For What Reason is it so Critical to Ensure the Protection of Children’s Personal Data?
Children constantly seek for new adventures and experiences online. While accessing internet, they tend to expose themselves to social media evils by disclosing excess of their personal data. Earlier, there was no specific law or regulation under Data Protection Directive (herein after ‘Directive 95/46/EC’) for protecting child’s rights online. But after EU General Data protection Regulation (hereinafter ‘GDPR’) was adopted it altered the situation and jilted the old approach towards children as data subject. GDPR brings in special protection for children’s personal data. The original intention behind Article 8 of GDPR is privacy and security of children from online predators and to protect children’s personal information from commercial exploitation and targeted marketing strategies. The paper perceives and explains how EU children will be needing more protection than adults with the coming in of digital age. This paper will also present various alternatives that can be taken to avoid unjustified obstruction with child’s rights while providing online security and privacy. In this matter it is hoped and trusted that countries and information society service providers will embrace measures to protect the child’s personal data in this digital age.
I. Introduction
‘ITU data on Internet usage uncovers that in developing countries, people below the age of 18be more active on internet than the general online population by a factor of two or three.’2 With the coming in of digital revolution, people no longer has their nose deep in their books but are now addicted to internet and social media. Currently internet is a vital lifeline andan integral part of every individual including children. Children constantly seek for new adventures and experiences online for free. What they don’t recognise is how their personal data is exchanged for their “Free” experiences. This free experience is more deceptive and injurious to teens. While accessing internet, they tend to expose themselves to social media evils by disclosing excess of their personal data.
Children are becoming object of these service providers, which generate and misuse their personal data. The consequences of this includes loss of reputation online, discrimination, and identity theft at young age. The fact that they are less culpable to understand how their personal data is misused makes children more risk prone and vulnerable online than adults.“These explicit formative highlights of youngsters may be effectively abused by online advertisers who gather individual information and utilize exceptional procedures, for example, 'ongoing offering, area focusing on (particularly when the client is close to a point of procurement), and "dynamic imaginative" promotions customized to their individual profile and personal conduct standards.”3They freely trade their personal data to dart them with ads, track their behaviour and manipulate public opinion. “The Children’s Commissioner’s Digital Taskforce appointed a law firm, to redraft the terms and conditions of Instagram in simple language. An excerpt of which reads as:“Officially you own any original pictures and videos you post, but we are allowed to use them, and we can let others use them we well, anywhere around the world. Other people might pay us to use them and we will not pay you for that.” “Although you are responsible for the information you put on Instagram, we may keep, use and share your personal information with companies connected with Instagram. This information includes your name, email address, school, where you live, pictures, phone number, your likes and dislikes, where you go, who your friends are, how often you use Instagram, and any other personal information we find such as your birthday or who you are chatting with, including in private messages (DMs)”4
Earlier, there was no specific law or regulation under Data Protection Directive (herein after ‘Directive 95/46/EC’) for protecting child’s rights online. But after EU General Data protection Regulation (hereinafter ‘GDPR’) was adopted it altered the situation and jilted the old approach towards children as data subject. For the first time in EU, children are specifically considered under a data protection regulation, as GDPR brings in special protection for children’s personal data. It contains new provisions which intends to enhance the protection of children. GDPR perceived and explained how EU children will be needing more protection than adults with the coming in of digital age. As interpreted by Recital 38 of the GDPR, children are generally less attentive to the outcomes, risks, dangers, consequences and their rights in relation to the processing of personal data, they need more protection with respect to their personal data more than adults. Such protection applies to utilization of personal data of children for reasons for promoting, marketing or gathering personal information for client profiling.
II. How GDPR Improves Children’s Privacy?
Since Directive 95/46/EC was implemented before digital revolution, it pretty much closed its eyes towards the rights of children at the online platform. But after the adoption of the GDPR, the attitude towards this issue has drastically transformed. The new regulation devotes a specific Article to the processing of the personal data of children which gives careful consideration to issues of consent. Under Article 8 of the GDPR, it is established that parental consent is required to process personal data of the children under the age of 16 (unless a lower national age threshold between 13 and 16 applies). Particularly there has been few elements and developments which prepared grounds due to which minor’s security in relation to the processing and protection of their data on the internet was included in the new regulation.
