Children on Social Media: Should India Introduce a Statutory Digital Age of Consent?

Author: Chandramani Bhaskar, ILS Law College, Pune

TO THE POINT

India’s data protection law treats anyone under eighteen as a child and requires a platform to obtain parental consent before it processes that child’s data. It does not fix an age at which a child may open a social media account in the first place. That decision is still made by the platform itself, through a terms-of-service box that asks a user to type in a birth year nobody checks. The short answer this article works toward is yes: India needs a dedicated statutory digital age of consent for social media access, distinct from the data-processing consent already required under the Digital Personal Data Protection Act, 2023, and calibrated to the specific risks social platforms present rather than borrowed wholesale from a law written for a broader purpose.

USE OF LEGAL JARGON

A short glossary is useful before the analysis, since the statutory scheme relies on defined terms that do not always mean what they sound like.

Data Fiduciary refers to any person or platform that determines the purpose and means of processing personal data, roughly equivalent to a “data controller” under the GDPR.

Data Principal is the individual to whom the data relates; where that individual is a child, the DPDP Act treats the parent or lawful guardian as exercising rights on the child’s behalf.

Verifiable Consent is consent that a data fiduciary must be able to demonstrate was actually given by the parent or guardian, not merely asserted by the child at sign-up.

Age of Consent, in the data-protection sense used here, means the age below which an individual cannot independently agree to a platform’s processing of their data or, on the narrower question this article addresses, cannot independently hold an account.

Age Assurance or Age Verification describes the technical methods, ranging from self-declaration to document checks to facial age-estimation, that a platform uses to confirm a user’s age band.

Significant Data Fiduciary is a category of data fiduciary designated by the government because of the volume or sensitivity of data it handles, subject to heightened obligations such as audits and impact assessments.

Intermediary, under the Information Technology Act, 2000, is a platform that hosts or transmits third-party content, a status that carries conditional legal immunity known as safe harbour under Section 79.

Data Protection Board of India is the adjudicatory body created under the DPDP Act to investigate breaches, hear complaints, and impose penalties.

THE PROOF

Indian law does not lack provisions that touch children’s digital lives; it lacks a single provision addressed to the specific question of when a child may hold a social media account. At least three statutory regimes bear on the issue, and each was built for a different purpose.

The constitutional starting point is the right to privacy recognised by a nine-judge bench in Justice K.S. Puttaswamy (Retd.) v. Union of India, which held that informational privacy falls within the protection of Article 21. The judgment did not address children specifically, but its reasoning, that consent must be free and informed for privacy to mean anything at all, sits uneasily with a regime in which a child can open an account by self-declaring an age that nobody checks.

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 impose due diligence duties on social media intermediaries, including grievance redressal timelines and restrictions on certain categories of content, but they fix no minimum age for account holders. The age limits that do exist on Indian social media are a matter of platform terms of service, typically thirteen years, a figure borrowed from American practice under the Children’s Online Privacy Protection Act rather than drawn from any Indian statute.

The Digital Personal Data Protection Act, 2023 comes closest to legislating an age threshold. Section 9 defines a “child” as any individual who has not completed eighteen years of age and requires data fiduciaries to obtain verifiable consent from a parent or lawful guardian before processing a child’s personal data. The same section bars tracking, behavioural monitoring, and targeted advertising directed at children, and Section 9(3) makes this prohibition absolute: it applies even where a parent has consented. The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 and brought into force in three phases running to 14 May 2027, operationalise this scheme through Rules 10 to 12, which prescribe how verifiable parental consent is to be obtained and carve out narrow exemptions for fiduciaries able to show that they process children’s data in a demonstrably safe manner.

Two features of this scheme matter for the present inquiry. First, Section 9 governs consent to data processing, not the separate question of whether a child should be permitted to hold an account at all. A platform could, in principle, obtain valid parental consent under Section 9 and still allow a fifteen-year-old to operate a fully public account with an algorithmically curated feed. Second, the eighteen-year threshold, higher than the European Union’s default of sixteen and far higher than the United States’ thirteen, was fixed with reference to the age of majority under the Juvenile Justice (Care and Protection of Children) Act, 2015, rather than any study of the capacity an Indian teenager actually has to assess the risks that social media poses.

