Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 19 Apr 2023
on the proposal for a regulation of the European Parliament and of the Council Laying down rules to prevent and combat child sexual abuse
To · plenary report· 16 Nov 2023
on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse
+421 added · −186 removed · 51 changed paragraphs, packaging included.
Part 3 of 14: Paragraphs 121–180
Change 19
Changed:Article 1 – paragraph 31 – subparagraph 2 – point d a (new): (da) Regulation(d (EU)a) .../...obligations on Artificialproviders Intelligenceof (Artificialonline Intelligencegames; Act).and
Change 20
Added:Article 1 – paragraph 1 – subparagraph 2 – point e: (e) rules on the implementation and enforcement of this Regulation, including as regards the designation and functioning of the competent authorities of the Member States;
Added:Article 1 – paragraph 1 – subparagraph 2 – point e a (new): (ea) rules on the establishment, functioning, cooperation, transparency and powers of the EU Centre For Child Protection on Child Sexual Abuse established in Article 40 (‘EU Centre’);
Added:Article 1 – paragraph 2 a (new): 2a. This Regulation shall not apply to audio communications.
Added:Article 1 – paragraph 3 – point b: (b) Directive 2000/31/EC and Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) and amending Directive 2000/31/EC];
Added:Article 1 – paragraph 3 – point d a (new): (da) Directive (EU) 2022/2555 of the European Parliament and the Council of 14 December 2022 on measures for high common level of cybercecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 (NIS 2 Directive); and
Added:Article 1 – paragraph 3 – point d b (new): (db) Regulation (EU) .../... on Artificial Intelligence (Artificial Intelligence Act);
Added:Article 1 – paragraph 3 a (new): 3a. Nothing in this Regulation shall be interpreted as prohibiting, weakening or undermining end-to-end encryption. Providers shall not in particular be prohibited to offer end-to-end encrypted services.
Added:Article 1 – paragraph 3 b (new): 3b. Nothing in this Regulation shall undermine the prohibition of general monitoring under Union law or introduce general data retention obligations, or be interpreted in that way.
Added:Article 1 – paragraph 4: 4. This Regulation limits the exercise of the rights and obligations provided for in 5(1) and (3) and Article 6(1) of Directive 2002/58/EC with the sole objective of enabling relevant information society services to use specific technologies for the processing of personal and other data to the extent strictly necessary to detect and report online child sexual abuse and remove child sexual abuse material from their services for the execution of the detection orders issued in accordance with Section 2 of Chapter 1 of this Regulation.
Article 2 – paragraph 1 – point a: (a) ‘hosting service’ means an information society service as defined in Article 3, point (g), third indent, of Regulation (EU) 2022/2065;
Change 21
Changed:Article 2 – paragraph 1 – point c:b (c)a ‘software(new): application’(ba) means‘number-independent ainterpersonal digitalcommunications productservice’ ormeans an interpersonal communications service as defined in Article 2,(2), point 15,(7) of RegulationDirective (EU) 2022/1925;2018/1972;
Change 22
Changed:Article 2 – paragraph 1 – point d:b (d)b ‘software(new): application(bb) store’‘number-independent meansinterpersonal acommunications service aswithin games’ means any service defined in Article 2,(2), point 14,(7) of RegulationDirective (EU) 2022/1925 [on contestable and fair markets in2018/1972 thewhich digitalis sectorpart (Digitalof Marketsa Act)];game;
Change 23
Changed:Article 2 – paragraph 1 – point e ac: (new):(c) (ea)‘software “onlineapplication’ searchmeans engine”a meansdigital anproduct intermediaryor service as defined in Article 3,(2), point (j),(15), of Regulation (EU) 2022/2065;2022/1925;
Change 24
Changed:Article 2 – paragraph 1 – point e bd: (new):(d) (eb)‘software ‘intermediaryapplication service’store’ means a service as defined in Article 3,(2), point (g),(14), of Regulation (EU) 2022/2065;2022/1925;
Change 25
Removed:Article 2 – paragraph 1 – point e c (new): (ec) ‘artificial intelligence system’ (AI system) means software as defined in Article 3(1) of Regulation (EU) .../... on Artificial Intelligence (Artificial Intelligence Act);
Added:Article 2 – paragraph 1 – point f – point ii: (ii) a number-independent interpersonal communications service;
Change 26
Changed:Article 2 – paragraph 1 – point f – point iv a (new): (iv(iva) a)a annumber-independent onlineinterpersonal searchcommunication engine;service within online games.
Change 27
Removed:Article 2 – paragraph 1 – point f – point iv b (new): (iv b) an artificial intelligence system.
Article 2 – paragraph 1 – point g: (g) ‘to offer services in the Union’ means to offer services in the Union as defined in Article 3, point (d), of Regulation (EU) 2022/2065;
Article 2 – paragraph 1 – point j: deleted
Change 28
Removed:A “child user” is a “child” as defined in point (i) and a “user” as defined in point (h) thus this would be redundant.