At first, there has been an increased in commitment by the EU states and institution to promote, protect and secure the children’s in all the relevant polices. Moreover, protecting children’s rights are now one of the main priorities under many of the EU policies and strategic documents. This can be perceived by appreciating how promoting children rights has been an important objective of EU under the Article 3(3) of the treaty on European Union. A high level of protection of personal data of children on the internet while completely maintaining their rights to access internet and utilise it for their benefits is now perceived as one of the main objectives of EU Agenda for the Rights of Child. 5As per Article 24 of the European Charter of Fundamental Rights, EU is now dedicated on guarding and protecting children’s rights. In the year 2015, European Commission (EC) was approached by the European Parliament to come up with another exhaustive plan on the rights and privileges of children. This mean that UN Convention of the Rights of the Child (herein after UNCRC) would now guide and manage the EU policies which are related to children’s rights. Hence, the interest of children are ought to be considered now while drafting legislative proposals. Secondly, increase amount of data about children’s internet use and danger related to it has been accumulated across Europe and is now available with policy maker. Various studies has been conducted relating to usage of internet by the children. As per the research conducted in 2011, around 9% of children between 11-16 years of age, face misuse of their personal data online and are unable to report such issues nor use privacy settings to protect themselves.6 In 2014, research reaffirmed that children still worry mostly about the misuse of the personal information and reputation of harm through hacking of their Facebook accounts and creation of fake profiles by hackers. Thirdly, there has been an increase in number of mobile applications and websites which are mostly downloaded and used by teenagers. There is lack of transparency about collection of children’s data by these application as evaluated by the Federal Trade Commission (FTC) in the US. ‘When GDPR was still under debates and discussion, data protection authorities from around the globe completed a Global Privacy Sweep which was a joint survey and review more than thousands of websites and applications developed mainly for children and teenagers. The survey revealed numerous issues for example, over the top unnecessary collection of personal data from the children and regular divulgence of their data to outsiders or third parties’.7These finding of the sweep could have crystalize the final position in GDPR on the protection of personal data of children online.
(A) Other Relevant Provisions In GDPR:
Article 6(1) (f)
As to the legitimate interest, processing can happen for the genuine interests pursued by the controller, “except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child”8
Article 12
This Article provides for transparent information where the controller will provide information to users in concise, transparent, intelligible and accessible form using plain and clear language specifically for any information tended explicitly to children. As per recital 58, any processing which is related to a child, ought to be in such a clear and pain language that the child can easily get it.
Article 17(1)(f)
This Article refers to the right of erasure of children. It provides that the subject will have the right of deleting his or her personal data. This rights exists where the individual information have been gathered in connection to the offer of ISSs referred to in /article 8(1). As per the Recital 65, this right is especially applicable where the data subject has given consent as a child and isn’t completely aware of the risks involved in processing and wants to delete the data on the internet.
(B) Legal Basis Of Processing Under GDPR
Explicit conditions are imposed under Article 8 where a controller can process the data simply on the consent of child. However, GDPR does not restrict the processing of child’s data to this requirement. In appropriate circumstances there are other lawful bases of processing of data. For instance, contractual necessity can be used as a legal ground for processing of data when child is able to enter into contracts rendering to the law of that country. But this should be cautiously applied without jeopardizing child’s right and privacy. For example when a child downloads and uses an app, there are identifiers linked with it. Functionality of the app can be enhanced by processing of such identifiers. Therefore, in case of disparity of power between ISS and child, it is controller who needs to intensely think and examine the appropriate legal basis for processing of data in an exact situation but within the framework of GDPR.
(C) Online Services Offered Directly To Child
The requirements under Article 8 relates only where information society services are offered directly to a child. “Information society services” are defined by reference to Directive 2015/1535 1(1) (b). “The definition states than an ISS is any service provided at a distance, by electronic means, and at the individual demand of a recipient of the services.”9
Whether it’s about playing online games, watching movies, sharing videos or social media interaction via Facebook, Instagram or Snapchat, kids today grow up with computerized and digital technology as a crucial piece of their everyday lives. The new and updated applications follow a strategies to personalise children’s involvement on internet and urge them to remain online longer. Half of the online users who are between 9-16 years say that they visit their social media profile every day. Thus making themselves more vulnerable to the risks attached to these online services. There are different types of identified online risks. First is the content risk. This includes receiving of mass conveyed messages which when opened would expose them to in appropriate material like pornography or outrageously violent videos. Second is the conduct risk. Children’s own behaviour and conduct like involving in sexting, oversharing their own personal data, bullying, harassing or stalking can make them more vulnerable. Third is the contact risk. This incorporates being stalked, bullied, meeting strangers, sharing of humiliating photos without their permission. That’s why the online service provider now have to evaluate whether automated profiling of youngsters or using their geolocation information will be appropriate and suitable for advertising and marketing purposes.10
In spite of the fact that the aim of GDPR to create a precise protection regime for services that process children’s data is clear, the correct refinement of services to which the protection applies is mind boggling issue. Because in practice, services focused at children form a small part of their services that they can use and join. Even though in practice substantive number of young people are the active users, these sites guarantee and claim that their services are not proposed for children specially those under age of 13. Thus, the children are treated as grownups and are given same data protection settings, with no consideration of their specific needs online. Therefore it is important to look into the extent the GDPR will reflect reality and to what degree the necessity of parental consent will cover general or blended audience services.
