·The Hindu·15 marks·250–350 wordsPolityS&TIR

Examine the EU KIDS Act's approach to age-tiered social media regulation. What lessons does it offer for India's Digital Personal Data Protection (DPDP) Act, 2023, in protecting children online?

In this answer
  1. How the age-tiered approach works
  2. Where it remains vulnerable
  3. Lessons for the DPDP framework

On 17 September 2026 the European Commission proposed the EU KIDS Act ("Keeping Internet Digital Spaces Accountable and Trustworthy"), replacing a blanket ban with graded, age-tiered access to social media, gaming and AI chatbots [1]. Its real significance lies less in the age number than in where it places the burden of proof.

How the age-tiered approach works

  • Graded access, not prohibition: under-13s get no independent account; 13–15 year-olds use parent-managed "mini accounts" with limited features and a one-hour daily cap; independent accounts begin at 15 [1].
  • Design regulated alongside age: infinite scroll, reward tricks and push notifications during sleeping hours are barred, and AI chatbots must default to off and not cultivate emotional dependence [1].
  • Accountability shift: very large online platforms must themselves demonstrate their service is safe for children, instead of regulators proving harm [1].

Where it remains vulnerable

  • Verification is the weak link: the OECD finds age limits are often stated without specifying how they are to be respected, and that poorly designed age assurance over-collects data and excludes those without identity documents [3].
  • UNICEF cautions that age gates alone may backfire, pushing children onto smaller, less-regulated platforms [4]; enforcement here targets only the largest platforms [1].
  • It is still a proposal, requiring negotiation by the European Parliament and Council [1].

Lessons for the DPDP framework

  • India is stricter on paper — a child is anyone under 18, with verifiable parental consent mandatory [2], operationalised through the DPDP Rules notified in 2025 [5] — yet the statute does not settle how a platform identifies a minor, a gap PRS links to reduced digital anonymity [2].
  • Regulate design, not only consent: the undefined "detrimental effect on well-being of a child" [2] could be given content through rules on addictive features, mirroring the EU model.
  • Adopt data-minimising, token-based age assurance satisfying Puttaswamy proportionality, and consider graded autonomy for older adolescents.

A consent-centred law and a design-centred law are complements, not alternatives. India's next step should be to pair its robust parental-consent standard with enforceable safety-by-design duties and a verifiable, privacy-preserving age check — advancing both Article 21 privacy and the UNCRC's promise of a child-appropriate digital environment.

Sources

  1. 1EU KIDS Act: helping children navigate a safer online world — European Commission (17 September 2026)age tiers, one-hour cap, bans on infinite scroll and sleep-hour notifications, AI chatbot defaults, burden of proof on platforms, legislative status
  2. 2PRS Legislative Research — The Digital Personal Data Protection Bill, 2023child defined as under 18, verifiable parental consent, age-verification/anonymity concern, undefined "detrimental effect on well-being"
  3. 3The Legal and Policy Landscape of Age Assurance Online for Child Safety and Well-being — OECD, 2025age limits lacking specificity on enforcement; data over-collection and exclusion risks of age assurance
  4. 4Social media: Age-related bans won't keep kids safe, UNICEF warns — UN Newsbans may backfire and push children to less-regulated platforms
  5. 5DPDP Rules, 2025 Notified — Press Information Bureauoperationalisation of the DPDP Act, 2023
Practice
12 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

More from this note

More on Polity