Brazil requires social media accounts held by under-16s to be linked to a legal guardian. China caps daily app use at one hour for under-16s and two hours for 16 and 17-year-olds, and switches services off between 10pm and 6am. Indonesia lets a 14-year-old onto a low-risk platform with parental consent, but not a high-risk one.
India’s Digital Personal Data Protection Act requires verifiable parental consent for every user under 18, and draws no distinction at all between a nine-year-old and a 17-year-old.
All four call this protecting children online. The instruments have almost nothing in common.
That divergence is the live question for India’s BRICS chairship. New Delhi hosts the 18th BRICS Summit on September 12 and 13. Children’s digital safety sits inside a grouping that has already, on paper, agreed to work on it together. The 2025 Rio de Janeiro declaration acknowledged progress on Child Online Protection and pointed to “the exchange of knowledge and best practice among member states.” Knowledge exchange is a low ceiling. Why it is that the ceiling becomes clear once the statutes are laid side by side.
This piece draws in part on a closed-door discussion held under the Chatham House Rule. The regulatory detail is from the public record.
Four theories of what a child needs protecting from
The instruments diverge because the underlying theory diverges. Four theories are in play across the grouping.
- Data protection. The child is a data subject. The harm is unlawful processing. The remedy is consent, plus limits on profiling. India and South Africa sit here.
- Platform duty of care. The child is a user the platform must design for. The harm is exposure by default. The remedy is age assurance, tiered access and guardian linkage. Brazil and Indonesia sit here.
- Content and time control. The child is someone whose consumption the state supervises. The harm is the content itself, and the hours spent on it. The remedy is curfews, minor modes and blocking. China sits here, and Russia’s older framework is closest to it.
- Sectoral obligation. The child is protected by imposing duties across a whole regulated industry, platforms and network operators alike. The UAE’s 2025 decree-law works this way.
These are not points on one spectrum. They put the duty in different places. A data protection regime asks whether the platform had a lawful basis. A duty-of-care regime asks whether the platform knew the user was 14. Those questions have different answers and different remedies.
Brazil has gone furthest
Brazil’s Law No. 15,211 of 2025, known as the ECA Digital, updates the country’s 1990 Statute of the Child and Adolescent for digital services. Its grace period ended on March 17, 2026.
The obligations are specific. Providers must run reliable age verification, and self-declaration alone is expressly not enough. Accounts held by users under 16 must be linked to a legal guardian. Platforms must supply parental supervision tools and apply protective settings by default. They must not profile minors for advertising. They must remove manipulative design patterns and run impact assessments on their minor users.
Enforcement sits with the data protection authority, the ANPD, restructured as an autonomous regulator in April 2026. Penalties run to 10% of the economic group’s revenue in Brazil. Suspension and prohibition from operating are available too. Administrative sanctions begin in November 2026, and formal compliance verification in January 2027.
The scope is deliberately wide. The law reaches any provider, domestic or foreign, offering a service with probable access by minors — social networks, messaging, streaming, games, marketplaces and health apps.
Indonesia’s rule is tiered, not the blanket ban it is usually called
Indonesia is routinely described as having barred under-16s from social media outright. The regulation is more graduated than that, and the difference matters for anyone drawing lessons from it.
Government Regulation No. 17 of 2025, known as PP Tunas, sets access by age band against platform risk level. Children under 13 may hold accounts only on low-risk products designed for children, with parental permission. Children between 13 and 16 may hold accounts on low-risk products and features, with parental consent. Those between 16 and 18 may hold accounts with parental consent.
Platforms must verify age and provide parental controls. They must filter and remove harmful content, run risk assessments, restrict commercial use of children’s data, and offer accessible reporting tools. Sanctions are administrative — warnings, compliance orders, platform restrictions — rather than the large fines seen elsewhere.
The regulation took effect in April 2025, with a transition period of up to two years. Enforcement began phasing in on March 28, 2026. Reporting from that date is where the “under-16 ban” description comes from. Accounts differ on whether that step, and an accompanying ministerial regulation, hardened the tiers into something closer to a flat bar for under-16s. MediaNama could not resolve that against the Indonesian instruments directly, and has sought clarification.
China regulates in two layers, and the second is new
China’s approach predates the current wave. A minor mode framework has applied since 2023, restricting under-18 access during night hours. The Regulations on the Protection of Minors in Cyberspace took effect in 2024.
The newer layer is narrower, and more revealing. The Interim Measures for the Management of AI Human-Like Interaction Services were published on April 10, 2026 by the Cyberspace Administration of China, with four other agencies. They took effect on July 15, 2026.