Article 2 – paragraph 1 – point m: (m) ‘known child sexual abuse material’ means child sexual abuse material detected using the indicators contained in the database of indicators referred to in Article 44(1), point (a);
Change 29
Changed:Article 2 – paragraph 1 – point q a (new): (qa) ‘victim’ means: / Person residing in'victim' themeans Europeana Unionperson who being under 18 suffered child sexual abuse offences. For the purpose of exercising the victim’soffences rightsor/and recognisedwhose inchild thissexual Regulation,abuse parentsmaterial andis guardianshosted areor todisseminated bein consideredthe victims.Union;
Change 30
Changed:Article 2 – paragraph 1 – point r: (r) ‘recommender system’ means the system as defined in Article 3,2, point (s),(o), of Regulation (EU) 2022/2065;
Change 31
Changed:Article 2 – paragraph 1 – point t:s: (t)(s) ‘content moderation’data’ means the activities as defined in Article 3, point (t), oftexts, Regulationvideos (EU)and 2022/2065;images;
Change 32
Changed:Article 2 – paragraph 1 – point v: (v)t: ‘terms(t) and‘content conditions’moderation’ means terms andthe conditionsactivities as defined in Article 3,2, point (u),(t), of Regulation (EU) 2022/2065;
Change 33
Removed:Article 2 – paragraph 1 – point w a (new): (wa) ‘metadata‘ means data processed for the purposes of transmitting, distributing or exchanging content data; including data used to trace and identify the source and destination of a communication, data on the location and the date, time, duration and the type of communication;
Added:Article 2 – paragraph 1 – point v: (v) ‘terms and conditions’ means terms and conditions as defined in Article 2, point (u), of Regulation (EU) 2022/2065;
Change 34
Changed:Article 2 – paragraph 1 – point w ba (new): (wb)(wa) ‘hotline’ means an organisation officially recognised by its Member State of establishment that provides a mechanism, other than the reporting channels provided by law enforcement authorities, for receiving anonymous complaints from victims and the public about alleged online child sexual abuse online.abuse;
Change 35
Removed:Article 3 – paragraph 1: 1. Providers of hosting services and providers of interpersonal communications services shall identify, analyse and assess, for each such service that they offer, the risk of use of the service for the purpose of online child sexual abuse. To that end, providers subject to an obligation to conduct a risk assessment under Regulation (EU) 2022/2065 may draw on that risk assessment and complement it with a more specific assessment of the risks of use of their services for the purpose of online child sexual abuse.
Added:Article 2 – paragraph 1 – point w b (new): (wb) “help-line” means an organisation that provides services for children in need officially recognised by its Member State of establishment;
Removed:Article 3 – paragraph 2 – point b – indent 3: — functionalities enabling age assurance and age scoring, without prejudice to other mechanisms that enable age-verification, with particular consideration to the impacts of such measures on fundamental rights;
Added:Article 3 – paragraph 1: 1. Providers of hosting services and providers of number-independent interpersonal communications services shall identify, analyse and assess for each such service that they offer, the significant risk stemming, inter alia, from the design, functioning and use of their services for the purpose of online child sexual abuse. That risk assessment shall be specific to the services they offer and proportionate to the risk considering its severity and probability. To that end, providers subject to an obligation to conduct a risk assessment under Regulation (EU) 2022/2065 may draw on that risk assessment and complement it with a more specific assessment of the risks of the use of their services for the purpose of online child sexual abuse.
Removed:Article 3 – paragraph 2 – point b – indent 4: — functionalities enabling users to flag or notify online child sexual abuse to the provider through tools that are easily accessible and age-appropriate, including already available anonymous reporting channels as defined by Directive (EU) 2019/1937;
Added:Article 3 – paragraph 1 a (new): 1a. Providers which are not substantially exposed to online child sexual abuse and which are not very large online platforms pursuant to Article 33 of Regulation (EU) 2022/2065 are exempted from these obligations provided for in this Article and Article 4. / A hosting service provider or a number-independent interpersonal communication service provider is substantially exposed to online child sexual abuse and therefore subject to the obligation to conduct a risk assessment in accordance with this Article: / (a) if it has received two removal orders in the previous 12 months; / (b) from the moment the provider becomes aware of any information indicating potential online child sexual abuse on its services and submits, in accordance with Article 12, a report to the EU Centre; or / (c) from the moment the provider is notified by the national competent authority or by the EU Centre, in accordance with Article 49, of the presence of one or more specific items of known child sexual abuse material on its services.
Removed:Article 3 – paragraph 2 – point b – indent 4a (new): — functionalities enabling age-appropriate parental controls;
Added:Article 3 – paragraph 2 – point b – introductory part: (b) the existence and implementation by the provider of a policy and the availability and effectiveness of functionalities and protocols to prevent and address the risk referred to in paragraph 1, including through the following:
Removed:Article 3 – paragraph 2 – point b – indent 4b (new): — functionalities enabling self-reporting.
