Safeguarding
Child safeguarding
Child safeguarding is the set of policies, procedures and practices an organisation puts in place so that its own staff, operations, programmes and partners do no harm to children, and so that any concern about a child is reported and acted on. It is broader than child protection: it covers prevention, culture and accountability, not only the response after harm. The organisation is responsible for the risks it creates, wherever it works. See how to build a child safeguarding policy framework and our policy and framework services.
Child protection
Child protection is the response to a child who has been harmed or is at risk of significant harm: identifying, reporting, investigating and supporting. In most countries it is a duty of the state, delivered through social services, police and courts. Organisations meet child protection through their referral and reporting procedures; child safeguarding is the wider system that makes those procedures work and prevents harm in the first place.
Safeguarding policy framework
A safeguarding policy framework is the connected set of documents that turns a commitment to keeping children safe into rules people can follow: a policy statement, a code of conduct, reporting and response procedures, safer recruitment and training requirements, risk-assessment tools, partner requirements and a governance and review cycle. A single policy is not a framework; the framework is what makes the policy operational. Our step-by-step guide covers each component.
Safeguarding audit
A safeguarding audit is an independent assessment of how well an organisation's safeguarding measures work in practice, tested against recognised standards rather than against the organisation's own paperwork. It examines policy, people, procedures and accountability, gathers evidence from documents, interviews, site visits and case files, and produces a rated findings report with a prioritised action plan. Read what a child safeguarding audit covers.
International Child Safeguarding Standards
The International Child Safeguarding Standards are the four standards published by Keeping Children Safe, the coalition founded in 2010 that has become the reference point for safeguarding in international NGOs, donors and UN agencies: policy, people, procedures and accountability. Many funders require partners to meet them. Child Safe ME founder Maryam Ehsani managed the Keeping Children Safe global network from 2010 to 2018.
Safeguarding focal point
A safeguarding focal point (in UK usage, the designated safeguarding lead) is the named person in an organisation who receives concerns, keeps records, advises colleagues and makes or escalates referrals to the authorities. Larger organisations designate one per country office or site and a senior focal point at headquarters. The role needs written terms of reference, training, time and a direct line to leadership; a name on a policy is not enough.
Code of conduct
A code of conduct is the document that sets out the behaviour an organisation expects from staff, volunteers, contractors and visitors when they are in contact with children, both in person and online. It is written as specific do's and don'ts (never being alone with a child out of sight of others, never contacting a child on a personal account) rather than as values, and it is signed as a condition of engagement so that breaches can be acted on.
Safer recruitment
Safer recruitment is the practice of designing every stage of hiring so that people who pose a risk to children are deterred, identified or excluded: advertising the organisation's safeguarding stance, interview questions on attitudes to children, verified references, criminal-record checks where they exist, identity checks and a probation period with supervision. It applies to volunteers, consultants and partner staff, not only to employees.
Reporting and response procedure
A reporting and response procedure sets out what a person must do when they see, hear or suspect harm to a child: whom to tell, within what time, how the report is recorded, who decides on referral to the authorities, how the child and the reporter are supported, and how the case is closed and learned from. The procedure covers concerns about staff and partners as well as concerns about a child's home life, and it must work for children themselves.
Safeguarding risk assessment
A safeguarding risk assessment identifies how a specific activity, programme, location or product could bring harm to children, rates the likelihood and severity of each risk, and records the measures that reduce it to an acceptable level. It is done before an activity starts and is reviewed when circumstances change. For digital products the equivalent instrument is a child rights impact assessment or, for personal-data processing, a DPIA.
Duty of care
A duty of care is the legal and ethical obligation of an organisation to take reasonable steps to prevent foreseeable harm to the people it affects. Safeguarding is how an organisation discharges its duty of care to children. Online safety laws have started to write a version of this duty into statute: the UK Online Safety Act's safety duties and Australia's proposed digital duty of care both place a positive obligation on services rather than relying on complaints after harm.
