A formal complaint filed with the National Human Rights Commission (NHRC) has brought the simmering global controversy over Meta Platforms’ child-safety practices to India’s doorstep. Filed by A.S. Santhosh, General Secretary of the Legal Rights Protection Forum (LRPF) in Hyderabad, the complaint urges the NHRC to launch an independent inquiry into whether Meta’s Indian operations—specifically Facebook and Instagram—are failing to prevent underage children from accessing their platforms, processing children’s personal data without adequate safeguards, and deploying algorithmic systems that may amplify harm to minors.
The trigger for the complaint is not a local incident but a cascade of revelations from the United States. On August 19, 2026, former Meta engineering director Arturo Béjar testified in ongoing federal litigation that Instagram had operated a “don’t ask, don’t tell” policy toward children under 13. According to Béjar’s reported testimony, Meta possessed technical and behavioral signals capable of identifying underage users but lacked the institutional incentive to deploy effective detection and removal mechanisms because product incentives prioritized growth, engagement, and time-on-platform over child-safety interventions. That testimony is part of a broader legal offensive: a coalition of 29 U.S. state attorneys general is pursuing Meta over allegations that its platforms are designed to addict young users, harvest their data, and expose them to harmful content.
The complaint argues that these U.S. developments are not merely foreign litigation. Because Meta deploys substantially the same technical architecture, recommendation algorithms, and age-assurance systems in India as it does in the United States, the American allegations function as “material external risk indicators” that warrant independent verification within the Indian regulatory and human-rights framework. The complaint draws a direct line to the Digital Personal Data Protection Act, 2023 (DPDP Act), whose Section 9 imposes heightened obligations for processing children’s personal data—including verifiable parental consent, prohibitions on behavioral tracking and targeted advertising directed at children, and restrictions on processing likely to cause detrimental effects on a child’s well-being. The accompanying Digital Personal Data Protection Rules, 2025 further prescribe technical and organizational measures for verifiable parental consent. The complainant argues that a nominal age gate—relying primarily on self-declaration—cannot satisfy these statutory obligations if the platform simultaneously possesses the technical means to infer a user’s minority but chooses not to act on those signals.
The complaint frames the issue as a systemic human-rights failure rather than a mere terms-of-service violation. It invokes the NHRC’s own mandate, noting that the Commission convened an Open House Discussion on “Access to Social Media by Children under 18 years” on March 16, 2026, where it flagged excessive social-media use by children and inadequate safeguards against harmful content. The present complaint, the filing argues, offers a concrete, platform-specific, and technically grounded entry point into that same policy space.
The prayer is expansive. The complainant asks the NHRC to: (i) initiate an independent inquiry into Meta’s child-safety architecture in India; (ii) call for detailed reports from Meta, the Ministry of Electronics and Information Technology (MeitY), and the Ministry of Women and Child Development (MWCD) on age-assurance mechanisms, underage detection rates, parental-consent workflows, behavioral profiling of minors, and recommender-system safeguards; (iii) examine Meta’s compliance with the DPDP Act’s child-protection provisions; (iv) order or recommend an independent third-party technical, algorithmic, and child-rights audit of Meta’s Indian operations; (v) assess whether existing regulatory mechanisms are sufficient to prevent platforms from “knowingly, negligently, or structurally” permitting children’s access under risky conditions; and (vi) recommend a comprehensive Child Online Safety and Age-Assurance Framework that embeds privacy-preserving age assurance, verifiable parental consent, child-specific data protection, recommender-system accountability, independent algorithmic audits, transparent underage-detection reporting, effective grievance redressal, and inter-agency coordination among MeitY, MWCD, the National Commission for Protection of Child Rights (NCPCR), the Data Protection Board of India, and other authorities.
Critically, the complaint insists that age assurance itself must adhere to privacy-by-design and data-minimization principles. It warns against using child protection as a pretext for indiscriminate collection of identity documents or biometric data from all users. Instead, it advocates a risk-based, proportionate framework that limits data collection to what is strictly necessary for age verification, enforces purpose limitation and retention controls, and subjects the system to independent oversight.
The complaint also asks Meta to disclose specific operational metrics for India: the number and proportion of users identified or suspected to be below the minimum age; the number of accounts restricted, suspended, or removed for underage status; the technical and behavioral signals used for age estimation; safeguards applied to suspected child accounts; the mechanism for obtaining and verifying parental consent; categories of personal data processed for age assurance; retention periods for such data; and measures to prevent re-registration by removed underage users.
Meta has not yet responded publicly to the NHRC complaint. In the United States, the company has consistently denied the allegations, stating that it has invested heavily in age-verification technology, parental-supervision tools, and age-appropriate experiences, and that it removes millions of underage accounts each quarter. Whether those claims hold up in the Indian context—and whether they satisfy the DPDP Act’s statutory thresholds—is now a question the NHRC has been asked to answer.
The complaint arrives at an inflection point for Indian digital governance. The DPDP Act and its rules are still being operationalized; the Data Protection Board of India is being constituted; and the Ministry of Electronics and Information Technology is drafting the Digital India Act, which is expected to address platform accountability, algorithmic transparency, and child safety in a more structural manner. The NHRC’s decision on whether to admit and investigate this complaint could set the tone for how India’s human-rights architecture engages with platform power in the age of algorithmic recommendation.
For now, the ball is in the Commission’s court. If it takes cognizance, the inquiry could become the first major Indian regulatory stress-test of Meta’s child-safety infrastructure—and a bellwether for how the world’s largest democracy translates its new data-protection law into enforceable guardrails for children online.
