July 823:59 was the deadline for the call for comments on the draft first report. I ended the FAPI WG early and23:40 began the submission process around then, but filename, file, and address-search errors prevented submission by the deadline1. Many people helped prepare them, so I am publishing them here rather than leaving them unpublished. The original is a Microsoft Word file.


Comments on the Draft First Report of the Youth Protection Working Group on Information Distribution in the Digital Space

I.  General Comments

The importance of protecting children is beyond dispute.

Policy should prohibit profiling, targeting, and manipulation that exploit vulnerabilities, prohibit addictive interface design, and mitigate the harms of the attention economy, with especially urgent protection for young people.1Policy should prohibit profiling, targeting, and manipulation that exploit vulnerabilities, prohibit addictive interface design, and mitigate the harms of the attention economy, with especially urgent protection for young people.

International work makes this report timely, and the draft commendably balances youth safety with information access, creation, expression, participation, and well-being.

Age verification may help identify protected users, but careless adoption could invite needless identity-document demands and aggravate data power imbalances and misuse (Note 2). Data acquisition and use should be minimized, and profiling, targeting, or manipulation with data collected for this purpose should be prohibited.

>, cited from7Other countries use the broader term age assurance. The G

Effective implementation could use a fair, transparent, human-centric provider (Note 2), accountable and strictly supervised, with notice, appeal, and redress mechanisms, issuing an age-assurance token. Such a provider could help empower people through their own data (Note 2).

Age assurance or verification is only a means to create a safe digital space for young and vulnerable people; it must not become the objective itself.

Age-assurance requirements must not impede inclusion, discriminate, or reduce participation and information access. Users need suitable choices, transparency, and opportunities to appeal.

The EU treats age assurance as part of comprehensive protection of individual rights and interests; Japan should promptly do the same.

The comments below follow the ministry’s format and address the specified portions of the draft.

(※1)Commission preliminarily finds TikTok’s addictive design in breach of the Digital Services Act <https://ec.europa.eu/commission/presscorner/detail/en/ip_26_312>

(※2) MyData Declaration <https://mydatajapan.org/documents/mydatadocuments/declaration/>, cited from

II. Comments on Each Section Presented by the Ministry

Chapter 1 Chapter
2. Changes in How Young People Use the Internet
Draft report 1(2. Changes in How Young People Use the InternetYouth social-media use should not be treated solely as risk; its roles in communication, news, participation, creation, learning, consultation, and self-expression should be stated.

Blanket restrictions and excessive verification may reduce news access, civic awareness, learning, creation, and support for marginalized children. Benefits as well as risks should be assessed.
3. Trends in Problems Associated with Use
Draft report 1(3. Trends in Problems Associated with UseCyberbullying, sexual harm, illicit recruitment, and related problems require action, but isolated harms do not justify disproportionate blanket restrictions.