(D) Approaches taken by ISS:
As the deadline of GDPR implementation was approaching, inbox of users across EU were flooded by emails regarding privacy policies by the companies and social media websites which collects and processes their personal data. Quiet number of changes were made all at once by social Medias. Website like Facebook and Google, gathers an extraordinary amount of personal data of users. Facebook has been under great degree scrutiny after 87 million users data was harvested without their consent by a political advertising firm Cambridge Analaytica. Most of the online users doesn’t even know that for years Facebook and Google has been using user’s personal data to make money. They freely trade their personal data to dart them with ads, track their behaviour and manipulate public opinion. Even if users completely remove sensitive data from Facebook, Facebook could still glean for their data by analysing their behaviour on the platform and on other websites too Facebook users across Europe received an email instructing them that they need to accept the updated versions and settings in order to use its services. At this point it became clear to everybody that some data was classified as sensitive, that Facebook was now about to start facial recognition of every user and that there were conditions and ways in which Facebook would use their data to profile, target and advertise.
Sadly, the new regulation does not express any clear and reasonable requirement to verify the age of a child. Therefore, online service providers should make reasonable efforts to check that the individual giving consent is in fact the parent or a guardian who is entitled to do so.
1. Facebook:
Complying with the new regulation, users under the age of 16 will see a less customized form of Facebook until a parent consent to let Facebook show targeted advertisements. Promotions and advertisements categories for children are now limited unless they have permission from a parent to change it.The company also introduce Messenger for kids which is an advertisement free application. The new Facebook face recognition feature will not be available to users under the age of 18. As well, anything posted be a child between age 13 to 15 won’t be public by default. Facebook will soon launch a new world wide online resource centre for teenagers to offer education and training about their most basic privacy queries. As per the company, it is now committed to make sure that the users understand how the company utilises their personal information and how they control it.The Facebook and Instagram accounts of users who are suspected to be below the age of 13 will be locked. Further, Facebook recently announced that it will require users to provide proof of the suspected user’s age if they want to regain their access.
2. WhatsApp:
On the other hand, popular messaging service, “WhatsApp” which has faced scrutiny for its data sharing practice, raised minimum age limit for its users to 16 in EU. Before the implementation of GDPR, the application did not use to ask the age of the user while downloading it nor does it cross check the age on the Facebook accounts. Likewise users can now download a detailed reports on the data collected and stored by WhatsApp.11But it is vague how WhatsApp will check the age of the users. ‘Because looking at the new policy it looks that teens only have to select “agree” on their application to agree with the new terms of service notification.’12
3. YouTube:
Google is making arrangements to make its dubious YouTube kids application much more secure. This app was widely criticised for showing inappropriate videos and clips with explicit language to children. YouTube kid is a family friendly version of sharing video via tech devices. With new feature, parents can choose what videos will be seen by their child.
4. Twitter
Twitter removed some users who were suspected to have been under the age of 13 depending when they joined the website. Further, it also invited users to agree to the new term that they are over 13 while signing up for the twitter account.
III. Why Do We Need Alternative Approaches?
The term ‘information society services,’ has been interpreted broadly. Hence, the necessity of parental consent under GDPR would be applicable to an extensive variety of online services. But there are numerous websites and application that can be accessed without giving personal data for example, news and entertainment websites like Buzz Feed. These sites don’t collect the data directly but indirectly through following methods like program fingerprinting and cookies. The other problem is that GDPR does not refer to verification of age. The possibility that all the web users are requested to give their age or to identify themselves may prompt to excessive collection of personal data. ‘In spite of the fact that people under the age of 21 or 25 are still asked to show their ID to prove their age while buying alcohol or tobacco as there is risk attached to consuming these products, the risks related to privacy and data protection is different to consuming of alcohol and Tabaco by the minors.’13 “Risk of privacy and evaluation of harm is still a heated debate topic and yet there is no agreement as to what exactly constitutes a privacy harm. There is no comprehensive list of privacy harms as companies and controllers have neglected to recognise the impact of the harms on data subjects”.14
It would be problematic if children somehow are forced to make a decision to choose between losing their accounts on Facebook, Instagram, WhatsApp and YouTubeand lying about their age. If they start lying about their age, they would be treated as adults and will not be able to utilise the benefits from the protection under the regulation. The problem is not only related to children but also concerns the situation and position of parents. As a parent, they would want that their child could engage sincerely on the website with appropriate protections. Both child and parents battle to comprehend the accessible alternative and tool, along with the danger they confront online and their obligations. Parents are disappointed and stressed by the unresponsive digital market that doesn’t take into account their necessities, respond to their problems or give provide with options and tools they need. Different service providers are coming up with different options and tools which are confusing and thus parents are not able to find any help they need and children are often able to sidestep the securities set up by the companies. Practical implication for attaining and verifying parental consent for signing up at Facebook and other similar social media is a joke. Lip-synchronizing applicationslike Musical.ly are especially famous for highlighting children dancing to current pop melodies before millions of users which includes grown-ups.
Social media companies doesn't put any genuine barrier during sign ups. It's easy that some 8 years old would deceive their age while creating an account to get access. Users can simply enter their own alternative email address when asked for parental consent. These company would aimlessly believe that the child have really given his parents or guardians email but in fact child can give anybody’s email address. So it appears that these companies are happily letting the teenagers sidestep this barrier of parental consent. Blindly trusting self-certification prompted the Cambridge Analytica outrage, as the data research company strongly guaranteed Facebook it had erased clandestinely gathered user’s information, yet Facebook neglected to cross check that.
