Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 19 Apr 2023

LIBE-PR-746811

on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse

To · plenary report· 16 Nov 2023

A-9-2023-0364

on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse

+421 added · −186 removed · 51 changed paragraphs, packaging included.

Part 2 of 14: Paragraphs 61–120

Added:Recital 25: deleted

Added:Recital 26: (26) The measures taken by providers of hosting services and providers of publicly available number-independent interpersonal communications services to execute detection orders addressed to them should remain strictly limited to what is specified in this Regulation and in the detection orders issued in accordance with this Regulation. In order to ensure the effectiveness of those measures, allow for tailored solutions, remain technologically neutral, and avoid circumvention of the detection obligations, those measures should be taken regardless of the technologies used by the providers concerned in connection to the provision of their services. Therefore, this Regulation leaves to the provider concerned the choice of the technologies to be operated to comply effectively with detection orders and should not be understood as incentivising or disincentivising the use of any given technology, provided that the technologies and accompanying measures meet the requirements of this Regulation. When executing the detection order, providers should take all available safeguard measures to ensure that the technologies employed by them cannot be used by them or their employees for purposes other than compliance with this Regulation, nor by third parties, and thus to avoid undermining the security and confidentiality of the communications of users, while ensuring the effective detection of child sexual abuse material and the balance of all the fundamental rights at stake. In that regard, …

Added:Recital 27: (27) In order to facilitate the providers’ compliance with the detection obligations, the EU Centre should make available to providers technologies that they may choose to use, on a free-of-charge basis, for the sole purpose of executing the detection orders addressed to them. The European Data Protection Board must be consulted on the use of those technologies and the ways in which they should be best deployed to ensure compliance with applicable rules of Union law on the protection of personal data. The advice of the European Data Protection Board should be taken into account by the EU Centre when compiling the lists of available technologies and also by the Commission when preparing guidelines regarding the application of the detection obligations. The providers should not be limited to operating the technologies made available by the EU Centre or by others but should always be allowed to use or technologies that they developed themselves, as long as they meet the requirements of this Regulation and other applicable Union law, such as Regulation (EU) 2016/679. Those technologies should be independently audited as regards their performance and reliability.

Added:Recital 27 a (new): (27a) Since the Commission consultations to the EDPB regarding several aspects of this Regulation will entail more work for the EDPB, its budget and staffing should be adapted accordingly. The situation of national authorities, who likewise will be regularly consulted by service providers, should also reflect their increased responsibilities.

Added:Recital 28: (28) With a view to constantly assess the performance of the detection technologies and ensure that they are sufficiently accurate and reliable, as well as to identify false positives and false negatives and avoid to the extent erroneous reporting to the EU Centre, providers should ensure adequate human oversight and, where necessary, human intervention, adapted to the type of detection technologies and the type of online child sexual abuse at issue. Such oversight should include regular assessment of the rates of false negatives and false positives generated by the technologies, based on an analysis of anonymised representative data samples. Providers should ensure that staff carrying out such task is adequately trained.

Added:Recital 29: (29) Providers of hosting services, and providers of publicly available number-independent interpersonal communications services are uniquely positioned to detect potential online child sexual abuse involving their services. The information that they may obtain when offering their services is often indispensable to effectively investigate and prosecute child sexual abuse offences. Therefore, upon obtaining actual knowledge on potential online child sexual abuse on their services, they should act expeditiously to remove or to disable access to that content and to report it to the EU Centre in accordance with this Regulation. The removal or disabling of access should respect the fundamental rights of the recipients of the service, including the right to freedom of expression and of information. / In the interest of effectiveness, it should be immaterial in which manner they obtain such awareness. Providers can obtain such actual knowledge on potential online child sexual abuse on their services, for example, through its own-initiative investigations, through the execution of detection orders, through notifications done by the Coordinating Authorities, as well as through information flagged by users, self-reported by victims or organisations, such as hotlines, acting in the public interest against child sexual abuse. To this end, it is important that providers, regardless of their size, have the obligation to put in place mechanisms that facilitate the flagging or notification o…

Added:Recital 30: (30) To ensure that online child sexual abuse material is removed as swiftly as possible after its detection and in order to stop or limit its dissemination, Coordinating Authorities of establishment should have the power to request competent judicial authorities to issue a removal order addressed to providers of hosting services. As removal or disabling of access may affect the right of users who have provided the material concerned, providers should, without undue delay, inform such users of the reasons for the removal, to enable them to exercise their right of redress, subject to exceptions, established for a limited time period, needed to avoid interfering with activities for the prevention, detection, investigation and prosecution of child sexual abuse offences. As a matter of principle, removal orders should be addressed to the service provider acting as a controller. However, in some circumstances, determining whether a service provider has the role of controller or processor can prove particularly challenging or addressing the controller could be detrimental to an ongoing investigation. Consequently, by way of derogation, it should be possible to address a removal order directly to the service provider that stores or otherwise processes the data.

