Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
LIBE-PR-746811 → A-9-2023-0364
- From
- LIBE-PR-746811 report parliamentary committee draft of 19 Apr 2023
- To
- A-9-2023-0364 Plenary report of 16 Nov 2023
- Changes
- 95 changes to the text
- Paragraphs
- +421 added · −186 removed · 51 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 6 of 14: Paragraphs 301–360
Change 55
RemovedArticle 7 – paragraph 8 – subparagraph 3 – point a: (a) where that risk is limited to an identifiable part or component of a service, the required measures are only applied to an identifiable part or component of a service, such as a specific channel of communication or a specific group of users identified with particularity for which the significant risk has been identified, in respect of that part or component;
AddedArticle 7 – paragraph 8 – subparagraph 2: To that end, they shall take into account all relevant parameters, including the availability of sufficiently reliable detection technologies in that they limit to the maximum extent possible, in accordance with the state of the art, the rate of errors regarding the detection, and their suitability and effectiveness for achieving the objectives of this Regulation, as well as the impact of the measures on the rights of the users affected, and require the taking of the least intrusive measures, in accordance with Article 10, from among several equally effective measures.
RemovedArticle 9 – paragraph 2 – subparagraph 1: When the detection order becomes final, the competent judicial authority or independent administrative authority that issued the detection order shall, without undue delay, inform the Coordinating Authority of establishment thereof. The Coordinating Authority of establishment shall then, without undue delay, inform all other Coordinating Authorities through the system established in accordance with Article 39(2).
AddedArticle 7 – paragraph 8 – subparagraph 3 – point a: deleted
RemovedArticle 10 – paragraph 1: 1. Providers of hosting services and providers of interpersonal communication services that have received a detection order shall execute it by installing and operating available technologies to detect the dissemination of known or new child sexual abuse material or the solicitation of children, as applicable, using the corresponding indicators provided by the EU Centre in accordance with Article 46.
AddedArticle 7 – paragraph 8 – subparagraph 3 – point c: (c) subject to paragraph 9, the period of application remains limited to what is strictly necessary and proportionate;
RemovedArticle 10 – paragraph 3 – point c: (c) in accordance with the state of the art and the least intrusive in terms of the impact on the users’ rights to private and family life, including the confidentiality of communication, and to protection of personal data;
AddedArticle 7 – paragraph 9 – subparagraph 1: The competent judicial authority shall specify in the detection order the period during which it applies, indicating the start date and the end date.
RemovedArticle 10 – paragraph 3 – point d a (new): (da) not able to weaken end-to-end encryption.
AddedArticle 7 – paragraph 9 – subparagraph 3: The period of application of detection orders concerning the dissemination of known or new child sexual abuse material shall be proportionate, taking all relevant factor into account, and not exceed 24 months and that of detection orders concerning the solicitation of children shall not exceed 12 months.
AddedArticle 7 – paragraph 9 a (new): 9a. Detections orders shall contain information about the right to appeal to a court of law according to the national legislation.
AddedArticle 8 – paragraph 1 – introductory part: 1. The competent judicial authority shall issue the detection orders referred to in Article 7 using the template set out in Annex I. Detection orders shall include:
AddedArticle 8 – paragraph 1 – point a: (a) information regarding the targeted and proportionate measures to be taken to execute the detection order, including, the individual users, or a specific group of users, either as such or as subscribers to a specific channel of communication, in respect of whom there are reasonable grounds of suspicion for a link, even an indirect one, with child sexual abuse material, the indicators to be used and the safeguards to be provided for, including the reporting requirements set pursuant to Article 9(3) and, where applicable, any additional safeguards as referred to in Article 7(8);
AddedArticle 8 – paragraph 1 – point b: (b) identification details of the competent judicial authority issuing the detection order and authentication of the detection order by that judicial;
AddedArticle 8 – paragraph 1 – point e: (e) whether the detection order issued concerns the dissemination of known or new child sexual abuse material;
AddedArticle 8 – paragraph 1 – point g: (g) a detailed justification of reasons explaining why the detection order is issued and how is necessary, effective and proportionate;
AddedArticle 8 – paragraph 1 – point i: (i) the date, time stamp and electronic signature of the judicial issuing the detection order;
AddedArticle 8 – paragraph 2 – subparagraph 1: The competent judicial authority issuing the detection order shall address it to the main establishment of the provider or, where applicable, to its legal representative designated in accordance with Article 24.
