·The Hindu·15 marks·250–350 words

Age-verification technology is central to enforcing child-safety rules on social media, yet remains easily circumvented. Discuss the implications for India's data protection framework.

In this answer
  1. Why age verification is load-bearing
  2. Why it is circumvented
  3. Implications for India's framework

Section 9 of the Digital Personal Data Protection Act, 2023 bars processing a child's data without verifiable parental consent, and prohibits tracking, behavioural monitoring and targeted advertising directed at children [2]. Age assurance is therefore the gate on which the entire child-protection edifice rests — and a porous gate weakens every obligation behind it.

Why age verification is load-bearing

  • Every child-specific duty — consent, no-profiling, no targeted ads — is triggered only once a user is identified as a minor [2].
  • Rule 10 of the DPDP Rules, 2025 operationalises this through verification of the parent's identity and the parent–child relationship, including via DigiLocker-based credentials [3].
  • Platform-led safeguards depend on the same trigger: Meta's default two-hour daily limit for under-18 users, part of its settlement with 52 US attorneys general, applies only to accounts flagged as teen accounts [1].

Why it is circumvented

  • Self-declared birth dates are trivially falsified; children routinely evade age checks, a weakness flagged even in the Meta case [1].
  • Robust checks demand identity documents or biometrics — expanding data collection precisely to protect against data collection.
  • Households without smartphones or digital IDs face exclusion, and shared devices blur who the actual user is.

Implications for India's framework

  • Privacy paradox: mandatory age proof risks mass identity collection, straining the Puttaswamy tests of necessity and proportionality and DPDP's data-minimisation principle [5][2].
  • Enforcement gap: significant data fiduciary duties and the 18-month phased compliance window will ring hollow if age determination itself is unreliable [3].
  • Intermediary due diligence under the IT Rules, 2021 similarly presumes accurate user classification [4].
  • Risk of migration of minors to smaller, non-compliant platforms outside enforcement reach.

India's challenge is to make age assurance accurate without making it intrusive. Privacy-preserving techniques — tokenised, zero-knowledge age tokens, device-level signals and DigiLocker attestations that confirm "over 18" without revealing identity — combined with digital literacy for parents and graded obligations by platform risk, can align enforcement with the constitutional promise of proportionate privacy.

Sources

  1. 1Can Meta's safety controls make Facebook and Instagram less addictive for teens? — The Hindu (31 Aug 2026)~$18 bn settlement with 52 attorneys general, default two-hour teen time limit, age-check evasion
  2. 2The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYSection 9: verifiable parental consent, bar on tracking and targeted advertising to children; data minimisation
  3. 3Government notifies DPDP Rules, 2025 — PIBRule 10 verification mechanisms including DigiLocker; 18-month phased compliance
  4. 4Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — MeitYintermediary due-diligence obligations
  5. 5Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) — Supreme Court of Indiaprivacy as a fundamental right; necessity and proportionality test

More from this note