Analysis urges design rules, not just age limits, for child online safety

Age-gating alone cannot protect children online, argues ORF research assistant Purushraj Patnaik. India's Economic Survey 2025-26 recorded 96.96 crore internet connections in 2024, up from 25.15 crore a decade earlier. Karnataka proposed barring under-16s from social media and Andhra Pradesh under-13s. In Australia, where an under-16 rule took effect on 10 December 2025, account ownership among 10- to 15-year-olds fell from 52 to 42 percent. He urges applying DPDP Act Sections 9(2) and 9(3) to product design.

Source

Observer Research Foundation (ORF) · read the original report ↗

#child safety#online regulation#dpdp act#social media#meity

Desk check · compared with the source

What the desk checked (5)
  • India had 96.96 crore internet connections in 2024, up from 25.15 crore a decade earlier. — Attributed in the source to India's Economic Survey 2025-26; figure appears in source.
  • NCRB recorded 1,238 cybercrimes against children under the IT Act in 2024, including 1,099 for publishing or transmitting sexually explicit material. — Attributed to the National Crime Records Bureau in the source; not independently verified here.
  • Australia's under-16 rule took effect on 10 December 2025; account ownership among 10- to 15-year-olds fell from 52 to 42 percent in three months. — Attributed to the eSafety Commissioner's assessment of 31 July 2026 as cited in the source.
  • A 2025 survey of 1,003 American minors found 11 percent had an online sexual interaction on a given platform. — Survey cited in the source without naming the conducting organisation; sourcing is partial.
  • Meta settled a consumer protection suit by 51 US attorneys general in August 2026, agreeing to daily time limits and an unranked feed for minors. — Stated in the source without a cited document; unattributed claim an editor may wish to check.

Analysts’ view opinion

AI Technology Analyst

The interesting shift in this ORF analysis is that it moves the regulatory target from the front door to the machinery inside — ranking systems, autoplay, streak counters, stranger-messaging defaults and reporting queues. That matters technically because those are engineering choices made upstream, long before a moderator ever sees a post, and India already has hooks for them in Sections 9(2) and 9(3) of the DPDP Act, whose Rules notified on 13 November 2025 do not yet define a test or threshold for detrimental effect or behavioural monitoring. Australia's experience is the cautionary data point the piece leans on: after the under-16 rule took effect on 10 December 2025, account ownership among 10-15-year-olds fell from 52 to 42 percent, while use of at least one restricted platform stayed above 81 percent. With 96.96 crore internet connections recorded in 2024, the design layer is where scale actually bites.

  • Age gates are a checkable 'bouncer' duty, while India's existing regime under Section 79 of the IT Act and Rule 4(4) of the IT Rules 2021 is an open-ended 'chaperone' duty — the analysis argues design rules sit better with the latter.
  • If ranking a minor's feed on watch history were formally classed as behavioural monitoring under Section 9(3), that converts a legal principle into something product engineers can actually implement or switch off.
  • Current metrics measure the wrong thing: NCRB's 1,238 IT Act cybercrimes against children in 2024 and MeitY's two-hour takedown clock count complaints and removal speed, not how often a child encounters harmful material — a figure only platforms hold.
  • The survey evidence cited suggests risk varies by product rather than by post — 11 percent of the 1,003 American minors surveyed reported an online sexual interaction on a given platform, rising to 19 percent on Snapchat, Kik and BeReal.
  • The compliance-cost question is genuinely contested: the EU's Article 28(1) guidelines and the ICO's Children's Code push cost onto services via age estimation and default protections, whereas universal identity verification would push it onto households as a permanent condition of access.

What to watch — Watch whether MeitY moves beyond verifiable consent to define detrimental effect and behavioural monitoring in product terms — and whether disclosure or risk-declaration duties on ranking changes, along the lines of Article 34 of the DSA, are placed outside Section 79 with defined penalties.

This is one researcher's policy argument, not government intent: the story does not establish that MeitY or the states will adopt a design-regulation approach, nor does it quantify the compliance burden, technical feasibility or effectiveness of such rules in India.

