Less Than 1% Reported: Why a Reporting Button Is Not a Safe Disclosure System

A SAFECHAIN™ Directive on Digital Safeguarding, Disclosure and the Protective Burden

By Samantha Avril-Andreassen, LLB (Hons), LLM, LPC, FRSA
Founder, SAFECHAIN™

There is a statistic in UNICEF's latest research that every organisation designing digital safeguarding systems should confront.

It is not only that an estimated 20 million children aged 12–17—almost one in five of the internet-using children studied across 21 countries—experienced technology-facilitated sexual exploitation or abuse within a single year.

It is what happened afterwards.

Fewer than 1% of those experiences were reported to police, social workers or helplines.

More than four in ten were never disclosed to anyone at all.

That is not simply a reporting statistic.

It is a safeguarding warning.

Because when millions of children experience harm but only a tiny fraction reach formal systems of protection, the question cannot simply be:

Why didn't they report it?

The institutional question must be:

What have we designed that makes safe disclosure so difficult?

That distinction matters.

And it should fundamentally change how governments, technology companies, schools, regulators, police and safeguarding organisations assess digital safety.

The existence of a reporting mechanism does not prove the existence of a safe disclosure system

There is a dangerous assumption embedded in many digital services.

A reporting button exists.

A complaints form exists.

A helpline exists.

A safeguarding email address exists.

Therefore, the organisation believes that people have been given a route to disclose.

Technically, perhaps they have.

Safeguardingly, that tells us almost nothing.

A disclosure pathway only works when the person experiencing harm can actually use it.

That means asking whether they:

  • recognise what happened as abuse;

  • understand how to report it;

  • believe disclosure will be taken seriously;

  • can communicate what happened safely;

  • understand who will receive their information;

  • know what will happen after pressing “submit”;

  • can disclose without increasing their exposure to harm;

  • can participate without repeatedly retelling traumatic experiences;

  • receive a meaningful safeguarding response afterwards.

If those conditions are absent, the reporting mechanism may exist while the safeguarding pathway effectively does not.

This is the distinction at the heart of SAFECHAIN™ Safe Disclosure™.

Safe Disclosure™ treats disclosure not as a moment in which information is transferred from victim to institution, but as a governed safeguarding pathway.

The institutional responsibility does not begin when somebody successfully completes the form.

It begins with designing conditions in which disclosure is realistically possible.

What the UNICEF evidence tells us

UNICEF's September 2026 Through Children's Eyes report draws on nationally representative surveys involving approximately 21,000 internet-using children aged 12–17 across 21 countries, alongside in-depth interviews with 100 young people who experienced abuse during childhood.

The scale is substantial.

UNICEF estimates that:

  • more than 15 million children were exposed to unwanted sexual content;

  • around 9 million were asked to engage in sexual conversations or share sexual images against their will;

  • approximately 4 million had sexual images of themselves shared without consent.

Nearly 60% of cases occurred on mainstream social-media platforms, while 14% occurred in online games.

But another finding should change how we think about online safeguarding.

57% of cases involved someone the child already knew.

That included peers, romantic partners, friends and family members.

The digital safeguarding conversation therefore cannot remain trapped within a simplistic stranger-danger model.

Digital harm can operate through existing relationships.

It can exploit trust.

It can exploit intimacy.

It can exploit dependency.

And, critically, it can exploit the same relational dynamics through which coercive control operates.

Disclosure cannot be separated from power

Safeguarding systems frequently treat disclosure as an individual decision:

Tell someone.

Report it.

Ask for help.

But disclosure does not happen in a vacuum.

A child or vulnerable person may be weighing fear, shame, loyalty, dependency, retaliation, uncertainty and the possibility that disclosure could make their situation worse.

UNICEF found that globally the most common reason children remained silent was that they did not know where to go or whom to tell.

That is an infrastructure failure.

If a safeguarding system depends upon a vulnerable child understanding:

what happened,

that it constitutes abuse,

which institution has jurisdiction,

where the reporting function is,

what evidence is required,

who will receive it,

and what will happen next,

then the system has transferred an extraordinary amount of safeguarding responsibility onto the person least equipped to carry it.

SAFECHAIN™ describes this wider phenomenon through Protective Burden™.

Protection fails when the individual experiencing harm must repeatedly identify the risk, interpret the system, find the correct agency, communicate the danger, coordinate fragmented responses and pursue action before protection materialises.

Digital systems can reproduce exactly the same burden.

A reporting button does not remove that burden merely because it is clickable.

Safe Disclosure™: disclosure must be designed, not merely permitted

Safe Disclosure™ begins with a different premise:

A safeguarding system should create the conditions in which disclosure can occur safely, intelligibly and without imposing unnecessary additional harm upon the person disclosing.

