Privacy Policy
Terms of Use – YouthRadio.eu / europeanschoolradio.eu
- Introduction & Acceptance of Terms
- 1.1. These Terms of Use (hereinafter referred to as the “Terms”) regulate the contractual relationship between the User (hereinafter referred to as the “User”) and the europeanschoolradio.eu (school character) or youthradio.eu (broader, non-formal education) platform (hereinafter referred to as the “Platform”), with regard to accessing, participating, posting, listening to and generally using the European Student Radio and Podcast. These Terms apply to the Platform regardless of which of the two aforementioned entry points (brand names) the user chooses. Both entry points lead to the same unified Platform, operating on a single database and offering identical functions. Consequently, any content uploaded by the user is shared and accessible across the Platform, irrespective of the entry point or brand name. For clarity, YouthRadio.eu is a deliverable of the Kids Radio Europe project see the project page: https://ec.europa.eu/info/fundingtenders/opportunities/portal/screen/opportunities/projects-details/43251814/101136199
- 1.2. By creating an account, posting, and/or listening to content, you expressly represent that you have read, understood, and accepted the Terms, as well as the policies referenced or linked to them.
- 1.3. The Terms comply with Regulation (EU) 2022/2065 – Digital Services Act (DSA); the respective provisions are herein.
- 1.4. If you do not agree to the Terms, please stop using the Platform immediately.
- Definitions
-
Terms Definition Service Provider The international consortium Kids Radio Europe, whose technical coordinator and provider is the non-profit civil company Interdisciplinary Intercultural Radio of the Educational Community (trading as “European School Radio – the First Student Radio”), has its registered office at the International Hellenic University in Sindos, Thessaloniki. User(s) Any natural person (e.g. young person, student, teacher, parent, listener) or legal entity that accesses or contributes content. User Content Audio Material Submissions (podcasts, live radio shows), metadata, translations, images, texts and any other material produced or uploaded by a User. Referral System The personalization and classification algorithm that displays relevant content to Users (Article 27 DSA). Notice The notice sent to the Service Provider of any illegal or harmful content (Section 16 DSA). Trusted Flagger The organisation designated by a national authority as a trusted flagger (Article 22 DSA).
-
- Provider Details & Contact Points (Articles 11 & 12 DSA)
- 3.1. Legal entity: Non-Profit Civil Company “Interdisciplinary Intercultural Radio of the Educational Community,” trading as “European School Radio – the First Student Radio.”
- 3.2. Headquarters: I.H.U., Sindos 574 00, Thessaloniki, Greece
- 3.3 Tax Identification Number: EL-998502950 / Tax Office of Thessaloniki
- 3.4. Point of Contact for DSA: compliance@youthradio.eu (support in English & Greek).
- 3.5. Contact Point for Enforcement Authorities: compliance@youthradio.eu (24/7, Article 9 DSA).
- 3.6. Internal Data Protection Officer (DPO): dpo@youthradio.eu
- Eligibility & Age Restrictions (Article 28 DSA)
- 4.1. The Platform is mainly aimed at young people (pupils, students, etc.) and youth workers (teachers, educators, facilitators, etc.)and the general public in the context of formal and non-formal education
- 4.2. For reasons of pedagogical suitability, minors are categorized into the following age groups (4-6, 7-11, 12-15, 16-18+). The category determines the content filters and privacy settings that are automatically applied.
- 4.3. To create a “Young User” account (< 16 years old) it is required:(a) a signed guardian declaration allowing the minor to use all the functions of the platform and (b) After step (a), an adult Team Leader/teacher connected to the user’s educational unit verifies that the minor belongs to the correct age zone and does not violate the content rules. Until the minor is verified by their adult teacher/team leader, the account stays as a “Visitor” and can only access public, non-personalized content.The signed declarations are retained by the Team Leaders and emailed to the Provider for archiving purposes. The guardian may revoke the consent at any time. In this case, the account is deactivated until a new valid consent is provided. Τhe team leader must notify the admins if the guardian asks to deactivate the account.
- 4.4. Minor Visitors without an Account:
- 4.4.1. Any user < the age of 18 can browse the podcasts without creating an account.
- 4.4.2. No personal data is collected for visitors beyond the strictly necessary technical identifiers, no profiling is carried out and no targeted advertising is displayed (Article 28 §3 DSA).
- 4.4.3. The content displayed for Visitor Minors has already been marked as suitable for all age zones under 18 years under the platform’s thematic/age zone system.
- 4.4.4. Visitors cannot upload content or comment.
- 4.5. The Provider does not present advertisements on its interface based on profiling, using the personal data of the minor User.
- User Obligations (Articles 14 §3-4 & 17 DSA)
- 5.1. The User warrants that the account information is true and up-to-date.
- 5.2. The User:
- Respects the rights of third parties (e.g. intellectual property, personal data).
- Does not post content with violence, sexual exploitation of minors, suicide, drugs.
- Does not harass or target individuals or groups on the basis of race, gender, religion, sexual orientation (hate speech no-tolerance clause).
- Does not intentionally misinform about scientific or political issues (especially health issues, elections).
- 5.3. Violations entail: (a) warning⋅ (b) temporary suspension⋅ (c) permanent deletion of an account, depending on severity.
- Prohibited Content (Articles 16 & 17 DSA)
- 6.1. “Illegal content” is indicatively defined as anything that is contrary to:
- 6.1.1. the law of an EU Member State
- 6.1.2. Directive 2011/93 (sexual abuse of minors)
- 6.1.3. Regulation (EU) 2019/880 (cultural goods)
- 6.1.4. Regulation (EU) 2024/936 (Combating terrorist content)
- 6.2. The Provider uses manual monitoring tools, to detect, flag and/or remove content that falls under paragraph 6.1 or is considered to be high risk for minors.
- 6.2.1. The process includes, but is not limited to: (a) preventive control during upload (“upload filters”) by the relevant team leaders – teachers who supervise the groups of young users (b) review of each proposed age marking (d) keeping logs of all actions.
- 6.2.2. The operation of these tools is governed by the principles of necessity and proportionality and technical and organisational measures are taken to reduce errors and protect freedom of expression.
- 6.1. “Illegal content” is indicatively defined as anything that is contrary to:
- Transparency of Algorithms & Use of Artificial Intelligence (Article 27 DSA)
- 7.1. Algorithms used by the Platform
- 7.1.1. Content recommendation system: provides podcast/show suggestions based on country of connection, content language, the user’s listening history and the user’s general data held on the platform.
- 7.1.2. Music suggestions: registered users submit songs. Once checked, they are included in lists broadcast in the “Music Zones”.
- 7.1.3. Audio-based search: AI search that recognizes speech/music, creates transcriptions, extracts tags, and locates a podcast genre or piece of music.
- 7.2. Key ranking factors
- (a) Topic tags & chapters added by the creator.
- (b) Age-appropriateness classification: each show may—at the creator’s discretion—be manually assigned to one of the 4-6, 7-11, 12-15, 16-18+ ranges and to the corresponding “Show / Music Zones.” This categorisation is not performed automatically by the system; it is carried out solely by the users themselves if they so choose. All content has been pre-screened and is considered suitable for minors under 18. The age-zone label serves only as a navigation/personalisation aid and does not impose an absolute access restriction.
