Case Study — ChildSafe AI

How ChildSafe AI Generates a
Child Rights Impact Assessment

A technical and regulatory walkthrough of how ChildSafe AI operationalises UNCRC General Comment No. 25 (2021) to produce an AI-assisted Child Rights Impact Assessment — with a worked example using the fictional EduBot AI platform.

📋 CRIA — UNCRC GC No. 25 📅 31 August 2026 🏢 PrivaComply Ltd ⏰ 12 min read
← Back to ChildSafe AI

1. What is a Child Rights Impact Assessment?

A Child Rights Impact Assessment (CRIA) is a structured process for identifying, assessing and mitigating the ways in which a product, policy or service may affect the rights of children as defined in the UN Convention on the Rights of the Child (UNCRC).

Unlike a standard Data Protection Impact Assessment (DPIA), which focuses primarily on privacy risks to data subjects, a CRIA takes a rights-based approach — examining whether the design, data practices and commercial model of a digital service are consistent with children's fundamental rights to participation, development, identity, health and protection.

UNCRC General Comment No. 25 (2021)
GC No. 25 is the UN Committee on the Rights of the Child's authoritative guidance on children's rights in the digital environment. Adopted in March 2021, it extends the UNCRC's 54 articles into the digital context — covering algorithmic decision-making, data profiling, commercial exploitation, digital wellbeing and children's right to be heard in platform governance. It is cited by the ICO, Ofcom and the European Commission in enforcement decisions and policy guidance.

ChildSafe AI is the first compliance tool to operationalise GC No. 25 — automatically generating a CRIA grounded in the exact paragraph references of the UN guidance, with RAG-rated scores for each article and specific mitigation actions drawn from your product's own compliance analysis.

2. Why the CRIA is becoming a regulatory requirement

CRIAs are increasingly expected — and in some contexts mandated — across UK, EU and international regulatory frameworks:

The enforcement trajectory is clear: CRIAs are moving from best practice to baseline expectation. Organisations that cannot demonstrate a structured child rights assessment are increasingly exposed to regulatory scrutiny in EdTech, gaming, social media and health sectors.

3. The 8 UNCRC Articles ChildSafe AI assesses

ChildSafe AI screens each product against 8 UNCRC articles identified in GC No. 25 as particularly relevant to digital environments. Each article receives a RAG score (0–100), GC No. 25 paragraph citations, and tailored mitigation actions.

Article 3
Best Interests of the Child
GC No. 25 para 38–40 · Commercial logic vs. child welfare
Article 6
Life, Survival & Development
GC No. 25 para 20–23 · Digital wellbeing & developmental harm
Article 8
Identity & Privacy of Digital Identity
GC No. 25 para 65–68 · Profiling, retention, identity formation
Article 12
Right to Be Heard & Participate
GC No. 25 para 42–45 · Child participation in platform governance
Article 13
Freedom of Expression & Information
GC No. 25 para 48–52 · Content moderation & access restrictions
Article 16
Right to Privacy
GC No. 25 para 70–74 · Data collection, consent & surveillance
Article 17
Access to Appropriate Information
GC No. 25 para 56–58 · Age-appropriate content & digital literacy
Article 24
Health, Wellbeing & Mental Health
GC No. 25 para 28–32 · Screen time, sleep, compulsive design

4. How ChildSafe AI generates the CRIA — source data and process

The CRIA is generated dynamically from the results of your compliance analysis. Every CRIA is specific to the product or document assessed. Here is the full data pipeline:

Document or website ingestion

Your privacy policy, product description, DSA or terms of service is parsed and chunked. For website scans, ChildSafe AI extracts the live privacy policy, cookie banner, tracking scripts, age gates and dark pattern signals directly from the URL.

Input: document text or live website URL

Multi-framework compliance analysis

The document is assessed sequentially against each selected regulatory framework (UK GDPR, ICO Children's Code, OSA, DUAA 2025, EU AI Act, KCSIE etc.). Each framework produces a RAG score, article-level breakdown, findings list and recommendations — typically completing in 45–90 seconds using Google Gemini 2.5 Flash.

Output: structured JSON — scores, findings, recommendations per framework

CRIA prompt construction

When you click Generate CRIA, ChildSafe AI constructs a specialised prompt including: the full compliance analysis results (every finding, recommendation and article score), the document name and type, frameworks assessed, and an expert CRIA instruction set grounded in GC No. 25 (2021). This is sent to the AI as an independent inference pass.

Source data: compliance analysis results + document context

AI assessment against 8 UNCRC articles

The AI evaluates against each article, drawing from compliance findings to identify specific rights impacts. For each article it produces: a RAG score (0–100), the GC No. 25 paragraphs that apply, a detailed finding grounded in the document's actual text, and 3–4 concrete mitigation actions referencing specific document sections.

