Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

LIBE-PR-746811 → A-9-2023-0364

From
LIBE-PR-746811 report parliamentary committee draft of 19 Apr 2023
To
A-9-2023-0364 Plenary report of 16 Nov 2023
Changes
95 changes to the text
Paragraphs
+421 added · −186 removed · 51 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse
Title (to)
on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 5 of 14: Paragraphs 241–300

AddedArticle 4 a (new): Article4a / Mitigation measures for platforms primarily used for the dissemination of pornographic content / Where an online platform is primarily used for the dissemination of pornographic content, the platform shall take the necessary technical and organizational measures to ensure: / a. functionalities according to Article 12(3) enabling users to flag or notify potential online child sexual abuse; / b. adequate professional human content moderation to rapidly process notices of potential child sexual abuse material; / c. automatic mechanisms and interface design elements to inform users about external resources in the user’s region on preventing child sexual abuse, counselling by specialist helplines, victim support and educational resources by hotlines and child protection organizations; / d. automatic detection of searches for child sexual abuse material, warning and advice alerts displayed to users doing such searches, and flagging of the search and the user for human moderation; / e. functionalities enabling age verification that meet the criteria of Article 4a (new) of this Regulation.

RemovedArticle 7 – paragraph 1: 1. The Coordinating Authority of establishment shall have the power, when the requirements of Articles 3, 4, 5 or 5a have not been met, to request the competent judicial authority of the Member State that designated it or another independent administrative authority of that Member State to issue a detection order requiring a provider of hosting services or a provider of interpersonal communications services under the jurisdiction of that Member State to take the measures specified in Article 10 to detect online child sexual abuse on a specific service.

AddedArticle 4 b (new): Article4b / Mitigation measures for number-independent interpersonal communications service within games / Providers of online games that operate number-independent interpersonal communications service within their games, shall take all of the following mitigation measures in addition to the requirements referred to in Articles 3 and 4: / 1. prevent users from initiating unsolicited contact with other users; / 2. facilitate functionalities according to Article 12(3) enabling users to flag or notify potential online child sexual abuse / 3. provide technical measures and tools that allow users to manage their own privacy, visibility, reachability and safety and that are set to the most private and secure levels by default; / 4. provide tools in a prominent way on their platform that allow users or their guardians or legal representatives and potential victims to seek help from their local helpline.

RemovedArticle 7 – paragraph 2 – subparagraph 1: The Coordinating Authority of establishment shall request the issuance of the detection order and the competent judicial authority or independent administrative authority shall issue the detection order where it considers that the following conditions are met:

AddedArticle 5 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall transmit, by three months from the date referred to in Article 3(4), to the Coordinating Authority of establishment a report specifying the following:

RemovedFor clarity purposes, moving Article 7.4 here and adding a new point (b).

AddedArticle 5 – paragraph 1 – point a: (a) the process and the results of the risk assessment conducted or updated pursuant to Article 3;

RemovedArticle 7 – paragraph 2 – subparagraph 1 – point a (new): (a) there is evidence of a significant risk of the service being used for the purpose of online child sexual abuse, within the meaning of paragraphs 5, 6 and 7, as applicable;

AddedArticle 5 – paragraph 3 – subparagraph 1: Where necessary for that assessment, that Coordinating Authority may: / (a) carry out the consultations with the provider that it may deem necessary to determine whether the requirements of Articles 3 and 4 have been met; / (b) require further information and clarification from the provider within a reasonable time period set by that Coordinating Authority which shall not be longer than two weeks; / (c) request the EU Centre, the competent data protection authorities, another national public authority or relevant experts or entities to provide the necessary additional information.

RemovedArticle 7 – paragraph 2 – subparagraph 1 – point b (new): (b) mitigation measures put in place by the provider are not considered effective and proportionate to the risk of the misuse of the service offered or the service provider fails to conduct the risk assessment, the risk mitigation or the risk reporting obligations set out in this Regulation.

AddedArticle 5 – paragraph 3 – subparagraph 2: deleted

RemovedArticle 7 – paragraph 2 – subparagraph 1 a (new): The reasons for issuing the detection order shall outweigh negative consequences for the rights and legitimate interests of all parties affected, having regard in particular to the need to ensure a fair balance between the fundamental rights of those parties.

AddedArticle 5 – paragraph 4: 4. Without prejudice to Articles 7 and 27 to 29, where the Coordinating Authorithy of establishment considers that the requirements of Articles 3 and 4 have not been met, that Coordinating Authority shall have the power to address a reasoned decision to the provider requiring it to re-conduct or update the risk assessment or to take the necessary mitigation measures so as to ensure that Articles 3 and 4 are complied with, within a reasonable time period set by that Coordinating Authority. That time period shall not be longer than one month.

