India Child Safety Plan Would Force Every Adult To Submit Biometrics Via Aadhaar | #childsafety | #kids | #chldern | #parents | #schoolsafey


At India’s first major expert convening on children’s social media policy, held in Bengaluru on May 15, one conclusion cut through the room: “All age verification in India becomes Aadhaar verification.” The implication was not subtle. To determine that a user is a child, every user must first be identified. In India, that means routing hundreds of millions of adults through the national biometric identity system — the same infrastructure that links fingerprints and iris scans to welfare payments, tax records, and mobile phone registrations for over a billion people, as MediaNama’s event report from the Bengaluru roundtable confirmed.

That collision between child protection and adult surveillance forms the central tension at a second MediaNama roundtable, scheduled to open this Friday, July 31, from 1 PM to 5 PM at Viceroy Hall, The Claridges hotel in New Delhi, as announced on MediaNama.com. India’s Central government is reportedly preparing legislation with three distinct age tiers — 8 to 12, 12 to 16, and 16 to 18 — each carrying different platform obligations, according to a MediaNama summary of Indian Express reporting. If it passes, the framework would be the most finely graduated children’s digital-rights legislation anywhere in the world. The Aadhaar question is what makes the sophistication costly.

What the Three Tiers Would Do — and What They Require

The Central government has explicitly ruled out a blanket ban, with senior officials describing the approach as “nuanced” and “graded,” according to reporting from Indian Express. The framework under consideration would restrict access based on age bracket rather than impose a single cutoff, with measures including time-based login limits (prohibiting evening or overnight access), mandatory parental consent, and obligations on platforms to modify engagement-maximizing design features — infinite scroll, notification streaks, algorithmic recommendation loops.

That design-level ambition represents genuine regulatory sophistication. The UK’s proposed framework, announced in June 2026, targets similar mechanisms and is covered in depth in TechTimes’ analysis of the UK’s age verification privacy cost. The EU’s proposed framework, announced July 13, places the burden of safety proof on platforms rather than on governments or parents, as TechTimes reported when the EU moved to bar children from social media. India’s three-tier approach goes further than both by differentiating obligations across multiple age brackets rather than drawing a single line at 13, 15, or 16.

The structural problem every tier creates is identical: before a platform can apply the right rule to a given user, it must determine which bracket that user belongs to. Age brackets require age verification. And in India’s digital infrastructure landscape, age verification defaults to Aadhaar.

The Digital Personal Data Protection Act (DPDP Act, 2023) requires “verifiable parental consent” before platforms process children’s data — but does not specify a mechanism. The Draft Data Protection Rules of 2025 propose two practical pathways: an Aadhaar-linked DigiLocker system, in which a parent’s Aadhaar credentials are associated with their child’s account so that platforms can send a yes-or-no age query, or an electronic token system in which a government ID is converted into an encrypted credential that shares only name and age, as reported by the Deccan Herald.

DigiLocker Tokens: Privacy-Preserving, or Just Less Invasive?

Andhra Pradesh, which is separately evaluating an under-13 restriction, has moved furthest in specifying a verification mechanism. In April 2026, a Group of Ministers meeting chaired by Education and IT Minister Nara Lokesh concluded that the state would explore “age tokens integrated with DigiLocker” — a system in which social media platforms authenticate a user’s age bracket without receiving the underlying Aadhaar number itself, as Telangana Today reported.

The token architecture is technically meaningful. A platform would send a query to DigiLocker asking whether the user is over a specified age; DigiLocker would return a yes-or-no without transmitting the user’s Aadhaar details. This is structurally similar to the EU Data Protection Board’s model of tokenized age assurance, which separates attribute verification (is this person over 16?) from identity verification (who specifically is this person?).

What the token architecture does not eliminate is the metadata trail. A platform that pings DigiLocker about a user’s age now has a record that it queried India’s national identity infrastructure on behalf of that user, at that time, on that platform. At population scale — 1 billion internet users — that query log is a surveillance database even if no individual Aadhaar number is stored by the platform. Friday’s roundtable agenda explicitly flags this distinction as one of the central questions before the room.

The alternative is self-declaration: a user types their date of birth. This is the mechanism currently used by virtually every major platform in India, and it is trivially bypassed. Research from the UK — where self-declaration and soft biometric checks dominate — found that 39% of children aged 11 to 17 had successfully bypassed an age check, most by simply lying, according to a BMG Research survey commissioned by the UK Department for Science, Innovation and Technology.

