A/HRC/52/61
70.
To ensure preventive action by industry, States should take measures to ensure that
businesses comply with their obligations to prevent their networks or online services from
being used in ways that cause or contribute to violations or abuses of children’s rights. These
measures could include the development, monitoring, implementation and evaluation of
legislation, regulations and policies.
71.
The Committee on the Rights of the Child has highlighted that States parties should
require the business sector to undertake child rights due diligence and to implement
regulatory frameworks, industry codes and terms of services which adhere to the highest
standards of ethics, privacy and safety in relation to the design, engineering, development,
operation, distribution and marketing of their products and services. The Committee calls on
States parties to require a high standard of cybersecurity, privacy by design and safety by
design in the digital services and products that are used by children to minimize the risk of
crimes against them.
72.
The reality is that purely voluntary approaches are insufficient. It is time to rethink
the model for Internet and technology companies, many of which for the most part have not
chosen – and have not been required – to prioritize children’s rights or safety. While some
companies invest substantially in making their products and platforms safe, the approach
across the sector is highly inconsistent. Moreover, requiring that products and services for
children be safe to use is a central requirement for other industries. States should mandate
safety standards and regulations for the online world that are comparable to those that they
have mandated for the offline, physical world.
73.
Examples of these requirements exist in practice. Regarding safety by design, the
eSafety Commissioner of Australia, following extensive consultations with industry, children
and young people, parents and guardians, has developed a framework for tech companies,.
This approach recognizes the importance of proactive and conscious consideration of user
safety as a standard risk mitigation and development process, as opposed to retrofitting safety
considerations after online harms emerge or damage has occurred. 39
74.
Several jurisdictions have introduced or are considering age verification or age
assurance to limit the access of children to age-inappropriate content that may be harmful but
not illegal, such as sexually explicit or violent content.40 This is a crucial dimension of an
effective response focused on prevention. Age-based or content-based systems designed to
protect children from age-inappropriate content should be consistent with the principle of
data minimization.41
75.
A key dimension of child rights due diligence for businesses is the conducting of child
rights impact assessments and disclosing them to the public, with consideration of the
differentiated and, at times, severe impacts of the digital environment on children. 42
Legislative measures have been introduced or are planned in some Member States that would
oblige online platforms to carry out periodic risk assessments focused on any negative
impacts of their services on children’s rights, with a corresponding requirement that any
identified risks be mitigated through adapting of their service or platform as needed, along
with a requirement for transparency.43 Such transparency is essential because it can pinpoint
where weaknesses exist in safety practices and reporting, where enforcement is required and
where discrepancies between different companies exist in respect of the extent of their
action.44 It is important that regulatory bodies responsible for ensuring implementation of
such child rights due diligence measures by industry and for ensuring oversight are also
39
40
41
42
43
44
GE.22-29128
See https://www.esafety.gov.au/industry/safety-by-design.
See, for example, the age-appropriate design code introduced in the United Kingdom of Great Britain
and Northern Ireland (https://ico.org.uk/for-organisations/guide-to-data-protection/ico-codes-ofpractice/age-appropriate-design-code/) and in California
(https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202120220AB2273).
Committee on the Rights of the Child, general comment No. 25 (2021).
Ibid.
See, for example, Republic Act No. 11930 (2022) of the Philippines and regulation 2022/2065 of the
European Parliament and of the Council.
See https://apo.org.au/node/321193.
15