AddedArticle 5 – paragraph 4 a (new): 4a. The provider may, at any time, request the Coordinating Authority of establishment to review and, where appropriate, amend or revoke a decision as referred to in paragraph 4. The Coordinating Authority shall, within three months of receipt of the request, adopt a reasoned decision on the request based on objective factors and notify the provider of that decision.

AddedArticle 5 – paragraph 4 b (new): 4b. Where the requirements of Articles 3 and 4 are met, the Coordinating Authority shall issue a positive opinion, which shall be transmitted to the EU Centre and taken into account prior to any decision pursuant to Article 7.

AddedArticle 5 – paragraph 5: 5. The Coordinating Authority of establishment shall transmit the report referred to in paragraph 1 to the EU Centre, as well as any further information resulting from paragraph 3 and, where applicable, the positive opinion issued according to paragraph 4c.

AddedArticle 5 – paragraph 6: 6. Providers shall, upon request, transmit the report to the providers of software application stores, insofar as necessary for the compliance with the obligations set out in Article 6. Where necessary, they may remove confidential information from the reports.

AddedArticle 6 – paragraph 1 – introductory part: 1. Providers of software application stores considered as gatekeepers under the Regulation (EU) 2022/1925 shall, based on the information provided by the providers of software applications:

AddedArticle 6 – paragraph 1 – point a: (a) indicate that the provider of software application does not permit its use by children or that the software application has an age rating model in place;

AddedArticle 6 – paragraph 1 – point b: (b) when, according to Union law, parental consent is required for children to access the sofware application, make reasonable efforts to verify that the consent is given or authorised by the holder of parental responsibility over the child, taking into consideration the available technology.

AddedArticle 6 – paragraph 1 – point c: deleted

AddedArticle 6 – paragraph 2: 2. Providers of software application stores considered as gatekeepers under the Regulation (EU) 2022/1925 may, when the provider of software application has indicated to the provider of software application store that it does not permit its use by children, take additional measures to implement those restrictions on children, including reasonable measures to prevent children from accessing those software applications. When putting in place age verification systems, providers of software application stores shall meet the criteria set out in Article 4 (3a) of this Regulation.

AddedArticle 6 – paragraph 3: 3. Where software application stores take measures under this Article, those software application stores shall not be exempted from the obligations set out in this Regulation.

AddedArticle 6 – paragraph 4: 4. The Commission, in cooperation with Coordinating Authorities and the EU Centre and after having consulted the European Data Protection Board and after having conducted a public consultation, may issue guidelines on the application of paragraph 1 and 2 having due regard in particular to relevant technological developments and to the manners in which the services covered by that provision are offered and used.

AddedArticle 7 – paragraph 1: 1. The Coordinating Authority of establishment shall have the power, as a last resort after all the measures in Article 3, 4 and 5 have been exhausted, to request the competent judicial authority of the Member State that designated it to issue a detection order requiring a provider of hosting services or a provider of number-independent interpersonal communications services under the jurisdiction of that Member State to take the measures specified in Article 10 to detect child sexual abuse material on a specific service. / The detection order shall be targeted, specified and limited to individual users, a specific group of users, either as such or as subscribers to a specific channel of communication, in respect of whom there are reasonable grounds of suspicion for a link, even an indirect one, with child sexual abuse material as defined in Article 2. / Interpersonal communications to which end-to-end encryption is, has been or will be applied shall not be subject to the measures specified in Article 10. / Detection orders shall be addressed to the service provider acting as controller in accordance with Regulation (EU) 2016/679. By way of exception, the detection order may be directly addressed to the service provider that stores or otherwise processes the data on behalf of the controller, where: / (a) the controller cannot be identified despite reasonable efforts on the part of the issuing authority; or / (b) addressing the controller might be detrimental to an ongoing inve…

AddedArticle 7 – paragraph 2 – subparagraph 1: Based on a reasoned justification, the Coordinating Authority of establishment shall, request the issuance of the detection order and the competent judicial authority shall issue the detection order where it considers that all the following conditions are simultaneously met: / (a) there are reasonable grounds of suspicion on individual users, or on a specific group of users, either as such or as subscribers to a specific channel of communication, in respect of whom there is a link, even an indirect one, with child sexual abuse material as defined in Article 2. Reasonable grounds of suspicion are those resulting from any information reliable and legally acquired that suggest that individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication might have a link, even an indirect or remote one, with online child sexual abuse material. / (b) the mitigation measures put in place by the provider have insufficient material impact on limiting the identified risk or the service provider fails to to put in place reasonable and proportionate mitigation measures set out in this Regulation. / (c) issuing the detection order is necessary and proportionate and outweighs negative consequences for the rights and legitimate interests of all parties affected, having regard in particular to the need to ensure a fair balance between the fundamental rights of those parties, and without jeopardising the security of communications.

Article 7 – paragraph 2 – subparagraph 2: deleted

Change 47

RemovedIdea included in Article 5.3.

