International RelationsGS221 September 2026
EU’s Proposed Kids Act Would Put Under-15s Behind Parental Gates on Social Media and AI
Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें
The news
BRUSSELS — The European Union is considering age-based rules that would restrict children’s access to social media, video-sharing platforms, AI chatbots and online games, The Hindu (John Xavier) reported, citing Reuters. The proposal, being prepared by the European Commission, is part of the EU Kids Act, aimed at making digital services safe for children. Rather than one rule for every child, it would create tiers of access. Children aged 15 and above could create their own accounts. For those aged 13 and 14, access to social media and video-sharing platforms would require parental involvement: parents could create ‘introductory accounts’ with restrictions on contacts and time spent. For children between 3 and 12, accounts would be controlled entirely by parents and limited to services considered suitable for children and meeting stronger safety standards. The proposal could ban access to digital platforms for children under 3. The rules would go beyond Facebook, Instagram, TikTok and YouTube to cover AI chatbots and online gaming platforms, on the premise that children’s internet use is no longer limited to social feeds. Platforms could be required to reduce features designed to encourage engagement and limit exposure to harmful recommendation feeds — the algorithms that decide what a user sees next — to make reporting of inappropriate content easier, and to provide parents stronger controls over content and time. Age verification, meaning checking a user’s actual age rather than accepting a self-declared one, could become mandatory when a new account is created, and gaming platforms would have to check age before children download games. Tech companies could also be expected to pay a supervisory fee to fund enforcement. Platforms argue that they already have safeguards, since major apps set a minimum sign-up age of 13; critics say age limits on paper are not enough if platforms cannot reliably determine users’ ages. The exact rules could change: the Commission must still negotiate the plan with member states and the European Parliament, and the final rules could look different from the current draft.
The chain in one line: Recommendation algorithms optimise for engagement → evidence of harm to children’s well-being mounts → self-declared age limits of 13 prove unenforceable → EU proposes tiered age rules and mandatory age verification → platforms and other regulators, including India’s, face a new global benchmark
Static syllabus linkage
- The EU regulates platforms through a layered rulebook. The General Data Protection Regulation, 2018 governs personal data and sets a default age of 16 for consent to information society services, which member states may lower to 13. The Digital Services Act, 2022 obliges platforms to assess and reduce systemic risks and bans targeted advertising based on profiling to minors. A Kids Act would add age-specific access rules to this framework. EU rules often become global norms because companies apply them worldwide, an effect known as the ‘Brussels Effect’.
- India’s DPDP Act treats everyone under 18 as a child. The Digital Personal Data Protection Act, 2023 defines a child as a person under 18. Section 9 requires verifiable parental consent before processing a child’s data and bars tracking, behavioural monitoring and targeted advertising directed at children. The DPDP Rules, 2025 prescribe how verifiable consent is to be obtained. The Act regulates data processing, not access to platforms, which is the key difference from the EU proposal.
- Intermediary liability in India rests on Section 79 of the IT Act. Section 79 of the Information Technology Act, 2000 gives intermediaries a safe harbour from liability for third-party content if they observe due diligence. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 set that due diligence, including grievance officers and additional duties for significant social media intermediaries. Child safety obligations could be added through these rules.
- Children’s rights have an international charter. The UN Convention on the Rights of the Child, 1989, which India ratified in 1992, recognises children’s rights to protection and to information and participation. The UN Committee on the Rights of the Child’s General Comment No. 25 (2021) applies these rights to the digital environment. Regulation must therefore balance protection with access.
Why UPSC loves this
- Social media regulation and children appear in GS2 and the Essay paper. UPSC has asked about the impact of social media on society and on governance, and essay topics have addressed technology and human well-being. The EU proposal offers a comparative model.
- Data protection is a recurring GS3 topic. Questions on the right to privacy and data protection followed the Puttaswamy judgment and the DPDP Act. A candidate who compares India’s consent-based model with the EU’s access-based proposal adds depth.