IV. ‘The Million Euro Question’
As Hodgkin and Nowell have appropriately noted “setting an age for the securing of specific rights or for the loss of specific insurances and protection is a complex mind boggling matter which balances the idea of the child as a subject of rights whose advancing limits must be regarded with the idea of the State's commitment and obligation to give special protection”.15 Absence of harmonization over the EU members, caused legitimate vulnerability among data controllers who were presented to veering lawful standards when gathering children’s personal data. Assurance of the legitimate ability of minors to consent to processing of their personal data was an entangled task. Coming up with an exact age limit for processing of data and drawing a line showing a specific age of adulthood isn’t a test confronted exclusively by laws regarding data protection but also in other areas like contact, criminal, family and civil laws.
The UNCRC defines “child” as every human being underneath the age of 18 years unless under the law, majority is attained earlier. ‘Same was followed by the Article 29 of the Working Party. But this age did not make into the final version of GDPR, as parental consent until the age of 18 can be observed as overprotective. Many EU states consider age 14-16 as considerable age to give consent for processing of their data.’16Therefore, under Article 8 of the GDPR it is established that parental consent is required to process personal data of the children under the age of 16.The exact question of whether a child has given consent might still depend on more than one condition for example whether the consent was given in immediate interest of child and whether the guardians were or ought to have been included or consulted.
V. Privacy Under GDPR & Rights Under UNCRC
Children’s rights are set out in the UNCRC and other international and regional human rights instruments including the Universal Declaration on Human Rights (UDHR), the UN Covenant on Civil and Political Rights, European Convention for the Protection of Fundamental Rights and Freedoms, and the Council of Europe Convention on the Protection of Children against Sexual Exploitation and Sexual Abuse.17 “The implementation of the UN Convention on the Rights of the Child in 1989 manifests a significant landmark in the advance of an international framework of rights for children18”. Children’s rights are world-wide, applying similarly to all children in all social, economic and cultural contexts.
Given that the parental consent prerequisite under Article 8 of the GDPR is applicable to all youngsters under the age of 16, children especially between the ages 13-16 might feel that their right to freedom of expression on the internet is restricted. “Article 13 of UN CRC enshrines children's right to freedom of expression. The first part of the article upholds children's right to 'seek, receive and impart information and ideas of all kinds', in a range of formats and across borders. The second part limits restrictions that can be placed on this right”.19 The parental consent requirement gives the power to parents to decide how their child would behave online, without enabling the child to express his or her choice. Therefore, until and unless there is a serious risk that the child wont effectively understand the result of its choice, parental consent should not be used as a component which allows parents to supersede the child’s will and choice. It’s not always that parents are in a situation to completely understand what is best for their child. Sometimes parents may wind up as trespassers of their child’s right and privacy. There could be instance of contradiction among parents and children over the dangers and usefulness in connection to online services.
At last, the GDPR does not adequately consider the right to be heard which is a fundamental principle of UN CRC and right of expression of children in all matters affecting him or her. There was continuous contention and confusion over the age of consent as mentioned in the GDPR. Amid 2017/2018, considerable attention was paid to Article 8 of the GDPR regarding children’s protection of data online on the one hand and on the other hand, right to participate and express online as established under UNCRC. This discussion played out differently in the EU member states, bringing age between 13 and 16 under the web of digital age of consent. This was done without consulting children or child advocates completely by-passing Article 12 of UN CRC which states that the child has a right to be heard in all matters affecting them.
The law makers has a key job to comply with UN CRC to guarantee that their rights are secured and protected and to act to the greatest advantage of the child. In an advanced age in which every activity of children is recorded, it has become obvious that privacy under Article 16 of UN CRC is essential to children for their best interest (Article 3 UN CRC) and their chance to develop to maximum capacity and right to participate (Article 29). With the ink not yet dry on the GDPR it is too early to be certain whether children’s' rights will be satisfied or, at the very least, undermined by GDPR and whether Article 8 adequately balances the right of children to the protection of their personal data with their other rights under the UN Convention of the Rights of the Child (UNCRC).
VI. What Should Be Done?
As interpreted above the original intention behind Article 8 of GDPR is privacy and security of children from online predators and to protect children’s personal information from commercial exploitation and targeted marketing strategies. GDPR expects that all the information service providers in different sectors should adhere to the requirement of parental consent. In spite of the fact that the GDPR sets up parental consent as a medium to secure children on the web, this consent for processing of data is a complex solution.