AddedArticle 7 – paragraph 3 – subparagraph 1 – introductory part: Where the Coordinating Authority of establishment takes the view that all the conditions of paragraph 2 have been met, it shall:

RemovedArticle 7 – paragraph 3 – subparagraph 1 – introductory part: Where the Coordinating Authority of establishment takes the preliminary view that the conditions of paragraph 2 have been met, it shall:

AddedArticle 7 – paragraph 3 – subparagraph 1 – point a: (a) establish a draft request to the competent judicial authority of the Member State that designated it for the issuance of a detection order, specifying the factual and legal grounds upon which the request is based and the duration of the order, as well as, the main elements of the content of the detection order it intends to request and the reasons for requesting it;

Change 48

ChangedArticle 7 – paragraph 3 – subparagraph 21 – introductory part: Where, having regard to the comments of the provider andpoint thed: opinion(d) ofinvite the EU Centre, that Coordinating Authority continues to be of theand viewin thatparticular theits conditionsTechnology ofCommittee, paragraphto 2provide haveits beenopinion met,on the provider shall do all of thedraft following,request, within a reasonable time period setof byfour thatweeks Coordinatingfrom Authority,the whichdate cannotof exceedreceiving fourthe weeks:draft request.

Change 49

RemovedArticle 7 – paragraph 3 – subparagraph 2 – point b: (b) where the draft implementation plan concerns an intended detection order concerning new child sexual abuse material or the solicitation of children other than the renewal of a previously issued detection order without any substantive changes, conduct a data protection impact assessment and a prior consultation procedure as referred to in Articles 35 and 36 of Regulation (EU) 2016/679, respectively, in relation to the measures set out in the implementation plan;

AddedArticle 7 – paragraph 3 – subparagraph 2 – introductory part: Where, having regard to the comments of the provider and the opinion of the EU Centre, that Coordinating Authority continues to be of the view that the conditions of paragraph 2 have been met and prior to requesting the competent judicial authority the issuance of the detection order, it shall request the provider to do all of the following, within a reasonable time period set by that Coordinating Authority, which cannot exceed four weeks:

RemovedJoint Opinion of the EDPB and the EDPS 04/2022 (point 104)

AddedArticle 7 – paragraph 3 – subparagraph 2 – point a: (a) draft an implementation plan setting out the measures it envisages taking to execute the intended detection order, including detailed information regarding the envisaged technologies and their technical feasibility and safeguards and if any, the negative impacts and safeguards on the rights of all parties involved. The provider may consult the EU Centre, and in particular its Technology Committee, to obtain support in identifying appropriate measures in this respect;

RemovedArticle 7 – paragraph 3 – subparagraph 3: Where, having regard to the implementation plan of the provider and the opinion of the data protection authority, that Coordinating Authority continues to be of the view that the conditions of paragraph 2 have met, it shall submit the request for the issuance of the detection, adjusted where appropriate, to the competent judicial authority or independent administrative authority. It shall attach the implementation plan of the provider and the opinions of the EU Centre and the data protection authority to that request.

AddedArticle 7 – paragraph 3 – subparagraph 2 – point b: (b) where the draft implementation plan concerns the use of any specific technology for the purpose of complying with an intended detection order concerning new child sexual abuse material other than the renewal of a previously issued detection order without any substantive changes, conduct a data protection impact assessment and a prior consultation procedure as referred to in Articles 35 and 36 of Regulation (EU) 2016/679, respectively, in relation to the measures set out in the implementation plan;

RemovedArticle 7 – paragraph 4 – subparagraph 1: deleted / (deleted) / (deleted)

AddedArticle 7 – paragraph 3 – subparagraph 2 – point c: (c) where point (b) applies, or where the conditions of Articles 35 and 36 of Regulation (EU) 2016/679 are met, adjust the draft implementation plan, where necessary in view of the outcome of the data protection impact assessment and in order to take due account of the opinion of the data protection authority provided in response to the prior consultation;

RemovedMoved to Article 7.2.

AddedArticle 7 – paragraph 3 – subparagraph 2 – point d: (d) submit to that Coordinating Authority the implementation plan, where applicable attaching the opinion of the competent data protection authority and specifying how the implementation plan has been adjusted to take due account of the outcome of the data protection impact assessment and of that opinion.

RemovedArticle 7 – paragraph 4 – subparagraph 2 – introductory part: When assessing whether the conditions of paragraph 2 have been met, account shall be taken of all relevant facts and circumstances of the case at hand, in particular:

AddedArticle 7 – paragraph 3 – subparagraph 3: Where, having regard to the implementation plan of the provider and the opinion of the data protection authority and, where applicable, the opinion issued in accordance with article 5 (4c), that Coordinating Authority continues to be of the view that the conditions of paragraph 2 have been met, it shall submit the request for the issuance of the detection order, adjusted where appropriate, to the competent judicial authority. It shall attach the implementation plan of the provider and the opinions of the EU Centre and the data protection authority to that request.