The Protection of Children from Sexual Offences Act, 2012 supplies a further layer, criminalising the sexual exploitation and abuse of children including through electronic means. It addresses harm once it has occurred; it does nothing to govern a child’s initial exposure to a platform’s design. Taken together, these regimes regulate what happens to a child’s data after an account exists and punish abuse after the fact, but say almost nothing about the antecedent question of access.

The comparative evidence points the same way. The European Union’s General Data Protection Regulation sets sixteen as the default age at which a child may consent to information-society services without parental involvement, though it permits member states to lower that threshold to as young as thirteen, producing a fragmented patchwork across the Union rather than one uniform rule. The United States’ Children’s Online Privacy Protection Act fixes thirteen as the age below which parental consent is required for the collection of a child’s personal information, a threshold set in 1998 and widely criticised today as poorly suited to an era of algorithmic recommendation. Australia’s Online Safety Amendment (social media Minimum Age) Act 2024 took effect on 10 December 2025, barring platforms including Instagram, TikTok, Facebook, Snapchat, and YouTube from permitting anyone under sixteen to hold an account, and placing the entire compliance burden, backed by fines of up to fifty million Australian dollars, on the platform rather than on the child or parent. None of these models maps onto Section 9’s eighteen-year threshold; India’s law is stricter than any of them on data-processing consent, yet silent on account access itself.

The proof is not one-sided, and a fair reading of the evidence has to account for its limits. Verification itself creates a privacy problem: confirming a user’s age typically requires collecting more identifying information, a photograph for facial age-estimation, a government identity document, or biometric data, than the platform previously needed to operate the account at all, so age assurance can increase the very data-protection risk that Section 9 was written to reduce. Enforcement will also be uneven across India’s population, since a verification regime built around a government identity document assumes ready access to one, along with a smartphone capable of completing the check, an assumption that does not hold for every household. A hard age bar risks pushing older adolescents toward platforms with weaker safeguards or none at all, and it risks cutting off access to examination, scholarship, and public health information that a sixteen- or seventeen-year-old has every reason to see. Australia’s experience, still being assessed less than a year into enforcement, is the clearest live evidence available anywhere of how these trade-offs play out in practice.

ABSTRACT

This article examines whether India should enact a statutory digital age of consent specifically governing a child’s access to social media accounts, as distinct from the data-processing consent already mandated under Section 9 of the Digital Personal Data Protection Act, 2023. It surveys India’s existing framework, the constitutional privacy jurisprudence of Justice K.S. Puttaswamy (Retd.) v. Union of India, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the DPDP Act and the Digital Personal Data Protection Rules, 2025, and the Protection of Children from Sexual Offences Act, 2012, and finds that none of them answers the specific question of the age at which a child may hold a social media account. It then places India’s eighteen-year data-consent threshold against the European Union’s General Data Protection Regulation, the United States’ Children’s Online Privacy Protection Act, and Australia’s Online Safety Amendment (social media Minimum Age) Act 2024, before weighing the case for a dedicated statute against the privacy, equity, and free-expression costs of blunt age verification. It concludes that India should legislate a calibrated, platform-facing account-access threshold, distinct from Section 9, paired with privacy-preserving age assurance and a mandatory statutory review.

Keywords: Digital Personal Data Protection Act 2023; children’s data; social media regulation; age of consent; age verification; comparative data protection law.

CASE LAWS

Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 S.C.C. 1, is the foundational case for any discussion of digital consent in India. A nine-judge bench held that the right to privacy, including informational privacy, is a fundamental right under Article 21, and that any restriction on it must satisfy a test of legality, necessity, and proportionality. The judgment supplies the constitutional basis for treating a child’s consent to data collection as a matter of fundamental-rights concern rather than mere contract law.

