← Back to ChildSafe AI
1. What is a Child Rights Impact Assessment?
A Child Rights Impact Assessment (CRIA) is a structured process for identifying, assessing and mitigating the ways in which a product, policy or service may affect the rights of children as defined in the UN Convention on the Rights of the Child (UNCRC).
Unlike a standard Data Protection Impact Assessment (DPIA), which focuses primarily on privacy risks to data subjects, a CRIA takes a rights-based approach — examining whether the design, data practices and commercial model of a digital service are consistent with children's fundamental rights to participation, development, identity, health and protection.
UNCRC General Comment No. 25 (2021)
GC No. 25 is the UN Committee on the Rights of the Child's authoritative guidance on children's rights in the digital environment. Adopted in March 2021, it extends the UNCRC's 54 articles into the digital context — covering algorithmic decision-making, data profiling, commercial exploitation, digital wellbeing and children's right to be heard in platform governance. It is cited by the ICO, Ofcom and the European Commission in enforcement decisions and policy guidance.
ChildSafe AI is the first compliance tool to operationalise GC No. 25 — automatically generating a CRIA grounded in the exact paragraph references of the UN guidance, with RAG-rated scores for each article and specific mitigation actions drawn from your product's own compliance analysis.
2. Why the CRIA is becoming a regulatory requirement
CRIAs are increasingly expected — and in some contexts mandated — across UK, EU and international regulatory frameworks:
- ICO Children's Code — Standard 1 requires organisations to demonstrate that the best interests of the child are the primary consideration in product design. The ICO's enforcement guidance references GC No. 25 in defining "best interests" in the digital context.
- Online Safety Act 2023 (Ofcom) — Children's risk assessments under Part 3 must consider UNCRC-defined impacts. Ofcom's Children's Safety Codes reference GC No. 25 as the international standard.
- EU AI Act (Article 9) — High-risk AI systems interacting with children require a fundamental rights impact assessment. GC No. 25 is the applicable standard for the child rights component.
- DfE / Schools procurement — EdTech suppliers are increasingly expected to demonstrate child rights compliance as part of DfE and local authority due diligence.
The enforcement trajectory is clear: CRIAs are moving from best practice to baseline expectation. Organisations that cannot demonstrate a structured child rights assessment are increasingly exposed to regulatory scrutiny in EdTech, gaming, social media and health sectors.
3. The 8 UNCRC Articles ChildSafe AI assesses
ChildSafe AI screens each product against 8 UNCRC articles identified in GC No. 25 as particularly relevant to digital environments. Each article receives a RAG score (0–100), GC No. 25 paragraph citations, and tailored mitigation actions.
Article 3
Best Interests of the Child
GC No. 25 para 38–40 · Commercial logic vs. child welfare
Article 6
Life, Survival & Development
GC No. 25 para 20–23 · Digital wellbeing & developmental harm
Article 8
Identity & Privacy of Digital Identity
GC No. 25 para 65–68 · Profiling, retention, identity formation
Article 12
Right to Be Heard & Participate
GC No. 25 para 42–45 · Child participation in platform governance
Article 13
Freedom of Expression & Information
GC No. 25 para 48–52 · Content moderation & access restrictions
Article 16
Right to Privacy
GC No. 25 para 70–74 · Data collection, consent & surveillance
Article 17
Access to Appropriate Information
GC No. 25 para 56–58 · Age-appropriate content & digital literacy
Article 24
Health, Wellbeing & Mental Health
GC No. 25 para 28–32 · Screen time, sleep, compulsive design
4. How ChildSafe AI generates the CRIA — source data and process
The CRIA is generated dynamically from the results of your compliance analysis. Every CRIA is specific to the product or document assessed. Here is the full data pipeline:
Document or website ingestion
Your privacy policy, product description, DSA or terms of service is parsed and chunked. For website scans, ChildSafe AI extracts the live privacy policy, cookie banner, tracking scripts, age gates and dark pattern signals directly from the URL.
Input: document text or live website URL
Multi-framework compliance analysis
The document is assessed sequentially against each selected regulatory framework (UK GDPR, ICO Children's Code, OSA, DUAA 2025, EU AI Act, KCSIE etc.). Each framework produces a RAG score, article-level breakdown, findings list and recommendations — typically completing in 45–90 seconds using Google Gemini 2.5 Flash.
Output: structured JSON — scores, findings, recommendations per framework
CRIA prompt construction
When you click Generate CRIA, ChildSafe AI constructs a specialised prompt including: the full compliance analysis results (every finding, recommendation and article score), the document name and type, frameworks assessed, and an expert CRIA instruction set grounded in GC No. 25 (2021). This is sent to the AI as an independent inference pass.
Source data: compliance analysis results + document context
AI assessment against 8 UNCRC articles
The AI evaluates against each article, drawing from compliance findings to identify specific rights impacts. For each article it produces: a RAG score (0–100), the GC No. 25 paragraphs that apply, a detailed finding grounded in the document's actual text, and 3–4 concrete mitigation actions referencing specific document sections.
