Examine the effectiveness of platform-driven self-regulation versus statutory regulation in protecting children from social media harms, with reference to recent global settlements.
Meta's roughly $18 billion settlement of August 2026 with 52 US attorneys general — over allegations that Facebook and Instagram harm children and illegally collect their data — has revived a core governance question: can platforms police themselves, or must the State legislate? [1] The evidence suggests self-regulation supplies speed, but only statutory backing supplies accountability.
Where platform self-regulation works
- Design-level reach: alongside the settlement, Meta made a two-hour daily time limit the default for under-18 users across both apps — a change no regulator can code directly [1].
- Speed and scale: defaults are deployed instantly worldwide-capable, whereas rule-making and litigation take years.
- Technical capacity: platforms alone hold the behavioural data needed to detect addictive-use patterns.
Where it falls short
- Reversibility: the time limit can be switched off, and applies only in "participating" US states and territories — protection is thus geographically uneven and not a guaranteed floor [1].
- Weak age assurance: children routinely evade age-verification checks, undermining the entire teen-safety architecture [1].
- Incentive mismatch: a settlement paid in annual instalments over ten years is absorbed as a cost of business rather than a redesign of engagement-maximising algorithms [1].
The statutory counterweight
- India's Digital Personal Data Protection Act, 2023 bars tracking, behavioural monitoring and targeted advertising directed at children, mandates verifiable parental consent, and prescribes penalties up to ₹200 crore — obligations that are not optional [2]; the DPDP Rules operationalise them [3].
- The IT Rules, 2021 impose due-diligence duties on significant social media intermediaries, tying safe harbour to compliance [4].
- Justice K.S. Puttaswamy (2017) anchors informational privacy in Article 21, giving children's data protection a constitutional basis [5].
Self-regulation is therefore a useful supplement, never a substitute. The way forward is co-regulation: statutory floors on children's data and design, privacy-preserving age assurance, independent audits of platform claims, and digital literacy for parents and schools — aligning platform incentives with the child's best interest under Article 21 and SDG 16.2.
Sources
- 1Can Meta's safety controls make Facebook and Instagram less addictive for teens? — The Hindu (31 Aug 2026)$18 bn settlement, 52 attorneys general, two-hour teen default, participating states, age-check evasion, ten-year instalments
- 2The Digital Personal Data Protection Act, 2023 — MeitYbar on tracking/behavioural monitoring/targeted advertising of children, parental consent, ₹200 crore penalty
- 3Government notifies DPDP Rules — PIBoperationalisation of the DPDP framework
- 4IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — MeitYdue diligence and safe-harbour conditionality for significant social media intermediaries
- 5Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) — Supreme Court of Indiainformational privacy as part of Article 21