EBP Integra — Enterprise Technology, Digital Trust & Strategic Protection
Child Safety / Applicability

Product / PLF Classification & Threshold Assessment.

Know the regulatory status of the product before committing to the downstream control and filing path.

Business context

What this capability solves

Determine whether a digital product, service or feature is designed for children, may be accessed by children, or falls outside the relevant child-protection scope.

EBP Integra delivery principle

Advice, controls, technology, governance, evidence and operating procedures are designed together so the capability can be sustained after implementation.

Deep-dive capabilities

Capability model

The service can be scoped as a focused engagement or combined into a broader enterprise programme.

Product Scope Mapping

Define product, service, feature, users, channels, content and processing in scope.

Indicator Assessment

Evaluate the formal indicators and threshold conditions used for child-related applicability.

User & Access Analysis

Assess intended audience, likely access by children and account/age controls.

Evidence Review

Review UX, terms, onboarding, analytics, content and product decisions supporting classification.

Classification Decision Pack

Document rationale, assumptions, evidence and resulting obligations.

Next-Step Mapping

Identify whether risk self-assessment, implementation or filing is required.

The source service catalogue references PP TUNAS and the formal indicators in Kepmen Komdigi 142/2026 as the regulatory basis for this classification workflow.
Reference operating model

How the capability fits together

Final scope, control ownership and delivery model are confirmed during discovery.

Governance & Scope
Objectives, applicability, decision rights, owners, policies, risk appetite and acceptance criteria.
Assessment & Design
Evidence collection, gap/risk analysis, target controls, architecture, procedures and prioritized roadmap.
Implementation
Controls, documentation, workflows, integrations, configuration, training and remediation.
Assurance & Operations
Testing, evidence, management reporting, escalation, review cadence and continuous improvement.

Controls & governance

  • Child-first risk and best-interest lens
  • Data minimization and privacy-protective defaults
  • Age/parental/guardianship governance
  • Dark-pattern and excessive-engagement review
  • Documented escalation for high-risk findings
  • Evidence suitable for regulator and management review

Priority use cases

  • New consumer platform
  • Product feature change
  • Education/family product
  • Potential child access
  • Regulatory readiness
  • M&A/product due diligence

Key deliverables

  • Scope map
  • Indicator assessment
  • Classification rationale
  • Evidence pack
  • Obligation/action map
  • Management brief

Integration considerations

  • Product/SDLC governance
  • Privacy/PDP programme
  • Identity/age assurance
  • Consent/preferences
  • Trust & safety operations
  • Incident/complaint management
Implementation

Phased delivery

Each phase produces decision-ready evidence and clear ownership for the next stage.

1. DiscoverConfirm scope, stakeholders, obligations, evidence, dependencies and risk drivers.
2. Assess & DesignAnalyze current state, define target controls and agree the implementation roadmap.
3. ImplementDeploy controls, documents, workflows, training and required technology/integration.
4. Assure & OperateValidate effectiveness, close residual gaps, hand over and establish recurring governance.

Outcome and KPI framework

Classification completionEvidence completenessOpen assumptionsDownstream action closure
Typical deliverables

What the engagement produces

Final deliverables are tailored to scope, maturity, regulatory context and commercial agreement.

Assessment
  • Scope and data/process map
  • Requirement / risk findings
  • Gap or issue register
  • Priority actions
Design
  • Policy / SOP / control design
  • Roles and workflow
  • Templates / registers
  • Implementation roadmap
Implementation
  • Configured controls / artifacts
  • Evidence collection
  • Stakeholder workshops
  • Remediation support
Assurance
  • Management report
  • Evidence pack
  • Open issues / residual risk
  • Handover and next-step plan