Child participation
Child participation means involving children in the decisions that affect them, in ways suited to their age and understanding. In safeguarding it means asking children what makes them feel safe, designing reporting routes they will actually use and testing policies with them. Article 12 of the UNCRC makes it a right, and General Comment 25 extends it to the digital environment, so consultation with children is part of a defensible design process.
Whistleblowing
Whistleblowing is the reporting of wrongdoing inside an organisation, including safeguarding failures, by someone who works there. A whistleblowing policy protects the reporter from retaliation and provides a route outside the line-management chain, for the case where a manager is the subject of the concern. Safeguarding investigations regularly begin with a whistleblower, so the two policies must refer to each other.
Children's rights
UN Convention on the Rights of the Child (UNCRC)
The UN Convention on the Rights of the Child is the 1989 treaty that sets out the civil, political, economic, social and cultural rights of everyone under 18. It is the most widely ratified human-rights treaty; every UN member state except the United States is a party. Its four general principles are non-discrimination, the best interests of the child, the right to life and development, and the right to be heard. It is the legal foundation for safeguarding standards, child rights impact assessments and, through General Comment 25, children's rights online. See our General Comment 25 explainer.
General Comment No. 25
General Comment No. 25 (2021) is the UN Committee on the Rights of the Child's authoritative interpretation of how the UNCRC applies in the digital environment. It tells states and, through them, businesses that children's rights apply online exactly as they do offline: to privacy, protection from exploitation, information, play and participation. It has shaped the UK Online Safety Act, the EU Digital Services Act's minor-protection provisions and age-appropriate design codes. Read the explainer.
Best interests of the child
The best interests of the child (UNCRC Article 3) is the principle that in every decision affecting a child, the child's interests must be a primary consideration. For an organisation it is the test to apply when safeguarding conflicts with another goal: growth, revenue, a programme deadline or a product feature. Regulators now apply it directly; the UK Children's Code, for example, requires online services to weigh a child's best interests when designing data-processing.
Evolving capacities
Evolving capacities (UNCRC Article 5) is the principle that children gain the ability to exercise their own rights gradually, so protection and autonomy should be balanced according to age and maturity rather than treating everyone under 18 the same. It is why age-appropriate design distinguishes a 6-year-old from a 15-year-old, and why blanket measures such as a single social media minimum age are debated.
Child rights impact assessment (CRIA)
A child rights impact assessment is a structured process for predicting how a policy, product, service or AI system will affect children's rights under the UNCRC, and for changing it before launch so that harms are removed and benefits are strengthened. It is broader than a data-protection impact assessment, which looks only at personal data, and is increasingly expected of digital services used by children. Read what a child rights impact assessment is, and see responsible AI and child safety assessment.
Child rights by design
Child rights by design is an approach to digital product development that embeds the full range of children's rights, not only protection from harm, into every design decision from the outset. It builds on safety by design and privacy by design and adds children's rights to participation, play, information and non-discrimination. The CRIA is its main working tool.
Online safety and regulation
Online child safety
Online child safety is the protection of children from harm in digital environments: harmful content, harmful contact from other users, harmful conduct by the child or peers, and harmful commercial practices (the "4 Cs" classification used by the CO:RE research network and adopted by regulators). It now spans product design, age assurance, moderation, reporting and the regulatory regimes described below. Our online safety guide and articles cover the field, and online safety advisory describes how we help.
UK Online Safety Act 2023
The Online Safety Act is the UK law, enacted in October 2023, that places duties on user-to-user services and search services to protect users from illegal content and to protect children from content that is harmful to them, enforced by Ofcom with fines of up to 10% of global revenue. Services likely to be accessed by children must carry out children's risk assessments, use highly effective age assurance to keep children away from pornography and other primary-priority content, and follow Ofcom's Protection of Children Codes, in force since July 2025. Compare it with the EU regime in Online Safety Act vs DSA for children.