Deep dive

Research brief · 8 facts · 10 dates · exam-ready

The brief

Context

India's internet base has expanded rapidly — the Economic Survey 2025-26 records 96.96 crore connections in 2024 against 25.15 crore a decade earlier — pushing child online safety to the centre of policy. Several states and the Union government have responded mainly with age bars and takedown deadlines: Karnataka proposed barring under-16s from social media in March 2026, Andhra Pradesh under-13s, and MeitY told Parliament that intermediaries must remove nudity and morphed images within two hours of a complaint. Writing for the Observer Research Foundation, research assistant Purushraj Patnaik argues that such entry-and-exit rules ignore what happens in between — ranking algorithms, autoplay, streak counters, stranger-messaging defaults and slow reporting queues. He proposes using Sections 9(2) and 9(3) of the DPDP Act, 2023 to regulate product design rather than only access.

Key facts

  • Economic Survey 2025-26: 96.96 crore internet connections in 2024, up from 25.15 crore a decade earlier; 89 percent of rural 14- to 16-year-olds have a smartphone at home.
  • Australia's under-16 social media rule took effect 10 December 2025; eSafety Commissioner's 31 July 2026 assessment found account ownership among 10- to 15-year-olds fell from 52 to 42 percent in three months.
  • In Australia, use of at least one restricted platform stayed above 81 percent, down from 85.9 percent before the law; about half of those still using one said the platform never checked their age.
  • A 2025 survey of 1,003 American minors: 11 percent had an online sexual interaction on a given platform, 19 percent on Snapchat, Kik and BeReal; 7 percent had seen AI-generated nude imagery of another child.
  • 47 percent of American minors had used a platform before its minimum age; 19 percent were helped by a parent or older sibling; 41 percent of underage users reported online sexual interactions versus 13 percent of non-underage users.
  • NCRB recorded 1,238 cybercrimes against children under the IT Act in 2024, of which 1,099 were for publishing or transmitting sexually explicit material.
  • A survey of 89,000 urban parents found 82 percent described the reporting route as slow or unclear; after an online sexual interaction, 75 percent of minors block the account and 53 percent report it.
  • DPDP Rules notified 13 November 2025 require verifiable consent but set no test or threshold for 'detrimental effect' or behavioural monitoring; Meta settled a consumer protection suit by 51 US attorneys general in August 2026, agreeing to daily time limits, an overnight block and an unranked feed f

Timeline

  1. 2000Information Technology Act enacted; Section 79 ties intermediary safe harbour to due diligence.
  2. 2021IT Rules 2021 notified; Rule 4(4) asks large platforms to endeavour to identify child sexual abuse imagery.
  3. 2023DPDP Act passed with Sections 9(2) and 9(3) on children's data; CCPA notifies Guidelines for Prevention and Regulation of Dark Patterns identifying 13 interface designs.
  4. July 2025European Commission's Article 28(1) guidelines retain document checks for highest-risk services and accept age estimation elsewhere.
  5. 13 November 2025DPDP Rules notified, requiring verifiable consent but no measurable test for detrimental effect.
  6. 10 December 2025Australia's under-16 social media rule takes effect.
  7. March 2026Karnataka proposes barring under-16s from social media; Andhra Pradesh proposes under-13s; Union government examines graded age brackets.
  8. July 2026Allahabad High Court issues notice on a petition to keep minors off Roblox; MeitY tells Parliament intermediaries must remove nudity and morphed images within two hours of a complaint.
  9. 31 July 2026Australian eSafety Commissioner's assessment reports the fall in account ownership among 10- to 15-year-olds.
  10. August 2026Meta settles consumer protection suit by 51 US attorneys general, agreeing to design changes for minors.

Who has a stake

  • Children and adolescents online — Exposure is shaped by ranking, autoplay and stranger-messaging defaults; underage users who evade age gates face the highest reported risk of sexual interactions.
  • MeitY — Sets intermediary obligations and takedown clocks; could specify what DPDP Sections 9(2) and 9(3) require of product design on minors' accounts.
  • State governments (Karnataka, Andhra Pradesh) — Have proposed age bars of under-16 and under-13 respectively for social media access.
  • Large platforms and their engineers/product managers — Upstream design choices — ranking, notifications, retention — decide exposure; may face declarations, audits and published encounter rates.
  • Parents and families — 82 percent of 89,000 urban parents found reporting slow or unclear; universal identity verification would shift verification costs to households, including on shared handsets.
  • Regulators abroad (Australia's eSafety Commissioner, European Commission, UK ICO) — Provide the comparative evidence: age-gating results, age estimation guidelines, and the Children's Code fallback of protecting all uncertain-age users.
  • Judiciary and NCRB — Allahabad High Court is hearing a petition on minors and Roblox; NCRB data captures complaints filed, not actual exposure.