Recital 31: (31) The rules of this Regulation should not be understood as affecting the requirements regarding removal orders set out in Regulation (EU) 2022/2065.

Change 10

Removed:Recital 33: (33) In the interest of consistency, efficiency and effectiveness and to minimise the risk of circumvention, such blocking orders should be based on the list of Uniform Resource Identifiers, leading to specific items of verified child sexual abuse, compiled and provided centrally by the EU Centre on the basis of diligently verified submissions by the relevant authorities of the Member States. In order to avoid the taking of unjustified or disproportionate measures, especially those that would unduly affect the fundamental rights at stake, notably, in addition to the rights of the children, the users’ freedom of expression and information and the providers’ freedom to conduct a business, appropriate limits and safeguards should be provided for. In particular, it should be ensured that the burdens imposed on the providers of internet access services concerned are not unreasonable, that the need for and proportionality of the blocking orders is diligently assessed also after their issuance and that both the providers and the users affected have effective means of judicial as well as non-judicial redress.

Added:Recital 34: (34) Considering that acquiring, possessing, knowingly obtaining access and transmitting child sexual abuse material constitute criminal offences under Directive 2011/93/EU, it is necessary to exempt providers of relevant information society services from criminal liability when they are involved in such activities, including when carrying out voluntary own-initiative investigations, or taking other measures, insofar as their activities remain strictly limited to what is needed for the purpose of complying with their obligations under the Union law, including this Regulation and they act in good faith and in a diligent manner.

Removed:Recital 33 a (new): (33a) To prevent the dissemination of the known child sexual abuse material to users in the Union, online search engines and any other artificial intelligence systems should be subject to delisting orders. Coordinating Authorities should have the power to issue a delisting order addressed to the provider of online search engines or any other artificial intelligence systems under the jurisdiction of the Member State that designated them to take reasonable measures to delist a particular resource or resources indicating specific items of known child sexual abuse material.

Added:Recital 35: (35) Each act of dissemination of child sexual abuse material, including the non-consensual dissemination of self-generated material, is a criminal offence that affects the rights of the victims depicted, of whom the vast majority are girls. Repeated dissemination of child sexual abuse material constitutes a form of revictimization which could cause long-lasting negative consequences on the victim, and may reach extreme level in cases of so-called ‘highly traded’ material. Victims or their parents and guardians or legal representatives acting on their behalf should therefore have the right to obtain, upon request, from the EU Centre yet via the Coordinating Authorities, relevant information if known child sexual abuse material depicting them is reported by providers of hosting services or providers of publicly available number-independent interpersonal communications services in accordance with this Regulation. In dealing with such requests from cases of highly traded child sexual abuse material, particular care should be taken by the EU Centre and Coordinating Authorities to ensure the safeguarding of the victims concerned. For that purpose, staff dealing with such cases shall be specifically trained to interact with victims of serious abuse. / This information should be provided, within a reasonable period of time, in the language indicated by the victim, in a confidential, age-appropriate, accessible, understandable and gender-sensitive manner and tailored to the specific …

Removed:Recital 35: (35) Each act of dissemination of child sexual abuse material is a criminal offence that affects the rights of the victims depicted. Repeated dissemination of child sexual abuse material constitutes a form of revictimisation and may reach extreme level in cases of so-called 'highly traded' material. Victims should have the right to obtain, upon request, from the EU Centre yet via the Coordinating Authorities, relevant information if known child sexual abuse material depicting them is reported by providers of hosting services or providers of publicly available interpersonal communications services in accordance with this Regulation. In dealing with such requests from cases of highly traded child sexual abuse material, particular care should be taken by the EU Centre and Coordinating Authorities to ensure the safeguarding of the victims concerned.

Added:Recital 36: (36) Given the impact on the rights of victims depicted in such known child sexual abuse material and the typical ability of providers of hosting services to limit that impact by helping ensure that the material is no longer available on their services, those providers should assist victims or their parents and guardians or legal representatives who request the removal or disabling of access of the material in question in a timely manner, in order to minimise the impact that such offences have on the physical and mental health of the victim. That assistance should remain limited to what can reasonably be asked from the provider concerned under the given circumstances, having regard to factors such as the content and scope of the request, the steps needed to locate the items of known child sexual abuse material concerned and the means available to the provider. The assistance could consist, for example, of helping to locate the items, carrying out checks and removing or disabling access to the items. Considering that carrying out the activities needed to obtain such removal or disabling of access can be painful or even traumatic as well as complex, victims should also have the right to be assisted and receive adequate support by specifically trained staff of the EU Centre in this regard, via the Coordinating Authorities.

