Written by Vishal Vaibhav Singh, a fifth-year law student at National Law University Odisha.
Karnataka’s Chief Minister used his 2026 budget speech to announce that the state would bar under-16s from social media the first such move by any Indian state, though no bill has followed. Australia has already run the experiment nationally; France legislated the same idea and had it struck down within a month. Both expose a question India has not asked seriously: when a law says “social media,” what is it actually regulating the platform, the account, or the specific feature producing the risk? Get that wrong, and a ban meets its limits in enforcement, as Australia is discovering, or in constitutional design, as France just found without protecting a single child either way.
THREE JURISDICTIONS, THREE DIFFERENT QUESTIONS
Australia’s Online Safety Amendment, in force since 10 December 2025, answers who is responsible: platforms, not parents or children, must take reasonable steps to keep under-16s off. eSafety’s own three-month evaluation, published 31 July 2026, found account ownership among 10-to-15-year-olds fell from roughly 52% to 42%, but use of age-restricted platforms stayed above 81%, barely down from 86% mostly because platforms never asked users to prove their age. Tellingly, Australia’s own regulator had to narrow its definition in March 2026 to cover only services with a recommender feature or a logged-in feature even the flattest ban on the books ends up scoped by function, not category.
France asked how far the State may go, and the answer came back narrower than expected. Its law banning under-15s from social media, passed in July 2026, was struck down by the Constitutional Council on 14 August ten days before this article was researched on two separate grounds. First, under Article 11 of the 1789 Declaration (freedom of expression), the ban was disproportionate because its scope borrowed from EU platform-regulation definitions could catch services never shown to pose any risk, applied uniformly regardless of a minor’s age or maturity, and gave parents no way to tailor it. Second, and separately, under Article 2 (privacy), the law failed even assuming the restriction itself was sound, because it would have required everyone, not just minors, to prove their age, without legislating any limit on how. Two failures, two different rights, tested independently.
The UAE asked a third question how should an age threshold actually work and answered with graduation rather than a flat line: Cabinet Resolution No. 106 of 2026 sets access at 15, but 15- and 16-year-olds keep it only with stranger-contact restrictions, content filters, and a ban on behavioural profiling switched on by default.
WHAT INDIAN LAW CURRENTLY REGULATES
India is often described as having no law here. That is not accurate it has several, and each governs a different stage of a child’s digital life. Section 9 of the DPDP Act, 2023 governs data: verifiable parental consent, no behavioural tracking, no targeted advertising under 18. POCSO governs conduct: it criminalises sexual exploitation of a child wherever it occurs, online included. The IT intermediary rules govern content: takedown duties once harmful material surfaces. None asks what an access-age law would ask at what age, and under what conditions, a child may operate an account on a high-risk platform. India lacks a dedicated statute for that question, and even the data layer is not fully live: the DPDP Rules, 2025, notified 13 November 2025, stagger the children’s-consent machinery under Rule 10 to commence eighteen months later, on 13 May 2027. Ten days before this article was written, the Delhi High Court confirmed the gap directly, disposing of Kirti Dua v. Union of India a PIL seeking exactly this kind of access framework by holding it was “in the realm of a policy,” leaving the fourth layer to Parliament, where it does not yet exist.
IS “SOCIAL MEDIA” THE WRONG UNIT TO LEGISLATE?
The French Council’s first ground was not really about France. It was about whether a single functional label services that let users link, post and interact can rationally carry a restriction meant to respond to specific risks like algorithmic amplification, stranger contact or livestreaming, when a moderated forum and an engagement-optimised feed both fit the label equally. Indian commentary has begun moving this way: Vidhi Centre for Legal Policy has argued the real target should be platform design infinite scroll, autoplay, algorithmic amplification rather than access as such, and a rights-calibrated framework proposed in recent scholarship argues for tiered, age-graded access. What that discussion has not yet connected is France’s own two-track reasoning to Indian doctrine specifically.
Article 14 supplies the Indian analogue to France’s first ground: a classification survives scrutiny only where an intelligible differentia bears a rational nexus to the statute’s object. Where the object is protecting children from specific technological risks, a category built only from “lets users interact and post” catching a school forum and a public recommendation feed alike struggles to show that nexus, because it groups materially different risk profiles under one label. The claim is not that Article 14 mandates feature-based regulation; it is narrower a classification untethered from risk is more vulnerable to a challenge for over-inclusiveness, exactly the technical failure the French Council identified.
AGE ASSURANCE AS A SEPARATE QUESTION
Even with feature-based restriction, it is necessary to know the user’s age to determine which functions to turn off. The OECD benchmarking study of 50 child-used services only identified two services that have verified age at account creation, so this is what most services already have. There is a real alternative, a user can prove that an issuer certified them as being over a threshold without revealing a name or birth date to the platform, in the form of zero-knowledge proofs. But Brave’s technical analysis shows the cryptography alone does not solve the problem combine the proof with the site it was used on and the issuer’s identity, and a person can still be tracked across services.
The better response is not a licensing regime that would concentrate age-assurance infrastructure in a handful of large providers, cutting against data minimisation rather than serving it. A lighter model data-minimisation standards, a bar on linking age credentials to account activity, and independent third-party audit, layered onto the DPDP Act’s existing data-fiduciary obligations rather than a new licence achieves the same accountability without creating a new identity chokepoint. That is precisely the gap Article 2 of the French Declaration exposed: not that verification is impossible, but that it was never given rules of its own.
AGE, FEATURE, RISK, ASSURANCE
Put together, the model has four moving parts rather than one threshold. Age sets a floor of vulnerability no independent account below 13, restricted access with parental visibility from 13–15, protective defaults from 16. Within any band, specific features recommendation, stranger contact, livestreaming, behavioural advertising switch on or off independently of the platform’s general label, following the logic Australia’s own regulator was forced into rather than a flat cut-off. Assurance is regulated separately, under its own privacy rules. And two distinct proportionality questions apply, following France’s own structure: whether the access restriction is necessary and rationally tied to risk, and whether the verification method is independently justified.
This will not survive every objection. A platform could argue recommendation is an editorial choice entitled to expressive protection; regulators will struggle to keep feature definitions current as products are redesigned around them; smaller platforms will find per-feature compliance costlier than a single age gate; and children will misreport their age regardless, exactly as Australia’s data shows happening at scale. These are real costs, not answered by relabelling the problem. But they argue for calibrating the model, not for retreating to an undifferentiated category which fails on enforcement for the reason Australia’s is failing, and would fail constitutionally for the reason France’s did.
CONCLUSION
The question India’s coming law will actually be judged on is not whether it sets an age, but what it decides to regulate at that age. Children are not simply vulnerable users to be walled off they hold their own Article 19(1)(a) interest in expression and access to information, alongside a developing autonomy the law has to weigh rather than override, which is exactly the interest the French Council found the blanket ban had disregarded. A statute built around a single undifferentiated category repeats that error before a single account is switched off. One built around age, feature, risk and a separately accountable assurance mechanism has a harder drafting task ahead but a real chance of surviving the test that has already defeated Paris and is quietly unravelling in Canberra.


Leave a Reply