Prelims nuggets
- The Digital Personal Data Protection Act, 2023 defines a child as an individual who has not completed 18 years of age.
- Section 9 of the DPDP Act, 2023 requires verifiable parental consent for processing children’s data and prohibits tracking, behavioural monitoring and targeted advertising directed at children.
- The EU’s Digital Services Act, 2022 prohibits targeted advertising based on profiling to minors.
- Under the EU GDPR, the default age of digital consent is 16, which member states may lower to not below 13.
- Section 79 of the Information Technology Act, 2000 provides safe harbour to intermediaries subject to due diligence.
- India ratified the UN Convention on the Rights of the Child in 1992.
Analysis
- The shift from content rules to design rules is the real innovation. Earlier regulation asked platforms to remove harmful content. This proposal targets design: engagement features, recommendation feeds and account structures. That is more effective because harm often comes from how content is delivered, not from single posts. It also places responsibility on companies rather than on parents alone.
- Age verification is the weak link and a privacy risk. Verifying age reliably usually requires identity documents or biometric estimation, which means collecting more personal data about children. A rule meant to protect children could therefore create large new databases of sensitive data. The design challenge is privacy-preserving verification, such as age tokens that confirm an age band without revealing identity. Without it, the cure may create its own harm.
- India’s approach is stricter on paper but weaker in practice. The DPDP Act sets the child age at 18, higher than the EU’s 15 threshold, and demands parental consent. But it regulates data processing, not access, and verifiable consent at scale is untested in India. A 17-year-old is treated the same as a 7-year-old. The EU’s tiered model is more realistic; India may need age bands in its rules.
- The counter-view: bans push children to less safe spaces. Critics argue that restrictions lead children to lie about age, use parents’ accounts or migrate to unregulated platforms. Digital literacy and parental engagement may matter more than bans. There is also an access question: for many Indian children, a shared phone is their only gateway to learning. Regulation must avoid cutting off benefits along with harms.
Possible Mains question
“Protecting children online requires regulating platform design, not merely content.” Examine this statement in the light of the European Union’s proposed age-based rules, and suggest a suitable approach for India. (15 marks, 250 words)
Model approach
- Introduction. Summarise the EU proposal: tiers at 15, 13-14 and 3-12, coverage of AI chatbots and games, and mandatory age verification.
- Body — why design regulation. Engagement features and recommendation feeds; limits of self-declared age of 13; shift of burden to platforms and supervisory fee.
- Body — India’s framework. DPDP Act Section 9, age 18, verifiable consent; IT Act Section 79 and 2021 Rules; gaps in access regulation.
- Body — concerns. Privacy of age verification, circumvention, digital divide and children’s right to information under the UNCRC.
- Conclusion. Suggest age-banded rules, privacy-preserving verification and design obligations under the IT Rules, combined with digital literacy.
Administrator's brainstorm
As Secretary, MeitY, would you adopt an EU-style age ban?
I would study the EU model but adapt it to India, where devices are often shared and identity verification is sensitive. The first step would be design obligations on platforms — default privacy settings, limits on engagement features for minors — which can be enforced under existing rules. Age verification should be privacy-preserving and piloted before being mandated. Consultation with parents, schools and child-rights experts is essential.
A District Collector receives complaints about online gaming addiction among schoolchildren. What can she do?
She can coordinate with the education department to run awareness programmes for parents and students. Schools can be encouraged to set up counselling support. She can report illegal gaming or betting platforms to the relevant authorities. Local action cannot replace national regulation, but it can reduce harm.
An interview board asks whether protecting children justifies restricting free speech online.
Children’s protection is a legitimate aim, and reasonable restrictions under Article 19(2) and child-protection laws exist for it. But restrictions must be proportionate and should target specific harms rather than broadly limit access. The Puttaswamy proportionality test is the right framework. The best approach limits harmful design while keeping access to information and learning.