Most of the laws now regulating children's digital lives were written in the last five years, and many of them point back to the same document. The UK's Age Appropriate Design Code guidance cites it. The European Commission's guidelines on protecting minors under the Digital Services Act cite it. That document is General Comment No. 25 of the UN Committee on the Rights of the Child, and any organisation whose products, services or programmes touch children online will eventually be asked whether it has read it.

What is UNCRC General Comment No. 25?

General Comment No. 25 (CRC/C/GC/25), issued on 2 March 2021, is the UN Committee on the Rights of the Child's guidance on how the Convention on the Rights of the Child applies to the digital environment. It explains what governments must do, and require of businesses, so children's rights are respected, protected and fulfilled online.

Where it came from and what legal weight it carries

The Convention on the Rights of the Child is the most widely ratified human rights treaty in the world: every UN member state except the United States is a party. The Committee on the Rights of the Child is the body of independent experts that monitors how states implement it, and one of its tools is the general comment: a formal statement of how a particular part of the Convention should be read.

According to its own text, General Comment 25 draws on the Committee's review of state reports, its earlier day of general discussion on digital media and children's rights, two rounds of consultation with states, experts and other stakeholders, and an international consultation with 709 children living in a wide variety of circumstances in 28 countries.

Its legal status is often misunderstood in both directions. A general comment is not a treaty and creates no new obligations, but it is not a policy wish list either. It is the treaty body's authoritative interpretation of obligations that states have already accepted by ratifying the Convention. In practice it is used:

  • By the Committee, as the benchmark when it reviews states.
  • By legislators and regulators, as a reference when drafting codes and guidance.
  • By courts and national human rights institutions, as persuasive guidance on what the Convention means online.
  • By civil society, as the yardstick for draft laws and industry practice.

For a business or NGO, the short version is this: General Comment 25 does not bind you directly, but the laws that do bind you are increasingly written with it open on the desk.

The four general principles, applied to the digital environment

The Committee treats four principles of the Convention as the lens through which every other right should be read. General Comment 25 applies each of them to digital life.

  1. Non-discrimination. All children should have equal and effective access to the digital environment. Discrimination includes digital exclusion, hateful communications, and automated filtering, profiling or decision-making based on biased or unfairly obtained data about a child.
  2. Best interests of the child. In all actions regarding the provision, regulation, design, management and use of the digital environment, the best interests of every child should be a primary consideration. Best interests assessments should consider all of a child's rights, including to information and to have their views heard, not only protection.
  3. Life, survival and development. States should protect children from risks relating to content, contact, conduct and contract, including violent and sexual content, harassment, exploitation and abuse, and the promotion of suicide or self-harm.
  4. Respect for the views of the child. Children should be involved when laws, policies, services and products that affect them are developed. States should ensure that digital service providers actively engage with children, with appropriate safeguards, and give their views due consideration in product development.

Alongside these, the comment gives a full section to evolving capacities: the principle that children gain competence, understanding and agency gradually and unevenly. Measures should be age-appropriate, informed by current research, and services should suit children's evolving capacities. The European Commission's Digital Services Act guidelines cite exactly these paragraphs when explaining why platforms should differentiate by age.

What the main sections cover

After the principles, the comment works through the Convention's rights area by area:

  • General measures of implementation. Legislation, strategy, coordination, resourcing, monitoring and training, plus the business obligations covered below and access to justice: complaint and reporting mechanisms should be free, safe, confidential, responsive and child-friendly.
  • Civil rights and freedoms. Content controls and school filtering systems should prevent the flow of harmful material, not restrict children's access to information. Age-based or content-based protective systems should be consistent with data minimisation.
  • Privacy, part of the civil rights section. Privacy is described as "vital to children's agency, dignity and safety". States should require privacy by design in products that affect children. Digital surveillance of children should not be routine, indiscriminate or conducted without the child's knowledge, and parental monitoring should be proportionate to the child's evolving capacities.
  • Violence against children. Grooming, live-streamed abuse, sexual extortion, cyberaggression and non-consensual sharing of sexualised images, including by people a child trusts. Where children themselves cause harm, the comment favours preventive, safeguarding and restorative responses.
  • Family environment and alternative care. Support for parents' digital literacy, guidance that favours balance between protection and emerging autonomy over prohibition or control.
  • Children with disabilities. Accessible content, affordable assistive technology, universal design, and a warning against prejudice that leads to overprotection or exclusion.
  • Health and welfare. Confidential access to trustworthy health information and services, and regulation against digital design that undermines children's development.
  • Education, leisure and play. Digital literacy from preschool onwards, standards for educational technology that prevent misuse of children's data and commercial exploitation, and protection from "gambling-like" design in leisure services.
  • Special protection measures. Exploitation, child justice, and children in conflict or migration. The comment says self-generated sexual material that children possess or share consensually and solely for their own private use should not be criminalised, and that robust age verification should prevent children accessing products and services that are illegal for them, consistent with data protection and safeguarding.

