Supreme Court Pushes for Stronger Safeguards for Minors on Social Media

The Supreme Court of India has asked the Centre to consider a statutory framework that would prevent or regulate minors under 18 from independently creating social-media accounts, bringing children’s online safety, age verification and personal-data protection into sharper focus. The matter arises from a petition by the Just Rights for Children Alliance, which argues that children are currently able to create accounts on platforms that generally permit users from around 13 years of age, despite Indian contract law treating persons below 18 as not competent to enter into contracts independently. The Court has indicated that safeguards should be given a statutory basis rather than remaining merely voluntary or guideline-based.

The issue is particularly important because the Digital Personal Data Protection Act, 2023 (DPDP Act) already creates a separate framework for children’s personal data. Under Section 9, a data fiduciary must obtain verifiable parental or lawful-guardian consent before processing a child’s personal data. The Act also prohibits processing that is likely to cause a detrimental effect on a child’s well-being and prohibits tracking, behavioural monitoring and targeted advertising directed at children. The DPDP Rules, 2025 provide mechanisms for verifying that the person giving consent is an identifiable adult, including through information already held by the data fiduciary, information voluntarily provided, or a virtual token issued by an authorised entity.

Why the Supreme Court’s intervention matters for DPDP

The important distinction is that DPDP regulates the processing of children’s personal data, whereas the Supreme Court case raises a broader question about whether a child should be permitted to independently maintain a social-media account in the first place. This distinction could become significant for platforms. A platform might comply with a parental-consent requirement for processing personal data, but that does not necessarily answer the separate legal question of whether a person below 18 can independently accept platform terms and create an account.

The petition specifically highlights this gap. It argues that social-media registration involves acceptance of terms of service, user agreements and privacy policies, effectively creating a contractual relationship. The petition therefore seeks stronger age-assurance mechanisms and parental involvement. The Court has asked the government to examine whether the existing statutory framework can address the issue, while the government has indicated that it will consider the matter.

For DPDP compliance, this could increase the importance of age assurance and parental-consent architecture. Platforms processing children’s data would need to establish reliable processes for determining whether a user is a child and, where required, obtaining verifiable consent from a parent or lawful guardian. This is substantially different from simply asking users to enter a date of birth. The DPDP Rules specifically contemplate technical and organisational measures and due diligence concerning the identity and age of the person claiming to be the parent.

The practical compliance challenge: age verification without creating another privacy risk

There is, however, an important technical and privacy question. If platforms attempt to establish that a user is under or over 18, they may themselves need additional personal information to perform age assurance. That creates a potential tension: a system designed to protect children’s privacy should not unnecessarily result in the collection and retention of large amounts of identity information.

This makes data minimisation, purpose limitation, security and retention controls particularly important. A platform may need to demonstrate not only that it can distinguish children from adults, but also that the verification process itself does not create unnecessary personal-data exposure. The Delhi High Court has previously considered proposals involving stronger verification mechanisms for children’s social-media access while expressly raising privacy considerations around possible identity-verification models.

What could change for social-media platforms and digital businesses?

If the government ultimately introduces statutory restrictions following the Supreme Court proceedings, platforms could face requirements across several layers:

  • Age assurance: establishing whether a user is below 18.
  • Parental consent: obtaining and verifying consent where children’s data is processed.
  • Account controls: potentially restricting independent accounts of minors.
  • Data governance: preventing prohibited tracking, behavioural monitoring and targeted advertising.
  • Consent management: maintaining records and mechanisms for withdrawal where applicable.
  • Data deletion: implementing appropriate deletion processes when data is no longer required or consent is withdrawn.
  • Auditability: maintaining evidence that age, consent and processing controls are functioning as required.

The government’s own recent statement confirms that the DPDP Act and Rules are intended to provide safeguards including verifiable parental consent, restrictions on tracking and behavioural monitoring, and controls on targeted advertising to children.

The larger DPDP implication

The Supreme Court proceedings could therefore push India’s child-data protection framework towards a more integrated model combining privacy, age assurance, platform access and online safety. This is important because the risks identified in the litigation extend beyond data misuse to grooming, sexual exploitation, cyberbullying, behavioural profiling and exposure to inappropriate content.

For organisations preparing for DPDP compliance, the key takeaway is that parental consent should not be viewed as a standalone checkbox. Businesses dealing with children’s data need to think through the complete lifecycle: identifying a child, verifying the consenting adult, limiting permissible processing, preventing prohibited profiling and advertising, securing the data, managing withdrawal and deletion, and demonstrating compliance through appropriate records and controls.

The legal position is still developing. The Supreme Court has asked the Centre to examine the issue, and the government has indicated that it will consider statutory measures. Therefore, the final requirements for social-media access, age verification and their interaction with DPDP should not yet be treated as settled law.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Riskmanagementnews

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.