Ofcom
Ofcom is the UK communications regulator and the enforcement body for the Online Safety Act. It publishes the codes of practice and guidance that define what compliance looks like (illegal-harms codes, Protection of Children Codes, age-assurance guidance), assesses services' risk assessments, and can fine, require changes or apply for services to be blocked in the UK.
EU Digital Services Act (DSA)
The Digital Services Act is the EU regulation, fully applicable since February 2024, that sets platform accountability rules for online intermediaries. For children the key provision is Article 28: every online platform accessible to minors must take appropriate and proportionate measures to ensure a high level of privacy, safety and security for them, and may not show them advertising based on profiling. The European Commission's guidelines on the protection of minors (July 2025) explain what Article 28 requires in practice, including age assurance, default settings and recommender design. See how the DSA and the Online Safety Act compare.
Very large online platform (VLOP)
A very large online platform, or very large online search engine (VLOSE), is a service designated by the European Commission under the DSA because it has more than 45 million monthly users in the EU. VLOPs carry extra obligations: an annual systemic-risk assessment that must cover risks to minors, independent audits, transparency reports and direct Commission supervision. Most of the services children use most are designated.
Australia Online Safety Act 2021
Australia's Online Safety Act 2021 gives the eSafety Commissioner powers to require removal of harmful material, sets Basic Online Safety Expectations for services, and underpins the industry codes and standards that now cover age assurance, generative AI and app stores. It was amended in 2024 to add the under-16 social media minimum age, in force since December 2025, and the government has committed to adding a digital duty of care. Read our guide to Australia's 2026 rules for children online.
eSafety Commissioner
The eSafety Commissioner is Australia's independent online-safety regulator, established in 2015 as the first of its kind. It runs complaints schemes for cyberbullying of children, image-based abuse and illegal content, registers and enforces industry codes, and publishes the Safety by Design framework and assessment tools that many regulators and companies elsewhere have adopted.
Social media minimum age
A social media minimum age is a legal requirement that platforms prevent people under a set age, usually 16, from holding accounts. Australia's requirement took effect in December 2025 with the obligation placed on platforms rather than parents, and Malaysia, Indonesia, the Philippines and several European countries are following or considering similar rules. The debate is whether exclusion protects children or merely delays exposure without fixing design. Our view is in beyond a social media ban, and the Asia-Pacific picture in Southeast Asia's 2026 laws.
Digital duty of care
A digital duty of care is a statutory obligation on online services to take reasonable steps to prevent foreseeable harm to their users, shifting regulation from removing content after the fact to preventing harm through design and systems. Australia committed to legislating one in its 2026 response to the statutory review of the Online Safety Act; the UK Online Safety Act's safety duties and the DSA's Article 28 work on the same principle.
Age assurance
Age assurance is the umbrella term for any method a service uses to establish a user's age or age range, so that it can apply age-appropriate protections or restrict access. It includes age verification, age estimation and self-declaration, at different levels of confidence. The international standard is ISO/IEC 27566-1, and regulators in the UK, EU and Australia now require "highly effective" or "appropriate and proportionate" methods for specific content and services. Read what age assurance is and which methods work.
Age verification
Age verification establishes a user's age with a high level of confidence by checking it against a trusted source: an identity document, a bank or mobile-operator record, a digital identity wallet or a credit card. It is the strongest form of age assurance and the most intrusive, which is why regulators reserve it for the highest-risk content and why privacy-preserving designs (verify once, share only "over 18") matter.
Age estimation
Age estimation infers a user's likely age or age range from signals rather than from a record: facial analysis of a selfie, behavioural and usage patterns, voice, or language. It gives a probability, not a fact, so services set a buffer (treating anyone estimated under 20 or 21 as possibly under 18) and offer verification as a fallback. Accuracy varies with age, sex and skin tone, and that bias is a compliance and a rights issue.