Removed:Recital 36: (36) Given the impact on the rights of victims depicted in such known child sexual abuse material and the typical ability of providers of hosting services to limit that impact by helping ensure that the material is no longer available on their services, those providers should assist victims who request the removal or disabling of access of the material in question. Parents or guardians should have equal legal standing to exercise victim's rights when the victim is not able to do so due to age or other limitations. That assistance should remain limited to what can reasonably be asked from the provider concerned under the given circumstances, having regard to factors such as the content and scope of the request, the steps needed to locate the items of known child sexual abuse material concerned and the means available to the provider. The assistance could consist, for example, of helping to locate the items, carrying out checks and removing or disabling access to the items. Considering that carrying out the activities needed to obtain such removal or disabling of access can be painful or even traumatic as well as complex, victims should also have the right to be assisted by the EU Centre in this regard, via the Coordinating Authorities.

Added:Recital 37: (37) To ensure the efficient management of such victim support functions, victims should be informed about the existence of such functions and be allowed to contact and rely on the Coordinating Authority that is most accessible to them, which should channel all communications between victims and the EU Centre.

Removed:Recital 38: (38) For the purpose of facilitating the exercise of the victims’ right to information and of assistance and support for removal or disabling of access, victims should be allowed to indicate the relevant item or items of child sexual abuse material in respect of which they are seeking to obtain information or removal or disabling of access either by means of providing the image or images or the video or videos themselves, or by means of providing the Uniform Resource Identifiers leading to the specific item or items of child sexual abuse material, or by means of any other representation allowing for the unequivocal identification of the item or items in question.

Added:Recital 38 a (new): (38a) The Union budget should provide complementary funding to ensure a high level of support and protection for victims, including through sufficient resources in dedicated funding programmes, and through the promotion of innovative solutions to improve the quality and accessibility of the needed services. The relevant programmes under the next Multiannual Financial Framework should contain sufficient financial and human resources to ensure sufficient funding for an adequate Union contribution to the proper implementation.

Recital 40: (40) In order to facilitate smooth and efficient communications by electronic means, including, where relevant, by acknowledging the receipt of such communications, relating to matters covered by this Regulation, providers of relevant information society services should be required to designate a single point of contact and to publish relevant information relating to that point of contact, including the languages to be used in such communications. In contrast to the provider’s legal representative, the point of contact should serve operational purposes and should not be required to have a physical location. Suitable conditions should be set in relation to the languages of communication to be specified, so as to ensure that smooth communication is not unreasonably complicated. For providers subject to the obligation to establish a compliance function and nominate compliance officers in accordance with Regulation (EU) 2022/2065, one of these compliance officers may be designated as the point of contact under this Regulation, in order to facilitate coherent implementation of the obligations arising from both frameworks.

Change 11

Changed:Recital 42: (42) Where relevant and convenient, subject to the choice of the provider of relevant information society services and the need to meet the applicable legal requirements in this respect, it should be possible for those providers to designate a single point of contact and a single legal representative for the purposes of Regulation (EU) 2022/20652022/2065, and this Regulation.

Change 12

Removed:Recital 48: (48) Given the need to ensure the effectiveness of the obligations imposed, Coordinating Authorities should be granted enforcement powers to address infringements of this Regulation. These powers should include the power to request the competent judicial authority or independent administrative authority of the Member State that designated them to temporarily restrict access of users of the service concerned by the infringement or, only where that is not technically feasible, to the online interface of the provider on which the infringement takes place. In light of the high level of interference with the rights of the users and the service providers that such a power entails, the latter should only be exercised when certain conditions are met. Those conditions should include the condition that the infringement results in the regular and structural facilitation of child sexual abuse offences, which should be understood as referring to a situation in which it is apparent from all available evidence that such facilitation has occurred on a large scale and over an extended period of time.

Added:Recital 44: (44) In order to provide clarity and enable effective, efficient and consistent coordination and cooperation both at national and at Union level, where a Member State designates more than one competent authority to apply and enforce this Regulation, it should designate one lead authority as the Coordinating Authority, whilst the designated authority should automatically be considered the Coordinating Authority where a Member State designates only one authority. For those reasons, the Coordinating Authority should act as the single contact point with regard to all matters related to the application of this Regulation, including issues related to prevention and combating child sexual abuse and assistance to victims, without prejudice to the enforcement powers of other national authorities.

