Polity & GovernanceGS229 September 2026
Supreme Court Asks Centre to Use IT Rules to Bar Under-18s From Opening Social Media Accounts
Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें
The news
New Delhi. The Supreme Court on Monday, September 28, asked the Union government to put in place statutory rules so that social media platforms and other digital intermediaries comply with Indian law on minors and make 18 years the minimum age for membership. A three-judge Bench presided over by Chief Justice of India Surya Kant, with Justices Joymalya Bagchi and V. Mohana, was hearing a public interest litigation (PIL) by the NGO Just Rights for Children Alliance (JRCA), filed through advocate Saksham Maheshwari and argued by senior advocate H.S. Phoolka. Notices went out on September 10 to the Electronics and IT, Law and Labour Ministries. The core of the argument is legal capacity. Under Section 3 of the Majority Act, 1875, a person attains majority only on completing 18 years, and under Section 11 of the Indian Contract Act, 1872, a person below majority is not competent to contract. An account is a contract, and a minor’s contract is, as the Bench put it, void ab initio — void from the very beginning, as if it never existed. “What are these social media platforms doing? Are they permitting children as young as 12 years to 15 years to have accounts? And what is an ‘account’? It is a contract between the social media platform and a child,” Justice Bagchi said, The Hindu reports. The petition says platforms let children aged 13 and above open accounts merely by declaring their age, a “fundamental legal and regulatory inconsistency”. Justice Bagchi noted that these intermediaries — companies that host content posted by others — are registered under US law and have “imported into Indian digital space the restrictions which are applicable in the US”. The Indian Express reports that CJI Kant said the government can invoke sections 4 and 9 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, to issue directions, and Justice Bagchi urged the government to direct platforms to “fashion their software or platform in conformity with Indian law” with “a minimum threshold of 18 years”. Solicitor-General Tushar Mehta agreed that minors cannot contract under Indian law, said “we will have to control the intermediaries”, and added, “Government is ready to do that.” He also submitted that the issue is prima facie covered by the Digital Personal Data Protection Act, 2023; Mr. Phoolka replied that its provisions come into force only in 2027. The PIL seeks age-assurance mechanisms (real checks of age, not self-declaration), an end to independent accounts for minors, and educational access through parent-run accounts. The 21 September card covered the EU’s under-15 proposal; what is new is that India’s top court has framed the question through contract law. The syllabus link is GS2 on government policies, statutory bodies and the protection of vulnerable sections, and GS3 on cyber security.
The chain in one line: Platforms built under US norms set 13 as the minimum age and rely on self-declared birth dates → crores of Indian children open accounts that Indian contract law does not recognise → the DPDP Act, 2023 requires parental consent for under-18s but its operative provisions are not yet in force → an NGO’s PIL asks the Supreme Court to close the gap → the Bench asks the Centre to use the IT Rules, 2021 to impose an 18-year threshold, and the Solicitor-General agrees
Static syllabus linkage
- A minor cannot make a contract in India, and such an agreement is void from the start. Section 10 of the Indian Contract Act, 1872 says an agreement is a contract only if made by the free consent of parties competent to contract, for a lawful consideration and a lawful object. Section 11 defines a competent person as one who has attained the age of majority, is of sound mind and is not disqualified by law. In Mohori Bibee v. Dharmodas Ghose (1903), the Privy Council held that a mortgage executed by a minor was void ab initio, not merely voidable, and that the minor could not be made to repay the money advanced. Section 68 of the Act is a narrow exception: a supplier of “necessaries” to a minor can recover the price from the minor’s property, but not from the minor personally. The Majority Act, 1875 fixes the age of majority at 18.
- The DPDP Act, 2023 treats everyone below 18 as a child and demands parental consent. The Digital Personal Data Protection Act, 2023 defines a “child” as an individual who has not completed 18 years. Section 9 requires a data fiduciary — the company deciding why and how personal data is processed — to obtain the verifiable consent of a parent or lawful guardian before processing a child’s personal data. It also bars processing likely to harm a child’s well-being and prohibits tracking, behavioural monitoring and targeted advertising directed at children. The Act lets the government exempt certain classes of fiduciaries or purposes from these conditions. The DPDP Rules, 2025 phase in the substantive obligations, which is why the petitioner told the court the provisions come into force only in 2027.
