Australia's under-16 ban offers a caution for India: its eSafety Commission found seven in ten affected children still kept their access.
NEW DELHI: The Centre will amend the IT Intermediary Rules to bar social media platforms from letting under-18s open accounts on their own, Solicitor General Tushar Mehta told the Supreme Court during hearings on 28 and 29 September 2026. The bench of Chief Justice of India Surya Kant, Justice Joymalya Bagchi and Justice V. Mohana was hearing a PIL filed by the Just Rights for Children Alliance. Exceptions would remain for educational and informational use, provided a parent or legal guardian consents or controls the account.
An undertaking, not yet a rule
The commitment carries weight, but it is not law yet. An oral submission by a Law Officer signals executive intent. However, it becomes binding only after the Ministry of Electronics and Information Technology (MeitY) drafts the amendment, consults on it and notifies it in the Gazette of India. Until then, platforms face no new legal obligation.
An 1872 law meets the sign-up screen
The petition’s argument is strikingly old-fashioned. Senior Advocate H. S. Phoolka, appearing for the petitioner, argued that Section 11 of the Indian Contract Act, read with Section 3 of the Majority Act, 1875, makes anyone under 18 incompetent to contract. Consequently, he said, the sign-up agreements minors accept are void from the start. The petition links this gap to risks such as grooming, exploitation, profiling, cyberbullying and exposure to unsuitable content.
The bench pressed the point. Justice Bagchi told the Solicitor General that platforms must set 18 as the minimum age for registration, and said the requirement should sit in statutory form rather than a guideline. Meanwhile, Chief Justice Kant noted that the government already holds rule-making powers under the 2021 Intermediary Rules to issue binding directions. The Solicitor General, in turn, accepted that agreements executed by minors are void.
What the rules say today
Currently, the Intermediary Rules contain no explicit bar on under-18 accounts and prescribe no age-verification method. Rule 3 requires platforms to prohibit content harmful to minors, while Rule 4 adds duties for large platforms with over 5 million users. Notably, these provisions govern content after an account exists, not who may open one.
Separately, Section 9 of the Digital Personal Data Protection Act, 2023 requires verifiable parental consent before processing a child’s data and bans tracking and targeted advertising aimed at children. However, that section takes effect only on 13 May 2027. Phoolka argued the court need not wait, since contract law already applies.
What compliance would demand
A statutory duty would shift platforms from moderating content to controlling entry. Today, most rely on users simply declaring their age. Instead, they would need age assurance tools, which the dossier groups into three routes: checks against government ID such as Aadhaar or PAN, facial age estimation, or linking a minor’s account to a verified parent.
For large platforms, this means re-engineering sign-up flows and switching off personalised feeds and targeted ads for minor accounts. Smaller firms and startups face a steeper climb, since third-party verification carries per-check fees and the framework offers no small-business exemption.
Safe harbour as the enforcement lever
The rules gain teeth through Section 79 of the IT Act, which shields platforms from liability for user content only if they meet prescribed due diligence. If age-gating becomes part of that duty, a non-compliant platform could lose its immunity and face liability under the Bharatiya Nyaya Sanhita and the IT Act. Additionally, the Centre can issue blocking orders under Section 69A, while the Data Protection Board could impose penalties under the DPDP Act once its child data provisions take effect.
The trade-offs
The policy carries real tensions. Reliable age checks mean collecting IDs or biometrics from adults and minors alike, and groups such as the Internet Freedom Foundation and SFLC.in warn this erodes online anonymity and creates data breach risks. Furthermore, critics argue a blanket bar could restrict older teenagers’ Article 19(1)(a) rights to news and peer support. Policy researchers also warn that parental consent can become a veto on girls’ internet access in conservative households.
Global experience offers a caution. Australia enacted an under-16 ban in December 2025, yet its eSafety Commission reported that seven in ten affected children still retained access. Technology firms, meanwhile, want verification moved to app stores. At home, Karnataka and Andhra Pradesh have floated their own age thresholds, which a central rule could bring into line.
Open questions
Several details remain unpublished. Firstly, MeitY has not said whether it will impose a blanket under-18 bar or a graded model, such as the tiers discussed around the Economic Survey 2025–26. Secondly, the acceptable verification methods are undefined. Thirdly, it is unclear whether gaming, forums and EdTech apps fall within scope. Finally, no transition window has been set for verifying or converting millions of existing minor accounts.
What comes next
The next markers are clear: a draft Gazette notification from MeitY, any formal orders from the Supreme Court and consent standards under the DPDP Act before May 2027. Encouragingly for child safety advocates, the Centre and the court now share a starting point. How the rules balance protection, privacy and access will decide whether that principle works in practice.
