Carry out a DPIA, which is mandatory for such services, before launch and before significant changes (and review it on external triggers such as new security flaws or public concern), focused on risks to children of different ages and on conformance with every standard: describe the processing including target ages, parental controls, age assurance, benefits, commercial interests, profiling, geolocation, nudges, special category and inferred data and relevant codes; consult children and parents (expected of larger organisations) and experts; assess necessity, lawful basis, bias and AI explanation and security; assess risks of physical harm, grooming, bullying, harmful content, misinformation, risky behaviour, loss of autonomy, compulsive use, sleep disruption and economic exploitation by likelihood and severity with a precautionary approach; mitigate beyond transparency; record the DPO's advice; and consult the ICO on unmitigated high risk. Publishing the DPIA is good practice.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.