderation or recommender systems, its decision-making processes, the operation or functionalities of the service, or the content or enforcement of its terms and conditions, including the speed, quality and effectiveness of processing notices and reports of alleged online child sexual abuse and, where appropriate, the expeditious removal of the child sexual abuse material;
RemovedArticle 4 – paragraph 2 – point b: (b) targeted and proportionate in relation to that risk, taking into account, in particular, the provider’s financial and technological capabilities and the number of users;
AddedArticle 4 – paragraph 1 – point a a (new): (aa) adapting the design, features and functions of their services in order to ensure the highest level of privacy, safety, and security by design and by default. / In particular, when the service is directly targeting children, providers shall include all of the following mitigation measures unless they are not technically feasible for the service: / i. limiting users, by default, to establish unsolicited contact with other users directly, in particular through private communications, by asking for user confirmation before allowing an unknown user to communicate and before displaying their communications; / ii. limiting users, by default, to directly share unsolicited content with other users directly, in particular through private communications; / iii. limiting users, by default, to directly share personal contact details with other users, such as phone numbers, home addresses and e-mail addresses, via pattern-based matching; / iv. providing meaningful and proportionate age-appropriate user-device-based parental control tools which allow parents or guardians to exercise appropriate control over children while respecting the fundamental rights and the confidentiality of communications of the child; / v. encouraging children, prior to registering for the service, to talk to consult their parents about how the service works and what parental controls tools are available; vi. providing readily accessible mechanisms for users to block or mute other users; / vii. providing human…
Removed"Seriousness" is an abstract and vague legal term. The risk has already been assessed and identified (risk assessment) by the providers.
AddedArticle 4 – paragraph 1 – point c: (c) initiating or adjusting cooperation, in accordance with competition law, with other providers of relevant information society services, public authorities, hotlines, helplines, civil society organisations or, where applicable, entities awarded the status of trusted flaggers in accordance with Article 22 of Regulation (EU) 2022/2065;
RemovedArticle 4 – paragraph 3: 3. Providers of interpersonal communications services that have identified, pursuant to the risk assessment conducted or updated in accordance with Article 3, a risk of use of their services for the purpose of the solicitation of children, shall take the necessary age assurance measures to reliably identify child users on their services, enabling them to take the mitigation measures.
AddedArticle 4 – paragraph 1 – point c a (new): (ca) informing and reminding users and non-users, such as parents, about the risks related to the use of their services, the nature of the service and the functionalities offered, what constitutes online child sexual abuse and what is typical offender behaviour;
RemovedArticle 4 – paragraph 4 a (new): 4a. On the basis of the separate risk assessment submitted in accordance zith Article 3 (2a), providers may request the Coordinating Authority of establishment to proceed in accordance with Article 5a based on the need of continuing, as part of their mitigation measures, to use specific technologies for the processing of personal and other data to the extent strictly necessary and proportionate to mitigate the risk of misuse of their services for the purpose of online child sexual abuse.
AddedArticle 4 – paragraph 1 – point c b (new): (cb) enabling users according to Article 12 to flag or notify potential online child sexual abuse to the provider;
RemovedArticle 5 – paragraph 1 – point b: (b) any mitigation measures both taken and requested pursuant to Article 4.
AddedArticle 4 – paragraph 1 – point c c (new): (cc) reinforcing awareness-raising measures and adapting their online interface for increased in order to give user and child-friendly information about the risk of online child sexual abuse on its services;
RemovedArticle 5 – paragraph 3 – subparagraph 1: Where necessary for that assessment, that Coordinating Authority may:
AddedArticle 4 – paragraph 1 – point c d (new): (cd) including clearly visible and identifiable information on the minimum age for using the service;
RemovedMoving Article 7.2 of the proposal here to reinforce the consultation and exchange of information between the provider and the coordinating authority prior to any decision pursuant to Article 7.
AddedArticle 4 – paragraph 1 – point c e (new): (ce) Setting up mechanisms to raise awareness among users of any potential infringement by them of this Regulation.