- (c) Listening history & preferences: used for personalized recommendations; the user can disable personalization in the profile settings (non-personalized viewing), if they do so, content based on (a) and (b) without profiling is displayed.
- (d) Language & country of connection: content in the same language or from users in the same country is recommended.
- 7.3. Alternative non-personalized viewing:
- 7.4. In accordance with Article 27 §1 b DSA, the platform provides a ‘No Personalisation’ button; When activated, the algorithms ignore (c) & (d) and rank exclusively at the level of thematic/age tags.
- 7.5. Each recommended piece of content is accompanied by a “Why am I seeing it?” pop-up explaining what factors contributed.
- 7.6. A brief technical description of the algorithms and data sources is published in the annual Transparency Report.
- 7.1. Algorithms used by the Platform
- Notification & Action Procedure (Articles 16 – 20 DSA)
- 8.1. Below each video, podcast, image, or comment, the button / “Report” (flag icon) is steadily displayed. One-click opens a pop-up complaint form.
- 8.2. Mandatory references:
- 8.2.1. URL or content ID
- 8.2.2. Description of the violation
- 8.2.3. Legal basis/category
- 8.2.4. Petitioner’s contact details
- 8.3. An automatic receipt with ticket number is sent within 1 hour.
- 8.4. The first evaluation of the report is carried out by the content coordinator within 24 hours.
- 8.5. The final decision of the content coordinator (removal, restriction, no action) is issued within 7 days, fully reasoned, notified to both the petitioner and the content creator, along with objection instructions.
- 8.6. Reports from trusted flaggers are reviewed in < 48 hours (Article 22 DSA).
- 8.7. In case of an incomplete report, a request for completion is sent by the content coordinator within 48 hours, without a response, the report is archived.
- 8.8. All reports, measures and time limits are kept on file for 6 years and summarised in the annual “Transparency Report” (Article 15 DSA).
- Internal Complaint Management System (Article 20 DSA)
- 9.1. Submission of an objection – free of charge, via the form https://community.europeanschoolradio.eu/gdpr, within 14 days from the notification of the decision.
- 9.2. Appeals Committee (Eftychia Touliou (Greece), Susanne Böhmig (Germany), and Myrto Stamelaki (France)).
- 9.3. The decision is issued within 14 days with full reasons and communicated via email.
- 9.4. All objections and decisions are kept for 6 years and are reported in aggregate in the annual “Transparency Report”.
- Protection of Minors & Accessibility (Articles 28 & 34 DSA)
- 10.1. Technical Measures for the Protection of Minors:
- 10.1.1. The Platform proposes four age ranges for young users: 4-6, 7-11, 12-15 and 16-18+. This categorisation is not automatic; the user manually selects the appropriate range during registration or via the account settings. Based on this choice, the Platform displays content only within the selected range. All available material has been pre-screened and is suitable for minors; the age range serves solely as a navigation/personalisation aid and does not constitute an absolute technical restriction.
- 10.1.2. No advertising profiling for < 18 years old: Child data is not used for personalised advertising
- 10.2. WCAG 2.2 Accessibility & Compliance
- 10.2.1. Customizable font sizes, high color contrast, accessible fonts and compatibility with assistive technologies (screen-readers, switch controls)
- 10.2.2. Audio descriptions, transcripts & subtitles for users with hearing/visual impairment
- 10.2.3. Cooperation with the TJFBG organization for continuous integration and usability control
- 10.1. Technical Measures for the Protection of Minors:
- Data Processing & Privacy (Article 42 DSA & GDPR)
- 11.1. Legal basis: Performance of a contract (Art. 6 §1 b GDPR), consent (Art. 6 §1 a), legal interest (Art. 6 §1 f).
- 11.2. Data categories & technical security measures• Account data (name, email, educational unit ) – stored exclusively in EU/EEA data centers and encrypted with AES-256 at-rest & TLS 1.3 in-transit.• Podcast content & metadata
- 11.3. Access only via RBAC.• Usage data (IP, cookies, logs)
- 11.4. Only as much data as is functionally required is collected
- 11.5. Retention time
- 11.5.1. Active accounts: until – account deletion
- 11.6. Subjects’ rights – access, rectification, erasure, portability, restriction, opposition; exercised in compliance@youthradio.eu
- 11.7. Transfers outside the EU/EEA: No
- Cookies
- Strictly necessary and statistical analysis cookies are used https://community.europeanschoolradio.eu/gdpr
- Limitation of Liability & Rejection of Warranties (Article 4 DSA)
- 13.1. The Provider acts as an intermediary; does not proactively check every post.
- 13.2. The provider makes no warranty for uninterrupted operation. In no case shall the Provider be liable for direct or indirect damages resulting from the use or inability to use the Platform.
- 13.3. Specifically for the safety of minors, the content submitted by users goes through the review and approval of “Team Leaders” and/or administrators before it is published. They can reject or remove material that does not meet the educational and legal criteria of the platform.
- 13.4. Each user over the age of 18 has an individual responsibility to ensure that the content they upload complies with the law of their country and EU law.
- Amendment of Terms & Service (Article 14 §5 DSA)
- 14.1. Notification of changes: double; via email and in-app banner, at least 15 days before the effective date.
- 14.2. Critical modifications (e.g., new AI features) require express acceptance.
- Applicable Law & Dispute Resolution
- 15.1. The Terms are governed by EU law, any gaps are covered by Greek law.
- 15.2. The competent courts for the resolution of disputes arising from the present are the courts of Thessaloniki, Greece.
- Communication
- General: info@youthradio.eu
- DSA Topics & Personal data: compliance@youthradio.eu
- Postal address: Alexander Campus of IHU, Sindos, 574 00 Thessaloniki, Greece.
DATA PROTECTION POLICY
- Purpose & Scope
- This Policy describes how the europeanschoolradio.eu (educational character) / youthradio.eu (broader, non-formal education) platform (hereinafter referred to as the “Platform”) collects, uses, stores, and shares personal data. It applies to all registered users (students, teachers, guardians, podcast creators) as well as to visitors browsing the Platform.
- Data Controller & Data Protection Officer (DPO)
- Data Controller: Non-profit Civil Company “Interdisciplinary Intercultural Radio of the Educational Community” (trading as European School Radio – the First Student Radio) for the Kids Radio Europe Consortium.
- Headquarters: Alexander Campus of IHU, Sindos 574 00, Thessaloniki, Greece
- Tax Registration: EL998502950 – Tax Office D’ of Thessaloniki
- Data Protection Officer (DPO): dpo@youthradio.eu
- DSA & Compliance Contact Point: compliance@youthradio.eu
- Data Controller: Non-profit Civil Company “Interdisciplinary Intercultural Radio of the Educational Community” (trading as European School Radio – the First Student Radio) for the Kids Radio Europe Consortium.