Removed:Recital 49: (49) In order to verify that the rules of this Regulation, in particular those on mitigation measures and on the execution of voluntary detection orders, detection, removal, blocking or delisting orders that it issued, are effectively complied in practice, each Coordinating Authority should be able to carry out searches, using the relevant indicators provided by the EU Centre, to detect the dissemination of known or new child sexual abuse material through publicly available material in the hosting services of the providers concerned.

Added:Recital 47: (47) The Coordinating Authority, as well as other competent authorities, play a crucial role in ensuring the effectiveness of the rights and obligations laid down in this Regulation and the achievement of its objectives. Accordingly, it is necessary to ensure that those authorities have not only the necessary investigatory and enforcement powers, but also all necessary resources, including sufficient financial, human, technological and other resources to adequately carry out their tasks under this Regulation. In particular, given the variety of providers of relevant information society services and their use of advanced technology in offering their services, it is essential that the Coordinating Authority, as well as other competent authorities, are equipped with the necessary number of staff, including experts with specialised skills. The resources of Coordinating Authorities should be determined taking into account the size, complexity and potential societal impact of the providers of relevant information society services under the jurisdiction of the designating Member State, as well as the reach of their services across the Union.

Change 13

Changed:Recital 53:48: (53)(48) MemberGiven Statesthe shouldneed ensureto thatensure forthe infringementseffectiveness of the obligations laidimposed, downCoordinating inAuthorities thisshould Regulationbe theregranted areenforcement penaltiespowers whichto canaddress beinfringements of anthis administrativeRegulation. orThese penalpowers nature,should asinclude wellthe as,power whereto appropriate,request finingthe guidelinescompetent judicial authority of the Member State that aredesignated effective,them proportionateto andtemporarily dissuasive,restrict takingaccess intoof accountusers elementsof suchthe asservice concerned by the nature,infringement gravity,or, recurrenceonly andwhere durationthat ofis thenot infringement,technically infeasible, viewto the online interface of the publicprovider intereston pursued,which the scopeinfringement andtakes kindplace. In light of activitiesthe carriedhigh out,level asof wellinterference aswith the economic capacityrights of the providerusers and of relevantthe informationservice societyproviders servicesthat concerned.such Particularlya severepower penaltiesentails, the latter should only be imposedexercised onwhen thecertain providersconditions ofare relevantmet. informationThose societyconditions servicesshould ininclude the eventcondition that thosethe serviceinfringement providersresults systematicallyin orthe persistentlyregular failand tostructural complyfacilitation withof thechild obligationssexual setabuse outoffences, inwhich thisshould Regulation.be Memberunderstood Statesas shouldreferring ensureto thata thosesituation penaltiesin dowhich notit encourageis theapparent overfrom reportingall oravailable theevidence removalthat ofsuch materialfacilitation whichhas doesoccurred noton constitutea childlarge sexualscale abuseand material.over an extended period of time.

Change 14

Added:Recital 49: (49) In order to verify that the rules of this Regulation, in particular those on mitigation measures and on the execution of detection orders, removal, blocking orders that it issued, are effectively complied in practice, each Coordinating Authority should be able to carry out searches, using the relevant indicators provided by the EU Centre, to detect the dissemination of known or new child sexual abuse material through publicly available material in the hosting services of the providers concerned.

Added:Recital 50: (50) With a view to ensuring that providers of hosting services are aware of the misuse made of their services and to afford them an opportunity to take expeditious action to remove or disable access, Coordinating Authorities of establishment should be able to notify those providers of the presence of known child sexual abuse material on their services and requesting removal or disabling of access thereof. Such notifying activities should be clearly distinguished from the Coordinating Authorities’ powers under this Regulation to request the competent judicial authority of the Member State that designated them the issuance of removal orders.

Added:Recital 53: (53) Member States should ensure that for infringements of the obligations laid down in this Regulation there are penalties which can be of an administrative or criminal nature, as well as, where appropriate, fining guidelines, that are effective, proportionate and dissuasive, taking into account elements such as the nature, gravity, recurrence and duration of the infringement, in view of the public interest pursued, the scope and kind of activities carried out, as well as the economic capacity of the provider of relevant information society services concerned. Particularly severe penalties should be imposed in the event that the provider of relevant information society services in the event that those service providers concerned systematically or persistently fail to comply with the obligations set out in this Regulation. Member States should ensure that those penalties do not encourage the over reporting or the removal of material which does not constitute child sexual abuse material.

Added:Recital 55: (55) It is essential for the proper functioning of the system of mandatory detection and blocking of online child sexual abuse set up by this Regulation that the EU Centre receives, via the Coordinating Authorities, material identified as constituting child sexual abuse material or transcripts of conversations identified as constituting the solicitation of children, such as may have been found for example during criminal investigations, so that that material or conversations can serve as an accurate and reliable basis for the EU Centre to generate indicators of such abuses. In order to achieve that result, the identification should be made after a diligent assessment, conducted in the context of a procedure that guarantees a fair and objective outcome, either by the Coordinating Authorities themselves or by a court or another independent administrative authority than the Coordinating Authority which must be subject to judicial validation. Whilst the swift assessment, identification and submission of such material is important also in other contexts, it is crucial in connection to new child sexual abuse material and the solicitation of children reported under this Regulation, considering that this material can lead to the identification of ongoing or imminent abuse and the rescuing of victims. Therefore, specific time limits should be set in connection to such reporting.

Added:Recital 58: (58) In particular, in order to facilitate the cooperation needed for the proper functioning of the mechanisms set up by this Regulation, the EU Centre should establish and maintain the necessary secure information-sharing systems, such as, once available, the software provided by eu-LISA pursuant to Regulation1a (EU) 2023/969. When establishing and maintaining such systems, the EU Centre should cooperate with the European Union Agency for Law Enforcement Cooperation (‘Europol’) and national authorities to build on existing systems and best practices, where relevant. / 1a Regulation (EU) 2023/969 establishing a collaboration platform to support the functioning of joint investigation teams and amending Regulation (EU) 2018/1726

Added:Recital 59: (59) To support the implementation of this Regulation and contribute to the achievement of its objectives, the EU Centre should serve as a central facilitator, carrying out a range of specific tasks. The performance of those tasks requires strong guarantees of independence, in particular from law enforcement authorities, a governance structure ensuring the effective, efficient and coherent performance of its different tasks, legal personality to be able to interact effectively with all relevant stakeholders and an autonomous budget. Therefore, it should be established as a decentralised Union agency, and provided with the necessary human and financial resources to fulfil the objectives, tasks and responsibilities assigned to it under this Regulation, including expenditure related to the making available of technologies and the costs related to the analysis of data samples undertaken for micro, small and medium enterprises. It should be mainly financed by a contribution from the general budget of the Union, with the necessary appropriations drawn exclusively from unallocated margins under the relevant heading of the Multiannual Financial Framework and/or through the mobilisation of the relevant special instruments. In order to ensure that the Agency can respond flexibly to human resource needs, it is in particular appropriate that it has autonomy regarding the recruitment of contract agents.

Added:Recital 59 a (new): (59a) Taking into consideration the central role of the EU Centre in the implementation of the Regulation and in view of the date of expiry of the interim Regulation on 3 August 2024, the EU Centre activities should start as soon as possible. The Commission should allocate an adequate level of resources for the quick establishment and initial operation of the EU Centre and provide commensurate assistance, including by seconding staff, to help the EU Centre reaching cruising speed in due time and no later than three years after the adoption of this Regulation.

Added:Recital 59 b (new): (59b) The arrangements concerning the seat of the EU Centre should be laid down in a headquarters agreement between the EU Centre and the host Member State. The headquarters agreement should stipulate the conditions of establishment of the seat and the advantages conferred by the Member State on the EU Centre and its staff. In line with point 9 of the Common Approach of 19 July 2012 on the location of the seats of decentralized agencies, the EU Centre should conclude a headquarters agreement with the host Member State in a timely manner before it starts its operational phase. In light of the case-law of the Court of Justice, the choice of the location of the seat should be made in accordance with the ordinary legislative procedure and should comply with the criteria laid down in this Regulation.

Added:Recital 59 c (new): (59c) The selection procedure for the location of the seat of the EU Centre should respect the following steps: (i) Parliament’s mandate for the interinstitutional negotiations would provide criteria for the selection of the host city; (ii) Parliament would negotiate those criteria with the Council; (iii) such criteria would constitute the basis for an inter-institutional call for applications made together by Parliament and Council; (iv) the candidates would be invited to joint hearings among Parliament and Council; (v) Parliament’s negotiating team would draw a short-list of candidates; (vi) such short-list would be negotiated against the Council’s short-list; (vii) before an agreement among co-legislators on the host city is reached; (viii) and before the plenary approves the outcome of the interinstitutional negotiations.

