The Squirrels
Tuesday, 1 September 2026
‹ The Squirrels
Policy

India's proposed under-16 social media ban shifts the burden of algorithmic harm to parents, mandating mass surveillance while giving Big Tech a regulatory free pass.

By Squirrels·

The Indian government is actively considering amending the Information Technology Rules, 2021, to restrict social media access for children under 16. While officially championed as a vital "child protection" measure, a closer examination of the underlying data and regulatory frameworks reveals a profound regulatory misdirection. By focusing on age-gating, the state effectively shifts the burden of mitigating algorithmic harm from multi-billion-dollar tech giants directly onto the shoulders of parents.

More critically, this narrative masks the systemic failure to enforce the existing Digital Personal Data Protection (DPDP) Act and exposes the hidden privacy costs of a heavily surveilled digital ecosystem. The proposed ban is not a triumph of child safety; it is a structural failure disguised as decisive action.

The Algorithmic Root of Digital Harm

To understand the futility of an age-based ban, one must first understand the scale of the crisis and its actual catalyst. According to the ASER Report 2025-26, over 90% of Indian teenagers are active social media users. For these adolescents, the digital ecosystem is not merely a utility; it is the primary architecture of their social existence.

The harm generated by this ecosystem is quantifiable. Adolescents spending more than three hours a day on social media face a 2x multiplied risk of experiencing depression and anxiety. However, this psychological toll is not an accidental byproduct of internet access—it is the direct result of engagement-optimized algorithms designed to prioritize outrage, comparison, and endless scrolling.

Instead of forcing platforms to abandon these predatory architectures, the proposed under-16 ban simply attempts to build a wall around them. It is a policy that treats the symptom while granting the disease a regulatory free pass.

A parent's finger hovering over a digital consent button on a tablet

Regulatory Breadcrumbs: A Timeline of Inaction

To decode the current policy landscape, we must trace the regulatory breadcrumbs that have led to this juncture. The evolution of digital child protection in India is a masterclass in delayed enforcement and shifting goalposts:

  • 2021: The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules are enacted, establishing initial compliance frameworks for social media platforms but leaving algorithmic accountability largely untouched.

  • August 2023: The DPDP Act is passed, officially setting the age of digital majority at 18 and explicitly prohibiting the tracking or behavioral monitoring of children.

  • July 2024: The Ministry of Electronics and Information Technology (MeitY) meets with tech platforms, initially declining to mandate a specific age-verification method like Aadhaar due to feasibility concerns.

  • January 3, 2025: The Draft DPDP Rules 2025 are released, mandating "verifiable parental consent" (VPC) for users under 18 but leaving the technical implementation largely to the platforms.

  • February 2026: Following Australia's legislative lead, the Centre begins consultations to amend the IT Rules 2021 to introduce specific age-based restrictions for users under 16.

This timeline reveals a glaring inconsistency. The state possesses the legislative tools to protect minors—specifically the DPDP Act's prohibition on behavioral monitoring—yet it is pivoting toward a blunt-force ban that is technically porous and socially disruptive.

The DPDP Act Illusion: Consent as a Corporate Shield

The DPDP Act theoretically protects minors by requiring platforms to obtain verifiable parental consent before processing children's data. However, this framework suffers from a critical omission: it does not regulate the underlying algorithmic architectures that drive digital addiction.

The law simply requires a parent's permission to access these harmful systems. This transforms parents into the sole gatekeepers of the internet, absolving the state of its regulatory duties. Once a parent clicks "I Agree," tech giants are granted a legal free pass to subject the child to the same engagement-driven algorithms that cause psychological harm. The official claim of "child protection" falls flat when the law fails to mandate safety-by-design for the platforms themselves.

An identity card dissolving into digital pixels entering a server rack

The Privacy Trojan Horse: Mass Surveillance by Proxy

The ground reality of enforcing an under-16 ban is technically dystopian. Because self-declared birthdates are easily falsified, platforms cannot verify who is a child without verifying the age of every single user.

To achieve this, platforms are being pushed toward mandatory Know Your Customer (KYC) protocols. The Draft DPDP Rules suggest utilizing digital tokens or Aadhaar-based credentials via DigiLocker to verify parental identity. Given that India's Aadhaar digital ID system boasts an almost 90% penetration rate, it forms the underlying infrastructure likely to be exploited for mandatory age verification.

Consequently, age-gating acts as a Trojan horse for mass surveillance. It requires the eradication of online anonymity for all citizens, forcing adults to hand over government-issued IDs to private tech companies just to use a social network. The state is effectively mandating a privacy sacrifice from the entire population to enforce a ban on a demographic that will inevitably find workarounds.

The Technical Dystopia: Shared Devices and VPNs

Beyond the privacy implications, the ban ignores the technical realities of internet access in India. Device-level bans and biometric age-gates are fundamentally incompatible with how millions of Indian families interact with technology.

Currently, 71 million children aged 5-11 years in India access the internet via family members' devices. In households where a single smartphone is shared among multiple generations, enforcing an under-16 ban becomes an administrative nightmare. If a parent unlocks a device, the platform assumes an adult is using it, rendering the age-gate useless.

Furthermore, this massive privacy sacrifice is technically porous. Millions of Indian minors already utilize Virtual Private Networks (VPNs) to bypass existing digital restrictions and age-gates. Tech-savvy children routinely spoof their locations to access restricted content. A policy that can be defeated by a free app downloaded from the Google Play Store is not a policy; it is a performance.

Silhouette of a teenager in a dark room illuminated by a glowing VPN map on a laptop

A Fractured Ecosystem: State vs. Industry vs. Advocates

The debate over the under-16 ban has fractured stakeholders, revealing deep systemic concerns over privacy, feasibility, and human rights.

The Government's Stance: Officials maintain that age-based regulation is a necessary global standard. IT Minister Ashwini Vaishnaw recently articulated this position, stating, > "Right now, we are in conversation regarding deepfakes and age-based restrictions with various social media platforms to determine the most appropriate course of action."

The Industry Pushback: Tech lobbies warn that the compliance burden will break the digital economy. The Internet and Mobile Association of India (IAMAI) explicitly warned that requiring platforms to verify the identity of every user's parent or guardian could lead to "an onerous data maximisation approach" that violates the core principle of data minimization.

The Child Rights Perspective: Child rights advocates argue that bans are a blunt instrument that harms vulnerable youth. Experts caution that blanket restrictions may create new risks of harm by "cutting off vital support networks and undermining young people's rights to privacy and participation." For marginalized youth, social media often serves as a crucial lifeline for community and information—a lifeline the state is threatening to sever.

Conclusion: Regulate the Machine, Not the User

India's proposed under-16 social media ban operates on a flawed premise: that the user is the problem, rather than the platform. By ignoring the algorithmic root causes of digital harm and mandating privacy-destroying KYC infrastructure, the state is protecting Big Tech's business models while penalizing the public.

Shifting the burden of enforcement onto parents through "verifiable consent" is an abdication of regulatory responsibility. Until lawmakers target the algorithms—mandating chronological feeds, disabling infinite scroll, and enforcing strict safety-by-design principles—true digital child protection will remain an illusion. The state must stop trying to verify the age of the user, and start verifying the safety of the machine.