That requires more than technology.

It requires governance.

A safe disclosure pathway should therefore address at least five questions.

1. Can the person recognise the harm?

Safeguarding language is often written for professionals rather than the people experiencing abuse.

Children may not identify grooming, coercion, manipulation, image-based abuse or controlling behaviour using institutional terminology.

Reporting systems must therefore help users recognise experiences without requiring them first to correctly classify the offence or safeguarding category.

2. Can the person disclose safely?

The method of disclosure matters.

Can the perpetrator see browsing history?

Will a notification appear?

Will an email confirmation expose the report?

Can the user exit rapidly?

Can a disclosure be saved safely?

Could shared-device access reveal what has been reported?

These questions connect Safe Disclosure™ directly with Survivor Privacy by Design™, Quick Exit™, Stealth Mode™ and Journal Lock™.

Privacy cannot be added after the reporting pathway has been designed.

It must be part of the pathway.

3. Can the person understand what happens next?

Uncertainty suppresses disclosure.

If somebody does not know whether pressing “report” will trigger police contact, parental notification, account suspension, information sharing or some other intervention, they cannot meaningfully assess the consequences of disclosure.

This is where Consent Integrity™ becomes relevant.

Consent in safeguarding cannot be reduced to:

“I agree.”

Meaningful participation requires understandable information about:

  • what information is being collected;

  • why;

  • who may receive it;

  • what choices remain available;

  • where confidentiality may have limits;

  • what safeguarding action may follow.

Where immediate protection duties override choice, that should also be explained as clearly and sensitively as circumstances allow.

4. Does somebody own the disclosure after it is made?

This is where many systems fail.

Information is received.

A referral is generated.

A ticket is created.

A case is transferred.

The organisation records activity.

But nobody maintains ownership of the safeguarding outcome.

SAFECHAIN™ therefore applies a Disclosure-to-Protection Integrity Test™:

Can the organisation demonstrate an unbroken safeguarding pathway from disclosure or risk signal through recognition, ownership, escalation and protective action—without requiring the vulnerable person to coordinate the system themselves?

The pathway should look like:

Disclosure → Recognition → Risk Assessment → Ownership → Action → Escalation → Protection → Verification

Not:

Disclosure → Referral → Referral → Referral → Survivor Navigation

A referral is an administrative action.

Protection is a safeguarding outcome.

They are not interchangeable.

Participation by Design™: stop designing reporting systems without the people expected to use them

There is another governance problem.

Safeguarding systems are frequently designed by:

policy teams,

technology teams,

legal teams,

compliance teams,

and senior leadership.

Then vulnerable users are invited to test the finished product.

That is consultation.

It is not necessarily participation.

Participation by Design™ requires lived experience and affected communities to influence the architecture of a service before fundamental design decisions become fixed.

For disclosure systems, that means asking children and survivors:

What language would you understand?

What would stop you reporting?

What would make you fear pressing this button?

What information would you need first?

Which disclosure route would feel safest?

What would you expect to happen afterwards?

What would make you trust the response?

And then the governance question becomes:

Can the organisation evidence what changed because vulnerable users participated?

If nothing changes, participation risks becoming symbolic rather than meaningful.

Trauma-Informed Digital Design™: trauma changes how systems are experienced

Digital services are often designed around an imagined calm, confident and cognitively available user.

Safeguarding users may be none of those things.

Someone attempting disclosure may be frightened.

They may be interrupted.

They may be hypervigilant.

They may struggle to remember chronology.

They may abandon a form.

They may return several times.

They may provide information in fragments.

They may contradict themselves while trying to make sense of what happened.

That does not make their disclosure inherently unreliable.

It means the system must understand the conditions under which safeguarding disclosures occur.

Trauma-Informed Digital Design™ therefore asks whether digital systems account for:

  • cognitive load;

  • distress;

  • memory fragmentation;

  • fear;

  • decision fatigue;

  • accessibility;

  • interruption;

  • privacy;

  • safe re-entry;

  • understandable language;

  • unnecessary repetition.

A twenty-page online safeguarding form may satisfy organisational data requirements while being almost unusable by the person the system supposedly exists to protect.

That is not trauma-informed safeguarding.

It is administrative convenience imposed upon vulnerability.

Digital Safeguarding Maturity Model™: measure what the system actually does

This leads to the wider governance question.

How should an organisation know whether its disclosure system is good?

Not by counting how many reporting buttons exist.

Not by counting how many policies mention safeguarding.

Not even solely by counting reports received.