For minors, they impose an absolute prohibition on virtual intimate relationship services — virtual partners, virtual family members. There is no consent-based route around it. Other AI companion services need parental consent for children under 14. Age verification is mandatory. Providers must offer a minor mode carrying periodic reminders of reality and usage time limits, along with parental controls covering safety alerts and spending.
The design assumption is the opposite of Brazil’s. Brazil asks the guardian to supervise. China removes the category of service from minors altogether, and does not treat parental consent as curing it.
India is still choosing, and has said so
India’s position is the least settled of the large members. That is awkward in a chairship year.
The Digital Personal Data Protection Act, 2023 requires verifiable parental consent before a child’s personal data is processed. It bars tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 of the DPDP Rules sets out how the consenting adult’s identity may be confirmed, including through a virtual token. Both take effect on May 13, 2027. That is after Brazil’s compliance verification begins, and more than a year after Indonesia’s enforcement started.
A separate children’s social media law has been under discussion. MediaNama reported in March 2026 on a proposed three-tier structure: strictest restrictions for ages 8-12, moderate for 12-16, limited for 16-18. It closely resembles Indonesia’s banding. A government official quoted then said the reasoning was that “we do not believe in very harsh measures such as a ban.”
That position held. A government-led consultation concluded earlier in August 2026 that “a complete social media ban for children would not be effective.” It involved the National Commission for Protection of Child Rights, MeitY and the Department of Telecom. The consultation turned instead to age-gating, platform design duties and a code of conduct. It also recorded an intent to treat children as rights-bearers rather than only as victims — a framing closer to Brazil’s than to China’s.
India is not uniform internally either. Karnataka’s chief minister proposed an under-16 social media ban in March 2026. That is precisely the instrument the union government has declined.
Russia and South Africa sit at the thinner end
Russia’s protections rest largely on its 2010 law on information harmful to children’s health and development, together with content blocking. Lawmakers raised age verification proposals in late 2025. MediaNama could not confirm that an enacted platform-duty or age-assurance regime is in force in Russia, and has not treated it as having one.
South Africa relies on data protection. The POPI Act prohibits processing the personal information of children except in defined circumstances, with the Information Regulator able to authorise processing that would otherwise be barred. There is no age-gating or duty-of-care statute equivalent to Brazil’s. Content-side protection runs through the Films and Publications Act.
The four smaller and newer members — Egypt, Ethiopia, Iran and Saudi Arabia — have no comparable framework in force. Egypt’s parliament debated the question in January 2026 without introducing a law.
CSAM is the one place the ground is already shared
If BRICS agrees on anything here, Child Sexual Abuse Material (CSAM) is the obvious candidate. It surfaced in the closed-door discussion as exactly that.
The reason is structural. CSAM is already criminal in every member state. The definitional gap between jurisdictions is narrow. Cross-border cooperation mechanisms exist. No member has to adopt another’s theory of childhood to agree that this material should be detected and removed.
Age assurance is the contrast. Agreeing on the goal settles almost nothing there. The method decides everything — document upload, biometric estimation, device-level signals, a state identity token. Each carries different privacy consequences, and members disagree about which are acceptable.
Even on CSAM, the harder question is what common detection would look like in practice. It may require shared or interoperable systems, and the grouping’s structure does not currently support those.
Why the divergence is structural, not a drafting problem
Three things make this harder than it looks.
The theories conflict at the point of application. A regime built on parental consent and one that removes a service from minors regardless of consent cannot both be satisfied by a single product design. A platform can comply with both, but only by building separately for each market. That is what happens now, and it is the opposite of convergence.
Capacity varies enormously. Brazil’s regime presumes an active regulator able to fine a global company 10% of local revenue. Members with much lower internet penetration and thinner regulatory institutions cannot enforce an equivalent duty, even if they adopt the text.
Then there is trust. Any cross-border age assurance arrangement requires one state to accept another’s attestation that a user is over a given age. That is a question about institutions, not technology. It came up repeatedly in the closed-door discussion as the binding constraint on BRICS cooperation generally.
What a chairship year can realistically produce
BRICS operates by consensus. It has no body that can issue binding rules across members. That fact, combined with four incompatible regulatory theories, limits what September’s summit can deliver on children’s safety.
What it can do is narrower, and still worth something. The Rio declaration’s knowledge-exchange language is thin, but it is agreed language. India’s chairship could give it content. That might be a comparative record of what members have actually enacted. It might be evidence on whether age assurance is working where it has been tried. It might be a shared position on CSAM detection that asks nobody to redesign their domestic framework.
India has a specific reason to prefer that route. It is the member still deciding, with its own consultation pointing away from bans and towards design duties. A grouping that hardens around blanket restrictions before India has legislated would leave New Delhi arguing against a standard it helped convene.
Also read:
————————————————
