11/11/2024 – In today’s digital world, children are using technology more and more. While this can support certain aspects of children's development, it also exposes them to potential risks. Therefore, it is important to protect children in online spaces, but we need to find a balance between giving them freedom to grow and keeping them safe. International treaties on children’s rights, like the Convention on the Rights of the Child (CRC), and laws such as the General Data Protection Regulation (GDPR) and the Digital Services Act (DSA), provide frameworks to protect children online. But how can we apply these rules in practice? Here are some practical principles to consider when creating services or technology for children. 

1. Put the best interests of the child first

The first principle for protecting children in digital environments is to prioritize their best interests. This is included in international treaties like the CRC and the European Union Charter of Fundamental Rights. When designing digital services for children, we must balance their rights to access information, express themselves, and interact with media, with the need to protect them from harm. Keeping them safe can limit their ability to explore and learn. What is in the best interest of the child differs per child. In general, however, younger children will need stronger protection because of their vulnerability. The goal is to find a balance that encourages growth while ensuring safety at the same time. 

2. Take appropriate steps to protect children’s personal data 

A critical aspect for keeping children safe online is protecting their personal data. The GDPR (recital 38) states that children deserve specific protection because they may not fully understand the risks and consequences of sharing their data. This has significant implications for organizations that collect children’s data. They must take appropriate steps to protect it, such as minimizing data collection and being transparent in their practices.  

3. Ensure you have a legal basis to process personal data 

The issue of obtaining consent for data processing from children is complex. In many countries, like the Netherlands, children over sixteen years old can consent to data processing under the GDPR. In other EU countries, this age can be lower. However, valid consent requires more than just a simple “I agree” button. Consent must be freely given, informed, and specific. This can be challenging when dealing with children, as they may not fully grasp the consequences of what they agree to. In some countries, processing of personal data of children below the age of 16 is only lawful if consent is given or authorised by the holder of parental responsibility over the child. 

4. Transparency: communicate at a child’s Level

Organizations which provide services that are accessible for children, such as online platforms, must ensure that children understand how their data is used, what the risks are, and how they can manage their privacy. Both the GDPR and DSA emphasize the importance of clear, age-appropriate communication. This could involve using visuals, like icons, animations, or simple language to explain data processing. The idea is to ensure that children have enough information to make informed choices about their online activities. For younger children, this also means involving parents or guardians to help guide their online experiences. 

5. Preventing harmful design

Designing safe digital services for children means considering risks from the very beginning. This is called “safety by design,” and it ensures that services include features that protect children from harmful content or interactions. Age verification can help limit access to inappropriate content for younger users. Additionally, the principle of data minimization under the GDPR (Article 5) states that children’s data should only be collected if it is absolutely necessary for the service to function. Reducing data collection lowers the risk of misuse and helps ensure that services prioritize children’s safety.  

6. Preventing exploitation and profiling 

Economic exploitation of children on digital platforms is a growing concern. Practices like in-app purchases, “lootboxes” in games, and targeted advertising can take advantage of children’s lack of experience. This can affect their financial decisions and influence their behavior in harmful ways. Additionally, profiling children for personalized advertising is generally not allowed unless it is proven to be in their best interests. Profiling, which means using data to create personalized content or ads, can easily be exploitative or manipulative, especially when aimed at children who might not understand the implications of their online actions. 

7. Perform a child rights impact assessment 

To evaluate the potential risks that services or products may pose to children, organizations can conduct a child rights impact assessment. This tool is intended to initiate discussions about how a product or service affects children and to consider measures for mitigating any identified risks.  

Conclusion 

Protecting children in the digital world is a complex challenge that requires careful attention to their rights for safety and development. Laws like the GDPR and the DSA provide guidelines, but the responsibility remains with companies to create safe, transparent, and child-friendly digital environments. By focusing on the best interests of the child, you can ensure that they explore the digital world safely and securely, free from undue risks.

Evelijn van Wanroij Team Manager Legal & Responsible AI / Senior Legal Manager

Do you want to know more?

Working closely with other organizations, Considerati developed the Child Rights Impact Assessment. Feel free to reach out to us if we can help you implement the above principles or if you have further questions about children's rights in the digital world. 

Our services orContact