State-Level Patchwork Before Any National Law Exists

India’s legislative landscape adds a layer of complexity that the UK, Australia, and EU do not face: state governments are moving independently, with different age thresholds and different enforcement visions, ahead of any national framework.

Karnataka’s Chief Minister Siddaramaiah announced during the 2026-27 state budget speech in March that the state would ban social media for children under 16 — making Karnataka the first Indian state to announce such a measure. No legislation has been drafted; Siddaramaiah said only that the government would “formulate a program” for enforcement once the program was finalized.

Andhra Pradesh, evaluating DigiLocker tokens as described above, targets children under 13, not 16. Goa’s infotech minister has said the state is examining similar restrictions, citing Australia’s law. The Central government’s reported three-tier framework uses different age brackets again: 8-to-12, 12-to-16, and 16-to-18.

The result, before any legislation has passed at either level, is a patchwork of incompatible age thresholds (under-13 in AP, under-16 in Karnataka, three-tier nationally) with no shared technical standard, no defined enforcement mechanism, and no clarity on what happens when a child in Karnataka crosses state lines to Andhra Pradesh. Friday’s agenda devotes dedicated time to this jurisdictional problem, which the Bengaluru session identified as practically unanswerable within existing constitutional frameworks without a central law that preempts state variations.

Who Bears the Operative Cost: Children or Everyone Else?

A 2026 open letter signed by 438 security and privacy scientists from 32 countries called for a moratorium on age-based online restrictions, citing the absence of clear scientific evidence that such systems improve outcomes for children. The signatories — whose March 2, 2026 letter is included in the MediaNama reading list circulated to Delhi roundtable participants — argue that age assurance systems are easily circumvented through VPNs, borrowed credentials, and AI-generated profiles, and that the infrastructure they create is purpose-built for the kind of surveillance that governments and corporations subsequently expand beyond its original mandate.

India’s own experience with Aadhaar illustrates the expansion risk. A system originally justified for narrow subsidy distribution has since been applied to SIM card registration, income tax filing, and now potentially to social media age verification — a pattern that TechPolicy.Press described as “mission creep.” Unlike the UK or Australia, where age verification relies on commercially provided biometric tools (with documented breach histories — AU10TIX, Persona, Discord/Zendesk collectively exposed hundreds of thousands of identity documents), India’s verification infrastructure is government-operated at the national identity layer, which means the state itself becomes the intermediary between users and platforms.

The Internet Freedom Foundation, whose founder Apar Gupta is a confirmed speaker at Friday’s roundtable, has been consistent: blanket bans and mandatory age verification are “a disproportionate response that can do more harm than good,” per the IFF’s statement on the Karnataka ban. The concern is not only surveillance. Only 33.3% of Indian women have ever used the internet, compared to 57.1% of men, according to the National Family Health Survey 2019-21 as reported by UNFPA India. The IFF has specifically warned that a restriction framed as “child protection” can be used by families and communities to keep girls offline permanently, deepening the gender digital divide rather than narrowing it.

Does the Evidence Justify the Architecture?

The evidence base for harm is real but contested. India’s National Crime Records Bureau data, cited at the Bengaluru roundtable, shows a 400% rise in cybercrimes involving children between 2019 and 2021, as documented in the MediaNama event report. In February 2026, three minor sisters in Ghaziabad died by suicide; preliminary reporting cited social media addiction as a contributing factor. The 2026-27 Economic Survey, tabled in January, warned of “digital addiction” and exposure to harmful content, according to MediaNama’s March 2026 policy summary.

But the relationship between social media use and harm is empirically complex in ways the political urgency of legislation often cannot accommodate. A Frontiers in Developmental Psychology study published in 2026 found no solid scientific evidence that social media bans improve outcomes and argued they could backfire. The 438-scientist open letter echoes the same conclusion from a privacy-and-security lens rather than a psychology lens.

What no jurisdiction has yet resolved — and what makes Friday’s Delhi convening significant beyond India — is whether the harm evidence is strong enough to justify a verification architecture that imposes its primary operative cost not on platforms or children but on every adult user of every regulated platform. The Bengaluru roundtable consensus was that blanket bans are a blunt instrument. But the Delhi roundtable will have to answer a harder question: whether a tiered, sophisticated, design-regulation-oriented framework is meaningfully different from a blunt ban if it still requires Aadhaar from everyone.