- Categories of Data Collected
- 3.1. Account Data:First name, last name, username, email address, password (encrypted), and educational unit / school.
- 3.2. Content & Metadata: Audio recordings (podcasts, shows), transcripts, subtitles, uploaded images, text content, and voice recordings.
- 3.3. Usage & Technical Data: IP addresses, cookies, system logs, and listening history.
- Legal Basis for Processing
- 4.1. Performance of a Contract (Art. 6 §1(b) GDPR): To operate user accounts and provide repository and hosting services.
- 4.2. Consent (Art. 6 §1(a) GDPR): For optional functions, personalized recommendations, or processing of user content.
- 4.3. Legitimate Interest (Art. 6 §1(f) GDPR): To maintain platform security, prevent abuse, and optimize user experience.
- 4.4. Legal Obligation (Art. 6 §1(c) GDPR): To comply with the EU Digital Services Act (DSA), EU AI Act, and tax/consumer protection legislation.
- Protection of Minors
- 5.1. Guardian Consent (< 16 years old): Account creation for young users under 16 requires a signed guardian declaration and verification by an adult Team Leader / Teacher connected to the educational unit.
- 5.2. No Profiling / No Targeted Advertising: Child data is strictly never used for commercial profiling or targeted advertising (Article 28 DSA).
- 5.3. Age-Gating & Filtering: Content is classified into designated age zones (4–6, 7–11, 12–15, 16–18+) with automated filtering mechanisms to ensure pedagogical suitability.
- Algorithmic Transparency & Artificial Intelligence (AI)
- 6.1. Recommendation Systems: Content suggestions are generated based on language, country, and listening history. Users can disable personalization at any time by selecting the “No Personalisation” option.
- 6.2. AI-Assisted Subtitles & Transcripts:
- 6.2.1. Automated transcripts and subtitles are processed through enterprise AI services solely for syntax and grammatical corrections.
- 6.2.2. An active Data Processing Agreement (DPA) is maintained with the provider, ensuring that prompts and responses are not used for model training or product improvement.
- 6.2.3. Technical masking and pseudonymization of direct identifiers (such as names and phone numbers) are applied prior to submission wherever technically feasible.
- 6.3. Human Oversight & User Editing (Human-in-the-Loop):
- 6.3.1. Original AI-generated text is stored in a separate database field and flagged as “AI-generated / unreviewed”.
- 6.3.2. Users maintain full control to review, edit, and validate transcripts. The user-validated version acts as the prevailing public display version.
- Data Retention Policy
- 7.1. Active Accounts & Repository: User content and personal data are retained for as long as the account, project, or workspace remains active, or until the user requests deletion.
- 7.2. Inactive Accounts: Inactive accounts and associated personal data are deleted or anonymized after 24 consecutive months of inactivity.
- 7.3. System Logs: Server logs are retained for up to 12 months strictly for security, auditing, and incident response purposes.
- 7.4. Backups: Backup archives follow a documented purge cycle and are accessed strictly for disaster recovery and business continuity.
- Data Subject Rights
- 8.1. In accordance with the General Data Protection Regulation (GDPR), users hold the following rights:
- 8.1.1. Right of Access to their personal data.
- 8.1.2. Right to Rectification of inaccurate or incomplete data.
- 8.1.3. Right to Erasure (“Right to be Forgotten”).
- 8.1.4. Right to Restriction of Processing and Data Portability.
- 8.1.5. Right to Object to profiling and automated decision-making.
- 8.1.6. Right to Flag / Report Errors: A built-in reporting mechanism allows users and affected parties to flag inaccuracies, defamatory statements, or unlawful content in AI transcripts.
- 8.2. To exercise these rights, submit a request to dpo@youthradio.eu or compliance@youthradio.eu. Users also retain the right to lodge a formal complaint with their national Data Protection Authority (DPA).
- 8.1. In accordance with the General Data Protection Regulation (GDPR), users hold the following rights:
- Cookies & Tracking Technologies
- 9.1. The Platform utilizes strictly necessary technical cookies for essential operation and anonymous analytical cookies for statistical evaluation. Detailed information is available in our full Cookie Policy.
Privacy Policy
- Purpose & Scope
- 1.1. This policy describes how europeanschoolradio.eu (school character) or youthradio.eu (broader, non-formal education) platform (hereinafter referred to as the “Platform”), collects, uses, stores and shares personal data.
- 1.2. It applies to all registered users (students, teachers, guardians, podcast creators) as well as to visitors to the Platform.
- Data Controller & DPO
- 2.1. Data Controller: the non-profit civil company Interdisciplinary Intercultural Radio of the Educational Community (trading as “European School Radio – the First Student Radio”) for Kids Radio Europe Consortium, Alexander Campus of IHU, Sindos 574 00, Thessaloniki, Greece, Tax Number: EL998502950, Tax Office D Thessaloniki
- 2.2. Data Protection Officer (DPO): dpo@youthradio.eu
- Data Collected
- 3.1. Account data: first name, last name, username, email, password, school/organization.
- 3.2. Usage data: IP address, cookies, logs
- Legal Basis for Processing
- 4.1. Performance of a contract (Article 6§1b GDPR) for the operation of the account.
- 4.2. Consent (Article 6§1a) for optional functions (newsletters, customized suggestions).
- 4.3. Legitimate interest (Article 6§1f) in user security and service optimization.
- 4.4. Legal obligation (Article 6§1c) to comply with DSA, tax and consumer legislation.
- Purposes of Processing
- 5.1. Provision and management of podcast hosting services.
- 5.2. Community operation management & content coordination.
- 5.3. Personalized listening suggestions (opt-out available).
- 5.4. Statistical analysis and improvement of experience.
- 5.5. Compliance with legal obligations and dispute resolution.
- Automated Decision Making & Algorithm Transparency
- 6.1. The Platform uses ranking systems to display content based on: (a) thematic tags, (b) age appropriateness, (c) listening history.
- 6.2. Users can choose a non-personalized view at any time.
- 6.3. No decisions are taken that produce legal effects solely by automated means; If ranking has materially influenced a decision, users may request human review.
- Data Retention
- 7.1. Active accounts: the data is kept for the duration of the contractual relationship.
- 7.2. Inactive accounts: deleted or anonymized after 24 months of inactivity.
- 7.3. System logs are kept for up to 12 months for security reasons.
- Notifications & Recipients
- 8.1. Cloud-hosting, email & analytics providers
- 8.2. School units/teachers receive only data necessary for the educational process.
- 8.3. We do not sell data to third parties for direct marketing purposes.
- Subjects’ Rights
- 9.1. Access, Correct, Delete, Restrict, Portability, Oppose
- 9.2. Submit a request: dpo@youthradio.eu
- 9.3. Right to complain to the DPA.
- Protection of minors
- 10.1. The enrollment of children < 16 years of age requires parental consent.
- 10.2. Content is categorized by age-gate; unwanted or harmful material is detected and filtered.
