On 17 September 2026, Egypt's Supreme Council for Media Regulation (SCMR) and the National Telecommunications Regulatory Authority (NTRA) issued a joint decision on children's social media use. According to Egypt Independent's report, platforms must block independent accounts for children under 13 and automatically place users aged 13 to under 15 in a Safe Mode that cannot be switched off. They must run effective age verification, review existing accounts, and offer an appeals route for errors. Implementation plans are due within 30 days; full compliance within three months. No platform is named.
The strongest case for the rule
The case for acting is serious. SCMR chair Khaled Abdel Aziz framed the aim as protecting children from harmful content, exploitation, bullying, harassment and blackmail, and described child safety as a shared responsibility of the state, family, society and platforms. Egyptian officials have long flagged electronic blackmail of minors: in February the Prime Minister said the cabinet was finalising child-protection legislation, and Daily News Egypt reported that it would require platforms to keep local legal representatives, adopt unified age classification and offer parental controls. Parents alone cannot police products designed to maximise engagement, and a bright-line age floor is easier to explain and enforce than vague duties of care. A fixed floor at 13 also matches the age most large platforms already set in their own terms.
What is different about this decision
Three design choices deserve credit. First, the age floor is 13, not 16. That is a narrower intervention than blanket teenage bans elsewhere, and it mostly formalises existing platform policy. Second, users aged 13 to under 15 are not excluded; they get a protected experience. That preserves access to information and community, which matters for speech rights of young people. Third, the decision requires platforms to minimise the personal data collected for verification and provides an appeals path for misclassified users. Those are the right instincts: a rule that forces every adult to hand over identity documents would harm privacy and chill anonymous speech.
Where the risk sits
The difficulty is that "effective age verification" and "minimise personal data" pull in opposite directions. Every method of confirming age reliably either collects data (ID documents, biometrics) or relies on estimation that makes errors. The decision, as reported, cites no named law and gives no technical standard, so platforms must guess what regulators will accept. Vague standards backed by the threat of blocking push risk-averse companies toward over-collection or over-restriction.
Egypt's existing data law offers a partial guide. Law No. 151 of 2020 on personal data protection, published by the communications ministry, created the Personal Data Protection Center. According to Access Partnership, Executive Regulations No. 816/2025, issued 1 November 2025, require guardian consent for those under 15 and take effect on 1 November 2026 after a one-year grace period. That overlap is notable: the new decision's 15-year threshold aligns with the data law's, and its three-month compliance window ends in mid-December 2026, weeks after the data regulations begin to bite. Regulators should say explicitly how the two regimes interact, so platforms are not asked to verify age in ways the data centre would treat as excessive processing.
Lessons from elsewhere
Australia's approach shows both the appeal and the difficulty. eSafety says that since 10 December 2025 age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts, with civil penalties of up to A$49.5 million. The standard there is "reasonable steps", published alongside regulatory guidance. Egypt's decision, by contrast, has been reported without a comparable public guidance document. A workable Egyptian approach would publish one.
Egypt's wider context
The decision follows a series of child-safety moves. In February 2026, Egyptian Streets reported that the NTRA announced child-friendly SIM cards with activation codes restricting pornographic and violent content and VPN tools, following a 24 January presidential directive to study Australian and British models. Restrictions on VPN tools are a reminder that child-safety framing can expand into circumvention controls affecting all users. Whether this decision stays targeted at minors is a question for its implementation, not its text.
What proportionate implementation looks like
- Publish a standard. Say which age-assurance methods are acceptable, including privacy-preserving options such as on-device estimation or third-party tokens, so platforms have a safe harbour.
- Keep the appeals route real. Set response deadlines and prohibit platforms from demanding more data than the appeal requires.
- Limit the scope. Confine the duty to services where minors' accounts are the issue, and avoid extending verification to every adult user of every service.
- Measure outcomes. Report after the three-month window on how many accounts were blocked, how many appeals succeeded, and whether teenagers moved to unregulated services or VPNs.
The decision's design is more restrained than a blanket ban, and its safety goals are legitimate. Its success will hinge on whether regulators define verification in a way that protects children without building an identity checkpoint for the Egyptian internet.