Age-verification technology is central to enforcing child-safety rules on social media, yet remains easily circumvented. Discuss the implications for India's data protection framework.
In this answer
Section 9 of the Digital Personal Data Protection Act, 2023 bars processing a child's data without verifiable parental consent, and prohibits tracking, behavioural monitoring and targeted advertising directed at children [2]. Age assurance is therefore the gate on which the entire child-protection edifice rests — and a porous gate weakens every obligation behind it.
Why age verification is load-bearing
- Every child-specific duty — consent, no-profiling, no targeted ads — is triggered only once a user is identified as a minor [2].
- Rule 10 of the DPDP Rules, 2025 operationalises this through verification of the parent's identity and the parent–child relationship, including via DigiLocker-based credentials [3].
- Platform-led safeguards depend on the same trigger: Meta's default two-hour daily limit for under-18 users, part of its settlement with 52 US attorneys general, applies only to accounts flagged as teen accounts [1].
Why it is circumvented
- Self-declared birth dates are trivially falsified; children routinely evade age checks, a weakness flagged even in the Meta case [1].
- Robust checks demand identity documents or biometrics — expanding data collection precisely to protect against data collection.
- Households without smartphones or digital IDs face exclusion, and shared devices blur who the actual user is.
Implications for India's framework
- Privacy paradox: mandatory age proof risks mass identity collection, straining the Puttaswamy tests of necessity and proportionality and DPDP's data-minimisation principle [5][2].
- Enforcement gap: significant data fiduciary duties and the 18-month phased compliance window will ring hollow if age determination itself is unreliable [3].
- Intermediary due diligence under the IT Rules, 2021 similarly presumes accurate user classification [4].
- Risk of migration of minors to smaller, non-compliant platforms outside enforcement reach.
India's challenge is to make age assurance accurate without making it intrusive. Privacy-preserving techniques — tokenised, zero-knowledge age tokens, device-level signals and DigiLocker attestations that confirm "over 18" without revealing identity — combined with digital literacy for parents and graded obligations by platform risk, can align enforcement with the constitutional promise of proportionate privacy.
Sources
- 1Can Meta's safety controls make Facebook and Instagram less addictive for teens? — The Hindu (31 Aug 2026)~$18 bn settlement with 52 attorneys general, default two-hour teen time limit, age-check evasion
- 2The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYSection 9: verifiable parental consent, bar on tracking and targeted advertising to children; data minimisation
- 3Government notifies DPDP Rules, 2025 — PIBRule 10 verification mechanisms including DigiLocker; 18-month phased compliance
- 4Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — MeitYintermediary due-diligence obligations
- 5Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) — Supreme Court of Indiaprivacy as a fundamental right; necessity and proportionality test