The European Commission has proposed the
EU KIDS Act.
It is yet another set of Internet/web regulation proposals to
examine, for jurisdictional overreach, lack of common sense in terms of
material scope, and so on.
It is only a proposal
currently
It is only a legislative proposal at the moment, so it may not become
law, and it may not become law in this form.
Based on a quick skim, this is indeed another fine mess, full of
unrealistic expectations.
It has an incredibly broad
scope
The proposal covers a lot of services:
- online social networking services;
- video-sharing platform services;
- software application stores
- online games;
- operating systems;
- AI companions;
- general conversational chatbots.
I have read this from the perspective of online social networking
services, thinking predominantly about Mastodon and other fediverse
services.
At least code forges are out of scope (“open-source
software-developing and-sharing platforms”).
And Wikipedia seems to have its own bespoke exemption
(“not-for-profit online encyclopaedias”).
Small, low risk services are in scope. The covering material
specifically notes:
small and micro enterprises are not exempted from this Regulation,
since they may equally provide harms to minors. It would undermine the
objective of this proposal to exclude them from scope
Wow. I wonder if the drafters will realise just how harmful this
is.
In terms of territorial scope, it is broader than the EU GDPR, and
indeed the UK’s Online Safety Act, purporting to apply
to providers of services irrespective of where they have their place
of establishment where they offer those services to recipients of the
service that have their place of establishment or are located in the
Union
I wonder if anyone working on this stopped to think about the
boundaries of their laws, and whether they really think that they can
impose obligations on people in other countries, merely because that
person is running a service which happens to be available to people in
the EU?
Do I, as someone who runs my own fedi server, where people in the EU
can read my toots and respond to them from their own instance, fall into
scope? I do not know.
The
proposal would appear to demand age verification for the fediverse
Providers of online social networking services … shall not allow a
natural person below the age of 15 years to create an account with that
service or to access that service by means of an account, created for,
or attributed to, that person, where the service poses a risk to the
privacy, safety or security of a minor below that age. (Article
6(1))
The tests for “poses a risk” set an incredibly low threshold, and
include:
enables recipients who access the service through an account to
transmit content in real-time to an indeterminate number of other
recipients of the service, including through live streaming of
audio-visual content
and
enables recipients who access the service through an account to
contact, communicate and otherwise interact with other recipients of the
service not part of the recipient’s pre-existing connections or
subscriptions
So a “papers, please” web would become the norm, according to
this.
Some of the
obligations are just unrealistic
For example:
When creating an account for a minor pursuant to paragraph 2 of this
Article, the provider of online social networking services … shall take
measures to establish whether the person creating the account is the
holder of parental responsibility over that minor in accordance with
Article 26 and verify that the recipient of the service has reached the
age of 13 years in accordance with Article 28(1). (Article 6(3))
Article 26 sets out how the European Commission envisages this
working, but, wow, I just don’t see it.
A watershed for the web?
Harking back to (what should be the exceptionalism of) broadcast
regulation, there’s another banger:
Providers of online social networking services… shall put in place
effective measures to ensure:
time-limited access for minors on their service;
interruption of usage by minors on their service.
Such measures shall be designed in a way that protects school time
and core sleep hours of minors.
(Article 9)
Sorry, I have to turn off my fedi server now, because a child in a
different timezone might be heading off to bed and my toots might be
distracting…
Unrealistic requirements
Some of the proposals seem to relate to core browser
functionality:
Providers of online social networking services … shall put in place
measures to ensure that settings are set by default to a high level of
privacy, security and safety of minors. To ensure compliance with this
paragraph, such providers shall, by default, turn off at least the
following settings:
…
- access to microphone and camera
and
other recipients of the service shall not be able to download or take
screenshots of contact, location or account information of minors or of
any content uploaded or shared by minors on the service;
I have no idea how the drafters of this expect the provider of a
social media service available via a web browser to restrict screenshots
of everything posted by a user. It is not within their gift.
The only way to make this work would be either to force all access to
be via an app (which would be daft), or preclude child access (which has
age verification challenges).
Child use restrictions
Some of the use restrictions would seem very challenging:
Providers of online social networking services … shall put measures
in place that ensure a high level of privacy, safety and security of
minors as regards contacts between minors and other recipients of the
service. Those measures shall at least ensure that:
other recipients of the service are not able to initiate direct
contact with the minor, if the minor has not pre-approved such
contact
So a 17 year old here posts something interest. No-one is able to
interact with their post, unless the 17 year hold has “pre-approved”
it.
Oh, don’t worry, you won’t be able to see their post anyway:
by default, other recipients of the service not previously accepted
by the minor shall not be able to access account information of the
minor or content uploaded or shared by the minor on the service