Added:Recital 60: (60) In the interest of legal certainty and effectiveness, the tasks of the EU Centre should be listed in a clear and comprehensive manner. With a view to ensuring the proper implementation of this Regulation, those tasks should relate in particular to the facilitation of the detection, reporting and blocking obligations imposed on providers of hosting services, providers of publicly available number-independent interpersonal communications services and providers of internet access services, The EU Centre should also be charged with certain other tasks, notably those relating to the implementation of the risk assessment and mitigation obligations of providers of relevant information society services, the removal of or disabling of access to child sexual abuse material by providers of hosting services, the provision of assistance to Coordinating Authorities, as well as proactively and on its own initiative conduct searches on publicly accessible content on hosting services for known child sexual abuse material. The EU Centre should facilitate the generation and sharing of knowledge, best practices and expertise related to online child sexual abuse, supporting the development of awareness-raising and prevention campaigns, educational and intervention programs, tools and materials in order to increase digital skills, while integrating a child rights perspective and ensuring a gender-sensitive and age-appropriate approach. The EU Centre should promote and ensure the appropriate s…

Added:Recital 61: (61) The EU Centre should provide reliable information on which activities can reasonably be considered to constitute online child sexual abuse, so as to enable the detection and blocking thereof in accordance with this Regulation. Given the nature of child sexual abuse material, that reliable information needs to be provided without sharing the material itself. Therefore, the EU Centre should generate accurate and reliable hashes and indicators, based on identified child sexual abuse material and solicitation of children submitted to it by Coordinating Authorities in accordance with the relevant provisions of this Regulation. These indicators should allow technologies to detect the dissemination of either the same material (known material) or of different child sexual abuse material (new material), or the solicitation of children, as applicable.

Added:Recital 62: (62) For the system established by this Regulation to function properly, the EU Centre should be charged with creating databases for known child sexual abuse material, new child sexual abuse material and solicitation of children and with maintaining, timely updating and operating those databases. For accountability purposes and to allow for corrections where needed, it should keep records of the submissions and the process used for the generation of the indicators.

Added:Recital 63: (63) For the purpose of ensuring the traceability of the reporting process and of any follow-up activity undertaken based on reporting, as well as of allowing for the provision of feedback on reporting to providers of hosting services and providers of publicly available number-independent interpersonal communications services, generating statistics concerning reports and the reliable and swift management and processing of reports, the EU Centre should create a dedicated database of such reports. To be able to fulfil the above purposes, that database should also contain relevant information relating to those reports, such as the indicators representing the material and ancillary tags, which can indicate, for example, the fact that a reported image or video is part of a series of images and videos depicting the same victim or victims.

Recital 64: (64) Given the sensitivity of the data concerned and with a view to avoiding any errors and possible misuse, it is necessary to lay down strict rules on the access to those databases of indicators and databases of reports, on the data contained therein and on their security. In particular, the data concerned should not be stored for longer than is strictly necessary. For the above reasons, access to the database of indicators should be given only upon request to the parties and for the purposes specified in this Regulation, subject to the controls by the EU Centre, and be limited in time and in scope to what is strictly necessary for those purposes.

Change 15

Changed:Recital 65: (65) In order to avoid erroneous reporting of online child sexual abuse under this Regulation and to allow law enforcement authorities to focus on their core investigatory tasks, reports should pass through the EU Centre and those reportsreport should be thoroughly assessed in a timely manner to ensure that a decision on the criminal relevance of the reported material is made as early as possible and to limit the retention of irrelevant data as far as possible. ReportsReport willshould be considered manifestly unfounded, where it is immediately evident, without any substantive legal or factual analysis, that the reported activities do not constitute online child sexual abuse. In those cases,cases the EU Centre should provide feedback to the reporting provider of hosting services or provider of publicly available number-independent interpersonal communications services in order to allow for improvements in the technologies and processes used and for other appropriate steps, such as reinstating material wrongly removed. Where the EU Centre considers that a report is not manifestly unfounded, it should forward the report to the competent law enforcement authority or authorities of the Member State likely to have jurisdiction to investigate or prosecute the potential child sexual abuse to which the report relates or to Europol in those cases where that competent law enforcement authority or those competent law enforcement authorities cannot be determined with sufficient certainty. Even in cases where the competent national law enfo…enforcement authority has been identified, the EU Centre sho…

Change 16

Removed:Recital 68: (68) Processing and storing certain personal data is necessary for the performance of the EU Centre’s tasks under this Regulation. In order to ensure that such personal data is adequately protected, the EU Centre should only process and store personal data if strictly necessary for the purposes detailed in this Regulation. It should do so in a secure and supervised manner and limit storage to what is strictly necessary for the performance of the relevant tasks and for a maximum retention period of 24 months.

