Here is the honest situation. Here is the honest situation. Youth safety arrived on platforms from several directions at once and the regimes do not share a vocabulary, so the first failure is organisational rather than legal: privacy counsel reads one set of duties, the trust and safety team reads another, the product manager reads neither, and nobody holds the map that says which surface is in scope of what and why. The triggers cut across each other. One attaches when a service is directed at children, another when the operator actually knows that a particular user is under the relevant age, another when a service is simply likely to be accessed by children regardless of any account record, and a further set to whole categories of service subject to minimum age obligations. The likely access framing is the one that surprises people, because it does not care what the terms of service declare, and an age floor in the terms carries little weight against the platform's own analytics showing who is really there. Deliberate ignorance is a weak strategy rather than a clever one, since knowledge gets established from records the business already collected for other reasons: a birthdate entered at sign up, a parent contacting support about their child's account, an inference a model produces for an unrelated purpose. The second failure is treating age assurance as a gate rather than as a measurement with error in both directions. A minor passed through as an adult receives exactly the experience the obligation exists to prevent. An adult wrongly assessed as a minor is excluded, and with estimation methods that exclusion does not fall evenly across populations, so a system with no correction route in either direction is a coin flip with a compliance narrative attached. The third failure is the unknown state, which is a designed state whether or not anybody designed it, and which defaults to the adult experience in most implementations. The fourth is architectural and is usually the largest piece of work in the whole programme: the rule that a minor is not profiled for advertising takes a sentence to write and a year to implement, because the signal has to survive the recommender, the advertising selection path, the measurement stack and every third party integration, and most of those were built without the concept existing. Obligations attach to what is inferred as much as to what is collected, so a programme that removes form fields while continuing to build a rich behavioural profile has addressed the visible half. Where teams fall short is predictable: protections that exist but are off by default, a minor experience so uniformly restrictive that older teenagers claim adulthood and lose every protection at once, transitions nobody specified, an engagement mechanic defended as neutral because adults use it too with not one age banded number behind the claim, a risk assessment in which every risk resolves to low, a reporting route buried four levels into a settings menu, an imminent risk report waiting behind spam in arrival order, and a configuration history that cannot say what the default actually was on the date somebody is now asking about.
This Kit removes the guesswork. It is youth safety written as adopt-ready controls you personalize in a weekend, with the evidence a product lead, counsel, a trust and safety lead or a regulator examines.
What you get, the moment you buy
Grounded in youth safety, online safety and children's privacy practice as it is actually run by product, legal and trust and safety teams. Editable Word and Excel files. This is a practitioner method, not legal advice, and not a substitute for advice on the specific obligations that apply to your service in each market you operate in.
What one control looks like
This is the opening control, where the assessment begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A protection you cannot demonstrate on a date is a protection you did not have. This tells you what a product lead, counsel, a trust and safety lead or a regulator examines and where teams fall short, for every control.
- The hard specifics built in. A per surface map of markets, audience evidence and triggers met, age signals from support and analytics routed into one account record, assurance strength chosen per feature with error rates measured in both directions, an appeal path for wrongly excluded adults, a protective default for the unknown state, nothing retained from a verification check beyond its result, four explicit feature decisions with named owners, one testable minor configuration on by default, specified transition behaviour, a minor signal traced through every third party integration, and a time addressable configuration history are written into the controls, not left generic.
- Built on real practice, not one person's opinion, grounded in how applicability, age assurance, feature audits, minor defaults, reporting and risk assessments are actually run and actually go wrong.
- It compounds. This work shares its shape with privacy programme management, content moderation governance and platform risk assessment, so it feeds your wider product compliance and trust and safety discipline.
Who buys this
Product managers, legal counsel, privacy leads, trust and safety leads and compliance officers at social media, gaming, messaging, marketplace and user-generated content platforms, who have to say which duties their product triggers, how they know a user's age, why a feature was kept, what a minor account is set to by default, and what the configuration was on the date somebody is asking about. Whether you are standing the programme up from nothing or repairing one that exists only as a policy document, you save weeks and walk in with your scope, assurance, feature, defaults, reporting and records controls structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover the whole programme? Yes. Scope determination and applicability, age assurance and the unknown state, feature audit for age-specific harm, minor defaults, data limits and advertising, reporting, moderation and escalation, and risk assessment, records and change control each have their own controls with their own evidence.
Is this tied to one market or one regime? No. The controls are principle-level, the per surface applicability map, the age signal record, proportionate assurance with measured error, the protective unknown state, the feature decision log, the single minor configuration, the end to end minor signal, the escalation path and the configuration history, so they apply wherever you operate and whatever product, moderation and delivery tooling you run, alongside your team rather than replacing it.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com