AddedArticle 8 – paragraph 2 – subparagraph 2: The detection order shall be securely transmitted to the provider’s point of contact referred to in Article 23(1), to the Coordinating Authority of establishment and to the EU Centre, through the system established in accordance with Article 39(2).
AddedArticle 8 – paragraph 3: 3. If the provider cannot execute the detection order because it contains manifest errors or does not contain sufficient information for its execution, or it is manifestly unfounded, the provider shall, without undue delay, request the necessary correction or clarification to the Coordinating Authority of establishment, using the template set out in Annex II.
AddedArticle 9 – paragraph 1: 1. Providers of hosting services and providers of number-independent interpersonal communications services that have received a detection order, as well as users affected by the measures taken to execute it, shall have a right to information and effective redress. That right shall include the right to challenge the detection order before the courts of the Member State of the competent judicial authority that issued the detection order.
AddedArticle 9 – paragraph 2 – subparagraph 1: When the detection order becomes final, the competent judicial authority that issued the detection order shall, without undue delay, transmit a copy thereof to the Coordinating Authority of establishment. The Coordinating Authority of establishment shall then, without undue delay, transmit a copy thereof to all other Coordinating Authorities through the system established in accordance with Article 39(2).
AddedArticle 9 – paragraph 4 – subparagraph 1: In respect of the detection orders that the competent judicial authority issued at its request, the Coordinating Authority of establishment shall, where necessary and in any event following reception of the reports referred to in paragraph 3, assess whether any substantial changes to the grounds for issuing the detection orders occurred and, in particular, whether the conditions of Article 7(2) continue to be met. In that regard, it shall take account of additional mitigation measures that the provider may take to address the significant risk identified at the time of the issuance of the detection order.
AddedArticle 9 – paragraph 4 – subparagraph 2: That Coordinating Authority shall request to the competent judicial authority that issued the detection order the modification or revocation of such order, where necessary in the light of the outcome of that assessment. The provisions of this Section shall apply to such requests, mutatis mutandis.
AddedArticle 10 – paragraph 1: 1. Providers of hosting services and providers of number-independent interpersonal communication services that have received a detection order in accordance with to Article 7 shall execute it by installing and operating available, secure and privacy-friendly technologies to detect the dissemination of known or new child sexual abuse material, as applicable, using the corresponding indicators provided by the EU Centre in accordance with Article 46.
AddedArticle 10 – paragraph 2 a (new): 2a. The technologies relied on for the purpose of executing the detection order, regardless of whether they are provided by the EU Centre or procured or developped by the provider itself, shall be audited independently as regards their performance, reliability and security. The audit shall be made publicly available.
AddedArticle 10 – paragraph 3 – introductory part: 3. The technologies shall:
AddedArticle 10 – paragraph 3 – point a: (a) be effective in detecting the dissemination of known or new child sexual abuse material, as applicable;
AddedArticle 10 – paragraph 3 – point b: (b) not be able to permit the acquisition of knowledge of the content of the communications or any other information from the relevant communications than the information strictly necessary to detect, using the indicators referred to in paragraph 1, patterns pointing to the dissemination of known or new child sexual abuse material or the solicitation of children, as applicable;
AddedArticle 10 – paragraph 3 – point c: (c) be in accordance with the technological state of the art and the least intrusive in terms of the impact on the users’ rights to private and family life, including the confidentiality of communication, and to protection of personal data;
AddedArticle 10 – paragraph 3 – point d: (d) be sufficiently reliable, in that they limit to the maximum extent possible the rate of errors regarding the detection of online child sexual abuse, with special attention to avoid deviations and bias with proper testing and training of algorithms and models where applicable, and where such occasional errors occur, they are rectified without delay; and
AddedArticle 10 – paragraph 3 – point d a (new): (da) not apply to end-to-end encrypted communications.