- Cookies & Similar Technologies
- 11.1. We use functional cookies
- 11.2. Detailed Cookies Policy https://community.europeanschoolradio.eu/gdpr
- Communication
- 12.1. For questions about this policy: info@youthradio.eu
LEGAL ISSUES OF INTELLECTUAL PROPERTY AND COMPLIANCE WITH THE ARTIFICIAL INTELLIGENCE ACT
Taking into account certain basic capabilities and applications of the Kids Radio platform that you informed me about, I set out below a number of legal issues that require attention, further assessment, and implementation:
- Intellectual property
- The uploading of data (texts, video, music), insofar as they constitute original works, raises copyright issues.
- If the material is not original but has been taken from various other sources, the creator’s consent must be obtained, or the creator must have made the specific data available for free use.
- “Correction without change of meaning” still constitutes editing of the text, provided that the content of the speaker’s message is not altered.
- Thematic categories do not constitute processing that would fall under a personal data breach.
- Measures / safeguards
- The users’ participation terms should state that they consent to the display of the material they upload and to its processing based on categorisation, covering transcription, storage, display of excerpts, and indexing.
- Users should also be granted the right to request removal/deactivation of content upon their request, and the applicable procedure should be described.
- Protection of code / know-how of the “pipeline as a single entity”
- Although the models are public, the combination, organisation, configurations, and infrastructure may constitute original software and are therefore protected by copyright, and in practice as a trade secret.
- Measures / safeguards
- Include clauses in staff/collaborator agreements for assignment of rights, confidentiality, non-disclosure, and data-management policies (keys, prompts).
- Personal data (GDPR) – especially due to audio/image/user profile
- Voice recordings and transcriptions/entries may contain personal data (names, contact details, sensitive information).
- Listening history and recommendations constitute profiling.
- User/school/producer banners may include persons/children, thus personal data, as well as descriptions that reveal information.
- Measures / safeguards
- GDPR roles: the application and compliance with GDPR rules must be stated, including whether there is a Controller and/or Processor for each function.
- Legal basis: consent should be obtained for each processing activity: transcription, storage, search, categorisation, indexing.
- DPIA (data protection impact assessment): very likely required due to systematic monitoring/profiling and the participation of minors.
- Data minimisation: retention period for the material (audio, text, video, transcriptions, logs), and cases where deletion/anonymisation is applied.
- Data subject rights: access/correction/erasure/portability/objection to profiling (where applicable).
- Security: encryption, access control, audit logs, breach response policies.
- Processing by third parties and potential onward use
- The material should be protected with technical, machine-readable means so that it cannot be used by third parties. If such a restriction/prohibition does not apply, users should provide their consent from the outset for such use.
- Onward use is referenced, e.g., Gemini, ChatGPT, through use of or transfer of data to a third-party provider. This is critical both legally and contractually.
- Measures / safeguards
- Review the terms: whether data are used for training, the use of sub-processors, and the place of processing.
- Technical: pseudonymisation before text is sent to third parties (e.g., removal of names/phone numbers), where feasible.
- Regulatory obligations for platforms & content (especially if addressed to children)
- If the system operates as a platform for sharing/hosting or recommending content, obligations arise regarding transparency, reporting, and handling of illegal content (e.g., insults, defamation, intellectual property infringement).
- For minors: enhanced requirements for parental consent, privacy by design, and avoidance of “aggressive” profiling/targeting.
- Measures / safeguards
- Terms of use with content rules, a complaint procedure, escalation, and documentation of actions taken.
- Settings, suggestions, and recommendations aimed at protecting minors.
- Liability for errors, defamation, misinformation, and “incorrect” descriptions
- Incorrect transcription/punctuation may change the meaning, creating a risk of defamation or misleading content.
- Processing of the material may incorrectly describe a person/role, creating a risk of infringement of personality rights/privacy.
- Measures / safeguards
- Flagging/objection: where transcriptions are automatic and may contain errors.
- Correction mechanism by the holder/user.
- Clear limits of liability in the Terms of Use, without prejudice to mandatory consumer protection rules.
- Data governance & proof of compliance
- You must be able to demonstrate “what happened, when, and why” (especially for GDPR requests/IP complaints).
SETTINGS AND COMPLIANCE UNDER THE AI ACT
(EU Artificial Intelligence Act 1689/2024)
- Specific provisions
- Under Article 5 of the AI Act, the following AI practices are prohibited:
- a) placing on the market, putting into service, or using an AI system that deploys techniques aimed at a person’s subconscious, bypassing their conscious decision-making, or intentionally manipulative or deceptive techniques, with the objective or effect of materially distorting the behaviour of a person or a group of persons by significantly impairing their ability to make an informed decision, thereby causing them to take a decision they would not otherwise have taken, in a manner that causes, or is reasonably likely to cause, significant harm to that person, another person, or a group of persons;
- b) placing on the market, putting into service, or using an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability, or a specific social or economic situation, with the objective or effect of materially distorting the behaviour of that person or a person belonging to that group in a manner that causes, or is reasonably likely to cause, significant harm to that person or another person;
- c) placing on the market, putting into service, or using AI systems to evaluate or classify natural persons or groups of persons over a certain period of time based on their social behaviour or known, inferred, or predicted personal characteristics or personality traits, by means of social scoring that leads to one or both of the following: (i) detrimental or unfavourable treatment of certain natural persons or groups of persons in social contexts unrelated to the contexts in which the data were originally generated or collected; (ii) detrimental or unfavourable treatment of certain natural persons or groups of persons that is unjustified or disproportionate to their social behaviour or its severity;
- e) placing on the market, putting into service for that specific purpose, or using AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage;
- f) placing on the market, putting into service for that specific purpose, or using AI systems to infer the emotions of a natural person in the areas of the workplace and educational institutions, unless the use of the AI system is intended to be put into service or placed on the market for medical reasons or for safety reasons;
- g) placing on the market, putting into service for that specific purpose, or using biometric categorisation systems that individually categorise natural persons based on their biometric data in order to draw or infer conclusions relating to their race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation; this prohibition does not cover any labelling or filtering of biometric datasets lawfully acquired, such as images, based on biometric data or biometric categorisation in the field of law enforcement;
- High-risk AI systems under Article 6(2) of the AI Act are those listed in any of the following areas (Annex III):
- Under Article 5 of the AI Act, the following AI practices are prohibited:
- Biometrics, where their use is permitted under relevant EU or national law:
- a) remote biometric identification systems. AI systems intended to be used for biometric verification solely to confirm that a specific natural person is the person they claim to be are not included;
- b) AI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inferential derivation of those attributes or characteristics;
- c) AI systems intended to be used for emotion recognition.
- Education and vocational training:
- a) AI systems intended to be used to determine access or admission, or to place natural persons in education and vocational training institutions at all levels;
- b) AI systems intended to be used to evaluate learning outcomes, including where those outcomes are used to guide the learning process of natural persons in education and vocational training institutions at all levels;
- c) AI systems intended to be used to assess the appropriate level of education that a person will receive or be able to access, within the context of or inside education and vocational training institutions at all levels;
- d) AI systems intended to be used to monitor and detect prohibited behaviour of students during examinations within the context of or inside education and vocational training institutions at all levels.
- .