We discussed how personal data online cannot be controlled either by parents or by children. As these online service providers aim to advance their business interestby collecting users data instead of enabling the users to control their data. Another problem with the parental consent is the fact that parents themselves don’t understand the consequences of giving consent as they hardly read long and complex privacy terms and conditions. These terms and conditions and policies related to children are more confusing and difficult to understand. If parent refuse to consent it would lead to their child feeling socially excluded specially in today’s digital world where there is no real alternative to online services. Parents are then forced to give consent without their will. “Various scholarshave demonstrated that strengthening consent will not lead to a greater individual control for individuals over personal data”20and “that consent cannot always be considered a legitimate ground for data processing.”21
Shifting The Burden
Looking into the weakness of parental consent, the other realistic option is to shift the burden of responsibility to the data controller and processor. Policy makers should move forward and learn from United States, which has two decades of Children Online Privacy Protection Act (herein after COPPA) experience. Hoofnagle appreciates how “COPPA puts restriction on the controlling, processing and retention of personal data by the controller.”22 Perhaps the law should not only put limitation but should restrict on using children’s data for profiling and target advertising. Adam D Thierer in Kids, Privacy, Free Speech & the Internet: Finding the Right Balance, argues that “education, empowerment and targeted enforcement of unfair and deceptive practice is better way to protect the privacy of children than just burdening the parents and children.”23
Use Of Biometrics
The other alternative to obtain the age of a user is through using biometric data which includes fingerprints, and iris patterns to identify the users. This method is reliable but complex and difficult to go around. Further Article 29 working party has criticised this method highlighting the practical difficulty. If social media starts collecting biometric online to identify the users, would significantly affect the privacy of right of data protection of young children. Moreover this data can be outdated quickly as there is substantial changes in body of child24.
Affective Age Verification Tool
GDPR could be claimed as ineffective if children can easily evade the age limiting system. The new regulation thus poses a challenge to member states to come up with advanced system of online age verification. An attempt was made in Germany and in Belgium where child’s ID card were used as online age verification tool but this method was soon criticised for being too intrusive. Sadly, GDPR does not mention any effective alternative to parental consent and age limitation for protecting children’s data online. Therefore the burden is now on the member states to come up with the more affective and lest intrusive age verification methods which enhances privacy and respects the rights of children to access the internet. Further, controllers and social media companies like Facebook and Google should come up with secure eID to improve the internet safety of children.
Efforts Taken By The Member State Government
The other alternative is that member state’s government should invest and promote start-ups which helps companies and consumer to improve their online security. For example,‘UK base company Handle offers a device which can restrict and limits devices from accessing the internet according to time sensitive guidelines. This device can be used by parents who wants to monitor and limit the time their child spend online’.25
VII. Conclusion
Every few months social media companies are called into question for hampering the privacy of its users and posing a risk to its members. Just when we thought these companies are taking strict actions regarding protecting its member’s privacy, on the 5th of December it was revealed that the large amount of personal data is gathered and sold by big companies including Facebook to other multinational companies like Tinder and Netflix. According to the report published by “The Sun” ‘Medical details, kids' voice recordings and copies of passports are at risk when customers tick an online consent box.’26Video sharing company of Google, YouTube Kids, harvest the kid’s voice and then use it to promote other apps. ‘UK parliament published private emails sent by the Facebook chief Mark Zuckerberg demonstrating how Facebook makes money in exchange of its user’s personal information. “Time and again, Facebook proves itself untrustworthy and incapable of building the world it claims it wants to see”, Dr Gus Hosein, from Privacy International, told the BBC’27 this show how these apps mock the new regulation laws. It seems more likely that EU, without recognising the pitfallsand criticism related to COPPA actually copied itsage verification tool and requirement of parental consent without any affective alternatives. As previously discussed, this requirement faces numerous difficulties with its implementation and understanding.
As argued above, tougher regulation is needed for Facebook and other such companies because ultimately they look for different ways to gather more information about their users to make money. Further, more specification is needed when it comes to consent and age verification relationship and more reliable methods for verifying the age of users. The member states should urge industries to propose compelling parental consent techniques. EU ought to effectively take part in formulation of self-regulatory rules, so as to guarantee that self-regulation is efficient and able to carry on its societal goals and objectives. With respect to age, different age limits between 13 and 16 for different data collection may be adopted. The decision of most suitable age limit in the national law should be decided after extensive research and consulting with children.
This paper has also presented various alternatives that can be taken to avoid unjustified obstruction with child’s rights while providing online security and privacy. In this matter it is hoped and trusted that member states and information society service providers will embrace measures to protect the child’s personal data in this digital age.
*****
VIII. Bibliography
(A) List of Articles referred:
1. Sonia Livingstone, John Carr and Jasmina Byrne, ‘One in Three: Internet Governance and Children’s Rights’ (2015)
2. Kathryn C Montgomery, ‘Youth and Surveillance in the Facebook Era.’ Telecommunication Policy archive. Volume 39 Issue 9, pp-771-786 (October 2015)
3. Children’s Commissioner, Growing Up Digital: A report of the Growing Up Digital Taskforce (January 2017)
4. Commission (EC), ‘An EU Agenda for the Rights of the Child’, COM/2011/0060 final, (15 February 2011)
5. Sonia Livingstone and others, ‘Risks and Safety on the Internet: The Perspective of European Children’ (LSE, EU Kids Online, London 2011); Sonia Livingstone and others, ‘Towards a Better Internet for Children: Findings and Recommendations from EU Kids Online to Inform the CEO Coalition’ (LSE, EU Kids Online, London 2012).
