A Global Pattern Arrives in Cairo
On September 18, 2026, Egypt's Supreme Council for Media Regulation (SCMR) and the National Telecommunications Regulatory Authority (NTRA) issued a joint, binding decree barring children under 13 from holding independent social media accounts and requiring platforms to place 13-to-15-year-olds into a mandatory "safe-use mode" the user cannot switch off. Platforms have 30 days to submit technical and operational compliance plans and three months to bring existing accounts into line. SCMR chairman Khaled Abdel Aziz framed the measures as protection against "harmful content, exploitation, bullying, harassment and blackmail," while NTRA chief executive Mohamed Shamroukh described the approach as calibrated to "age- and risk-proportionate protection."
The decree sits on top of an existing enforcement apparatus: Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, and Law No. 151 of 2020 on the Protection of Personal Data, both of which already give Egyptian regulators broad latitude over platforms and data processors operating in the country.
The Case For It
The steelman here is genuinely strong. Child-safety researchers and regulators have documented real harms tied to unsupervised pre-teen social media use — grooming, sextortion, algorithmic exposure to self-harm content, and compulsive-use patterns linked to adolescent depression. A regime that keeps under-13s off platforms entirely, rather than relying on self-attested age gates any child can click past, targets a genuine enforcement failure: platforms' own terms of service already bar under-13 accounts almost universally, and almost none of them enforce it. Requiring a default, non-disabling safe mode for young teens — rather than an opt-in parental control buried in a settings menu — also reflects the "protection by design" logic regulators elsewhere have converged on. If the goal is fewer 12-year-olds with unsupervised access to strangers via DM, a hard age floor plus a locked default is a more honest tool than a checkbox.
Where the Design Gets Risky
The decree's weak point is the one every age-verification mandate runs into: how do you verify age without building a data-collection apparatus that outlives the child-safety justification? The rules ask platforms to deploy verification "resistant to circumvention" while simultaneously minimizing the data collected — a genuine tension, not a checklist item. Circumvention-resistant age assurance typically means document checks, facial-age estimation, or data-broker matching; each expands the personal data platforms hold on every user, not just minors, since confirming an account isn't a 13-year-old's requires screening adults too. Egypt's Personal Data Protection Law (151/2020) offers a domestic legal backstop, but the Personal Data Protection Center it created functions inside the executive branch rather than as a fully independent adjudicator — and this decree was issued by a media and telecoms regulator, not the data-protection authority, leaving unclear which body actually audits the verification method a platform chooses.
The Enforcement Gap
Egypt's broader digital-regulation record adds a second concern that has nothing to do with child safety. The same legal toolkit invoked here, Law 175/2018, has also been the statutory basis for blocking independent news sites and VPN services, and Egyptian regulators have a documented history of extending "protective" digital rules into broader platform-control levers. Public reporting on this decree does not specify penalties for noncompliance, nor an appeals mechanism beyond a vague reference to correcting mistaken age classifications. For a rule this operationally demanding — real-time age inference across an entire user base, on a 30-day plan deadline — the absence of a published penalty schedule or independent appeal path is not a technicality. It is the difference between a child-safety rule and a discretionary lever over platform operations, and Egypt's institutions have not earned the benefit of the doubt on which one this becomes.
Where This Leaves Platforms
None of this means the underlying goal is wrong. Keeping unsupervised pre-teens off open social platforms is a defensible position several jurisdictions have now converged on independently. But the quality of an age-verification regime is measured by what it does to the overwhelming majority of users who aren't its target — and a mandate that pairs "resist circumvention" with "minimize data collected" without specifying a verification method, transparency reporting, or independent oversight is asking platforms to guess at the tradeoff regulators actually want. Egypt has 30 days to find out how narrowly platforms interpret that instruction; until a compliance-plan review process or penalty schedule surfaces, this reads as a rule whose implementation details will end up defining it more than its stated purpose.
"Digital child safety is a shared responsibility between the state, the family, society, and digital platforms." — Khaled Abdel Aziz, SCMR Chairman