RemovedArticle 5 – paragraph 3 – subparagraph 1 – point a (new): (a) carry out the consultations with the provider that it may deem necessary to determine whether the requirements of Articles 3 and 4 have been met;
AddedArticle 4 – paragraph 2 – introductory part: 2. The mitigation measures shall meet all of the following requirements:
RemovedArticle 5 – paragraph 3 – subparagraph 1 – point b (new): (b) require further information and clarification from the provider within a reasonable time period set by that Coordinating Authority which shall not be longer than two weeks;
AddedArticle 4 – paragraph 2 – point a: (a) they shall be effective and proportionate in mitigating the identified risk, taking into account the characteristics of the service provided and the manner in which that service is used;
RemovedArticle 5 – paragraph 3 – subparagraph 1 – point c (new): (c) request the EU Centre, the competent data protection authorities, another public authority or relevant experts or entities to provide the necessary additional information.
AddedArticle 4 – paragraph 2 – point b: (b) they shall be targeted and proportionate in relation to that risk, the provider’s financial strength, technological and operational capabilities and the number of users and the amount of content that they provide;
Change 43
ChangedArticle 54 – paragraph 42 a– (new):point 4a.c: Where(c) thethey requirementsshall ofbe Articlesapplied 3in a diligent and 4non-discriminatory aremanner, met,having thedue Coordinatingregard, Authorityin shallall issuecircumstances, ato positivethe opinionwhichpotential shallconsequences beof takenthe intomitigation accountmeasures priorfor tothe anyexercise decisionof pursuantfundamental torights Articleof 7.all parties affected;
Change 44
RemovedArticle 5 – paragraph 5: 5. Providers shall, when transmitting the report in accordance with paragraph 1 or further information in accordance with paragraph 3 to the Coordinating Authority of establishment, transmit the report or further information also to the EU Centre.
AddedArticle 4 – paragraph 2 – point d: (d) they shall be introduced, reviewed in light of their effectiveness and adapted in accordance with the state of the art, discontinued or expanded, as appropriate, each time the risk assessment is conducted or updated pursuant to Article 3(4), as soon as possible and in any case within three months from the date referred to therein;
RemovedArticle 5 a (new): Article 5a / Voluntary detection order / 1. Following the request of the provider under Article 4(4a) the Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State to issue an order that authorizes the provider to maintain or implement mitigation measures that consist of using specific technologies for the processing of personal and other data to the extent strictly necessary to detect, report and remove online child sexual abuse on their services. / 2. Before submitting the request, that Coordinating Authority shall request and take into consideration the opinion of the competent data protection authority. / 3. Taking into account this opinion and the assessment submitted by the provider under Article 3(2a), the Coordinating Authority shall have the power to propose to the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State the terms of authorisation for the provider to take measures specified in Article 10 to detect online child sexual abuse on a specific service. / 4. The Coordinating Authority shall decide whether to proceed according to paragraph 3 no later than three months from the provider’s request.
AddedArticle 4 – paragraph 2 – point d a (new): (da) they shall respect the principles of data protection by design and by default, as well as of data minimisation; and
RemovedArticle 6 – paragraph 1 – point a: deleted
AddedArticle 4 – paragraph 2 – point d b (new): (db) they shall not restrict the possibility to use a service anonymously.
Change 45
ChangedArticle 64 – paragraph 1 – point3: b:3. (b)Providers takeof reasonableinterpersonal measurescommunications toservices preventthat childhave usersidentified, frompursuant accessingto the softwarerisk applicationsassessment inconducted relationor toupdated whichin theyaccordance havewith identifiedArticle a3, significanta risk of use of the servicetheir concernedservices for the purpose of the solicitation of children, may take the necessary and proportionate age verification measures to reliably identify children oron where:their services, enabling them to take the mitigation measures.