Processing: ~15–20 seconds, Google Gemini 2.5 Flash

Output, certificate and Firestore sync

The CRIA is rendered in the app with an overall score, recommendation and expandable article cards. Simultaneously: saved to your Firestore audit library with a timing stamp; embedded in your compliance certificate between Framework Scores and Executive Summary; and available for download as a plain-text file with full UNCRC and GC No. 25 citations.

Output: CRIA report + certificate block + Firestore record
Important transparency note: The CRIA is AI-assisted analysis, not a legal opinion. All CRIAs should be reviewed by a qualified DPO or child rights specialist before use in regulatory submissions, procurement decisions or public reporting. ChildSafe AI's HITL sign-off flow allows an expert reviewer to countersign the CRIA as part of the compliance certificate.

5. Worked example — EduBot AI Privacy Policy

The following summarises the CRIA generated for EduBot AI, a fictional AI-powered learning assistant. The EduBot AI Privacy Policy is available as a sample document in ChildSafe AI for demonstration purposes.

Document's key characteristics

CRIA output summary

EduBot AI Privacy Policy — CRIA
UNCRC General Comment No. 25 (2021) · 8 articles assessed · 31 August 2026
40/100
🔴 RED — Suspend pending remediation
🔴 Article 3 — Best Interests of the Child
GC No. 25 para 38–40
30/100
Finding: EduBot AI subordinates child users' best interests to commercial optimisation by relying on Article 6(1)(f) legitimate interests for AI training and behavioural nudging (Sections 3.3, 3.4). Third-party advertising tracking on the free tier demonstrates an impermissible commercial trade-off against child safety.
🔴 Article 6 — Life, Survival & Development
GC No. 25 para 20–23
35/100
Finding: Daily streaks, non-disableable inactivity reminders and default push notifications utilise persuasive design to maximise session duration, undermining healthy developmental routines, sleep patterns and cognitive wellbeing contrary to GC No. 25 developmental mandates.
🟡 Article 8 — Identity & Privacy of Digital Identity
GC No. 25 para 65–68
45/100
Finding: Section 3.6 permits indefinite retention of derived profiling models and maintains inactive account data for 24 months, constructing persistent, uncorrected algorithmic profiles of learners. This long-term profiling threatens children's evolving capacities and right to develop without permanent digital labelling.
🔴 Article 12 — Right to Be Heard & Participate
GC No. 25 para 42–45
30/100
Finding: There are no mechanisms for children to participate in service governance, express views on algorithmic adaptation, or influence data practices. Section 3.10 provides human review of automated decisions, but it is purely reactive and not tailored for meaningful child engagement.
🟢 Article 17 — Access to Appropriate Information
GC No. 25 para 56–58
72/100
Finding: EduBot AI demonstrates genuine commitment to age-appropriate content filtering and educational content quality. The 30-day deletion policy and subject matter restrictions meaningfully support children's right to access safe, appropriate information.

Key CRIA mitigations identified

  1. Establish a Child and Youth Advisory Board to participate in service governance, privacy updates and AI feature decisions — implementing Article 12 GC No. 25 para 42.
  2. Cease reliance on legitimate interests for AI training and behavioural profiling; establish valid consent or educational public task bases — addressing Articles 3 and 16.
  3. Remove all third-party advertising measurement tools and tracking pixels from services accessible to children — addressing Articles 3 and 16.
  4. Enforce strict automated deletion of derived algorithmic models and telemetry data upon account closure — addressing the 24-month profiling window under Article 8.
  5. Eliminate compulsive engagement loops including daily streak counters and non-disableable inactivity reminders — addressing Article 6 developmental harm.

6. Source references

UN Committee on the Rights of the Child (2021). General Comment No. 25 on children's rights in relation to the digital environment. CRC/C/GC/25. https://www.ohchr.org/en/documents/general-comments-and-recommendations/general-comment-no-25-2021-childrens-rights-relation
Information Commissioner's Office (2021). Age Appropriate Design: A Code of Practice for Online Services (Children's Code). https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/
Ofcom (2024). Children's Safety Codes of Practice. Online Safety Act 2023. https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/protecting-children
European Parliament and Council (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (EU AI Act). Article 9. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
UNICEF (2022). Children's Rights and Business Principles — Child Rights Impact Assessments: A Guide for Business. https://www.unicef.org/child-rights-business

Generate your CRIA in under 20 seconds

Upload your privacy policy, product description or paste a website URL. ChildSafe AI produces a full Child Rights Impact Assessment against UNCRC GC No. 25 alongside your DPIA and 90-day remediation roadmap.

📋 Open ChildSafe AI