Analysis should distinguish content, contact, conduct, service-design, and emerging risks including generative AI, and use the least intrusive measure for each.
Chapter 2 Chapter: Developments in Other Countries and Local Governments
1. Developments in Other Countries
Draft report 2(1. Developments in Other Countries7The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above. Chapter 1 paragraphForeign systems are instructive but should not simply be imported into Japan; age-based social-media bans can harm news access, participation, support, anonymity, and digital inclusion.
(i) EU and United Kingdom:EU: Policy should prohibit profiling, targeting, and manipulation that exploit vulnerabilities, prohibit addictive interface design, and mitigate the harms of the attention economy, with especially urgent protection for young people.February 2026Policy should prohibit profiling, targeting, and manipulation that exploit vulnerabilities, prohibit addictive interface design, and mitigate the harms of the attention economy, with especially urgent protection for young people.1The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.April announcement of an age-verification app, its same-day compromise, shortcomings in threat modeling and data storage, and the warning this provides against hasty measures. Relevant EDPB and European Commission age-assurance materials should also be introduced.February 2025 ※3The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.2024, ※4The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.3)Statement 1/2025 on Age Assurance <https://www.edpb.europa.eu/system/files/documents/2025-04/edpb_statement_20250211ageassurance_v1-2_en.pdf>(※4) Research report: Mapping age assurance typologies and requirements <https://digital-strategy.ec.europa.eu/en/library/research-report-mapping-age-assurance-typologies-and-requirements>
The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.The report should state that widespread VPN circumvention after OSA implementation undermined effectiveness.(ii) Australia:December 2025 line5The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.February 2026The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.10〜17The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.1,027The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.16The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.61% reported little or no change, while among users seriously affected,51% reported receiving less news as a direct result, showing possible effects on civic participation and political socialization. (Note 5) The Guardian. “Australia’s social media ban preventing teenagers from accessing the news, research finds.” The Guardian, 19 May 2026. (iii) United States:The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.SB 976 / Protecting Our Kids from Social Media Addiction Act (※6) prohibits addictive feeds for minors; New York’s SAFE for Kids Act restrictions should also be described. (Note 7The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.6)SB-976 Protecting Our Kids from Social Media Addiction Act. <https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB976>(※7)S7694A Stop Addictive Feeds Exploitation (SAFE) for Kids act prohibiting the provision of addictive feeds to minors <https://www.nysenate.gov/legislation/bills/2023/S7694/amendment/AThe report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.1043)(※8) requires an age-band signal from OS providers. Although it does not directly mandate government ID or facial recognition, shared-device and privacy-focused-OS effects should be discussed. (Note 8)AB-1043 Age verification signals: software applications and online services. <https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043>
④ G7: G7Age verification may help identify protected users, but careless adoption could invite needless identity-document demands and aggravate data power imbalances and misuse (Note 7Other countries use the broader term age assurance. The G7The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.
Chapter 3 Chapter: Initiatives by Stakeholders
2. Youth-Protection Initiatives by Mobile Operators
Draft report 3(2The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.4(6The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.Mobile operators perform identity and age checks, but contract data strongly identifies people and can weaken anonymous or pseudonymous use.

Disclosures should be limited to age bands or threshold results, without identifiers or cross-service tracking, and secondary use should be prohibited or strictly limited.
3. Youth-Protection Initiatives by OS Providers
Draft report 3(3The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.) requires an age-band signal from OS providers. Although it does not directly mandate government ID or facial recognition, shared-device and privacy-focused-OS effects should be discussed. (Note
4. Youth-Protection Initiatives by Platform Providers
Draft report 3(4The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.P35 Chapter 9The passage should distinguish self-declaration, age inference, and document or selfie-based verification within a graduated age-assurance framework.1The report should add a column explaining collected data and flows, including likely use of foreign identity services and biometrics.35Age verification may help identify protected users, but careless adoption could invite needless identity-document demands and aggravate data power imbalances and misuse (Note
5. Youth-Protection Initiatives by App-Store Operators
Draft report 3(5. App-Store Ratings
Chapter 4 Chapter: Discussion at This Meeting
1. Basic Direction of the Review
Draft report 4(1. Basic Direction of the ReviewYoung people should be treated as principals of their personal data, not merely as objects of protection, with agency, minimization, purpose limitation, non-traceability, transparency, explainability, and appeal rights.

The report should add a column explaining collected data and flows, including likely use of foreign identity services and biometrics.

Necessity, proportionality, and least intrusion should prevent safety measures from unduly restricting information, expression, participation, creation, consultation, anonymity, and privacy.
2. Shared Understanding at This Meeting
Draft report 4(2. Shared Understanding at This MeetingIt is commendable to include youth expression, creation, participation, and well-being.

