How EU plans to keep children under 15 away from social media
In this note
- At a Glance
- Why in the News
- Background & Evolution
- Core Static Facts
- Multi-Dimensional Analysis
- Recent Developments (last 12–18 months)
- Prelims Hooks
- Australia Tried a Stricter Ban First — Most Teens Stayed Online
- The Price of Proving Your Age Is Handing Over Your Identity
- UNICEF Says Such Bans Can Backfire — How Far Is That Right?
- India Has a Stricter Line on Paper and a Weaker Gate in Practice
- What India Should Copy From This, and What It Should Skip
- Anchors for Answers
- Mains Relevance
- Related Topics to Study Next
- Common Errors / Trap Areas
1. At a Glance
- The European Commission published a proposal on 17 September 2026 for the EU KIDS Act ("Keeping Internet Digital Spaces Accountable and Trustworthy"), introducing tiered, age-based restrictions on children's access to social media, video-sharing platforms, AI chatbots, and online games [1][2].
- Sets an EU-wide minimum age of 15 for minors to independently open a social media account, with graded access for younger children [1][2].
- Shifts the burden of proof to platforms — very large online platforms must demonstrate their services are safe for children, rather than regulators proving harm [2].
- Relevant for UPSC as a case study in platform regulation, child online safety, and comparative data/tech governance — useful for GS-II (governance, international bodies) and GS-III (technology, cyber issues) answers referencing global regulatory trends alongside India's IT Rules/DPDP Act.
2. Why in the News
- On 17 September 2026, the European Commission formally unveiled the EU KIDS Act proposal, reported widely including by Reuters and covered in The Hindu's 21 September 2026 edition [1][2][3].
- Comes amid global scrutiny of social media's addictive design and algorithmic harm to children's mental well-being [3].
3. Background & Evolution
- The proposal builds on the EU's existing Digital Services Act (DSA) framework governing online platform accountability (background context; not explicitly detailed in retrieved sources).
- 17 September 2026: European Commission publishes the EU KIDS Act proposal [1][2].
- Next steps: to be examined and negotiated by the European Parliament and the Council of the EU before becoming law [2].
- Complements the EU's planned open-source Age Verification Solution, expected for release by end of 2026 [1].
4. Core Static Facts
| Item | Detail |
|---|---|
| Full name | EU KIDS Act — "Keeping Internet Digital Spaces Accountable and Trustworthy" [2] |
| Proposing body | European Commission [1][2] |
| Date of proposal | 17 September 2026 [2] |
| Age tiers | Under 13: no independent social media access, only child-friendly video services via parent-managed account; 13–14: "mini account" managed by parent/guardian, limited features, capped at 1 hour/day; 15+: independent account creation allowed [1][2] |
| Scope of services | Social media, video-sharing platforms, online games, AI companions/chatbots [2][3] |
| Verification requirement | Certified age verification (self-declaration not sufficient); existing accounts to be checked; underage accounts must be reportable [1] |
| Key safety mandates | Ban on addictive design features, endless scrolling, push notifications during children's sleep hours; safety-by-design principles [1][2] |
| Legislative status | Proposal stage — requires European Parliament and Council negotiation before enactment [2] |
5. Multi-Dimensional Analysis
Social
- Targets addictive app design and harmful algorithmic recommendation systems affecting child mental health [3].
- Introduces parental oversight mechanisms (mini/introductory accounts) for the 13–14 age bracket [1][3].
Legal / Regulatory
- Reverses the burden of proof — platforms, not regulators, must prove child safety compliance [2].
- Builds on EU's broader digital regulatory architecture (DSA-adjacent), reflecting a shift toward ex-ante platform obligations.
Technological
- Relies on a certified age-verification infrastructure, including a Commission-built open-source Age Verification Solution [1].
- Extends regulation to emerging technology — AI chatbots/companions — not just legacy social media [2].
Administrative / Implementation
- Enforcement burden falls on "very large online platforms" (echoing DSA's VLOP category) [2].
- Requires audit of existing accounts for age compliance, a significant retrofitting challenge for platforms [1].
Comparative/Governance
- Represents a graduated, tiered-access model rather than a blanket ban — distinct from single-age-cutoff approaches seen in other jurisdictions (e.g., Australia's under-16 ban), relevant for comparative governance analysis.
6. Recent Developments (last 12–18 months)
- 17 September 2026: European Commission formally releases EU KIDS Act proposal text [1][2].
- Proposal leaked and previewed in media around 15 September 2026, ahead of formal publication [1].
- 21 September 2026: Reported in Indian press (The Hindu), placing the story in the global child-online-safety discourse [3].
7. Prelims Hooks
- EU KIDS Act = "Keeping Internet Digital Spaces Accountable and Trustworthy" Act.
- Proposed by the European Commission on 17 September 2026.
- Minimum independent social media account age set at 15 years.
- Children under 13: barred from independent social media access.
- Children 13–14 years: allowed "mini accounts" managed by a parent/guardian.
- Time cap for 13–14 age group: 1 hour per day.
- Proposal covers social media, video-sharing platforms, online games, and AI chatbots/companions.