- However, an AI system referred to in Annex III (as above) is not considered high-risk if it does not pose a significant risk of harm to the health, safety, or fundamental rights of natural persons, including where it does not materially influence the outcome of decision-making. This applies when any of the following conditions is met:
- a) the AI system is intended to perform a limited procedural task;
- b) the AI system is intended to improve the result of a human activity previously completed;
- c) the AI system is intended to detect decision-making patterns or deviations from previous decision-making patterns and is not intended to replace or influence the previously completed human assessment, without appropriate human review; or
- d) the AI system is intended to perform a preparatory assessment task for the purposes of the use cases listed in Annex III.
- By way of derogation from the above, an AI system referred to in Annex III is in any event considered high-risk where it performs profiling of natural persons.
- A provider who considers that an AI system referred to in Annex III is not high-risk documents its assessment before placing that system on the market or putting it into service. That provider is subject to the registration obligation set out in Article 49(2) of the AI Act. Upon request by the national competent authorities, the provider provides the documentation of the assessment.
- Characterisation of the specific project
- This project is a system for processing/indexing/recommending content. Recommender/search systems of this type do not appear as a stand-alone high-risk category in Annex III.
- However, it could become high-risk if the same system is used with an intended purpose that falls within the specific provisions above, in which case the classification changes. Indicatively:
- If used in an educational setting for decisions on students’ access/placement/assessment (e.g., selection, ranking, assessment/grading, or “determining access” to education), it may fall within the Annex III cases.
- If used for decisions in employment, access to essential services, etc., it may also fall under Annex III.
- Nevertheless, attention should be paid to the application of the AI Act rules to the project due to the participation of children and the use of generative content.
- Prohibited practices: exploitation of vulnerability due to age
- Since the target and user group of the system is children, all rules and mechanisms must be observed so that there is no exploitation of minors’ (age-related) vulnerability with the objective of distorting their behaviour and causing significant harm (an AI system of this kind falls under the prohibited practices category).
- Transparency obligations for certain AI outputs
- If incoming data are processed through an algorithm, the resulting output content—text/descriptions and, more generally, AI-generated content—may trigger transparency obligations (e.g., labelling/informing that content is AI-generated or that the user is interacting with AI, as applicable; accountability for the design and operation of the algorithm).
- Roles, responsibility
- Provider: whoever develops or places an AI system on the market under their own name/trade mark, free of charge or for consideration.
- Deployer: whoever uses an AI system “under their responsibility” (other than purely personal/non-professional use).
- In this project, insofar as the platform/service is provided to users or customers, the entity implementing the project may be considered the provider.
- Obligations also for non-high-risk applications
- 5.1. AI literacy
- Measures must be taken to ensure that the project staff who operate/use the system on behalf of the entity have an adequate level of “AI literacy”, taking into account knowledge/training, the context of use, and the groups affected.
- Practical meaning for the project: short training/instructions on:
- when transcriptions/alt-text are likely to be wrong;
- what may and may not be published;
- procedures for reports/complaints;
- protection of minors and children.
- 5.2. Prohibited practices – especially due to children
- AI practices are prohibited that:
- use manipulative/deceptive techniques that materially distort behaviour and cause, or are reasonably likely to cause, significant harm;
- exploit vulnerabilities due to age (e.g., children), with the objective/effect of materially distorting behaviour with (reasonably) likely significant harm.
- AI practices are prohibited that:
- 5.1. AI literacy
- Transparency obligations
- 6.1. If the system interacts directly with users
- Providers must ensure that where an AI system is intended for direct interaction with natural persons, those persons are informed that they are interacting with AI (unless this is obvious). Example in the project: if there is an “AI assistant” for search/summary/navigation or a “smart” interface, there must be clear labelling.
- 6.2. If synthetic text is generated
- Providers of AI systems that generate synthetic content (audio/image/video/text) must ensure that outputs are marked in a machine-readable form and are detectable as artificially generated/manipulated, to the extent technically feasible.
- 6.3. Deepfakes & “public interest” text
- If the system creates/manipulates image-audio-video that is a deepfake, deployers must disclose this.
- If the system creates/manipulates text published to inform the public on matters of public interest, deployers must disclose that it is AI-generated/AI-manipulated, except where it has undergone human editorial control and editorial responsibility exists.
- 6.4. Reducing deepfake risk
- Prohibit the creation/processing of image-audio-video that can reproduce/imitate real persons.
- Express prohibition in the Terms of Use of uploads or prompts aimed at impersonation/deception.
- Adopt technical measures to prevent such phenomena.
- State an acceptable use policy (what is prohibited; what happens with reports).
- Disclaimer of liability for material uploaded by third parties that may be deepfake.
- The above constitutes an effort to approach potential problems and proposals for avoiding violations of applicable rules and regulations.
- 6.1. If the system interacts directly with users
LEGAL DOCUMENTATION IN RESPONSE TO QUESTIONS RAISED REGARDING CERTAIN ASPECTS OF THE OPERATION OF THE PLATFORM DEVELOPED UNDER THE KIDS RADIO PROJECT
- Questions and factual assumptions
- This report responds to three specific questions raised by the KID’S RADIO project team.
- The three questions concern:
- the lawfulness and proper documentation of retaining material without predetermined automatic deletion;
- the transfer of generated subtitles to Google via Gemini for grammar and syntax correction;
- the legal significance of the user’s ability to modify and validate AI-generated text, as well as the need for flagging/objection in relation to automatic transcriptions that may contain errors.
- The assessment is based on the following factual assumptions:
- The platform stores user material, such as audio, video, text, subtitles, transcripts, metadata and potentially logs, and operates as a user-controlled repository.
- No general automatic deletion is currently applied to user-uploaded or user-generated material after the expiry of a predetermined period; the material remains until deletion by the user or the occurrence of another contractually or technically defined event.
- The only point of content transmission to a third-party AI provider that was brought to our attention is the transmission of generated subtitles to Google via Gemini for grammar and syntax correction.
- Gemini is used as a paid/enterprise service and a DPA with Google exists; however, the exact product and the applicable terms must be verified.
- After the initial generation of subtitles/transcript by the AI, the user may fully modify the text; the user-edited text is stored in a separate field from the original AI-generated text.
- For display purposes on the platform, the text that has been modified or validated by the user is deemed the prevailing version, while if no intervention takes place, the initial AI output is displayed.
- Applicable legal framework
- 2.1. GDPR and Greek data protection law
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) applies to any wholly or partly automated processing of personal data. Subtitles and transcripts may constitute personal data where they contain names, contact details, references to third parties, descriptions of events, professional or personal information, or other elements enabling the direct or indirect identification of a natural person. The concept of personal data is broad and covers any information relating to an identified or identifiable natural person.
- The core principles of Article 5 GDPR are central to all three questions: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. In particular, the principle of storage limitation requires that data not be kept in a form that permits identification for longer than is necessary for the purposes of processing, and that time limits for erasure or periodic review be established.