Why it matters

With nearly 97 crore internet connections and 89 percent of rural 14- to 16-year-olds having a smartphone at home, the scale of children's exposure makes design choices, not entry rules, the decisive variable. Australia's experience shows age bars can cut account ownership modestly while leaving most usage and the highest-risk evaders untouched. If India's existing DPDP provisions on children's data were turned into enforceable design rules with published exposure metrics, safety could be measured by how rarely children encounter harm rather than by how fast posts come down.

UPSC angle

Prelims pointers

  • Economic Survey 2025-26: 96.96 crore internet connections in 2024, up from 25.15 crore a decade earlier.
  • DPDP Act 2023: Section 9(2) bars processing detrimental to a child's well-being; Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children; Rules notified 13 November 2025.
  • Section 79 of the IT Act 2000 links safe harbour to due diligence; Rule 4(4) of IT Rules 2021 covers child sexual abuse imagery detection by large platforms.
  • CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023 identify 13 prohibited interface designs, including false urgency and subscription traps.
  • Australia's under-16 social media rule took effect 10 December 2025; NCRB recorded 1,238 IT Act cybercrimes against children in 2024.
  • Article 34 of the EU Digital Services Act requires risk assessment before changes; ICO Children's Code applies protections to all users whose age is uncertain.

Mains framing

India's child online safety framework currently operates at two ends of a service — who may enter (state proposals for under-16 and under-13 bans, graded age brackets) and how fast content leaves (MeitY's two-hour removal requirement) — while leaving untouched the middle, where ranking algorithms, autoplay, streak counters, stranger-messaging defaults and reporting queues actually shape a child's exposure. The evidence suggests the limits of this approach: Australia's under-16 rule cut account ownership among 10- to 15-year-olds from 52 to 42 percent but left usage above 81 percent, with about half of remaining users never age-checked; and 47 percent of American minors had used platforms below the minimum age, with underage users reporting sexual interactions at 41 percent against 13 percent. Measurement is also weak, since NCRB's 1,238 cases in 2024 count complaints rather than exposure, and 82 percent of surveyed parents call reporting slow or unclear. The way forward proposed is to treat DPDP Sections 9(2) and 9(3) as design rules — declaring watch-history-based ranking of minors' feeds as behavioural monitoring, requiring justification for engagement-maximising defaults — supported by pre-change declarations on the Article 34 DSA model, audited publication of how often minors encounter violating material including synthetic sexual imagery, duties placed outside Section 79 with defined penalties, and consumer-law routes under the Consumer Protection Act 2019, drawing on the dark patterns precedent that already treats interface design as a legal question.

Key terms

Age-gating
Restricting access to a service by minimum age, typically via self-declared birthdays, documents or age estimation.
DPDP Act Sections 9(2) and 9(3)
Provisions barring data processing detrimental to a child's well-being, and barring tracking, behavioural monitoring and targeted advertising directed at children.
Bouncer duty vs chaperone duty
A bouncer duty is narrow and checkable (verify a document, then serve or refuse); a chaperone duty is open-ended, requiring ongoing detection and disruption of wrongdoing — India runs a chaperone regime.
Dark patterns
Interface designs that push users towards unintended choices; the CCPA's 2023 guidelines identify and prohibit 13 such designs, including false urgency and subscription traps.
ICO Children's Code fallback
If a service cannot determine a user's age, it applies the code's child protections to all users.
Article 34, Digital Services Act
EU requirement that large platforms assess likely risks before changes; cited as a model for pre-change declarations on minors' accounts in India.

Practice questions

  1. Age limits and takedown deadlines are numerical targets, while design duties are rules. Examine this distinction with reference to India's child online safety framework and the DPDP Act, 2023.
  2. Critically evaluate the effectiveness of age-gating as a child protection tool, drawing on the Australian and European experiences discussed in the source.
  3. How can existing Indian law — the DPDP Act, IT Act safe harbour provisions, dark patterns guidelines and the Consumer Protection Act 2019 — be used to regulate the design of digital services for minors?

Grounded only in the source report — figures and dates are the source's, not inferred.

Next storyDelhi man killed after refusing to lend matchbox for cigarette →
← All stories