- Self-declared age is not sufficient — certified age verification mandated.
- EU is developing an open-source Age Verification Solution, expected by end of 2026.
- Proposal bans endless scrolling, addictive features, and night-time push notifications to children.
- Burden of proof for child safety shifted from regulators to platforms.
- Enforcement primarily targets "very large online platforms" (VLOPs) — a category from the Digital Services Act framework.
- Next legislative step: negotiation by the European Parliament and Council of the EU.
8. Australia Tried a Stricter Ban First — Most Teens Stayed Online
- The EU is not the first mover, and the first mover's numbers are not good
- Australia passed a flat ban on social media for under-16s in November 2024 [9].
- Three months after it started, most under-16s who already had accounts either kept them or opened new ones [5].
- About half of those who kept their accounts said the platform simply never checked their age [5].
-
Others said their account showed a false birth year, or the age-guessing software wrongly judged them to be older [5].
-
This is exactly the step the KIDS Act also depends on
- The EU proposal says platforms must check accounts that already exist, not just new ones [1].
-
Australia shows that re-checking old accounts is where the law leaks, because the platform has no fresh proof of age for a user who signed up years ago.
-
Big removal numbers do not prove the gate works
- Meta says it shut down 750,000 under-16 accounts in Australia [8].
- That number counts children the platform found. It says nothing about the children still on the platform, which is what the independent survey measured [5].
- For a Mains answer: judge such a law by survey evidence on children, not by company compliance reports.
9. The Price of Proving Your Age Is Handing Over Your Identity
- "Certified" age checking means someone must hold proof of who you are
- The EU says a user simply typing a birth date is not enough; the check must be certified [1].
- The OECD warns that badly designed age-assurance systems collect more personal data than they need, and that this makes any future data breach far more damaging [7].
-
The same systems shut out people who have no formal identity documents [7] — in India that would hit poor and migrant families hardest.
-
The tool is not ready when the rule is
- The Commission's open-source Age Verification Solution is expected only by end-2026 [1], while the proposal text is already out [2].
- Australia made the same sequencing mistake: platforms asked the Senate to delay the vote until the government-commissioned age-assurance evaluation reported, and the law was passed anyway [9].
- If the law lands before a tested tool exists, platforms fall back on asking every user to upload an ID — the outcome the OECD warns against [7].
10. UNICEF Says Such Bans Can Backfire — How Far Is That Right?
- The strongest argument against this approach
- UNICEF says age restrictions alone will not keep children safe, and may even backfire [4].
- Children get around the gate using shared devices, or move to smaller and less regulated apps, where they are harder to protect [4].
- For isolated or marginalised children, these platforms are how they learn, play and express themselves — a gate takes that away too [4].
-
UNICEF adds that an age law is not a substitute for companies improving platform design and content moderation [4].
-
Where the KIDS Act answers this
- Unlike a plain ban, it also bans addictive design, endless scrolling and night-time push notifications to children [1][2].
-
It shifts the burden of proof onto platforms to show their service is safe [2]. That is the design-side duty UNICEF asks for, not just a gate.
-
Where UNICEF is still right
- Enforcement is aimed at "very large online platforms" [2].
- So the children who move to small apps and unlisted chat services move into the part of the internet the law watches least — the migration risk UNICEF names [4].
11. India Has a Stricter Line on Paper and a Weaker Gate in Practice
- On age, India is stricter than the EU
- The DPDP framework treats anyone under 18 as a child and requires verifiable parental consent before their data is processed [6].
-
The EU proposal sets independent access at 15, with supervised "mini accounts" at 13–14 [1][2]. India's line is three years higher.
-
But India has not solved the first question: how does a platform know the user is a child?
- The draft DPDP Rules give little guidance on how a platform is to work out that a user is a minor in the first place [6].
- MeitY looked at DigiLocker and Aadhaar as ways to verify age and did not find the method effective [6].
- Most platforms therefore still rely on a self-declared date of birth [6] — which a child can simply type wrong.
-
Result: a strict consent rule sits on top of a group the platform cannot identify.
-
India regulates the consent, the EU regulates the design
- India's rule is about permission to process data [6]. It sets no cap on screen hours, and does not ban endless scrolling or night-time notifications.
- The EU proposal does all three, plus a one-hour daily cap for 13–14 year olds [1][2].
- So even a child with valid parental consent in India faces the same addictive design the EU is trying to outlaw.
12. What India Should Copy From This, and What It Should Skip
- MeitY should fix the age-detection step before enforcing the consent step
- The draft DPDP Rules already allow a "virtual token" issued by an entity entrusted by law to confirm age [6].
- Using one token, checked by many apps, avoids every child and parent uploading identity documents to every separate app — the repeated-upload risk the OECD flags [7].
-
Without this, the parental-consent rule cannot be enforced, because the platform never learns who the children are [6].
-
Regulate the design, not only the age gate
- Copy the EU's specific bans: addictive features, endless scrolling, notifications during children's sleep hours [1][2].
- UNICEF's point supports this — an age law is not an alternative to companies changing design and moderation [4].
-
These duties work even on children who slip past the age check, which a gate alone cannot do.
