Summary

  • The European Commission's 17 September EU KIDS Act proposal would require social-networking and video-sharing services designated as very large online platforms to notify a detailed child-safety compliance plan and pay for an independent audit of it.
  • The provider would publish a non-confidential summary. A Commission decision identifying shortcomings could require a corrective plan and verification of the fixes.
  • Article 5(8) says neither the auditor's final report nor Commission action or inaction on it or the plan counts as a finding of compliance. This is a legislative proposal, not a rule currently in force.

Imagine a platform publishing the summary of an auditor's report beside a reassuring safety claim. The document might be important evidence. Under the European Commission's proposed EU KIDS Act, it would not be a certificate. That distinction is written into Article 5(8) of the draft Regulation adopted by the Commission on 17 September.

The initial duty is narrower than the proposal's broad child-safety ambitions. Article 5 covers providers of social-networking and video-sharing services designated as very large online platforms under the existing Digital Services Act. They would notify the Commission of a detailed plan addressing the proposal's obligations, then commission and pay for an independent audit of that plan. The required expertise spans child rights, paediatrics and psychiatry, development, age assurance, interface and recommender design, and data protection and security.

It is a review of described measures, not a direct measurement of every child's experience on a live service.

The draft also specifies a sequence of usable records. The auditor sends a draft report to the provider, which may comment within 15 days. A final report identifying shortcomings goes to the Commission and provider simultaneously within two months after the auditor receives the plan. The provider publishes a summary excluding confidential information. If the Commission decides the plan has shortcomings, the provider must submit corrective measures; the auditor then checks implementation. These stages are more substantial than an unaudited promise, but none amounts to a blanket approval.

Article 5(8) closes the tempting shortcut explicitly. The final report, and even Commission action or silence about the report or plan, would not establish compliance with the proposed duties or constrain the Commission's enforcement powers. Later annual reporting would feed the Digital Services Act's risk-assessment and audit machinery. A plan can be scrutinised before implementation and still fail against actual conduct; an absence of objection does not reverse that burden.

The Commission's public FAQ describes the proposal as shifting the burden of proof onto large platforms. The legislative text explains a limit on how that proof can be advertised. Lu Heng's distinction between evidence and authority is useful here: an expert's examination can inform a decision without inheriting the public authority to declare the service lawful or safe. Nor does a written plan replace observation of running systems.

The Parliament and Council have not enacted this proposal. EUR-Lex lists the legislative procedure as ongoing, and the draft itself leaves application dates in brackets. No platform is accused of failing a rule that does not yet exist.

Sources