Parental Control: What must Providers do by the November 21 deadline?

New Assoprovider Webinar: with lawyer Sarzana di S. Ippolito, during APWeb1123 we delved into the Parental Control regulations, also in light of the upcoming deadline on November 21.

Il 14 novembre, Assoprovider ha organizzato un evento con Fulvio Sarzana di Sant’Ippolito, legale esperto in materia di TLC, per discutere le recent regulatory developments on Parental Control. Durante l’incontro sono stati esaminati i vari aspetti normativi di questo tipo di sistemi, tra cui le nuove linee guida dell’AgCom e il decreto legge Caivano, focalizzandosi sulle responsabilità degli operatori di telecomunicazioni e dei produttori di dispositivi connessi, nonché sulle implicazioni per la privacy e la protezione dei minori.

To review the full recording, including the "Questions and Answers" session with lawyer Fulvio Sarzana, visit the official Assoprovider YouTube channel:

Parental Control according to Law 28/2020

Nell’ottobre scorso, Assoprovider ha organizzato un webinar sul tema del Parental Control, la cui sintesi potete review at this link. La nuova sessione si è resa necessaria, però, in considerazione dell’imminente applicazione delle linee guida dell’AgCom in the matter, whose deadline is scheduled for the November 21, 2023. The government has also introduced the Caivano decree law, not yet converted into law at the time of recording, which includes relevant provisions on Parental Control.

Innanzitutto, riepiloghiamo brevemente le informazioni condivise nel precedente appuntamento. La legge 28/2020 ha introdotto il concetto di Parental Control, conferendo all’AgCom specifici poteri. L’obiettivo del legislatore è protect minors from inappropriate content on the internet. This is achieved through a filtering system che previene l’accesso a piattaforme con contenuti non adatti ai minori, indipendentemente dal tipo di connessione utilizzata (fibra ottica, banda larga, 4G, 5G).

It is important distinguish between illegal content, che sono regolati da normative specifiche e permettono alle autorità di ordinare ai provider di bloccare l’accesso, and legitimate but inappropriate content. Nel caso del Parental Control, ci concentriamo su quest’ultima categoria: il filtraggio mira a impedire il contatto dei minori con contenuti definiti inappropriati.

Depending on whether the content is illegal or inappropriate, different regulatory obligations and responsibilities are activated for providers.

The current legislation stipulates that contracts for the provision of electronic communication services must include, among the pre-activated services, parental control systems to filter inappropriate content for minors and block content reserved for adults. These services must be offered free of charge and must be able to be deactivated upon request of the consumer, provided that they are of legal age.

Operators must also ensure un’adeguata informazione on these systems, to enable consumers to make informed choices.

The original regulation, therefore, did not specifically define what constituted inappropriate content, nor which authority was responsible for overseeing the failure of electronic communication service providers to implement it. Both topics, however, were addressed in the AgCom Guidelines, which were further explored in the continuation of the event.

The AgCom Guidelines of January 2023

In January 2023, AgCom adopted new Guidelines on Parental Control, introducing significant aspects:

  • Parental Control systems must be automatically activated on all new lines telefoniche e internet. Per le linee esistenti, l’attivazione automatica si applica solo se intestate a un minorenne.
  • Contract holders, if of legal age, can request the deactivation of the system. In the case of underage users, deactivation can be requested by the person responsible for parental guardianship.
  • For other already active lines, the Parental Control service is offered but its activation remains optional.

It is also important to remember that these guidelines do not apply to business customers.

The AgCom provision has also defined the content categories subject to filtering:

  • Adult content
  • Gambling and betting
  • Weapons
  • Violence
  • Hate and discrimination
  • Promotion of practices harmful to health according to established medicine
  • Anonymizer
  • Sects and cults

By November 21, telecommunications operators should communicate the categories used in their Parental Control systems and include at least the blocking of domains and websites containing the aforementioned materials.

L’AgCom ha il potere di emettere warnings, se scopre che un operatore non ha implementato il servizio di Parental Control sulle reti dei propri clienti privati. L’operatore ha quindi 20 days time per conformarsi alla normativa. Gli operatori possono quindi scegliere di non comunicare preventivamente all’Autorità la presenza del sistema, ma in caso di diffida, devono adeguarsi. Questa scelta è discrezionale per ogni operatore.

However, as repeatedly emphasized by Sarzana, the actual obligation concerns the sphere information. Operators are indeed required to provide clear, transparent, and comprehensive information to its consumers on Parental Control systems, always by November 21. How should the information be communicated? On official websites, particularly on the homepage, where details on the configuration, deactivation, and reactivation of parental control must be available. This information must also be provided in self-care and customer-care areas. For fixed telephony, the information must also be communicated by attaching a notice in the billing.

The Caivano Decree

Decree 123/2023, also known as “Caivano Decree“, aimed at combating youth distress, emphasized the information obligations telecommunications operators, who represent a fundamental aspect of the regulations related to Parental Control, especially for providers.

The decree extends the existing obligations for electronic communication service providers, also including manufacturers of devices such as computers, smartphones, tablets, video game consoles, and other connected objects (such as Smart TVs, home automation devices, Internet of Things, and voice assistants). These manufacturers are required to implement and make available Parental Control applications within one year from the publication of the Decree, thus setting the deadline as September 16, 2024.

The provisions directed at ISPs (Internet Service Providers) are therefore to be considered immediately applicable, while those aimed at device manufacturers will come into effect starting from September of next year.
Furthermore, the decree reiterates certain specifications privacy restrictions: i dati personali raccolti o generati durante l’utilizzo delle applicazioni di controllo parentale non possono essere usati per finalità commerciali o di profilazione. Questa misura mira a salvaguardare la privacy degli utenti, in particolare dei minori, nell’ambito dell’utilizzo di tali applicazioni.