- 2.2. AI Act
- Regulation (EU) 2024/1689 (AI Act) introduces a horizontal framework in the European Union according to the level of risk presented by artificial intelligence (AI) applications. With regard to the issues under consideration, the particularly relevant obligations are transparency obligations for certain AI systems, AI literacy obligations and the distinction between provider, deployer and user.
- For a system generating subtitles/transcripts, the critical question is not only whether it constitutes a high-risk AI system. On the basis of the factual circumstances submitted for assessment, the generation of subtitles for editing/display of content does not appear, in principle, to fall automatically within a high-risk category under Annex III. Nevertheless, transparency obligations, the labelling of artificially generated or modified content, human oversight where applicable, and appropriate user information remain critical. Users must be informed by means of an express and clear notice on the website at the time they interact with an AI system.
- In particular, Article 50 of the AI Act provides for information obligations where natural persons interact with an AI system, as well as an obligation of technical marking of outputs that constitute synthetic audio, image, video or text content. In general, the platform must determine the following:
- whether it is a provider or a deployer in relation to each AI functionality;
- the purpose of the AI system;
- whether the system is low-risk or high-risk;
- whether transparency obligations apply;
- whether AI literacy is required for staff/collaborators;
- how human oversight or validation is carried out.
- 2.1. GDPR and Greek data protection law
- Question 1 – Retention period for material on a repository platform
- The absence of a single calendar-based retention period for all user content is not, in itself, contrary to the GDPR. In a service provided as a repository, storage of the material constitutes the very contractual purpose of the processing. Retention may be based, in particular, on the performance of a contract under Article 6(1)(b) GDPR, where the user requests the storage and availability of their material on the platform.
- However, the GDPR does not permit indefinite, undifferentiated and unrevised storage. The key issue is not whether a specific number of months exists in every case, but whether objective retention criteria and erasure or periodic review procedures are in place. The phrase “we do not have a retention period” should be avoided. It is legally more appropriate to state that the retention period is determined by the duration of active use of the repository, the contract, deletion by the user, termination of the account/workspace, compliance with legal obligations and the need to establish, exercise or defend legal claims.
- In addition, Article 13 GDPR requires the data subject to be informed of the storage period or, where it is not possible to determine a specific period in advance, of the criteria used to determine that period. Therefore, the platform must clearly describe in its privacy policy and terms of use the retention criteria, as well as the relevant exceptions.
- Particular attention is required in relation to backups and logs. Deletion from the active environment does not necessarily entail immediate deletion from every backup, but there must be a documented backup replacement/deletion cycle and restrictions on the use of backups solely for security, recovery and business continuity purposes. Logs should not automatically follow the same retention period as user content; they must have their own retention period, proportionate to the purpose of security, access control and incident response.
- Question 2 – Transfer of subtitles to Google/Gemini and pseudonymisation
- The transmission of subtitles to Google may constitute processing of data if the subtitles contain personal data, in which case it constitutes a transfer/disclosure to a recipient or processor. Google must be expressly included in the data flow map, the privacy policy and the relevant data processing agreement where the platform operates as controller vis-à-vis users or as processor vis-à-vis B2B customers.
- The existence of a DPA is a necessary condition where Google acts as processor. Article 28 GDPR requires the controller to use only processors providing sufficient guarantees and to ensure that the processing is governed by a contract with specific content. The existence of a DPA, however, is not sufficient on its own: the exact product, place of processing, subprocessors, international transfers, audit/information rights, deletion/return of data and the technical arrangements preventing use for training must be confirmed.
- Google’s public assurances for paid/enterprise environments significantly reduce the risk of unauthorised onward use. Nevertheless, they do not replace the obligation of data minimisation and privacy by design. Where grammar/syntax correction can be achieved without names, phone numbers, email addresses, physical addresses or other identifiers, the technical application of pre-submission masking or pseudonymisation must be examined. Where this is not feasible due to loss of meaning or quality, there must be a documented exception based on necessity and proportionality.
- Pseudonymisation within the meaning of Article 4(5) GDPR is not identical to the mere removal of names and is not the same as anonymisation. Pseudonymised data remain personal data, but this technique is a recognised risk-reduction measure.
- The use of Google/Gemini for grammar and syntax correction of subtitles may be compatible with the GDPR, in particular where it is carried out through a paid/enterprise service with a DPA and express commitments that prompts/responses will not be used for training or product improvement. Nevertheless, the platform must retain the safeguard on pseudonymisation “where feasible”.
- Accordingly, it must be verified that the use falls within a paid/enterprise framework and not within a consumer Gemini environment. Users must be informed of this specific processing operation, and masking/pseudonymisation should be applied before subtitles are sent to Google. Names, phone numbers, email addresses and physical addresses should not be sent where avoidable. It should also be emphasised that the purpose of the transmission is exclusively grammar and syntax correction and not independent analysis or model training. Finally, sending only the strictly necessary text limits the risk.
- Question 3 – User validation and liability for AI-generated transcripts
- The existence of a separate field for AI-generated and user-edited text is legally positive, as it creates traceability and documents user intervention. Under the GDPR, however, it is not sufficient merely to provide a technical editing capability. It must be clear whether the displayed version is:(a) automatic and unreviewed, (b) reviewed/approved by the user without changes, or (c) modified by the user. This distinction is linked to the principle of accuracy under Article 5(1)(d) GDPR and to the right to rectification under Article 16 GDPR.
- Where the transcript contains personal data of third parties, an incorrect transcription may create a risk of harm, defamation, breach of privacy or misinformation. Accordingly, there must be a flagging/objection/report error mechanism not only for the user who uploaded the material, but, where appropriate, also for persons affected by the content or persons who have a legitimate interest in requesting correction, concealment, restriction or deletion.
- Actual human modification/validation changes the assessment under the AI Act, but it does not fully eliminate the need for transparency. Article 50 of the AI Act includes obligations for AI systems that interact with natural persons or generate synthetic text content. If the platform displays an AI-generated transcript that has not been reviewed, there must be a clear indication that the text has been generated automatically and may contain errors.
- If the user has substantially modified or expressly approved the text, the platform may display it as a user-validated or user-edited version. This reduces the risk of misleading users and demonstrates a human-in-the-loop process. However, a mere ability to edit is not equivalent to human review. There must be an explicit action, timestamp, version history or status flag documenting validation.
- Particular significance attaches to cases where AI-generated or AI-manipulated text is published for the purpose of informing the public on matters of public interest. In such cases, the deployer is generally required to disclose that the text has been artificially generated or modified, unless there is human review or editorial control and a natural or legal person bears responsibility for it.
- Liability for errors, defamation and misinformation
- From the perspective of civil liability and personality rights, the platform must avoid creating the impression that it guarantees the absolute accuracy of automatic subtitles. The Terms of Use should provide that the AI output is auxiliary, may contain errors and must be checked by the user before publication or further use. At the same time, the platform should not disclaim all liability in a manner that would be invalid or abusive, especially if it becomes aware of unlawful or harmful content and fails to act.
- Where the platform hosts or makes content available, it is advisable to have a notice-and-action procedure, allowing for temporary concealment, correction, review, addition of a notice or removal of content. The existence of an audit trail showing who modified what and when is critical for the allocation of liability and the demonstration of due diligence.