AddedArticle 10 – paragraph 4 – point a: (a) take all the necessary measures to ensure that the technologies and indicators, as well as the processing of personal data and other data in connection thereto, are proportionate and limited to what is strcitly necessary for the sole purpose of detecting the dissemination of known or new child sexual abuse material, as applicable, insofar as strictly necessary to execute the detection orders addressed to them and, unless alleged child sexual abuse material has been confirmed as such, the data is erased immediately;
AddedArticle 10 – paragraph 4 – point b: (b) establish effective internal procedures to prevent and, where necessary, detect and remedy any misuse of the technologies, indicators and personal data and other data referred to in point (a), including unauthorised access to, and unauthorised transfers of, such personal data and other data;
AddedArticle 10 – paragraph 4 – point c: (c) ensure regular human oversight as necessary to ensure that the technologies operate in a sufficiently reliable manner and, where necessary, in particular when potential errors are detected, immediate human intervention;
AddedArticle 10 – paragraph 4 – point d: (d) establish and operate an accessible, age-appropriate and user- and child-friendly mechanism that allows users to submit to it, within a reasonable timeframe, complaints about alleged infringements of its obligations under this Section, as well as any decisions that the provider may have taken in relation to the use of the technologies, including the removal or disabling of access to material provided by users, blocking the users’ accounts or suspending or terminating the provision of the service to the users, and process such complaints in an objective, effective and timely manner;
Article 10 – paragraph 4 – point e: deleted
Change 56
ChangedArticle 10 – paragraph 4 – point f a (new): (fa) ensure privacy by designdesing and by default and, where applicable, without hampering thesafety-by-desing integrityand ofby encryption.default.
Change 57
RemovedArticle 11 – paragraph 1: The Commission, in cooperation with the Coordinating Authorities and the EU Centre and after having conducted a public consultation and consulted the European Data Protection Board, may issue guidelines on the application of Articles 7 to 10, having due regard in particular to relevant technological developments and the manners in which the services covered by those provisions are offered and used.
AddedArticle 10 – paragraph 5 – subparagraph 1 – point a: (a) the fact that it operates technologies to detect child sexual abuse material to execute the detection order, the ways in which it operates those technologies and the impact on the confidentiality of users’ communications;
Change 58
ChangedArticle 1210 – paragraph 2 – subparagraph6: 1:6. Where thea provider submitsdetects apotential reportchild pursuantsexual abuse material through the measures taken to paragraphexecute 1,the detection order, it shall inform the userusers concerned without undue delay, after Europol or the national law enforcement authority of a Member State that received the report pursuant to Article 48 has confirmed that the information to the users would not interfere with activities for the prevention, detection, investigation and prosecution of child sexual abuse offences.
Change 59
RemovedArticle 12 – paragraph 2 – subparagraph 2: deleted
AddedArticle 11 – paragraph 1: The Commission, in cooperation with the Coordinating Authorities and the EU Centre and after having consulted the European Data Potection Board and having conducted a public consultation, may shall issue guidelines on the application of Articles 7 to 10, having due regard in particular to relevant technological developments and trends reported by law enforcement, hotlines and civil society and the manners in which the services covered by those provisions are offered and used.
AddedArticle 12 – paragraph 1: 1. Where a provider of hosting services or a provider of number-independent interpersonal communications services obtains actual knowlege in any manner other than through a removal order issued in accordance with this Regulation of any information indicating potential online child sexual abuse on its services, it shall promptly submit a report thereon to the EU Centre in accordance with Article 13 and providers of hosting services shall expeditiously remove or disable access to it, except where communicated otherwise under Article 48(6) point (b). It shall do so through the system established in accordance with Article 39(2).
AddedArticle 12 – paragraph 2 – subparagraph 1: Where the provider submits a report pursuant to paragraph 1, it shall inform the user concerned without undue delay, except where the EU Centre has communicated otherwise under Article 48(6) point (a), providing information on the main content of the report, on the manner in which the provider has become aware of the potential child sexual abuse concerned, on the follow-up given to the report insofar as such information is available to the provider and on the user’s possibilities of redress, including on the right to submit complaints to the Coordinating Authority in accordance with Article 34.
AddedArticle 12 – paragraph 2 – subparagraph 2: The provider shall inform the user concerned without undue delay, either after having received a communication from the EU Centre indicating that it considers the report to be unfounded as referred to in Article 48(2), or after the expiry of a time period of three months from the date of the report without having received a communication from the EU Centre indicating that the information is not to be provided as referred to in Article 48(6), point (a), whichever occurs first.
Article 12 – paragraph 2 – subparagraph 3: deleted
Change 60
ChangedArticle 12 – paragraph 3: 3. TheProviders providerof hosting services and providers of number-independent interpersonal communication services shall establish and operate an accessible,easy age-appropriateto access, age-appropriate, child-friendly and user-friendly mechanism that allows any users or entity to flag or notify tothem of the providerpresence potentialon onlinetheir childservice sexualof abusespecific onitems of information that the service,individual or entity considers to be potential online child sexual abuse, including self-reportingself-generated tools.material. Those mechanisms shall allow for the submission of notices by users or entities exclusively by electronic means and allow for anonymous reporting already available through anonymous reporting channels as defined by Directive (EU) 2019/1937.
Change 61
RemovedArticle 13 – paragraph 1 – point c: (c) all content data;
AddedArticle 12 – paragraph 3 a (new): 3a. The Commission, in cooperation with Coordinating Authorities and the EU Centre after having conducted a public consultation shall, by [six months from the date of entry into force of this Regulation], adopt implementing acts laying down the practical and operational arrangements for the design of a uniform identifiable notification mechanism referred to in paragraph 3, including for the design of a uniform easily recognisable icon in the user interface. Those implementing acts shall be adopted in accordance with the advisory procedure referred to in Article 87.
RemovedArticle 13 – paragraph 1 – point f: (f) metadata related to the potential online child sexual abuse;
AddedArticle 13 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall submit the report referred to in Article 12 using the template set out in Annex III. They shall make all the reasonable efforts to ensure the quality of the information submitted in order to facilitate the assessment and process by the EU Centre in accordance with Article 49(1). The report shall include:
RemovedArticle 14 – paragraph 1 – subparagraph 1 a (new): Removal orders shall be addressed to providers of relevant information society services acting as recipient of the service in accordance with Regulation (EU) 2022/2065. As an exception, where content is stored or processed as part of an infrastructure provided by another provider of a relevant information society service, the removal order may be directly addressed to it where: / –(a) the recipient of the service cannot be identified despite reasonable efforts on the part of the Coordinating Authority; or / –(b) addressing the recipient of the service might be detrimental to an ongoing investigation.
AddedArticle 13 – paragraph 1 – point c: (c) all content data being reported;
RemovedArticle 14 – paragraph 2: 2. The provider shall execute the removal order as soon as possible and in any event within 24 hours of receipt thereof, unless the removal order indicates a shorter period.
AddedArticle 13 – paragraph 1 – point d: (d) all relevant available data other than content data related to the potential online child sexual abuse;
Change 62
ChangedArticle 1413 – paragraph 31 – point e: (e) anwhether exactthe Uniformpotential Resourceonline Identifierchild and,sexual whereabuse necessary,to additionaltheir informationknowledge forconcerns the identificationdissemination of theknown or new child sexual abuse material;material or the solicitation of children;
Change 63
RemovedArticle 15 – paragraph 2 – subparagraph 1: When the removal order becomes final, the competent judicial authority or independent administrative authority that issued the removal order shall, without undue delay, inform the Coordinating Authority of establishment thereof. The Coordinating Authority of establishment shall then, without undue delay, inform the EU Centre and all other Coordinating Authorities through the system established in accordance with Article 39(2).
AddedArticle 13 – paragraph 1 – point f: deleted
RemovedArticle 16 – paragraph 1: 1. The Coordinating Authority of establishment shall have the power to request the competent judicial authority of the Member State that designated it or an independent administrative authority of that Member State to issue a blocking order requiring a provider of internet access services under the jurisdiction of that Member State to take reasonable measures to prevent users from accessing known child sexual abuse material indicated by any Uniform Resource Identifiers on the list of Uniform Resource Identifiers included in the database of indicators, in accordance with Article 44(2), point (b) and provided by the EU Centre.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=6
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 27 September 2026
Cite as
European Parliament (2023). “Changes between LIBE-PR-746811 and A-9-2023-0364”. Text, 16 November 2023. from LIBE-PR-746811, to A-9-2023-0364. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=6 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-11-16,
author = {{European Parliament}},
title = {{Changes between LIBE-PR-746811 and A-9-2023-0364}},
year = {2023},
date = {2023-11-16},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=6}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-746811/compare/A-9-2023-0364?all=1&part=6},
urldate = {2026-09-27},
publisher = {EU Parl Watch Research},
note = {Text. from LIBE-PR-746811, to A-9-2023-0364. Data: European Parliament Open Data (CC BY 4.0)}
}