On 6 October 2026, the new CERRE report entitled ‘A Framework for Aligning Business Incentives to Protect Children Online’, authored by Jan Krämer (University of Passau), Michèle Ledger (University of Namur, Belgium) and Sonja Herrmann (University of Passau), was presented during a webinar.
Protecting Children Online: Tackling Harms at Their Root Through Business Incentives
Digital services offer children real opportunities to learn, create, connect and build digital skills, but these benefits come with significant risks. Much of the current debate focuses on banning children from social media or prohibiting specific design features such as infinite scroll, autoplay or loot boxes. This new CERRE Report from Academic Co-Director Jan Krämer, CERRE researcher Michèle Ledger and Sonja Hermann proposes a different approach.
Realigning incentives with child safety
Rather than cataloguing harmful features one by one, the report traces online harms to children back to their root cause: the business and financial incentives that drive providers’ design choices. The more revenue a service earns from a risk-inducing feature, the stronger its incentive to tolerate the resulting harm. Regulating features without addressing these incentives risks becoming a game of whack-a-mole.Building on the OECD’s typology of children’s online risks, the report identifies seven business model dimensions that shape a service’s risk profile: reliance on usage duration, opaque monetisation, harmful content, user-generated content, inter-user interaction, personal data collection, and experimental technologies such as generative AI. On that basis, the report shows the most risky business model. The report also shows that risks accumulate across the whole access chain, from device to intermediary to end-service. Control functions such as age verification are therefore best placed as far upstream as possible.
A new legal approach
Today’s EU rules, including the DSA, AVMSD, GDPR and UCPD, tackle these issues only piece by piece. The recently proposed EU Kids Act also introduces dedicated rules for minors, requiring safe-by-default design for a defined set of services considered high-risk. The report looks beyond specific service categories to the business incentives behind risky design, and offers a framework that can also capture new types of services as they emerge.
You can find the full report here: https://cerre.eu/wp-content/uploads/2026/10/CERRE_A-Framework-for-Aligning-Business-Incentives-to-Protect-Children-Online.pdf
You can watch the webinar here:
https://www.youtube.com/live/UFWfGyomjoY?si=N8u9vYeh1AOygnLO