Change 46
RemovedArticle 6 – paragraph 1 – point b – point i (new): i) the developer of the software application has informed the software application store that its terms and conditions of use do not permit child users,
AddedArticle 4 – paragraph 3 a (new): 3a. When providers put forward age verification systems, they shall meet the following criteria: / (a) Protect the privacy of users and do not disclose or process data gathered for the purposes of age verification for any other purpose; / (b) Not collect any data other than the age of the user for the purposes of age verification; / (c) Not retain personal data on the age verification process after its completion; / (d) Be proportionate to the risks associated to the product or service that presents a risk of misuse for child sexual abuse; / (e) Provide appropriate remedies and redress mechanisms for users whose age is wrongly identified; / (f) Allow selective disclosure of attributes; / (g) Use zero-knowledge protocol; / (h) Allow users to use anonymous accounts; / (i) Not require the identification of each user of a service; / (j) Not retain personal data on the age verification process after its completion; / (k) Not require the processing of biometric data.
RemovedArticle 6 – paragraph 1 – point b – point ii (new): ii) the software application has an appropriate age rating model in place, or
AddedArticle 4 – paragraph 4: 4. Providers of hosting services and providers of number-independent interpersonal communications services shall clearly describe in their terms and conditions the mitigation measures that they have taken. That description shall not include information that may reduce the effectiveness of the mitigation measures.
RemovedArticle 6 – paragraph 1 – point b – point iii (new): iii) the developer of the software application has requested the software application store not to allow child users to download its software applications.
AddedArticle 4 – paragraph 5: 5. The Commission, in cooperation with Coordinating Authorities and the EU Centre and after having consulted the European Data Protection Board and having conducted a public consultation, may issue guidelines on the application of paragraphs 1, 2, 3 and 4, having due regard in particular to relevant technological developments and in the manners in which the services covered by those provisions are offered and used.
RemovedArticle 6 – paragraph 1 – point c: (c) take the necessary age assurance measures to reliably identify child users on their services, enabling them to take the measures referred to in point (b).
AddedArticle 4 – paragraph 5 a (new): 5a. The Commission, in cooperation with Coordinating Authorities and the EU Centre and after having consulted the European Data Protection Board shall, by [date - 12 months from the date of entry into force of this Regulation], issue guidelines on how providers may implement age verification or age assessment measures on application of paragraph (3a), based on selective disclosure of attributes and zero-knowledge protocol.
RemovedArticle 6 a (new): Article 6a / Encrypted services and metadata processing / 1. Nothing in this Regulation shall be interpreted as prohibiting or weakening end-to-end encryption. / 2. On the basis of the risk assessment submitted and, where applicable, further information, the Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State to authorise a provider of hosting services or a provider of interpersonal communications services to process metadata to the extent strictly necessary and proportionate to mitigate the risk of misuse of their services for the purpose of online child sexual abuse. / When assessing whether to request the processing of metadata, the Coordinating Authority shall take into account any interference with the rights to privacy and data protection of the users of the service that such a processing entails and determine whether, in that case, the processing of metadata would be effective in mitigating the risk of use of the service for the purpose of child sexual abuse, and that it is strictly necessary and proportionate. / 3. Without prejudice to Regulation (EU) 2016/679, providers shall inform the users of such processing in their terms and conditions, including information on the possibility to submit complaints to the competent data processing authorities concerning the relevant processing and on the avenues for judic…
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=4
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 27 September 2026
Cite as
European Parliament (2023). “Changes between LIBE-PR-746811 and A-9-2023-0364”. Text, 16 November 2023. from LIBE-PR-746811, to A-9-2023-0364. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=4 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-11-16,
author = {{European Parliament}},
title = {{Changes between LIBE-PR-746811 and A-9-2023-0364}},
year = {2023},
date = {2023-11-16},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=4}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=4},
urldate = {2026-09-27},
publisher = {EU Parl Watch Research},
note = {Text. from LIBE-PR-746811, to A-9-2023-0364. Data: European Parliament Open Data (CC BY 4.0)}
}