The Digital Safeguarding Maturity Model™ (DSMM™) asks organisations to assess capability across governance, survivor-centred design, privacy, digital safety controls, evidence management, safeguarding practice, risk and assurance, workforce capability and continuous improvement.

Applied to disclosure, maturity should be demonstrated through questions such as:

  • Are reporting routes accessible?

  • Are they tested with intended users?

  • Are privacy risks assessed?

  • Are abandoned disclosures examined?

  • Are staff trained to recognise coercive patterns?

  • Is information transferred safely?

  • Is responsibility assigned?

  • Are response times measured?

  • Are safeguarding outcomes reviewed?

  • Are failures used to redesign the system?

  • Can leadership evidence that disclosure produces protection?

This moves safeguarding away from policy possession and towards demonstrable capability.

The reporting gap is a governance metric

The UNICEF finding that fewer than 1% of experiences reached police, social workers or helplines should therefore not be read simply as evidence that children are reluctant to report.

It should trigger scrutiny of the entire disclosure environment.

What did children understand?

What did they fear?

What reporting options existed?

Were those options visible?

Were they safe?

Were they trusted?

Did children believe anything useful would happen?

Did previous institutional experiences influence their decision?

Were platforms designed around disclosure—or around engagement?

Those are governance questions.

And they matter because UNICEF's research also found substantial associations between technology-facilitated exploitation and serious psychological harm: affected children were four times more likely to report suicidal thoughts or behaviours and self-harm, alongside higher anxiety.

The cost of silence therefore cannot be treated as an abstract data problem.

The burden must move

One of UNICEF's recommendations is particularly significant: shift the burden of protection away from children by ensuring families, schools and communities respond supportively to disclosures and help children access assistance safely. UNICEF also calls for safer-by-design platforms, stronger privacy protections, better detection and reporting, stronger regulation and reporting systems children can trust.

That principle should extend across safeguarding.

The child should not carry the system.

The survivor should not coordinate the agencies.

The vulnerable person should not have to become an expert in institutional architecture before protection becomes available.

The system must carry the protection.

That is the difference between providing a reporting mechanism and building a safeguarding system.

The SAFECHAIN™ Directive

Every organisation providing a digital reporting or safeguarding pathway should be able to answer one question:

Can a vulnerable person identify harm, disclose it safely and understand what happens next without carrying the burden of navigating the safeguarding system themselves?

If the answer cannot be demonstrated, the organisation should not describe the presence of a reporting button as evidence that safe disclosure has been achieved.

A button is functionality.

A form is infrastructure.

A referral is process.

Protection is the outcome.

SAFECHAIN™ therefore proposes that digital safeguarding be assessed across the complete chain:

Recognition → Safe Disclosure → Consent → Privacy → Risk Assessment → Ownership → Response → Escalation → Protection → Verification → Learning

Every broken link matters.

Because the central lesson from UNICEF's findings is not merely that children are experiencing extraordinary levels of technology-facilitated abuse.

It is that enormous numbers are experiencing that harm without ever reaching the systems created to protect them.

That is where safeguarding reform must begin.

Not by asking vulnerable people why they failed to report.

But by asking institutions:

Why did your system fail to become safe enough to tell?

SAFECHAIN™ Frameworks Applied

This analysis applies and connects:

Safe Disclosure™ — creating conditions in which disclosure can occur safely and lead to meaningful response.

Protective Burden™ — examining when responsibility for navigating protection is transferred onto the person experiencing harm.

Participation by Design™ — embedding meaningful participation in the design, testing and governance of safeguarding services.

Trauma-Informed Digital Design™ — designing digital environments around the realities of trauma, distress and vulnerability.

Survivor Privacy by Design™ — embedding privacy and safety within digital architecture rather than treating them as downstream compliance issues.

Consent Integrity™ — ensuring consent and participation are informed, understandable, specific and meaningful rather than procedural.

Digital Safeguarding Maturity Model™ (DSMM™) — assessing whether organisations possess demonstrable digital safeguarding capability.

Trust by Design™ — recognising trust as a product of transparent, accountable and consistently safe systems.

SAFECHAIN™ Digital Safeguarding Standard (DS-001) — bringing these requirements together within an auditable digital safeguarding governance model.

© 2026 Samantha Avril-Andreassen. All Rights Reserved.
SAFECHAIN™

Safeguarding should not depend upon whether a vulnerable person can successfully navigate the system. The system should be designed to reach protection.

Previous
Previous

Post-Separation Digital Residue, Coercive Control and the Case for Digital Exit Integrity™

Next
Next

SAFECHAIN™ RESEARCH & SYSTEMS REPORT 2026