6. GPEN,‘2015GPEN “Sweep Children’s Privacy”
7. ICO. Guide to the General Data Protection Regulation (GDRR). What is the ‘legitimate interests’ basis? (May,2018)
8. Directive 2000/31/EcOf The European Parliament And Of The Council Of 8 June 2000 On Certain Legal Aspects Of Information Society Services, In Particular Commerce, In The Internal Market. (Directive on electronic commerce). Official Journal of the European Communities.
9. Sonia Livingstone, John Carr and Jasmina Byrne, ‘One in three: internet governance and children’s rights’ Centre for International Governance Innovation and the Royal Institute of International Affairs, (2015).
10. Victoria Nash and others, ‘Effective AgeVerification Techniques: Lessonsto be learnt from the onlinegambling industry’ (Final Report). Oxford Internet Institute, University of Oxford. ) (2014)
11. M Ryan Calo, ‘The Boundaries of Privacy Harm’ Indiana Law Journal(2011)
12. Rachel Hodgkin and Peter Newell, “Implementation Handbook for the Convention on the Rights of the Child” (UNICEF, 2002)
13. Terri Dowty and DouweKorff, ‘Protecting the Virtual Child – The Law and Children’s Consent to Sharing Personal Data’, (2009)
14. AndreeaCampeanu “UN lauds Somalia as country ratifies landmark children’s rights treaty” UN News Centre (4 May 2015)
15. LokkeMoerel and CorienPrins, ‘Privacy for the Homo Digitalis: Proposal for a New Regulatory Framework for Data Protection in the Light of Big Data and the Internet of Things’ Tilburg University - Tilburg Institute for Law, Technology, and Society. (25th May 2016)
16. Jean-Marc Dinant and Yves Poullet, The Internet and Private Life in Europe: Risks and Aspirations in A T Kenyon and M Richardson (eds), New Dimensions in Privacy Law: International and Comparative Perspectives, Cambridge University Press (2006)
17. Chris Jay Hoofnagle, Deirdre K. Mulligan, Nathaniel Good, Jens Grossklag “The Federal Trade Commission and Consumer Privacy in the Coming Decade” A Journal of Law and Policy for the Information Society. 3 (3), 723-749 (2007)
18. Thierer, Adam D., “Kids, Privacy, Free Speech & the Internet: Finding the Right Balance” (August 12, 2011). Available at SSRN
(B) List of News Articles referred:
1. WhatsApp to raise minimum age limit to 16 in EU. BBC New (25th April, 2018)
2. Saqib Shah, “WhatsApp reveals how it will stop under-16s from using the app – could YOUR kid get around it?”The Sun (30th April 2018)
3. Danny Palmer, “GCHQ's latest start up picks aim at small business securityUK intelligence agency picks the next set of companies to go through its start-up accelerator programme.” ZDNET (21st November, 2018)
4. Harvey Sullivan, “Shock scale of how Facebook flogs your and your KIDS’ personal data – including health” The Sun. (6th December, 2018)
5. Leo Kelion, Facebook defends Mark Zuckerberg's exposed emails. BBC News. (6th December,2018)
(C) List of Legislations referred:
1. GDPR (Regulation (EU) 2016/679
2. Data Protection Directive (Directive 95/46/EC)
3. UN Convention of the Rights of the Child, 2 September 1990.
4. Article 29 Data Protection Working Party, ‘Opinion 3/2012 on Developments in Biometric Technologies WP 193’, (27April 2012)