Added:Recital 66: (66) With a view to contributing to the effective application of this Regulation and the protection of victims’ rights, the EU Centre should be able, upon request, to support victims and to assist Competent Authorities by conducting searches of hosting services for the dissemination of known child sexual abuse material that is publicly accessible, using the corresponding indicators. Where it identifies such material after having conducted such a search, the EU Centre should also be able to request the provider of the hosting service concerned to remove or disable access to the item or items in question, as soon as possible, given that the provider may not be aware of their presence and may be willing to do so on a voluntary basis. The EU Centre should be able to proactively, on its own initiative, analyse publicly accessible content for known child sexual abuse and to follow publicly accessible uniform resource locators.

Removed:Recital 70: (70) Longstanding Union support for both INHOPE and its member hotlines recognises that hotlines are in the frontline in the fight against online child sexual abuse. The EU Centre should leverage the network of hotlines, conclude, when necessary, memoranda of understanding with them, and encourage that they cooperate and coordinate effectively with the Coordinating Authorities, providers of relevant information society services and law enforcement authorities of the Member States. The hotlines’ expertise and experience is an invaluable source of information on the early identification of common threats and solutions, as well as on regional and national differences across the Union.

Added:Recital 67: (67) Given its central position resulting from the performance of its primary tasks under this Regulation and the information and expertise it can gather in connection thereto, the EU Centre should also contribute to the achievement of the objectives of this Regulation by serving as a hub for knowledge, for best practices, expertise and research on matters related to the prevention and combating of online child sexual abuse. In this connection, the EU Centre should cooperate with relevant stakeholders from both within and outside the Union and allow Member States to benefit from the knowledge and expertise gathered, including best practices and lessons learned. Where the EU Centre makes technologies available for providers of hosting services and providers of number-independent communication services to install and operate in order to execute detection orders, it should also make publicly available relevant information, such as the detailed licensing conditions, including licensing fees, under which the EU Centre is permitted, or has obtained permission to make such technologies available. Such information should cover all details regarding the procurement of such technologies, as well as their development over time, where relevant.

Removed:Recital 71: (71) Considering Europol’s mandate and its experience in identifying competent national authorities in unclear situation and its database of criminal intelligence which can contribute to identifying links to investigations in other Member States, the EU Centre should cooperate closely with it, especially in order to ensure the swift identification of competent national law enforcement authorities in cases where that is not clear or where more than one Member State may be affected. The EU Centre, while being an independent entity, should maximise efficiency by sharing, where possible, support functions with Europol and information technology (IT) services.

Added:Recital 68: (68) Processing and storing certain personal data is necessary for the performance of the EU Centre’s tasks under this Regulation. In order to ensure that such personal data is adequately protected, the EU Centre should only process and store personal data if strictly necessary for the purposes detailed in this Regulation. It should do so in a secure and supervised manner and limit storage to what is strictly necessary for the performance of the relevant tasks.

Removed:Recital 72: (72) The arrangements concerning the seat of the EU Centre should be laid down in a headquarters agreement between the EU Centre and the host Member State. The headquarters agreement should stipulate the conditions of establishment of the seat and the advantages conferred by the Member State on the EU Centre and its staff. In line with point 9 of the Common Approach of 19 July 2012 on the location of the seats of decentralised agencies, the EU Centre should conclude a headquarters agreement with the host Member State in a timely manner before it starts its operational phase. In light of the case-law of the Court of Justice, the choice of the location of the seat should be made in accordance with the ordinary legislative procedure and should comply with the criteria laid down in this Regulation.

Added:Recital 69: (69) In order to allow for the effective and efficient performance of its tasks, the EU Centre should closely cooperate with Coordinating Authorities, the Europol and relevant partner organisations, such as the US National Centre for Missing and Exploited Children or the International Association of Internet Hotlines (‘INHOPE’) network of hotlines for reporting child sexual abuse material, within the limits sets by this Regulation and other legal instruments regulating their respective activities. To facilitate such cooperation, the necessary arrangements should be made, including the designation of contact officers by Coordinating Authorities and the conclusion of publicly accessible memoranda of understanding with Europol and, where appropriate, with one or more of the relevant partner organisations.