Age-appropriate design
Age-appropriate design is the principle that a digital service likely to be used by children must be designed for the age of the children who actually use it, with defaults, language, data practices and features suited to them. The UK's Age Appropriate Design Code, known as the Children's Code, is the model most often copied, including in California, Australia and several EU member states.
Children's Code (Age Appropriate Design Code)
The Children's Code is the UK Information Commissioner's statutory code of practice, in force since September 2021, that sets 15 standards for online services likely to be accessed by under-18s: high-privacy defaults, no geolocation by default, no nudge techniques, data minimisation, age-appropriate transparency and a best-interests test. It is enforced under UK GDPR, so breaches attract data-protection fines. See GDPR and children's data.
Safety by design
Safety by design is the practice of anticipating and preventing harm to users, especially children, during the design and development of a product rather than adding safety after launch. It originated with Australia's eSafety Commissioner and rests on three principles: service-provider responsibility, user empowerment and autonomy, and transparency and accountability. It is now embedded in the DSA guidelines, Ofcom's codes and the OECD's recommendations. Use our safety-by-design checklist for children's products.
Privacy by design and by default
Privacy by design and by default is the GDPR Article 25 obligation to build data protection into systems from the outset and to set the most privacy-protective options as the default. For children it translates into high-privacy defaults, minimal data collection and no profiling unless there is a compelling reason. It is the data-protection counterpart of safety by design.
Content moderation
Content moderation is the set of policies, tools and people a service uses to detect, review and act on content and behaviour that breaks the law or its own rules: hash-matching for known abuse material, classifiers, user reports, human review and appeals. Online safety laws now require moderation to be proportionate to the risk to children, to be reported on transparently and to be backed by workable user reporting.
Recommender system
A recommender system is the algorithm that decides which content, accounts or products a user sees next, based on their behaviour and on what similar users engaged with. Because it can push a child from mild content towards self-harm, eating-disorder or sexualised material in a few sessions, regulators treat it as a safety feature: the DSA requires VLOPs to offer a non-profiled option, and Ofcom's codes require feeds to be configured to filter harmful content out of children's feeds.
Parental controls
Parental controls are the settings, on devices, operating systems, app stores and individual services, that let a parent or carer limit what a child can access, buy or share, and how long they can use a service. Regulators now regard them as a supplement to platform-level protection, not a substitute: a control the parent must find and switch on does not discharge the service's own duty.
Online Safety Commission (Singapore)
The Online Safety Commission is Singapore's statutory body, operating since June 2026 under the Online Safety (Relief and Accountability) Act, that can direct platforms to remove harmful content and give victims of online harm a route to relief. Together with the Infocomm Media Development Authority's codes of practice, including mandatory age assurance on app stores from April 2026, it forms Singapore's online-safety regime. See Southeast Asia's child online safety laws.
Children's data and privacy
GDPR and children
The General Data Protection Regulation treats children as vulnerable data subjects who merit specific protection. Its rules for children include the digital age of consent (Article 8), transparency written in language a child can understand, a strong right to erasure of data collected in childhood, and limits on profiling. Supervisory authorities have imposed some of the largest GDPR fines for children's data. Read GDPR and children's data across the EU.
Digital age of consent
The digital age of consent is the age from which a child can consent on their own to an online service processing their personal data. GDPR Article 8 sets it at 16 but lets member states lower it to 13, so it ranges from 13 (the UK, Denmark, Sweden) to 16 (Germany, the Netherlands, Ireland). Below that age a service needs verifiable parental consent, which in practice means a service used across Europe must know each user's age and country.
Data protection impact assessment (DPIA)
A data protection impact assessment is the GDPR Article 35 process for identifying and reducing the privacy risks of processing before it starts. It is mandatory for high-risk processing, and processing children's data at scale, profiling children, or using new technology such as AI on children's data are all listed as high-risk. A DPIA looks only at personal data; a CRIA covers the full range of a child's rights, and the two are best run together.
