some companies care about child safety and some…..

……and so it has come to pass.  The ePrivacy directive kicked in on the 20th of December.  This means two things – people have more privacy, a good thing and children are less safe online, not a good thing.

As explained in previous posts the ePrivacy directive coming into full force on the 20th of December means that companies who were voluntarily scanning for Child Sexual Abuse Material (CSAM) and patterns of Grooming could interpret the change as making their scanning activities illegal.

There is an active effort to bring in a regulatory framework that will cover these voluntary actions but this will take time and so a temporary derogation for a small number of articles was requested.   It is still under consideration by the EU Parliament, the EU Commission and the EU Council.

In the meantime, some companies have stood up and declared they not stop these efforts to keep children online while the political process continues.   These companies are Microsoft, Google, Linkedin, YUBO and ROBLOX.  Well done to all of you. 

Other companies have not stood up. We don’t know what they are doing because apart from Facebook they are saying nothing.

Facebook has declared that they will switch off scanning.  In a post on their blog they use a lot of language to basically say that they are choosing privacy over child safety.  This is a disappointing and strange decision given that they have been to the forefront of voluntary actions in the past.  At least they told us.  What of other companies?  The big ones? 

The political process continues, here is what you can do:

Talk to your local representatives and MEPs – list here .

and if you work for or use companies who provide online services other than those listed above, ask them stopping or continuing?

time is running out…..

There is 7 days to go until the ePrivacy regulation comes into force in the EU.  It actually passed in 2018 but member countries were given 2 years to prepare and so it “goes live” on 20th of December 2020.  [1] A temporary derogation applied for by the Commision has passed committe stage and now must get a reading in the plenary before being the subject of a trilogue. Is all this possible in 7 days?

Because it’s a regulation rather than a directive, it effectively supersedes existing law in member countries and therefore any laws passed locally since 2002 to meet the ePrivacy directive are effectively repealed.

The regulation, aimed at companies providing communication services in the EU, seeks to guarantee privacy through ensuring no interference or tracking of communications for marketing or other purposes.

One of the key unintended consequences of this regulation is that voluntary actions by the same companies to find, remove and report Child Sexual Abuse Material (CSAM) or Grooming activities on their networks will stop because companies cannot risk that they will be seen as illegal.

These voluntary actions are hard fought chips in the self-regulation wall that activists and advocates, even within the companies themselves, have achieved.  Stopping them in this manner is ridiculous and reduces the safeguarding opportunities for children being actively harmed.  Companies scan for CSAM with advanced technologies to ensure the privacy of their users in the same way they find, remove and report SPAM and malware.  Comparisons to someone at the post office opening every letter “IRL” are facetious and unhelpful.

Child abuse communication, whether grooming or CSAM, universally happens in private and the only people who know about it are the child and the abuser.  When the abuser shares the material there is an increased chance that it will be found, removed and reported to the police who can then take action to make the child safe.  There are very few other ways for people to find out about the abuse and help the child.

In an effort to avoid this unintended consequence the EU Commission has put a temporary derogation before EU lawmakers to stay just two articles within the regulation that will allow the voluntary actions to continue in the area of child abuse online only until they can get the law needed in place.  This temporary derogation has passed the committee stage and now will get its first reading in the EU Parliament then move into a formal “trilogue” or interinstitutional talks. 

The question is when?  The EU Parliament meets next week in plenary.  Will they do the first reading then?  When will the Trilogue meeting take place?  How long will it take?  Will they have this finalised and passed (without too much dilution) by 20th of December? 

I certainly hope so.

Here is what you can do:

Sign the petition

Talk to your local representatives and MEPs – list here .

Support your local InHope Hotline

Read more and see the supporting evidence of what stops if this derogation fails to pass here.


[1] It’s full name is actually “Regulation of the European Parliament and of the Council concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications)” and it repeals the ePrivacy Directive of 2002.  

on voluntary actions to combat child sexual abuse

Companies exist to make money for their shareholders and it’s important to remember that when we discuss what they do to deal with anything bad that happens on their network.  That includes Facebook, Google, Twitter et al.