K.S. Puttaswamy v. Union of India (Aadhaar), (2019) 1 S.C.C. 1, decided by a five-judge bench, applied the proportionality standard to the Aadhaar biometric identity scheme and upheld it with modifications. The case is relevant here because any statutory age-verification mechanism for social media would likely face the same proportionality scrutiny that Aadhaar did, particularly if verification involves biometric or document-based checks on minors.

Shreya Singhal v. Union of India, (2015) 5 S.C.C. 1, struck down Section 66A of the Information Technology Act, 2000 as unconstitutionally vague and overbroad. The judgment is a reminder that any new statute restricting online access, including a child age-verification law, must be drafted with precision if it is to survive constitutional challenge.

Sharat Babu Digumarti v. State (NCT of Delhi), (2017) 2 S.C.C. 18, addressed the safe-harbour protection available to intermediaries under Section 79 of the Information Technology Act, 2000, holding that an intermediary is generally shielded from liability for third-party content once statutory due diligence is observed. The case frames how far a future age-verification obligation could go in fixing liability on platforms rather than on users.

In Re: Prajwala Letter Dated 18.2.2015, Suo Motu Writ Petition (Criminal) No. 3 of 2015, saw the Supreme Court respond to the online circulation of child sexual abuse material by directing intermediaries and law enforcement to develop mechanisms for detection and reporting. The proceeding is the clearest existing instance of Indian courts engaging directly with children’s safety on digital platforms, though it addressed content already causing harm rather than preventive access control.

CONCLUSION

India’s Digital Personal Data Protection Act already treats every person under eighteen as a child for the purposes of data-processing consent, a stricter number than almost any comparable jurisdiction applies. What it does not do is answer the narrower, and arguably more urgent, question of when a child may hold a social media account at all, and on what terms. The proof assembled here, statutory, comparative, and judicial, points toward a specific answer: Parliament should legislate a platform-facing account-access threshold, plausibly sixteen, distinct from Section 9’s eighteen-year consent rule, enforced through privacy-preserving age assurance rather than blanket document verification, with compliance obligations falling on platforms rather than on parents or children, and a mandatory review after a fixed period to test the law against its actual effects. That question was settled by platform terms of service long before Parliament turned to data protection, and it remains unsettled in Indian statute today. A dedicated legislative answer, debated on its own terms, is the more honest way for India to decide it.

FAQ

Q1. What age does the DPDP Act, 2023 treat as the threshold for childhood? Section 9 defines a child as anyone who has not completed eighteen years of age, and requires verifiable parental consent before a data fiduciary processes that child’s personal data.

Q2. Does India currently restrict social media accounts by age, the way Australia does? No. Indian platforms set their own minimum age, usually thirteen, through their terms of service. No Indian statute currently bars a minor from holding a social media account, unlike Australia’s Online Safety Amendment (social media Minimum Age) Act 2024, which prohibits accounts for anyone under sixteen.

Q3. What does “verifiable parental consent” require under the DPDP Rules, 2025? The Rules, operative in phases through 14 May 2027, require a data fiduciary to be able to demonstrate that consent was actually given by a parent or lawful guardian, not merely asserted at sign-up, with narrow exemptions under Rule 10 for fiduciaries that meet specified safe-processing conditions.

Q4. Is targeted advertising to children ever permitted under Indian law, even with parental consent? No. Section 9(3) of the DPDP Act prohibits tracking, behavioural monitoring, and targeted advertising directed at children absolutely, and this prohibition applies even where a parent has consented to data processing.

Q5. Why does this article recommend a threshold different from the DPDP Act’s eighteen years? Because Section 9 governs consent to data processing across every sector, while the question of social media account access involves a distinct risk profile, algorithmic feeds, public visibility, and contact with strangers, that a dedicated statute could calibrate more precisely, drawing on comparative models such as the GDPR’s sixteen and Australia’s sixteen.

Q6. What happens if a data fiduciary violates the DPDP Act’s provisions on children’s data? Non-compliance with Section 9 can attract penalties of up to two hundred crore rupees, enforced by the Data Protection Board of India.