Profiling
Profiling is automated processing of personal data to evaluate or predict aspects of a person: interests, behaviour, location, health or reliability. For children the law now restricts it sharply: the DSA bans profiling-based advertising to minors, the Children's Code says profiling must be off by default, and the EU AI Act limits emotion recognition and social scoring. Recommender systems and targeted advertising are the two commonest forms of profiling children encounter.
Data minimisation
Data minimisation is the principle that a service should collect and keep only the personal data it needs for a specific purpose. For children's services it is the first line of defence: data that is never collected cannot be leaked, sold or used to profile. It also shapes age assurance design, since checking age should not itself create a record of the child's identity.
Deceptive design (dark patterns)
Deceptive design, often called dark patterns, is interface design that manipulates users into choices they would not otherwise make: nudging a child to share location, making "accept" prominent and "decline" hidden, infinite scroll and streaks that exploit a child's difficulty in stopping. The Children's Code prohibits nudging children towards weaker privacy, the DSA bans dark patterns on platforms, and the DSA minor-protection guidelines name engagement-maximising features as risks to be removed.
Online harms
Child sexual abuse material (CSAM)
Child sexual abuse material is any image, video or other material depicting the sexual abuse or exploitation of a child. The term has replaced "child pornography" in professional and legal usage because the material records a crime against a child, not a form of pornography. Its detection is the one area where every online-safety regime imposes an absolute duty, usually met by hash-matching against databases held by bodies such as the Internet Watch Foundation and NCMEC. See AI-generated CSAM.
Child sexual exploitation and abuse (CSEA)
Child sexual exploitation and abuse is the umbrella term regulators use for the full range of sexual harms to children online: production and sharing of CSAM, grooming, sextortion, live-streamed abuse and coercion into self-generated imagery. The UK Online Safety Act lists CSEA offences as priority illegal content, meaning services must proactively prevent them rather than only respond to reports.
Grooming
Grooming is the process by which an adult builds trust and emotional connection with a child, and often with the adults around the child, in order to sexually abuse or exploit them. Online it typically moves from a public platform to private messaging, uses flattery, gifts or shared secrets, and escalates to requests for images. Design features such as adult-to-child direct messaging by default, friend suggestions and location sharing are the main grooming risks regulators require services to address.
Sextortion
Sextortion is the coercion of a person into providing sexual images, sexual acts or money under threat of sharing intimate images they have already been persuaded or tricked into sending. Financially motivated sextortion of teenage boys by organised groups posing as girls has grown sharply since 2021 and has been linked to suicides in several countries. Detection of the initial contact pattern, and rapid takedown and support, are the service-side responses.
Cyberbullying
Cyberbullying is repeated, intentional harm inflicted on a child through digital means: abusive messages, exclusion, spreading rumours or images, impersonation. Because it follows the child home and can be anonymous and permanent, its impact can exceed that of offline bullying. Australia's eSafety Commissioner runs the first statutory complaints scheme for it, and reporting tools, blocking and safe defaults are the platform-side measures most regimes require.
Self-generated sexual imagery
Self-generated sexual imagery is sexual material a child has produced of themselves, whether voluntarily between peers, under pressure, or through coercion by an adult. It is the fastest-growing category of material identified by hotlines. The child is a victim, not an offender, and services need reporting and takedown routes that a child will use, such as the Internet Watch Foundation's Report Remove tool.
AI and children
Child safety in AI
Child safety in AI is the field concerned with how artificial intelligence systems affect children, whether or not the system was designed for them: AI products children use directly (chatbots, companions, educational tools), AI embedded in the platforms they use (recommenders, moderation, age estimation), AI used about them by institutions (schools, welfare, policing), and AI misused against them (generated abuse imagery, grooming at scale). Our AI safety guide and articles map the field, and responsible AI and child safety assessment is how we help organisations address it.