What it asks of states, and what it asks of businesses

General Comment 25 is addressed to states. Businesses appear throughout, but mostly as the subject of what states should require. The comment is explicit that the business sector, including not-for-profit organisations, affects children's rights in the digital environment, that businesses should respect those rights and prevent and remedy abuses, and that states have the obligation to make sure they do.

The specific expectations that flow through to businesses are demanding:

  • Child rights due diligence, in particular carrying out child rights impact assessments and disclosing them publicly.
  • The highest standards of ethics, privacy and safety across the design, engineering, development, operation, distribution and marketing of products and services that target children, have children as end users or otherwise affect children.
  • Age-appropriate explanations of terms of service, to children or, for very young children, to their parents.
  • No commercial profiling of children. States should prohibit by law the profiling or targeting of children of any age for commercial purposes based on their actual or inferred characteristics, and practices such as neuromarketing and emotional analytics should not be directed at children.
  • Effective complaint mechanisms that do not prevent children from also reaching state-based remedies.

Note the reach of the second point: affecting children is enough. The UK and EU regimes apply the same logic to services "likely to be accessed by" or "accessible to" minors.

How it shows up in later law and guidance

The clearest traces are in Europe and the UK.

  • European Union. The European Commission's guidelines under Article 28 of the Digital Services Act, published on 14 July 2025, state that children's rights are elaborated for the digital environment in General Comment 25 and cite it on evolving capacities and exploitation. They ask platforms to treat the best interests of the child as a primary consideration, to seek children's participation when reviewing risks, and point to existing child rights impact assessment tools. Our comparison of the UK Online Safety Act and the EU Digital Services Act covers how that duty works in practice.
  • United Kingdom. The Information Commissioner's Office was obliged to take the Convention into account when developing the Age Appropriate Design Code, whose first standard is the best interests of the child. The ICO's guidance on the Convention and online services refers to General Comment 25 directly.
  • Council of Europe. The Council of Europe's 2018 Recommendation CM/Rec(2018)7 on children's rights in the digital environment predates General Comment 25 and covers much of the same ground.
  • Australia. In the consultation on Australia's Children's Online Privacy Code, which the privacy regulator must register by 10 December 2026, child rights organisations and researchers urged alignment with General Comment 25. Whether the final code adopts its language remains to be seen.

What this means for organisations

For platforms, schools, NGOs and companies whose services reach children, General Comment 25 is most useful as one standard to design against, not a separate compliance exercise.

First, assess impact on children's rights, not only risk of harm. A child rights impact assessment asks what a product, policy or programme does to the full range of children's rights: protection, but also privacy, information, expression, play and non-discrimination. It is the tool the comment names. Building one into your safeguarding policy and governance framework means the reasoning exists before a regulator, funder or journalist asks for it.

Second, involve children. The comment expects providers to engage actively with children when developing products and services, with safeguards. That can be proportionate, such as structured consultation or testing with young users, but designing for children without asking them does not meet it.

Third, balance protection with provision and participation. The comment repeatedly warns against measures that protect children by excluding them: filters that block health information, surveillance without the child's knowledge, age checks that collect more data than necessary. This is where online safety strategy most often goes wrong, and where age assurance choices and safety-by-design decisions need to be documented and justified. Staff making those decisions need training grounded in children's rights, not only checklists.

Frequently asked questions

Is General Comment 25 legally binding? Not in itself. It is the UN Committee on the Rights of the Child's authoritative interpretation of the Convention, which is binding on the states that have ratified it. Regulators and legislators increasingly draw on it, so its expectations reach organisations through national law and guidance.

Does General Comment 25 apply to businesses? It is addressed to states, but it says businesses, including not-for-profit organisations, should respect children's rights in the digital environment, and that states must require child rights due diligence and impact assessments from them.

When was General Comment 25 published? The document, CRC/C/GC/25, is dated 2 March 2021.

What is the first step for an organisation? Map where your services, programmes or platforms affect children, then carry out a child rights impact assessment that weighs protection against privacy, participation and access, and record what you decided and why.

Regulatory and legal details cited here are accurate as of September 2026 and should be checked against the full text of General Comment 25 and the relevant national regulator before being relied on in a compliance decision.

Work with Maryam

Looking for expert guidance on child safeguarding, online safety, or AI governance? Maryam and the Child Safe ME team are here to help.

Get in Touch