Balancing child protection, privacy and platform regulation
A two-stage expert workshop series examined how the EU could address online child sexual abuse without treating privacy, confidential communications and children’s rights as expendable.
A polarised debate concealed the hard design questions.
The European Commission’s proposal sought a harmonised framework for preventing and combating online child sexual abuse. The proposal also raised difficult questions concerning the prohibition of general monitoring, the confidentiality of communications, the GDPR, platform responsibility, children’s rights and the use of automated detection systems.
Dr Mark R. Leiser worked with Dr Sabine K. Witting, ECPAT International and multidisciplinary experts to move beyond a simple contest between child protection and privacy. The workshops examined where the legal and technical architecture could protect children while preserving the fundamental rights of child and adult users.
Contribution
While at Vrije Universiteit Amsterdam, Dr Leiser helped design the workshop series, frame the platform-regulation and fundamental-rights analysis, synthesise expert discussion and co-author both outcome reports. The work translated disagreement across law, child protection, privacy, data protection and technology into concrete areas of common ground and further investigation.
Status: completed in a personal academic capacity while at Vrije Universiteit Amsterdam, with collaborators at Leiden University and ECPAT International. This was not a DigiData client engagement.
Legal framework, contentious issues and common ground.
The first workshop took place at Leiden University in October 2022 and brought together experts in child rights, privacy, data protection, fundamental rights and platform regulation.
Outcome Report of the 1st Expert Workshop
The report examined general monitoring, proportionality, consensual online sexual exploration between adolescents, continued voluntary detection and the institutional design of the proposed EU Centre.
- Clarified the relationship between the proposal, the Digital Services Act, the GDPR, ePrivacy law and the EU Charter.
- Identified legal-certainty and foreseeability problems in open statutory terms.
- Set out common ground on risk assessment, child-friendly reporting, institutional independence, law-enforcement capacity and safeguards.
- Placed children’s participation and the rights of adolescents at the centre of the regulatory analysis.

Detection technologies, end-to-end encryption and legal safeguards.
The second workshop at Vrije Universiteit Amsterdam in March 2023 examined the technologies that the proposed Regulation expected service providers to deploy.
Outcome Report of the 2nd Expert Workshop
The report reassessed hashing technologies, image and text classifiers, on-device scanning and secure enclaves across effectiveness, confidentiality, security and repurposing risk.
- Recommended a staggered and risk-based approach to technology deployment.
- Called for stronger legal prohibitions against repurposing detection systems.
- Proposed independent accreditation, auditing, accuracy standards and transparent oversight.
- Addressed human review, content-moderator welfare, classifier bias and the participation of children and survivors.
- Recognised the wider societal value of end-to-end encryption and cautioned against creating a general surveillance infrastructure.
Need independent research across law, technology and institutional design?
DigiData develops evidence-led research, expert reports and structured workshops for complex digital-regulation questions.