EU AI Act
The EU Artificial Intelligence Act is the first comprehensive AI law, in force since August 2024 with obligations phased in to 2027. For children it prohibits AI that exploits the vulnerabilities of age to distort behaviour in harmful ways, classifies AI used in education and in access to essential services as high-risk (with risk-management, data-governance and human-oversight duties), and requires disclosure when a person is interacting with an AI system or seeing AI-generated content. Read the EU AI Act and children explained.
Responsible AI
Responsible AI is the practice of developing and deploying AI systems so that they are safe, fair, transparent, accountable and respectful of human rights throughout their lifecycle. For organisations that affect children it means adding a children's-rights lens: assessing impact on children specifically, involving them in design, setting age-appropriate defaults and keeping humans in the loop for decisions about them. See safe and ethical AI for children.
AI governance
AI governance is the set of policies, roles, processes and controls through which an organisation decides which AI systems to build or buy, assesses their risks, monitors them in use and stays accountable for their outcomes. For a children's organisation or a child-facing service it includes an inventory of AI in use, a risk classification aligned to the EU AI Act, a CRIA or equivalent for high-impact systems, and board-level ownership. Our strategic advisory work covers this.
AI companion and chatbot
An AI companion is a conversational AI designed to act as a friend, partner or confidant, holding memory of the user and expressing emotion; a chatbot is any conversational AI, including general assistants. Children use both heavily, and the risks are documented: sexual content, encouragement of self-harm, emotional dependency and the absence of age checks. Australia's 2026 industry codes and the EU AI Act's transparency duties are the first rules to address them. Read children and chatbots.
AI-generated child sexual abuse material
AI-generated CSAM is sexual abuse imagery of children produced or altered by generative AI: fully synthetic images, real children's faces placed on abusive imagery, or "nudified" photographs of real children. It is illegal in the UK, the EU and most jurisdictions regardless of whether a real child was abused in its production, it is used to groom and extort real children, and it overwhelms hotlines' capacity to distinguish real victims. Read the threat of AI-generated abuse imagery.
Deepfake
A deepfake is synthetic audio, image or video that realistically depicts a real person doing or saying something they did not. For children the harms are sexual deepfakes of classmates, impersonation for scams or bullying, and undermining of their trust in evidence. The EU AI Act requires AI-generated content to be labelled, and the UK made creating sexually explicit deepfakes an offence in 2025.
Algorithmic impact assessment
An algorithmic impact assessment is a structured evaluation of an automated decision-making or recommender system's likely effects on people before and during its use, covering accuracy, bias, explainability, human oversight and recourse. When the affected people include children it should be combined with a CRIA, since the harms to children (developmental, educational, relational) are not captured by a fairness audit alone.
Human in the loop
Human in the loop describes an AI system in which a person reviews, approves or can override the system's outputs before they take effect, rather than the system acting autonomously. For decisions about children (safeguarding referrals, school placements, content removal that affects a child's account) regulators and the EU AI Act expect meaningful human oversight, which means the reviewer has the time, information and authority to disagree with the system.
Emotion recognition
Emotion recognition is AI that infers a person's emotional state from their face, voice, text or physiology. The EU AI Act prohibits its use in schools and workplaces except for medical or safety reasons, because the science is weak and the effect on children under constant observation is harmful. It appears in "engagement" analytics for education technology and in some AI companions, so it belongs on any AI inventory a children's organisation keeps.
AI content labelling
AI content labelling is the marking of AI-generated or AI-altered text, images, audio and video so that people, and other systems, can tell it is synthetic. Techniques include visible labels, invisible watermarks and content-provenance metadata (the C2PA standard). The EU AI Act makes it mandatory for deepfakes and AI-generated public-interest text, and it is one of the few defences a child has against synthetic material presented as real.
Need these terms applied to your organisation?
Child Safe ME helps governments, NGOs, corporates and technology companies turn safeguarding, online-safety and AI requirements into working policy, assessments and training.