Removed:Recital 74 a (new): (74a) One of the pillars of this Regulation is the assistance and support of victims of child sexual abuse. In order to better understand and address victims’ individual needs is essential to create a forum where victims’ organisations are heard and the EU Centre can learn from their experience, expertise and knowledge. The Victims' Consultative Forum will play a key role in advising the EU Centre in its approach to all victim-related issues.

Added:Recital 70: (70) Hotlines play a very important role in the fight against child sexual abuse online, namely with regard to the reporting, detection and rapid removal of child sexual abuse material. Helplines are also essential in providing support for children in need. Longstanding Union support for both INHOPE and its member hotlines recognises that hotlines are in the frontline in the fight against online child sexual abuse. The EU Centre should leverage the network of hotlines and encourage that they cooperate and coordinate effectively with the Coordinating Authorities, providers of relevant information society services and law enforcement authorities of the Member States. The hotlines’ expertise and experience is an invaluable source of information on the early identification of common threats and solutions, as well as on regional and national differences across the Union.

Added:Recital 72: deleted

Added:Recital 74: (74) In view of the need for technical expertise in order to perform its tasks, in particular the task of providing a list of technologies that can be used for detection, the EU Centre should have a Technology Committee composed of experts with advisory function. The Technology Committee may, in particular, provide expertise to support the work of the EU Centre, within the scope of its mandate, with respect to matters related to detection and prevention of online child sexual abuse, to support the EU Centre in contributing to a high level of technical standards, data protection and safeguards in detection technology.

Added:Recital 74 a (new): (74a) One of the pillars of this Regulation is the assistance and support of victims and survivors of child sexual abuse. In order to better understand and address victims’ individual needs is essential to create a forum where victims’ organizations are heard and the EU Center can learn from their experience, expertise and knowledge. The Victims’ Rights and Survivors Consultative Forum should play a key role in advising the EU Center in its approach to all victim-related issues. Its member should be appointed mainly among victims or their parents, guardians or legal representatives, as well as from representatives of organisations acting in the public interest against child sexual abuse and promoting victims’ and survivors’ rights, but could also include members from other organisations such as organisations promoting rights of children belonging to vulnerable groups, organisations promoting children's rights which includes children’s digital rights.

Added:Recital 75: (75) In the interest of transparency and accountability and to enable evaluation and, where necessary, adjustments, providers of hosting services, providers of publicly available number independent interpersonal communications services and providers of internet access services, Coordinating Authorities and the EU Centre should be required to collect, record and analyse gender- and age-disaggregated data and information, based on anonymised gathering of non-personal data and to publish in a machine-readable format annual reports on their activities under this Regulation. The Coordinating Authorities should cooperate with Europol and with law enforcement authorities and other relevant national authorities of the Member State that designated the Coordinating Authority in question in gathering that information.

Added:Recital 78: (78) Regulation (EU) 2021/1232 of the European Parliament and of the Council45 provides for a temporary solution in respect of the voluntary use of technologies by certain providers of publicly available interpersonal communications services for the purpose of combating online child sexual abuse. This Regulation, which provides for a clear and uniform long-term legal framework and establishes a mandatory regime for certain providers, should substitute the temporary and voluntary one. However, until the date of effective application of this Regulation and in order to secure that online child sexual abuse online can be effectively and lawfully combated without interruptions and that there is a smooth transition between the voluntary and the mandatory regime, Regulation (EU) 2021/1232 shall apply for a limited period of 9 months after the entry into force of this Regulation.

Added:Recital 82: (82) In order to allow all affected parties sufficient time to take the necessary measures to comply with this Regulation, and in particular the establishment of the EU Centre, provision should be made for an appropriate time period between the date of its entry into force and that of its application.

Recital 84: (84) The European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42(2) of Regulation (EU) 2018/1725 of the European Parliament and of the Council48 and delivered their joint opinion on 28 July 2022.

Change 17

Removed:Article 1 – paragraph 1 – subparagraph 2 – point d a (new): (da) obligations on providers of online search engines and any other artificial intelligence systems to delist or disable specific items of child sexual abuse, or both;

Added:Article 1 – paragraph 1 – subparagraph 1: This Regulation lays down uniform rules to address the misuse of relevant information society services for online child sexual abuse, in order to contribute to the proper functioning of the internal market and to create a safe, predictable and trusted online environment that facilitates innovation and in which fundamental rights enshrined in the Charter are effectively protected;

Change 18

Changed:Article 1 – paragraph 31 – subparagraph 2 – point b: (b) Directiveobligations 2000/31/ECon providers of hosting services and Regulationproviders (EU)of 2022/2065;number-independent interpersonal communication services to detect and report online child sexual abuse;