RemovedArticle 7 – paragraph 4 – subparagraph 2 – point a: (a) the risk assessment conducted or updated and any mitigation measures taken by the provider pursuant to Articles 3 and 4;

AddedArticle 7 – paragraph 4: deleted / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted)

RemovedArticle 7 – paragraph 4 – subparagraph 2 – point b: (b) any additional information obtained pursuant to Article 5(3) and (4) where applicable;

AddedArticle 7 – paragraph 5 – introductory part: 5. As regards detection orders concerning the dissemination of known child sexual abuse material, the reasonable grounds of suspicion referred to in paragraph 2, point (a), shall be deemed to exist where the following conditions are met:

RemovedArticle 7 – paragraph 4 – subparagraph 2 – point d: (d) the opinions of the EU Centre and of the data protection authority submitted in accordance with paragraph 3 and, where applicable, the opinion of the Coordinating Authority issued in accordance with Article 5(4a).

AddedArticle 7 – paragraph 5 – point a: (a) the mitigation measures that the provider has taken, have insufficient material impact on limiting the systemic risk and the service is being used by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication, to an appreciable extent, for the dissemination of known child sexual abuse material;

RemovedArticle 7 – paragraph 4 – subparagraph 3: Where that Coordinating Authority substantially deviates from the opinion of the EU Centre or the data protection authorities, it shall inform the EU Centre or the data protection authorities and the Commission thereof, specifying the points at which it deviated and the main reasons for the deviation.

AddedArticle 7 – paragraph 5 – point b: (b) there is evidence of the service, having been used in the past 12 months by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication to an appreciable extent for the dissemination of known child sexual abuse material.

Change 50

ChangedArticle 7 – paragraph 56 – introductory part: 5.6. As regards detection orders concerning the dissemination of knownnew child sexual abuse material, the significantreasonable riskgrounds of suspicion referred to in paragraph 2 point (a) shall be deemed to exist where the following conditions are met:

Change 51

ChangedArticle 7 – paragraph 56 – point a: (a) despite the mitigation measures that the provider has takentaken, have insufficient material impact on limiting the systemic risk and the service is being used by individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication, to an appreciable extentextent, for the dissemination of knownnew child sexual abuse material;

Change 52

ChangedArticle 7 – paragraph 6 – introductorypoint part:b: 6.(b) Asthere regardsis detectionevidence ordersof concerningthe service, having been used in the disseminationpast of12 newmonths childby sexualindividual abuseusers, material,or thea significantspecific riskgroup referredof tousers, ineither paragraphas 2such shallor beas deemedsubscribers to exista wherespecific channel of communication to an appreciable extent for the followingdissemination conditionsof arenew met:child sexual abuse material.

Change 53

RemovedArticle 7 – paragraph 7 – subparagraph 1 – introductory part: As regards detection orders concerning the solicitation of children, the significant risk referred to in paragraph 2 shall be deemed to exist where the following conditions are met:

AddedArticle 7 – paragraph 6 – point c: deleted / (deleted) / (deleted)

RemovedArticle 7 – paragraph 7 – subparagraph 2: The detection orders concerning the solicitation of children shall apply only to interpersonal communications between a child user and an adult.

AddedArticle 7 – paragraph 7: deleted / (deleted) / (deleted) / (deleted) / (deleted)

Change 54

ChangedArticle 7 – paragraph 8 – subparagraph 1: The Coordinating Authority of establishment when requesting the issuance of detection orders, and the competent judicial or independent administrative authority when issuing the detection order, shall,shall in accordance with Article 8 of Regulation (EU) 2022/2065,2022/2065 target and specify it in such a manner that the negative consequences referred to in paragraph 2 (c) remain limited to what is strictly necessary, justifiable and proportionate to effectively address the significant risk referred to in pointtarget (a)individual thereof,users, andor limita thespecific detectiongroup orderof tousers, aneither identifiableas partsuch or component of a service,as suchsubscribers asto a specific channel of communication or aas specificreferred groupto ofin userspoint identified(a) withthereof, particularitywhile fornot whichjeopardising the significant risk hassecurity beenof identified.communications.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2023). “Changes between LIBE-PR-746811 and A-9-2023-0364”. Text, 16 November 2023. from LIBE-PR-746811, to A-9-2023-0364. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=5 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-11-16,
  author = {{European Parliament}},
  title = {{Changes between LIBE-PR-746811 and A-9-2023-0364}},
  year = {2023},
  date = {2023-11-16},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=5}},
  url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=5},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from LIBE-PR-746811, to A-9-2023-0364. Data: European Parliament Open Data (CC BY 4.0)}
}