Young people should be treated as principals of their personal data, not merely as objects of protection, with agency, minimization, purpose limitation, non-traceability, transparency, explainability, and appeal rights.
3. Youth-Protection Measures in Platform-Service Design
Draft report 4(3The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.. Youth-Protection Initiatives by App-Store Operators

I strongly oppose blanket age bans. Platforms provide communication, news, creation, learning, participation, and consultation as well as risks; broader age assurance should be considered.

Age verification may help identify protected users, but careless adoption could invite needless identity-document demands and aggravate data power imbalances and misuse (Note

Risk assessments must include side effects of safeguards: reduced news, participation, learning, support, anonymity, privacy, experiential learning, and migration to less safe services.

Methods using government ID, faces, selfies, video, identifiers, or fingerprints approach identity verification and tracking and concentrate sensitive data and governance risks.

Evaluation should cover data types, holders, cross-service tracking, mixing with KYC/AML or watch-list functions, cross-border and government access, and alternatives.
4. App-Store Ratings
Draft report 4(4. App-Store RatingsI support the position that government should not designate ratings.

. App-Store Ratings
5. Technical Safeguards, Including Filtering. Safeguards should address broader risks without comprehensive monitoring, use privacy by design and minimization, and avoid universal age-gate infrastructure that harms anonymity, open systems, competition, accessibility, and inclusion.
Draft report 4(5. Technical Safeguards, Including Filtering. Safeguards should address broader risks without comprehensive monitoring, use privacy by design and minimization, and avoid universal age-gate infrastructure that harms anonymity, open systems, competition, accessibility, and inclusion.. Technical Safeguards, Including Filtering. Safeguards should address broader risks without comprehensive monitoring, use privacy by design and minimization, and avoid universal age-gate infrastructure that harms anonymity, open systems, competition, accessibility, and inclusion.
6. Various Verification Duties of Mobile Operators
Draft report 4(6. Various Verification Duties of Mobile OperatorsOperators may provide age assurance only with strict anti-tracking rules, minimal disclosure, specific consent, no disadvantage for refusal, and no secondary use.
7. Other Matters
Draft report 4(7ICT literacy is needed for young people, parents, teachers, and other adults.. Other Matters

Literacy education must accompany provider safety design, transparency, accountability, and independent audit, not shift responsibility to families.

Ratings should be understandable, transparent, independent, appealable, and reviewable rather than directly designated by government.
Chapter 5 Chapter: Next Steps
Draft report 5 Chapter: Next StepsFuture design must continuously assess the side effects of protective measures as well as their effectiveness.

Policy should prohibit profiling, targeting, and manipulation that exploit vulnerabilities, prohibit addictive interface design, and mitigate the harms of the attention economy, with especially urgent protection for young people.

Chapter: Next Steps

Assess effects on privacy-focused and open systems, concentration and cross-border risks, mixing with KYC/AML or surveillance functions, and availability of non-ID and non-biometric alternatives without disadvantage.
Free-form Comments
The report should address this point consistently with the privacy-preserving, rights-respecting, proportionate approach described above.I.  General Comments, but are reproduced here for completeness.I.  General CommentsThe importance of protecting children is beyond dispute.1Policy should prohibit profiling, targeting, and manipulation that exploit vulnerabilities, prohibit addictive interface design, and mitigate the harms of the attention economy, with especially urgent protection for young people.2). Data acquisition and use should be minimized, and profiling, targeting, or manipulation with data collected for this purpose should be prohibited.7Other countries use the broader term age assurance. The G2), accountable and strictly supervised, with notice, appeal, and redress mechanisms, issuing an age-assurance token. Such a provider could help empower people through their own data (Note 2).1)Commission preliminarily finds TikTok’s addictive design in breach of the Digital Services Act <https://ec.europa.eu/commission/presscorner/detail/en/ip_26_312>(※2) MyData Declaration <https://mydatajapan.org/documents/mydatadocuments/declaration/>, cited from

Footnotes

  1. After e-Gov showed that the consultation had closed, I sent the comments by email to the contact address

Related posts