Australia’s experience provides a cautionary datapoint. After the world’s first under-16 social media ban took effect in December 2025, the country’s eSafety Commissioner found by March 2026 that seven in ten parents reported their child still had an active account on a restricted platform. VPN usage among Australian teenagers spiked following the ban, as the Bengaluru roundtable speakers noted. The technical infrastructure to enforce the law existed. The verification gap was not technical — it was behavioral.

What Is at Stake for India, Specifically

India is Meta’s largest market by users — more people in India use Facebook, Instagram, and WhatsApp than in any other country. India has 750 million smartphones in use and over 1 billion internet users. Whatever framework emerges from Friday’s deliberations — and from the Central government’s ongoing drafting process — will be implemented at a scale that dwarfs Australia’s 26 million people or the UK’s 67 million. The enforcement architecture India chooses will face pressures from shared devices (common in lower-income Indian households where a single smartphone may be used by multiple family members of different ages), cross-state jurisdiction gaps, and platform compliance costs from companies that already operate complex age-differentiated systems across multiple national markets.

Friday’s roundtable will not produce legislation. What it will produce — if the Bengaluru experience holds — is a research-grounded consensus that feeds into the IT Ministry’s ongoing consultations with platforms. That process is what shapes the framework’s operational architecture before it reaches Parliament.

The room at The Claridges will include senior advocates, AIIMS psychiatrists, platform design experts, digital rights lawyers, and representatives from EY, Deloitte, Times Internet, HDFC Bank, NITI Aayog, the National Informatics Centre, and India’s Ministry of Corporate Affairs — a cross-section that reflects how widely the policy decisions being made will ripple across India’s commercial, constitutional, and civil society landscape.

The sessions will run under the Chatham House Rule, meaning participants may freely use the information they receive, but may not attribute specific statements to specific individuals. That condition — designed to produce candor in policy settings — also means the most useful findings from Friday’s discussion will surface indirectly, through the frameworks and recommendations that eventually reach the drafting process. For a billion adult Indians who may soon need to verify their Aadhaar identity to prove they are not children, that indirect path is the one that matters.

Exchange rate note: All Indian Rupee figures are converted to US dollars at the rate of approximately 95.75 INR per USD, as of July 30, 2026. Conversions are approximate.


Frequently Asked Questions

How does India plan to verify children’s ages on social media?

India’s DPDP Act (2023) requires “verifiable parental consent” before platforms can process children’s data, but does not specify a technical mechanism. The two pathways under consideration are an Aadhaar-linked DigiLocker system — in which a parent associates their child’s Aadhaar credentials with their DigiLocker account, allowing platforms to send a yes-or-no age query without receiving the Aadhaar number itself — and a standalone electronic token system, in which a government ID is encrypted into a credential that shares only name and age. Neither pathway has been adopted into law, and neither prevents the creation of a metadata trail linking a user to India’s national identity infrastructure every time they attempt to access a regulated platform.

What is the three-tier framework India is considering, and how does it differ from Australia’s ban?

Australia’s ban draws a single line: social media platforms must exclude users under 16, with no gradation. The Indian Central government’s reported approach establishes three distinct age brackets — children aged 8 to 12, those aged 12 to 16, and those aged 16 to 18 — each subject to progressively different obligations, including time-based login restrictions, parental consent requirements, and platform design mandates targeting engagement-maximizing features. This is more granular than any existing law anywhere in the world. The enforcement challenge is proportionally more complex: three brackets require three verification determinations, not one.

Does India’s proposed child social media law affect adult users?

Yes, in the most direct sense. Any system that categorizes users by age must first identify who is a child — which means identifying everyone. In India’s infrastructure context, that identification defaults to Aadhaar, the national biometric identity system used by over a billion people. Even privacy-preserving variants like DigiLocker tokens create a metadata record connecting a user to national identity infrastructure whenever they access a regulated platform. Adults who want to use regulated social media platforms may be required to demonstrate — through Aadhaar-linked verification — that they are not children, as a condition of access.

Why does the digital gender divide complicate India’s child social media restrictions?

Only 33.3% of Indian women have ever used the internet, compared to 57.1% of men, according to the National Family Health Survey 2019-21. The gap is wider in rural areas. The Internet Freedom Foundation has warned that a social media restriction framed as “child protection” can be repurposed by families and communities as a justification for keeping girls offline permanently — not because of any explicit provision in the law, but because the law provides social legitimacy for a pre-existing behavior. A well-designed framework would include explicit safeguards against this outcome; no state-level proposal in India has yet included such safeguards.

————————————————


Source link

National Cyber Security

FREE
VIEW