Initial thoughts on the EU KIDS Act

Neil's blog · 4 hours ago · discuss

The European Commission has proposed the EU KIDS Act. It is yet another set of Internet/web regulation proposals to examine, for jurisdictional overreach, lack of common sense in terms of material scope, and so on. It is only a proposal currently It is only a legislative proposal at the moment, so it may not become law, and it may not become law in this form. Based on a quick skim, this is indeed another fine mess, full of unrealistic expectations. It has an incredibly broad scope The proposal covers a lot of services: online social networking services; video-sharing platform services; software application stores online games; operating systems; AI companions; general conversational chatbots. I have read this from the perspective of online social networking services, thinking predominantly about Mastodon and other fediverse services. At least code forges are out of scope (“open-source software-developing and-sharing platforms”). And Wikipedia seems to have its own bespoke exemption (“not-for-profit online encyclopaedias”). Small, low risk services are in scope. The covering material specifically notes: small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope Wow. I wonder if the drafters will realise just how harmful this is. In terms of territorial scope, it is broader than the EU GDPR, and indeed the UK’s Online Safety Act, purporting to apply to providers of services irrespective of where they have their place of establishment where they offer those services to recipients of the service that have their place of establishment or are located in the Union I wonder if anyone working on this stopped to think about the boundaries of their laws, and whether they really think that they can impose obligations on people in other countries, merely because that person is running a service which happens to be available to people in the EU? Do I, as someone who runs my own fedi server, where people in the EU can read my toots and respond to them from their own instance, fall into scope? I do not know. The proposal would appear to demand age verification for the fediverse Providers of online social networking services … shall not allow a natural person below the age of 15 years to create an account with that service or to access that service by means of an account, created for, or attributed to, that person, where the service poses a risk to the privacy, safety or security of a minor below that age. (Article 6(1)) The tests for “poses a risk” set an incredibly low threshold, and include: enables recipients who access the service through an account to transmit content in real-time to an indeterminate number of other recipients of the service, including through live streaming of audio-visual content and enables recipients who access the service through an account to contact, communicate and otherwise interact with other recipients of the service not part of the recipient’s pre-existing connections or subscriptions So a “papers, please” web would become the norm, according to this. Some of the obligations are just unrealistic For example: When creating an account for a minor pursuant to paragraph 2 of this Article, the provider of online social networking services … shall take measures to establish whether the person creating the account is the holder of parental responsibility over that minor in accordance with Article 26 and verify that the recipient of the service has reached the age of 13 years in accordance with Article 28(1). (Article 6(3)) Article 26 sets out how the European Commission envisages this working, but, wow, I just don’t see it. A watershed for the web? Harking back to (what should be the exceptionalism of) broadcast regulation, there’s another banger: Providers of online social networking services… shall put in place effective measures to ensure: time-limited access for minors on their service; interruption of usage by minors on their service. Such measures shall be designed in a way that protects school time and core sleep hours of minors. (Article 9) Sorry, I have to turn off my fedi server now, because a child in a different timezone might be heading off to bed and my toots might be distracting… Unrealistic requirements Some of the proposals seem to relate to core browser functionality: Providers of online social networking services … shall put in place measures to ensure that settings are set by default to a high level of privacy, security and safety of minors. To ensure compliance with this paragraph, such providers shall, by default, turn off at least the following settings: … access to microphone and camera and other recipients of the service shall not be able to download or take screenshots of contact, location or account information of minors or of any content uploaded or shared by minors on the service; I have no idea how the drafters of this expect the provider of a social media service available via a web browser to restrict screenshots of everything posted by a user. It is not within their gift. The only way to make this work would be either to force all access to be via an app (which would be daft), or preclude child access (which has age verification challenges). Child use restrictions Some of the use restrictions would seem very challenging: Providers of online social networking services … shall put measures in place that ensure a high level of privacy, safety and security of minors as regards contacts between minors and other recipients of the service. Those measures shall at least ensure that: other recipients of the service are not able to initiate direct contact with the minor, if the minor has not pre-approved such contact So a 17 year old here posts something interest. No-one is able to interact with their post, unless the 17 year hold has “pre-approved” it. Oh, don’t worry, you won’t be able to see their post anyway: by default, other recipients of the service not previously accepted by the minor shall not be able to access account information of the minor or content uploaded or shared by the minor on the service