5. Children Online Privacy Protection Act, Act. 1992.
*****
Footnotes
1. BA.LLB (Hons.), KIIT School of Law, LLM (Criminal law and Justice), University of Edinburgh.
2. Sonia Livingstone, John Carr and Jasmina Byrne, ‘One in Three: Internet Governance and Children’s Rights’ (2015) Global Commission on Internet Governance Paper Series No. 22. ↩
3. KathrynCMontgomery,‘YouthandSurveillanceintheFacebookEra.’ Telecommunication Policy archive. Volume 39 Issue 9, pp-771-786 (October 2015) ↩
4. Children’s Commissioner, Growing Up Digital: A report of the Growing Up Digital Taskforce (January 2017): http://www.childrenscommissioner.gov.uk/sites/default/files/publications/Growing%20Up%20 Digital%20Taskforce%20Report%20January%202017_0.pdf ↩
5. Commission (EC), ‘An EU Agenda for the Rights of the Child’, COM/2011/0060 final, (15 February 2011) ↩
6. Sonia Livingstone and others, ‘Risks and Safety on the Internet: The Perspective of European Children’ (LSE, EU Kids Online, London 2011); Sonia Livingstone and others, ‘Towards a Better Internet for Children: Findings and Recommendations from EU Kids Online to Inform the CEO Coalition’ (LSE, EU Kids Online, London 2012). ↩
7. GPEN,‘2015GPEN “Sweep Children’s Privacy” https://www.garanteprivacy.it/documents/10160/0/GPEN+Privacy+Sweep+2015.pdf ↩
8. ICO. Guide to the General Data Protection Regulation (GDRR). What is the ‘legitimate interests’ basis? (May,2018) ↩
9. Directive 2000/31/EcOf The European Parliament And Of The Council Of 8 June 2000 On Certain Legal Aspects Of Information Society Services, In Particular Commerce, In The Internal Market. (Directive on electronic commerce). Official Journal of the European Communities. ↩
10. Sonia Livingstone, John Carr and Jasmina Byrne, ‘One in three: internet governance and children’s rights’ Centre for International Governance Innovation and the Royal Institute of International Affairs, (2015). ↩
11. WhatsApp to raise minimum age limit to 16 in EU. BBC New (25th April, 2018) https://www.bbc.co.uk/news/business-43888647 ↩
12. Saqib Shah, “WhatsApp reveals how it will stop under-16s from using the app – could YOUR kid get around it?”The Sun (30th April 2018) https://www.thesun.co.uk/tech/6175542/whatsapp-age-limit-new-terms-of-service/ ↩
13. Victoria Nash and others, ‘Effective AgeVerification Techniques: Lessonsto be learnt from the onlinegambling industry’ (Final Report). Oxford Internet Institute, University of Oxford. ) (2014) ↩
14. M Ryan Calo, ‘The Boundaries of Privacy Harm’ Indiana Law Journal(2011) ↩
15. Rachel Hodgkin and Peter Newell, “Implementation Handbook for the Convention on the Rights of the Child” (UNICEF, 2002) ↩
16. Terri Dowty and DouweKorff, ‘Protecting the Virtual Child – The Law and Children’s Consent to Sharing Personal Data’, (2009) http://medconfidential.org/wp-content/uploads/2013/03/Protecting-the-virtual-child.pdf ↩
17. Available at Council of Europe (2007) http:// conventions.coe.int/Treaty/Commun/QueVoulezVous. asp?NT=201&CM=8&DF=&CL=ENG. ↩
18. AndreeaCampeanu “UN lauds Somalia as country ratifies landmark children’s rights treaty” UN News Centre (4 May 2015) http://www.un.org/apps/news/story.asp?NewsID=50759#.WMfxcSlXXct ↩
19. Article 13: Freedom Of Expression, UNCRC. https://www.crin.org/en/home/rights/convention/articles/article-13-freedom-expression ↩
20. LokkeMoerel and CorienPrins, ‘Privacy for the Homo Digitalis: Proposal for a New Regulatory Framework for Data Protection in the Light of Big Data and the Internet of Things’ Tilburg University - Tilburg Institute for Law, Technology, and Society. (25th May 2016) ↩
21. Jean-Marc Dinant and Yves Poullet, The Internet and Private Life in Europe: Risks and Aspirations in A T Kenyon and M Richardson (eds), New Dimensions in Privacy Law: International and Comparative Perspectives, Cambridge University Press (2006), ↩
22. Chris Jay Hoofnagle, Deirdre K. Mulligan, Nathaniel Good, Jens Grossklag “The Federal Trade Commission and Consumer Privacy in the Coming Decade” A Journal of Law and Policy for the Information Society. 3 (3), 723-749 (2007) ↩
23. Thierer, Adam D., “Kids, Privacy, Free Speech & the Internet: Finding the Right Balance” (August 12, 2011). Available at SSRN: https://ssrn.com/abstract=1909261 or http://dx.doi.org/10.2139/ssrn.1909261 ↩
24. Article29DataProtectionWorkingParty,‘Opinion3/2012onDevelopmentsinBiometricTechnologiesWP 193’, (27April 2012) ↩
25. Danny Palmer, “GCHQ's latest startup picks aim at small business securityUK intelligence agency picks the next set of companies to go through its start-up accelerator programme.” ZDNET (21st November, 2018) | https://www.zdnet.com/article/gchqs-latest-startup-picks-aim-at-small-business-security/ ↩
26. Harvey Sullivan, “Shock scale of how Facebook flogs your and your KIDS’ personal data – including health” The Sun. (6th December, 2018) https://www.thesun.co.uk/news/7910755/personal-data-harvested-and-sold-by-big-firms/ ↩
27. Leo Kelion, Facebook defends Mark Zuckerberg's exposed emails. BBC News. (6th December,2018) https://www.bbc.co.uk/news/technology-46468108 ↩
- Sonia Livingstone, John Carr and Jasmina Byrne, ‘ One in Three: Internet Governance and Children’s Rights’ (2015) Global Commission on Internet Governance Paper Series No. 22.