- Safe harbour protects platforms only if they follow the government’s due-diligence rules. Section 79 of the Information Technology Act, 2000 exempts an intermediary from liability for third-party content it hosts, provided it observes due diligence and acts on lawful orders. In Shreya Singhal v. Union of India (2015), the Supreme Court read down Section 79 so that “actual knowledge” means a court order or a government notification, not a private complaint. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 spell out these due-diligence duties, with extra obligations for “significant social media intermediaries” above a user threshold notified by the government. A platform that ignores the Rules risks losing its safe harbour, which is the lever the Bench asked the Centre to pull.
- Children’s rights in the digital space rest on Article 21 and international commitments. In Justice K.S. Puttaswamy v. Union of India (2017), a nine-judge Bench held privacy to be a fundamental right under Article 21. India is a party to the UN Convention on the Rights of the Child, which defines a child as a person below 18 and makes the best interests of the child a primary consideration in all actions concerning children. The Juvenile Justice (Care and Protection of Children) Act, 2015 and the Protection of Children from Sexual Offences Act, 2012 also use 18 as the age line. Article 39(f) of the Directive Principles asks the State to ensure that children are protected against exploitation and moral and material abandonment.
Why UPSC loves this
- GS2 asks about the protection of vulnerable sections and the regulation of big technology. Mains questions have asked about data protection, the accountability of social media platforms and the balance between free speech and regulation. This case adds a clean legal hook — contractual capacity — that a candidate can use to argue that platform regulation need not wait for a new law. It also fits GS2’s “mechanisms, laws, institutions and bodies constituted for the protection and betterment of these vulnerable sections”.
- Prelims tests the vocabulary of digital law. UPSC has asked about the IT Act, 2000, the DPDP Act, 2023 and the meaning of terms such as intermediary and data fiduciary. The definition of a child under the DPDP Act, the safe-harbour provision in Section 79 and the Contract Act’s rule on minors are the kind of settled provisions Prelims prefers.
- A global wave of age limits is now reaching India. Australia legislated a minimum age of 16 for social media accounts, and the EU is weighing parental gates for under-15s, as this magazine reported on 21 September. An answer on children’s online safety should compare these models — outright bans, parental consent and design-based duties — rather than treat India’s debate in isolation.
Prelims nuggets
- Under Section 11 of the Indian Contract Act, 1872, a person who has not attained the age of majority is not competent to contract.
- In Mohori Bibee v. Dharmodas Ghose (1903), the Privy Council held that an agreement with a minor is void ab initio.
- Under the Majority Act, 1875, a person attains majority on completing 18 years of age.
- The Digital Personal Data Protection Act, 2023 defines a child as an individual who has not completed 18 years and requires verifiable parental consent before processing a child’s personal data.
- The DPDP Act, 2023 prohibits tracking, behavioural monitoring and targeted advertising directed at children.
- Section 79 of the Information Technology Act, 2000 grants intermediaries safe harbour from liability for third-party content, subject to due diligence.
- In Shreya Singhal v. Union of India (2015), the Supreme Court struck down Section 66A of the IT Act and read down Section 79 to require a court order or government notification for “actual knowledge”.
Analysis
- The Bench has found a way to regulate platforms without waiting for a new law. The usual debate on children and social media asks whether Parliament should ban accounts below some age. The Bench sidestepped that by pointing out that Indian law already does not recognise a child’s account as a valid contract. If the contract is void, the platform’s terms of service cannot bind the child, and the platform’s claim that the child “agreed” to data collection collapses. Combined with the IT Rules, which are delegated legislation the executive can amend quickly, this gives the government a route that does not require a fresh Bill. The counter-view is that courts should not push the executive into rule-making on a policy question, since the choice of an age line involves trade-offs that belong to the legislature.
- Void contract logic cuts both ways and could hurt children more than platforms. If a minor’s account is void, the child also loses the contractual protections — grievance redress, data deletion obligations under the platform’s own policy — that flow from the terms of service. Void-contract doctrine was built to protect minors from being bound by bad bargains, not to shut them out of public spaces. A child who uses a messaging app for school groups, or a teenage creator who earns from content, would find that the law treats their activity as legally non-existent. The better reading is that the contract point justifies stricter rules on platforms, not the exclusion of children, and the petition itself asks for parent-controlled access to educational content.