- The safeguard concerning flagging/objection should not be deleted; it should be reformulated. The platform correctly separates AI-generated text from user-edited text and may regard the user-validated text as the prevailing version. However, a clear status must be displayed: “AI-generated/unreviewed”, “user-edited”, or “user-approved/validated”. There must be a reporting/objection mechanism and an audit trail. The ability to edit improves the assessment under the AI Act only where genuine and documented human review or editorial control exists.
- Proposed safety and information notices
- 7.1. Storage limitation and deletion safeguards
- The platform operates as a user-controlled repository. User-uploaded material, including audio, video, text, transcriptions, subtitles and related metadata, is retained for as long as the relevant account, project or workspace remains active, or until the user/customer deletes it, requests deletion, or terminates the service, unless further retention is required by law or necessary for the establishment, exercise or defence of legal claims. The platform maintains documented retention criteria per data category, deletion workflows for active systems, defined backup purge cycles, separate retention rules for logs and billing data, anonymisation where feasible, and periodic review of inactive accounts and unnecessary data.
- 7.2. Third-party AI processing and pseudonymisation safeguards
- Where subtitles or transcripts are sent to a third-party AI provider, such as Google/Gemini, the transfer is limited to the purpose of grammar and syntax correction and is subject to an applicable Data Processing Agreement, documented security and confidentiality commitments, and verification that prompts/responses are not used for model training or product improvement in the relevant paid/enterprise service. Before submission, the platform applies masking or pseudonymisation of direct identifiers, such as names, phone numbers, email addresses and other unnecessary identifiers, where technically feasible and compatible with the correction purpose. Where pseudonymisation is not feasible, the exception is documented, and data minimisation, access control, logging, transfer safeguards and deletion commitments apply.
- 7.3. Flagging, objection, version control and user validation safeguards
- Automatic transcriptions and AI-generated subtitles are clearly flagged as machine-generated and may contain errors until reviewed, edited or expressly approved by the user. The platform stores the original AI-generated text separately from any user-edited or user-validated version and displays the user-validated version as the prevailing version where available. Each version is associated with status metadata, timestamps and audit logs. Users and, where applicable, affected persons may flag inaccuracies, unlawful content, defamatory statements or misleading descriptions through an objection/reporting mechanism, triggering review, correction, restriction, removal or other appropriate action.
- 7.1. Storage limitation and deletion safeguards
- In conclusion
- With regard to the repository and material retention, there is no mandatory requirement for general automatic deletion of all data after a uniform period. However, a documented retention policy is required, with objective criteria, deletion following user deletion/contract termination, backup cycles and management of inactive accounts.
- With regard to Google/Gemini, the use of a paid/enterprise service with a DPA and assurances that prompts/responses are not used for training or product improvement may constitute an adequate risk-reduction basis, together with the technical application of masking or pseudonymisation where feasible.
- With regard to flagging and liability for AI-generated transcripts, user editing capability and storage in a separate field are legally significant and positive measures. However, they are not sufficient without clear status labels, audit trails and a reporting/objection mechanism. The initial AI output must be displayed as unreviewed, whereas only the expressly modified or approved version may be displayed as user-validated.
- With regard to the AI Act, the described functionality does not appear, in principle, to transform the platform into a high-risk AI system solely because it generates subtitles/transcripts. Nevertheless, transparency obligations, AI literacy and the labelling of artificially generated or unreviewed content remain critical. User validation may reduce disclosure obligations only where it is genuine, express and documented.
- The platform should include extensive information on its website regarding the way it operates and the technical measures and means taken to inform and protect users, as well as the responsibility assumed and borne by those who upload material.
- Overall, the proposed approach is to retain the safeguards that have been set out and to reformulate others so that they accurately reflect the platform’s actual operation and are supported by technical, contractual and organisational documentation.
- It is recommended that the website state that the platform and its provider are non-profit in nature and that access to, use of, uploading of material to and visits to the platform are provided free of charge, with no financial consideration from users, uploaders or visitors.
- The platform must distinguish between the original AI-generated text and the user-edited/user-validated text. The existence of a separate field in the database is a sound practice. It must, however, be accompanied by clear reference/information, such as: The initial transcript is generated automatically and may contain errors. The user has the ability to fully modify and validate it. Where the user intervenes, the user-validated text prevails for display on the platform.
- The fact that the service is free of charge for users does not permit data to be sent to third parties without notification. It must be clearly stated that specific text, namely subtitles/transcripts, is sent to Google/Gemini for linguistic and syntax correction.
- Finally, the free nature of the service does not permit unlimited retention of the material. The platform may state that the material is retained for as long as the account or workspace remains active or until the user deletes it. Retention is carried out for the purpose of providing the free repository service and is subject to a deletion policy, backup purge, management of inactive accounts and exercise of erasure rights.
Licensing Terms for Podcast Uploads
(Based on Creative Commons Attribution – NonCommercial – NoDerivatives 4.0 International License)
- Purpose and Scope
- 1.1. YouthRadio.eu is an educational web platform that enables youth teams and their coordinators (“Contributors”) to create, upload, and share audio works (the “Works”).
- 1.2. By submitting a Work to YouthRadio.eu, Contributors grant the platform the rights described below, solely for purposes consistent with its educational, cultural, and non-profit mission.
- Rights Granted
- 2.1. Contributors grant to YouthRadio.eu and its managing entity a non-exclusive, worldwide, royalty-free, irrevocable, and perpetual license to:
- 2.1.1. Reproduce and store the Work in any format or medium, digital or otherwise.
- 2.1.2. Publish, distribute, transmit, and make the Work publicly available through the YouthRadio.eu platform and its associated channels (radio stream, community site, events, educational materials, or social-media promotion).
- 2.1.3. Use the Work for educational, research, promotional, and non-commercial purposes related to the objectives of YouthRadio.eu (e.g., festivals, showcases, awards, and workshops).
- 2.1.4. Maintain a permanent archival copy of the Work for documentation and long-term educational access.
- 2.2. The license is non-exclusive: Contributors retain ownership and may publish or license the Work elsewhere under compatible non-commercial terms.
- 2.1. Contributors grant to YouthRadio.eu and its managing entity a non-exclusive, worldwide, royalty-free, irrevocable, and perpetual license to:
- Rights Retained by the Contributors
- 3.1. Contributors remain the sole authors and copyright holders of their Works.
- 3.2. This license does not transfer ownership or any exclusive economic or moral rights.
- 3.3. Contributors:
- 3.3.1. may freely use, display, or share their Work elsewhere for personal or educational, non-commercial purposes
- 3.3.2. may re-license their Work under compatible Creative Commons licenses (e.g., BY-NC-ND or BY-NC-SA)
- 3.3.3. retain full moral rights of authorship and integrity of their Work
- Use of the Work by YouthRadio.eu
- 4.1. YouthRadio.eu agrees to:
- 4.1.1. Refrain from altering or editing the Work, except for minor technical adjustments (e.g., loudness normalization, file-format conversion, or metadata completion) required for platform compatibility.