They have grown in a low-regulation environment, which was encouraged by governments all over the world. So dealing with the dark-side of social media and the human condition was always going to be a hard sell to their boards as it costs money and is the antithesis of profit making.  See line one of this post.

Unlike the EU, the USA brought in regulation relating to the online facilitation of child sexual abuse through a law stating that when a company is aware of Child Sexual Abuse Material and Grooming on their network they will report it to NCMEC.

NCMEC processes these reports and sends the “cybertips” to law enforcement all over the world for action.  These cybertips have saved lives and helped remove countless children from harm all over the world.

So, how does a company become aware of CSAM or grooming on their network?  Users reports, sure, but in most cases they are actively scanning their systems for evidence of it in the same way they do for viruses or malware. There are “voluntary actions”.

When the ePrivacy directive comes into force on the 21st of December of this year those “voluntary actions will stop – dead.

The EU commission wants to bring in a law similar to the US law and the procedure to report (EU Style NCMEC) and so has applied for a limited temporary derogation from a number of articles (5 (1) and 6)  in the ePrivacy directive that will maintain the status quo until new law can be drafted.

This derogation is currently under consideration at the European Parliament. If it passes, the status quo remains while the EU Commission prepares regulation in the form of law for 2021/22. If it fails, the voluntary action by these companies stop and there will be less children saved or removed from dangerous situations.

Here’s what you can do, as soon as possible:

Sign the petition

Further reading/ watching:

Talk to your local representatives and MEPs – list here .

Support your local InHope Hotline

Read more and see the supporting evidence of what stops if this derogation fails to pass here.

abused children -the forgotten voice in privacy

Yesterday, a 36 year old man was prosecuted for sex offences in the United Kingdom. 

You’ll find quality reporting on the case in the local Eastern Daily Press

He pleaded guilty to intentionally causing or inciting boys to engage in sexual activity, blackmail, intentionally causing children to look at sexual images and intentionally facilitating the sexual exploitation of children by sending on images of those children. 

His name was David Nicholas Wilson and he pretended to be a teenage girl while grooming 51 boys aged from 4 (four) to 14 (fourteen). The NCA fear that his victims may actually number as many as 500 in the UK and abroad. 

This crime type is what we know in the trade as Online Sexual Coercion and Extortion of Children (OSCE) but the press generally simplify it to “Sextortion”.  There is a great detailed explainer on the Europol site here.

The thing about this crime type is that the multiplier effect of ICT allows one offender to contact thousands of children knowing that a percentage of them will respond and engage.  In this case his preferential target was young boys so most likely he was operating on gaming platforms before bouncing the ones who responded onto other platforms.

Now, while I do not have any knowledge of this case apart from the newspaper articles, I have read that the offender was traced because Facebook found abusive images, while scanning their network, that had been shared by young users to an apparent teenage girl; saw them for what they were and reported that to the National Centre for Missing and Exploited Children (NCMEC) in the USA. They passed the Cybertip to the National Crime Agency in the UK, who got a warrant to search the house of the offender and put him before the courts. 

NCMEC processes millions (6 zeros!) of these Cybertips every year from companies such as Microsoft, Google, Facebook, Yubo, Snapchat etc. and forwards them to law enforcement all over the globe for assesment and action where appropriate.

The above process is currently under threat from two directions:

  • The introduction of end to end encryption by Facebook on their messenger product

Safety –v Privacy is a complex area of society that needs proper, respectful and holistic debate. 

The 51 real life boys he abused should be more than a footnote in that debate.  It cannot just be an inconvenient truth to be brushed aside by privacy advocates and activists who rightly claim that all communications should be private. 

I fundamentally agree but argue that there is a difference between #privacy and #encryption.

There must be a middle ground where society can protect children and other vulnerable people from criminals like David Nicholas Wilson.

Please sign the petition