
Technical concept
A privacy-preserving architecture for an Internet that adapts.
A technology-neutral reference concept showing how networks and digital services could provide safer, age-appropriate and healthier experiences—without unnecessarily exposing who a child is.
What travels“Apply a child-friendly experience”
What does notName · civil identity · browsing history
The core proposition
Recognise the context.
Do not reveal the child.
Most online services currently receive either no reliable developmental context or far more personal information than they need. The concept introduces a narrow assurance layer between accountable sources of child context and the networks and services that can act on it.
The objective is not to track children across the Internet. It is to communicate the smallest trustworthy statement necessary for a specific protective or age-appropriate response.
01 — Design requirements
Six conditions shape the architecture.
A system should be judged not only by whether it can recognise childhood, but by how carefully it limits power, data and unintended consequences.
Minimum disclosure
Share only the context required to provide an appropriate experience—not a child’s identity.
Continuity
Maintain a coherent experience across cellular, home, school and public networks.
Proportionality
Apply safeguards that reflect developmental context without unnecessarily restricting beneficial access.
Service choice
Let digital services decide how to respond within transparent rules and child-rights expectations.
Security
Resist spoofing, profiling, correlation and misuse through short-lived, purpose-limited signals.
Evolving autonomy
Reduce intervention and widen agency as capability, confidence and independence develop.
02 — Reference architecture
One minimal signal. A coordinated response.
The functional roles can be implemented in different ways. Their separation is important: no single participant should automatically receive every piece of information.
Accountable context source
Establishes a policy class through a lawful, transparent and reviewable process.
Knows: the source recordShares: only an assurance
Child-friendly assurance layer
Transforms context into a short-lived, purpose-limited and verifiable signal.
Receives: necessary contextEmits: minimum attributes
Participating access network
Recognises or securely relays the signal across approved connection environments.
Understands: policy classDoes not need: identity
Responsive digital service
Applies proportionate product, content and wellbeing settings under clear rules.
Receives: required attributesChooses: compliant response
The assurance source, network and service do not need to be operated by the same organisation. Open interfaces and independent governance can prevent concentration of information and control.
03 — Network continuity
The experience should travel without creating a trail.
Children move through a mixed connectivity environment. A useful system must work across those transitions while avoiding a persistent identifier that lets unrelated parties reconstruct a child’s activity.
- Short-lived or connection-bound assurance
- Cryptographic authenticity and replay resistance
- No universal child identifier exposed to services
- Clear expiry, revocation and recovery processes
Context continuesServices can maintain appropriate settings.
No identity trailNo universal identifier follows the child.
04 — Signal lifecycle
From assurance to an appropriate experience.
Each stage has a bounded purpose and a clear responsibility.
- 1
Assure
An authorised source establishes the minimum child-related context under an accountable process.
- 2
Express
A short-lived assurance signal communicates an appropriate policy class, not a civil identity.
- 3
Carry
Participating networks recognise or securely relay that context wherever the child connects.
- 4
Request
A digital service receives only the attributes needed for a particular experience.
- 5
Respond
The service activates suitable search, content, communication or wellbeing settings.
- 6
Evolve
The policy changes over time as the child’s capability and autonomy grow.
05 — Privacy model
Data minimisation is part of the architecture.
The question is not “What can be collected?” It is “What is the least a participant must know to perform one legitimate function?”
Purpose limitation
Signals are usable only for declared child-friendly functions.
Unlinkability
Different services should not be able to correlate a child through a common identifier.
Ephemerality
Assurance expires and is renewed rather than becoming a permanent digital label.
Accountability
Issuers, networks and services are auditable against transparent rules.
06 — Digital-service integration
Services adapt the experience—not the child’s identity.
The same assurance can support different proportionate responses. A service remains responsible for designing, explaining and evaluating its implementation.
Search
Safer defaultsAppropriate result filtering without identifying the individual child.
Video
Suitable experience modeContent discovery, recommendations and interaction features respond to context.
Learning
Useful access preservedEducational resources remain open while unrelated risks are handled proportionately.
Communication
Age-aware featuresContact, discovery and messaging controls reflect developmental needs.
Wellbeing
Healthier defaultsAttention, notification and time-related settings support balance and agency.
Commerce
Proportionate safeguardsPurchases, advertising and persuasive design receive additional protections.
07 — Child Digital Autonomy
Protection should evolve—not become a permanent restriction.
The system should support a pathway from stronger early safeguards toward informed independence. Age may be one input, but capability, context, rights and meaningful participation matter too.
08 — Trust and governance
Technical assurance requires institutional assurance.
Cryptography can verify that a signal is authentic. It cannot, by itself, establish legitimacy, fairness or public trust.
09 — Implementation pathway
Begin with evidence, not scale.
A credible national programme should progress through bounded stages, with independent evaluation and the participation of children and young people throughout.
Define
Agree national principles, use cases, safeguards and measurable public-interest outcomes.
Prototype
Test the smallest privacy-preserving assurance signal in controlled environments.
Pilot
Connect selected networks and services with independent evaluation and child participation.
Interoperate
Publish open interfaces, conformance expectations and accountable governance.
Scale
Extend continuity nationally while monitoring equity, effectiveness and unintended effects.
A responsible first pilot
One network context. One or two services. Clear public outcomes.
- Defined user group and limited duration
- Independent privacy and child-rights assessment
- No commercial profiling or unrelated reuse
- Published findings, including failures and trade-offs
10 — Open questions
A serious concept makes uncertainty visible.
How should developmental context be defined?
It should avoid crude assumptions and discriminatory categories. Research, child participation and local legal context must shape proportionate policy classes.
Who is authorised to issue assurance?
Different national models may involve parents, education systems, trusted identity providers, operating systems or regulated services. Each model needs transparency, contestability and recovery.
How can signals resist tracking and abuse?
Short lifetimes, audience restriction, selective disclosure, cryptographic protection, unlinkability and strict governance should be tested together—not treated as optional add-ons.
How do we preserve access and participation?
Child-friendly design must not become blanket blocking. Evaluation should measure beneficial access, expression, education, play and participation alongside risk reduction.
How will children gain control over time?
The transition toward autonomy needs understandable explanations, meaningful choices, accessible challenge processes and safeguards against permanent labelling.
Help develop the concept
This architecture should be tested in the open.
We invite governments, telecom operators, digital services, standards communities, researchers, educators, child-rights organisations and young people to examine the assumptions, challenge the model and help design responsible demonstrations.