-
Measure success by surveying children, not by counting deleted accounts
- Australia's independent three-month study is what revealed the ban was leaking [5], while platform figures showed 750,000 removals [8].
-
MeitY should commission a similar periodic survey of children before claiming DPDP child provisions are working.
-
Do not copy Australia's sequencing
- Australia passed the law before its age-assurance evaluation reported [9].
- India should hold the child-account rules until the token-based age check is tested at scale, otherwise platforms default to ID uploads [7].
13. Anchors for Answers
- Data: Three months after Australia's under-16 ban began, most under-16s with existing accounts kept them or made new ones; about half said the platform never checked their age [5]
- Data: Meta reported shutting 750,000 under-16 accounts in Australia — a company compliance figure, not a measure of children remaining [8]
- Data: EU tiers — under-13 no independent account, 13–14 parent-managed "mini account" capped at 1 hour/day, 15+ independent [1][2]
- Report/Committee: OECD, The Legal and Policy Landscape of Age Assurance Online for Child Safety and Well-being, 2025 — warns age checks can over-collect data and exclude those without identity documents [7]
- Report/Committee: UNICEF statement, December 2025 — age-related bans alone will not keep children safe and may backfire [4]
- Law/Case: DPDP Act, 2023 and draft DPDP Rules — child is anyone under 18, verifiable parental consent needed before processing their data [6]; Justice K.S. Puttaswamy v. Union of India (2017) for the privacy standard any age-verification system must meet
- Comparison: Australia's flat under-16 ban [9] versus the EU's graded 13 / 15 model [1] — same aim, very different design; only the Australian model has real-world results so far [5]
- Scheme: DigiLocker — examined by MeitY as an age-verification route for DPDP and not found effective, making it the key gap to close before child provisions can bite [6]
14. Mains Relevance
- GS-II: Governance — transparency, accountability, and regulatory mechanisms; International groupings/agreements affecting India's interests (comparative digital governance).
- GS-III: Science & Technology — awareness in IT/cyber security; issues relating to data protection and platform regulation.
- Possible question stems: 1. Examine the EU KIDS Act's approach to age-tiered social media regulation. What lessons does it offer for India's Digital Personal Data Protection (DPDP) Act, 2023, in protecting children online? 2. Discuss the ethical and regulatory challenges in mandating age verification on digital platforms. How does the EU's proposed KIDS Act attempt to shift accountability onto tech companies? 3. Social media addiction among minors is a growing global governance challenge. Critically analyse regulatory responses across jurisdictions, with reference to the EU KIDS Act.
15. Related Topics to Study Next
- India's DPDP Act, 2023 — parental consent provisions for processing children's data; direct comparative angle.
- Digital Services Act (DSA), EU — the broader regulatory scaffolding underlying VLOP obligations.
- Australia's social media ban for under-16s — comparative model of blanket vs tiered restriction.
- IT Rules, 2021 (India) — intermediary due diligence and content regulation comparison.
- Algorithmic accountability & recommendation systems regulation — technical/ethical dimension shared across jurisdictions.
- UNCRC (UN Convention on the Rights of the Child) — international legal basis for child online protection norms.
- Right to Privacy (Justice K.S. Puttaswamy judgment, India) — constitutional angle on data/privacy rights extendable to minors.
- AI regulation — EU AI Act — since AI chatbots/companions now fall under child-safety scope.
16. Common Errors / Trap Areas
- Do not confuse the EU KIDS Act with the EU AI Act or Digital Services Act (DSA) — they are distinct but related instruments; KIDS Act specifically targets child online safety.
- The age threshold is not a blanket ban at 15 — under-13s face the strictest bar, while 13–14 get supervised "mini accounts," a graduated system often mistakenly flattened to "under-15 banned."
- Proposal ≠ Law: as of the note's writing, this is a Commission proposal, still requiring European Parliament and Council approval — do not state it as already enacted.
- Body issuing the proposal is the European Commission, not the European Parliament or Council (common ministry/body confusion in EU institutional questions).
- Scope extends beyond social media to video-sharing, gaming, and AI chatbots — don't restrict the answer to "social media" alone.
Sources
- 1EU to propose tiered social media age restrictions for under-15sbiometricupdate.com · tier 4
- 2EU KIDS Act: helping children navigate a safer online world — European Commissioncommission.europa.eu · tier 2
- 3How EU plans to keep children under 15 away from social media — The Hinduthehindu.com · tier 4
- 4Social media: Age-related bans won't keep kids safe, UNICEF warns — UN Newsnews.un.org · tier 2
- 5Most Australian teens still on social media 3 months after ban began: Study — Business Standardbusiness-standard.com · tier 4
- 6Draft DPDP rules mention parental consent for processing children's data — Business Standardbusiness-standard.com · tier 4
- 7The Legal and Policy Landscape of Age Assurance Online for Child Safety and Well-being — OECD, 2025oecd.org · tier 2
- 8Meta says it has shut down 750,000 under-16 accounts in Australia — Business Standardbusiness-standard.com · tier 4
- 9Australia passes law to impose ban on social media for children under 16 — Business Standardbusiness-standard.com · tier 4