Processing: ~15–20 seconds, Google Gemini 2.5 Flash
Output, certificate and Firestore sync
The CRIA is rendered in the app with an overall score, recommendation and expandable article cards. Simultaneously: saved to your Firestore audit library with a timing stamp; embedded in your compliance certificate between Framework Scores and Executive Summary; and available for download as a plain-text file with full UNCRC and GC No. 25 citations.
Output: CRIA report + certificate block + Firestore record
Important transparency note: The CRIA is AI-assisted analysis, not a legal opinion. All CRIAs should be reviewed by a qualified DPO or child rights specialist before use in regulatory submissions, procurement decisions or public reporting. ChildSafe AI's HITL sign-off flow allows an expert reviewer to countersign the CRIA as part of the compliance certificate.
5. Worked example — EduBot AI Privacy Policy
The following summarises the CRIA generated for EduBot AI, a fictional AI-powered learning assistant. The EduBot AI Privacy Policy is available as a sample document in ChildSafe AI for demonstration purposes.
Document's key characteristics
- ✅ Age gate and parental consent for under-13s documented
- ✅ 30-day data deletion policy stated
- ✅ Age-appropriate content filtering described
- 🟡 Privacy-by-default claimed, but push notifications default to “on”
- 🟡 Parental controls limited to account deletion only
- 🔴 Behavioural nudge mechanics (streaks, inactivity reminders) designed to maximise session duration
- 🔴 AI profiling of children using “engagement propensity scores” stored for 24 months
- 🔴 Third-party ad trackers active on free tier for all users including children
- 🔴 No mechanism for children to participate in service governance or provide feedback on AI decisions
CRIA output summary
🔴 Article 3 — Best Interests of the Child
GC No. 25 para 38–40
30/100
Finding: EduBot AI subordinates child users' best interests to commercial optimisation by relying on Article 6(1)(f) legitimate interests for AI training and behavioural nudging (Sections 3.3, 3.4). Third-party advertising tracking on the free tier demonstrates an impermissible commercial trade-off against child safety.
🔴 Article 6 — Life, Survival & Development
GC No. 25 para 20–23
35/100
Finding: Daily streaks, non-disableable inactivity reminders and default push notifications utilise persuasive design to maximise session duration, undermining healthy developmental routines, sleep patterns and cognitive wellbeing contrary to GC No. 25 developmental mandates.
🟡 Article 8 — Identity & Privacy of Digital Identity
GC No. 25 para 65–68
45/100
Finding: Section 3.6 permits indefinite retention of derived profiling models and maintains inactive account data for 24 months, constructing persistent, uncorrected algorithmic profiles of learners. This long-term profiling threatens children's evolving capacities and right to develop without permanent digital labelling.
🔴 Article 12 — Right to Be Heard & Participate
GC No. 25 para 42–45
30/100
Finding: There are no mechanisms for children to participate in service governance, express views on algorithmic adaptation, or influence data practices. Section 3.10 provides human review of automated decisions, but it is purely reactive and not tailored for meaningful child engagement.
🟢 Article 17 — Access to Appropriate Information
GC No. 25 para 56–58
72/100
Finding: EduBot AI demonstrates genuine commitment to age-appropriate content filtering and educational content quality. The 30-day deletion policy and subject matter restrictions meaningfully support children's right to access safe, appropriate information.
Key CRIA mitigations identified
- Establish a Child and Youth Advisory Board to participate in service governance, privacy updates and AI feature decisions — implementing Article 12 GC No. 25 para 42.
- Cease reliance on legitimate interests for AI training and behavioural profiling; establish valid consent or educational public task bases — addressing Articles 3 and 16.
- Remove all third-party advertising measurement tools and tracking pixels from services accessible to children — addressing Articles 3 and 16.
- Enforce strict automated deletion of derived algorithmic models and telemetry data upon account closure — addressing the 24-month profiling window under Article 8.
- Eliminate compulsive engagement loops including daily streak counters and non-disableable inactivity reminders — addressing Article 6 developmental harm.
6. Source references
UN Committee on the Rights of the Child (2021). General Comment No. 25 on children's rights in relation to the digital environment. CRC/C/GC/25.
https://www.ohchr.org/en/documents/general-comments-and-recommendations/general-comment-no-25-2021-childrens-rights-relation
Information Commissioner's Office (2021). Age Appropriate Design: A Code of Practice for Online Services (Children's Code).
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/
Ofcom (2024). Children's Safety Codes of Practice. Online Safety Act 2023.
https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/protecting-children
European Parliament and Council (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (EU AI Act). Article 9.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
UNICEF (2022). Children's Rights and Business Principles — Child Rights Impact Assessments: A Guide for Business.
https://www.unicef.org/child-rights-business
Generate your CRIA in under 20 seconds
Upload your privacy policy, product description or paste a website URL. ChildSafe AI produces a full Child Rights Impact Assessment against UNCRC GC No. 25 alongside your DPIA and 90-day remediation roadmap.
📋 Open ChildSafe AI