- Age assurance is the hard engineering problem the order does not solve. Platforms today rely on self-declared birth dates, which any child can falsify. Real age assurance means either document checks, which require collecting identity data from everyone, or estimation from face or behaviour, which raises privacy and error concerns. Requiring every Indian adult to prove age to open an account would expand data collection sharply, which sits awkwardly with the DPDP Act’s principle of data minimisation. The design of any rule will therefore decide whether child safety is bought at the cost of adult privacy. A graded approach — stricter checks only for features that carry higher risk, such as messaging strangers or monetisation — may be more workable than a single gate.
- The DPDP timetable exposes a gap between law on paper and law in force. The Solicitor-General’s answer that the DPDP Act already covers the issue and the petitioner’s reply that it takes effect only in 2027 show the cost of long phase-in periods. The Act was passed in 2023, yet its parental-consent rule for children is not yet enforceable. Meanwhile platforms have no statutory duty beyond self-declaration. The court’s suggestion to use the IT Rules is effectively a bridge until the DPDP regime starts. It also means two parallel regimes — MeitY directions under the IT Rules and the Data Protection Board under the DPDP Act — may later need to be reconciled.
- Setting the line at 18 is stricter than most of the world. The US-derived norm of 13 comes from American children’s privacy law, Australia chose 16 and the EU proposal discussed on 21 September looks at 15. An 18-year threshold would make India one of the strictest jurisdictions. Supporters argue that Indian law already uses 18 for majority, consent and child protection, so consistency demands it. Critics note that 16- and 17-year-olds use platforms for education, jobs and civic life, and a rigid ban may push them to borrowed accounts or unregulated apps. The choice is not only legal but social, and a public consultation before any rule would strengthen its legitimacy.
Possible Mains question
“The protection of children online cannot be left to self-declared age and platform terms of service.” In the light of the Supreme Court’s recent observations on minors’ social media accounts, examine the legal framework in India for regulating children’s access to digital platforms. Suggest a balanced approach. (15 marks, 250 words)
Model approach
- Introduction. Open with the September 28 hearing: a Bench led by CJI Surya Kant asked the Centre to use the IT Rules, 2021 to make 18 the minimum age for social media membership, reasoning that a minor’s account is a contract void ab initio.
- Body — the existing framework. Explain Sections 10 and 11 of the Contract Act and Mohori Bibee; the Majority Act, 1875; Section 9 of the DPDP Act, 2023 on verifiable parental consent and the bar on tracking and targeted ads; Section 79 safe harbour and the IT Rules, 2021. Note that the DPDP provisions take effect only in 2027.
- Body — gaps and dilemmas. Discuss self-declared age, platforms importing the US threshold of 13, the privacy cost of age verification for all users, the risk of excluding teenagers from educational and economic uses, and overlapping regulators.
- Body — a balanced approach. Propose risk-based age assurance, parent-controlled accounts for younger users, default privacy settings for minors, a ban on targeted advertising to children, digital literacy in schools, and clear enforcement by MeitY and the Data Protection Board. Cite Australia and the EU as comparisons.
- Conclusion. Conclude that India should anchor child online safety in the rights of the child under Article 21 and the best-interests principle, using design duties on platforms rather than relying only on bans.
Administrator's brainstorm
You are a Joint Secretary in MeitY asked to draft directions under the IT Rules after this hearing. What would you put in them?
I would require platforms to stop relying on self-declared age alone and to deploy age-assurance methods proportionate to risk, while prohibiting them from retaining identity documents beyond verification. Accounts for users under 18 would need linked parental consent, private-by-default settings and no targeted advertising, in line with Section 9 of the DPDP Act. I would publish a draft for public consultation and give a clear compliance timeline. Non-compliance would be linked to loss of safe harbour under Section 79.
As a District Magistrate, how would you address children’s online safety in your district before any national rule is in place?
I would work with the District Education Officer to run digital safety sessions for students and parents in government and private schools. The District Child Protection Unit and the cyber cell of the police would get a simple reporting channel for online exploitation cases. Schools would be asked to review whether they push children onto social media for homework groups. The aim is awareness and quick response, since regulation of platforms is beyond a district’s power.
An interview board asks: is banning teenagers from social media a violation of their freedom of expression?
Article 19(1)(a) protects expression, but reasonable restrictions are allowed and the State has a recognised duty to protect children. A complete ban for 16- and 17-year-olds may be disproportionate, because it cuts off lawful learning and expression along with the harm. A proportionate approach would restrict risky features and data practices rather than presence itself. So I would argue for regulation of platform design rather than a blanket prohibition.