- 4.1.2. Provide proper attribution to the Contributors in all displays or communications, in compliance with the license requirement that:
- 4.1.3. Use the Work only for non-commercial purposes.
- 4.1.4. YouthRadio.eu may introduce a general subscription or access fee to cover operational costs (hosting, technical support, maintenance, etc.), provided that such fee does not constitute commercial exploitation of the Work itself.
- 4.1. YouthRadio.eu agrees to:
- Restrictions and Prohibited Actions
- 5.1. No party (including YouthRadio.eu users or third-party viewers) may:
- 5.1.1. modify, remix, or create derivative works based on the original Work
- 5.1.2. use the Work for commercial gain or advertising
- 5.1.3. remove or obscure attribution or license information attached to the Work
- 5.2. Neither Contributors nor any third party may apply legal terms or technological measures that restrict others from exercising the rights granted by this license:
- 5.3. YouthRadio.eu reserves the right to remove any Work that violates these terms or applicable law.
- 5.1. No party (including YouthRadio.eu users or third-party viewers) may:
- Warranties and Responsibilities
- 6.1. Contributors declare and warrant that:
- 6.1.1. they are the original authors of the Work or have obtained all necessary permissions for included materials (music, sounds, interviews, etc.)
- 6.1.2. the Work does not infringe any copyright, privacy, or publicity rights of third parties
- 6.1.3. all necessary consents from guardians for minors involved in the Work have been obtained
- 6.1.4. they will indemnify YouthRadio.eu against any claims resulting from unlawful or unauthorized use of copyrighted material
- 6.1. Contributors declare and warrant that:
- Public Availability and Listener Rights
- 7.1. All podcasts published on YouthRadio.eu are made available under the Creative Commons BY-NC-ND 4.0 International License, which allows the public to:
- 7.1.1. share the Work freely (copy and redistribute it in any medium or format)
- 7.1.2. with proper credit to the creators
- 7.1.3. for non-commercial purposes only
- 7.1.4. without altering, transforming, or building upon the Work
- 7.2. A link to the full license text will accompany each published Work: https://creativecommons.org/licenses/by-nc-nd/4.0/
- 7.1. All podcasts published on YouthRadio.eu are made available under the Creative Commons BY-NC-ND 4.0 International License, which allows the public to:
- Acceptance
- 8.1. By selecting “I Agree to the Licensing Terms” and uploading the Work, Contributors confirm that they have read, understood, and accepted these terms, and that they grant YouthRadio.eu the rights described herein to host and distribute their Work in accordance with this License.
The Scientific Society “Interdisciplinary Intercultural Radio of the Educational Community,” also known as European School Radio, The First Student Radio, after a request regarding the legal operation of the station concerning music usage rights during broadcasting and distribution of produced radio content, has secured the appropriate music usage license from the relevant Collective Management Organization for its users—all participating schools that produce broadcasts on European School Radio.
We inform the visitors of this website that the online radio (web radio) with the domain name www.europeanschoolradio.eu is a certified partner of the GEA and GRAMMO Organizations and legally reproduces and publicly performs recorded music.
Cookie Policy – European School Radio & YouthRadio.eu
European School Radio (europeanschoolradio.eu) & YouthRadio.eu
Last updated: September 14, 2026
- Purpose & Overview
- This Cookie Policy outlines how the European School Radio / YouthRadio.eu platform (operated by the non-profit civil company “Interdisciplinary Intercultural Radio of the Educational Community” for the Kids Radio Europe Consortium) uses cookies and similar tracking technologies.
- Both domains (europeanschoolradio.eu & youthradio.eu) lead to the same unified platform operating on a single database. This policy applies to all registered users (students, teachers, youth workers, parents) and unregistered visitors.
- What Are Cookies?
- Cookies are small text files placed on your browser or device when accessing the platform. They allow the system to recognize your device, maintain security, remember user preferences, and collect anonymous system statistics.
- Categories of Cookies Used
-
Category Type Purpose & Function Retention Period Strictly Necessary Essential Essential for site operation, session security, role-based access control (RBAC), user authentication, and enforcing age-appropriate filters.
Session / Up to 12 months (Logs)
Preferences & Functional Functional Remembers accessibility preferences (WCAG 2.2 font size, contrast), language choice, volume settings, and the “No Personalisation” toggle choice.
Up to 12 months
Statistical & Analytics Statistical Collects aggregated, non-profiling usage data (page visits, podcast play counts, technical error logs) to optimize platform stability and prepare required annual DSA Transparency Reports.
Up to 12 months (System logs)
-
- Protection of Minors & Non-Profiling Rules (DSA Art. 28 & GDPR)
- 4.1. In accordance with Regulation (EU) 2022/2065 (Digital Services Act – DSA) and the GDPR:
- 4.1.1. No Advertising Profiling: Personal data collected via cookies is never used to display targeted or behavioral advertisements, especially for minor users under 18.
- 4.1.2. Minor Visitors (Without Account): Users under 18 browsing podcasts without an account generate only strictly necessary technical identifiers (IP address, system logs) for platform security. No personal profiles are built.
- 4.1.3. Non-Personalized Algorithm Toggle: Users can click the “No Personalisation” button at any time. This disables cookies/listening history from influencing recommendations and displays podcasts based purely on manual age and topic tags.
- 4.1. In accordance with Regulation (EU) 2022/2065 (Digital Services Act – DSA) and the GDPR:
- System Logs & Technical Identifiers
- 5.1. To satisfy cybersecurity requirements, incident reporting, and compliance under Regulation (EU) 2024/936, system logs (containing IP address, browser type, timestamps, and request headers) are stored securely in EU/EEA data centers encrypted with AES-256 and TLS 1.3. These logs are retained for up to 12 months and kept separate from general audio content.
- Third-Party Data Transfers & AI Processing
- 6.1. No third-party commercial marketing trackers or advertising pixels are integrated.
- 6.2. Where automated tools are used for transcriptions or subtitle grammar correction (e.g., Google Gemini under Enterprise DPA frameworks), technical pseudonymization and masking are applied prior to submission. Prompts and responses are not used for third-party AI training.
- Managing & Disabling Cookies
- 7.1. Platform Control Center: Manage your privacy and recommendation settings at any time via: https://community.europeanschoolradio.eu/gdpr
- 7.2. Browser Settings: You can restrict, block, or delete cookies directly through your web browser settings. Disabling essential cookies may impair core functionality (e.g., logging in or uploading podcasts).
- Legal Contact Details
- 8.1. Data Controller: Non-Profit Civil Company “Interdisciplinary Intercultural Radio of the Educational Community” (trading as European School Radio – the First Student Radio)
- 8.2. Headquarters: I.H.U. Alexander Campus, Sindos 574 00, Thessaloniki, Greece
- 8.3. Tax Reg. No.: EL-998502950 (Tax Office D Thessaloniki)
- 8.4. Data Protection Officer (DPO): dpo@youthradio.eu
- 8.5. DSA Compliance Contact: compliance@youthradio.eu