Added:Article 3 – paragraph 2 – point b – indent 2: – measures taken to enforce such prohibitions and restrictions and the amount of human and financial resources dedicated to address child sexual abuse material;
Change 36
Changed:Article 3 – paragraph 2 – point b a (new): (ba)– theindent capacity,2 havinga regard(new): to– theinformation stateand ofawareness thecampaigns art,educating toand meaningfullywarning dealusers withof reportsthe andrisk notificationsof aboutonline child sexual abuse in a timely manner;abuse;
Change 37
Changed:Article 3 – paragraph 2 – point c:b (c)– theindent manner3 ina which(new): users– usefunctionalities theenabling servicemeaningful and the negative impact thereofproportionate onage-appropriate thatparental risk;controls;
Change 38
Removed:Article 3 – paragraph 2 – point d: (d) the manner in which the provider designed and operates the service, including the business model, governance, type of users targeted, and relevant systems and processes, and the negative impact thereof on that risk;
Added:Article 3 – paragraph 2 – point b – indent 3 b (new): – functionalities, according to Article 12 (3), enabling users to flag or notify potential online child sexual abuse to the provider;
Change 39
Changed:Article 3 – paragraph 2 – point eb – point i: (i)indent the3 extentc to(new): which– the servicecapacity isof usedthe orprovider, ishaving likelyregard to be used bythe childrenstate andof the extentart, to whichmeaningfully thedeal servicewith isthose targetingreports childand users;notifications in a timely manner;
Change 40
Changed:Article 3 – paragraph 2 – point eb – pointindent iii3 d (new): – indentsystems 1and amechanisms (new):that —provide enablingchild- unsolicitedand contactuser-friendly forresources usersto and,ensure inthat particular,children forcan adultseek usershelp swiftly, including information on how to engagecontact andnational connecthotlines, withhelp-lines unknownor childnational users;law enforcement;
Change 41
Changed:Article 3 – paragraph 2 – point e – point iiib – indent 2: — enabling users to establish contact with3 othere users(new): directly,– infunctionalities particularallowing onto servicesdetect directlysuspicious targetinglinks, childincluding usersthose orcoming throughfrom privatethe communications;darknet.
Change 42
Removed:Article 3 – paragraph 2 – point e – point iii – indent 3: — enabling users to share content with other users, in particular through private communications.
Added:Article 3 – paragraph 2 – point b – indent 4: deleted
Removed:Article 3 – paragraph 2 – point e a (new): (ea) any other functionalities.
Added:Article 3 – paragraph 2 – point d: (d) the manner in which the provider designed and operates the service, including the design of their recommender systems and any relevant algorithmic systems, the business model, governance, type of users targeted and relevant systems and processes, and the impact thereof on that risk;
Removed:Article 3 – paragraph 2 a (new): 2a. The provider, where applicable, shall assess, in a separate section of its risk assessment, the voluntary use of specific technologies for the processing of personal and other data to the extent strictly necessary to detect, to report and to remove online child sexual abuse material from its services.
Added:Article 3 – paragraph 2 – point e – point i: (i) the extent to which the service is used or is likely to be used by children and the extent to which the service is directly targeting children;
Removed:Article 3 – paragraph 3 – subparagraph 1: The provider may request the EU Centre to perform a test on data samples made available to the EU Centre to support the risk assessment. / Neither the request referred to in the first subparagraph or any subsequent analysis that the EU Centre may perform thereunder shall exempt the provider from carrying out its obligation to conduct the risk assessment in accordance with paragraphs 1 and 2 of this Article or to comply with any other obligation set out in this Regulation.
Added:Article 3 – paragraph 2 – point e – point ii: (ii) where the service is used or is likely to be used by children or directly targeting children, the different age groups or likely age groups of children and the risk of solicitation of children in relation to those age groups;
Removed:Article 3 – paragraph 3 – subparagraph 2: The costs incurred by the EU Centre for the performance of such an analysis shall be borne by the requesting provider. However, the EU Centre may bear those costs where the provider is a micro, small or medium-sized enterprise, provided the request is reasonably necessary to support the risk assessment.
Added:Article 3 – paragraph 2 – point e – point iii – indent 1: – enabling users to search for other users, including through search engines external to the service and, in particular, for adult users to search for children;
Removed:Article 3 – paragraph 4 – subparagraph 2 – point a: (a) for a service which is subject to a detection order issued in accordance with Article 7, the provider shall update the risk assessment at the latest four months before the expiry of the period of application of the detection order;
Added:Article 3 – paragraph 2 – point e – point iii – indent 2: – enabling users to initiate unsolicited contact with other users, including children, directly, in particular through private communications;
Removed:Article 4 – paragraph 1 – introductory part: 1. Providers of hosting services and providers of interpersonal communications services shall put in place reasonable, proportionate, targeted and effective mitigation measures, tailored to their services and the risk identified pursuant to Article 3, with the aim of mitigating that risk. Such measures shall include some or all of the following: