lexiara

§5 RISK REVIEW

18. The heterogeneous nature of online platforms and diversity of contexts may require distinct approaches, with certain measures being better suited to some platforms over others. Where a provider of an online platform accessible to minors is deciding how to ensure a high level of safety, privacy and security to minors on its platform, and determining the appropriate and proportionate measures for that purpose, the Commission considers that that provider should, at a minimum, identify and take into account: (a) How likely it is that minors will access its service, notably in view of its nature, purpose, intended use as well as criteria relevant to determine whether the service is accessible to minors. (b) The actual or potential impact on the privacy, safety and security of minors that the online platform may pose or give rise to, based on the 5Cs typology of online risks to children (Annex). This includes an examination of how different aspects of the platform may give rise to these risks, their likelihood and severity, as well as consideration of their positive impact on children’s rights and well-being, taking into consideration the age and evolving capacities of children. For example, aspects such as the purpose of the platform, its design, interface, value proposition, marketing, features, functionalities, number and type of users and uses (actual and expected) may all be relevant. This should include an indication of the level of risk for minors on the platform (e.g. low, medium or high), based on clear criteria, in accordance with existing standards and best practices, for example for child rights impact assessment as mentioned in paragraph 22. (c) The measures that the provider is already taking to prevent and mitigate these risks. (d) Any additional measures that are identified in the review as appropriate and proportionate to ensure a high level of privacy, safety and security for minors on their service. The measures that providers may need to take should address the risks to privacy, safety, and security that originate from the experience of minors with the service, including those risks that originate from the actions of other users of the service. (e) How measures uphold the general principles of Section 4. (f) Metrics that allow the provider to monitor over time the effectiveness of the measures they have in place to address certain risks. (g) The potential positive and negative effects on children’s or other users’ rights of any measure that the provider currently has in place and any additional measures, ensuring that these rights are not disproportionately or unduly restricted and positive effects can be maximised. Children’s or other users’ rights that may be adversely affected by some measures include, for example, children’s rights to participation, privacy, protection of personal data, freedom of expression and information. This is relevant when determining the proportionality of measures. 19. When conducting this review, providers of online platforms accessible to minors should take into consideration the best interests of the child as a primary consideration (25) in line with the Charter and other UNCRC principles (26), as well as to other relevant Union guidance on the matter (27). They should include the perspectives of children by seeking their participation, as well as that of guardians, representatives of other potentially impacted groups and other relevant experts and stakeholders. 20. Providers should consider the most up-to-date available information and insight from scientific and academic sources, including by leveraging other relevant assessments conducted by the provider. They should adhere to the precautionary principle when there is reasonable indication that a particular practice, feature or design choice poses risks to children, taking measures to prevent or mitigate such risks until there is evidence that its effects are not harmful to children. 21. Providers should carry out the review periodically, and at least on an annual basis or whenever they make significant changes to the platform’s design (28) or become aware of other circumstances that affect the platform’s design and operation relevant for ensuring a high level of privacy, safety and security of minors on their online platform. Providers should make the risk review available to the relevant supervisory authorities and publish its outcomes without disclosing sensitive operational or security-related information at the latest before the following review is performed, as well as consider submitting it to the review of independent experts or relevant stakeholders. 22. Existing standards and tools to carry out child rights impact assessments can support providers in carrying out this review. These include, for example, the templates, forms and other guidance provided by UNICEF (29), the Dutch Ministry of the Interior and Kingdom Relations (BZK) (30), or the European standardisation body CEN-CENELEC (31). The Commission may issue additional guidance or tools to support providers in carrying out the review, including through specific tools for child rights impact assessments. Until the publication of this guidance, providers can use existing tools and best practices for these assessments. 23. For providers of VLOPs and VLOSEs this risk review can also be carried out as part of the general assessment of systemic risks under Article 34 of Regulation (EU) 2022/2065, which will complement and go beyond the risk review pursued in accordance with the present guidelines.

· All articles ·

Source: EUR-Lex (Cellar) · retrieved 2026-09-07