- KathrynCMontgomery,‘ YouthandSurveillanceintheFacebookEra .’ Telecommunication Policy archive. Volume 39 Issue 9, pp-771-786 (October 2015)
- Children’s Commissioner , Growing Up Digital: A report of the Growing Up Digital Taskforce (January 2017): http://www.childrenscommissioner.gov.uk/sites/default/files/publications/Growing%20Up%20 Digital%20Taskforce%20Report%20January%202017_0.pdf
- Commission (EC), ‘ An EU Agenda for the Rights of the Child’ , COM/2011/0060 final, (15 February 2011)
- Sonia Livingstone and others, ‘ Risks and Safety on the Internet : The Perspective of European Children’ (LSE, EU Kids Online, London 2011); Sonia Livingstone and others, ‘ Towards a Better Internet for Children: Findings and Recommendations from EU Kids Online to Inform the CEO Coalition’ (LSE, EU Kids Online, London 2012).
- GPEN,‘2015GPEN “Sweep Children’s Privacy” https://www.garanteprivacy.it/documents/10160/0/GPEN+Privacy+Sweep+2015.pdf
- ICO. Guide to the General Data Protection Regulation (GDRR). What is the ‘legitimate interests’ basis? (May,2018)
- Directive 2000/31/EcOf The European Parliament And Of The Council Of 8 June 2000 On Certain Legal Aspects Of Information Society Services, In Particular Commerce, In The Internal Market. (Directive on electronic commerce). Official Journal of the European Communities.
- Sonia Livingstone, John Carr and Jasmina Byrne, ‘ One in three: internet governance and children’s rights ’ Centre for International Governance Innovation and the Royal Institute of International Affairs, (2015).
- WhatsApp to raise minimum age limit to 16 in EU. BBC New (25 th April, 2018) https://www.bbc.co.uk/news/business-43888647
- Saqib Shah, “ WhatsApp reveals how it will stop under-16s from using the app – could YOUR kid get around it ?” The Sun (30 th April 2018) https://www.thesun.co.uk/tech/6175542/whatsapp-age-limit-new-terms-of-service/
- Victoria Nash and others, ‘ Effective AgeVerification Techniques: Lessonsto be learnt from the onlinegambling industry ’ (Final Report). Oxford Internet Institute, University of Oxford. ) (2014)
- M Ryan Calo, ‘ The Boundaries of Privacy Harm’ Indiana Law Journal(2011)
- Rachel Hodgkin and Peter Newell, “ Implementation Handbook for the Convention on the Rights of the Child ” (UNICEF, 2002)
- Terri Dowty and DouweKorff, ‘ Protecting the Virtual Child – The Law and Children’s Consent to Sharing Personal Data ’, (2009) http://medconfidential.org/wp-content/uploads/2013/03/Protecting-the-virtual-child.pdf
- Available at Council of Europe (2007) http:// conventions.coe.int/Treaty/Commun/QueVoulezVous. asp?NT=201&CM=8&DF=&CL=ENG.
- AndreeaCampeanu “UN lauds Somalia as country ratifies landmark children’s rights treaty ” UN News Centre (4 May 2015) http://www.un.org/apps/news/story.asp?NewsID=50759#.WMfxcSlXXct
- Article 13: Freedom Of Expression, UNCRC. https://www.crin.org/en/home/rights/convention/articles/article-13-freedom-expression
- LokkeMoerel and CorienPrins, ‘ Privacy for the Homo Digitalis: Proposal for a New Regulatory Framework for Data Protection in the Light of Big Data and the Internet of Things’ Tilburg University - Tilburg Institute for Law, Technology, and Society. (25 th May 2016)
- Jean-Marc Dinant and Yves Poullet, The Internet and Private Life in Europe: Risks and Aspirations in A T Kenyon and M Richardson (eds), New Dimensions in Privacy Law: International and Comparative Perspectives , Cambridge University Press (2006),
- Chris Jay Hoofnagle, Deirdre K. Mulligan, Nathaniel Good, Jens Grossklag “ The Federal Trade Commission and Consumer Privacy in the Coming Decade” A Journal of Law and Policy for the Information Society. 3 (3), 723-749 (2007)
- Thierer, Adam D., “ Kids, Privacy, Free Speech & the Internet: Finding the Right Balance” (August 12, 2011). Available at SSRN: https://ssrn.com/abstract=1909261 or http://dx.doi.org/10.2139/ssrn.1909261
- Article29DataProtectionWorkingParty,‘Opinion3/2012onDevelopmentsinBiometricTechnologiesWP 193’, (27April 2012)
- Danny Palmer, “ GCHQ's latest startup picks aim at small business security UK intelligence agency picks the next set of companies to go through its start-up accelerator programme. ” ZDNET (21 st November, 2018) | https://www.zdnet.com/article/gchqs-latest-startup-picks-aim-at-small-business-security/
- Harvey Sullivan, “ Shock scale of how Facebook flogs your and your KIDS’ personal data – including health” The Sun. (6 th December, 2018) https://www.thesun.co.uk/news/7910755/personal-data-harvested-and-sold-by-big-firms/
- Leo Kelion, Facebook defends Mark Zuckerberg's exposed emails. BBC News. (6 th December,2018) https://www.bbc.co.uk/news/technology-46468108
