On September 28, 2026, a Supreme Court bench of Chief Justice Surya Kant and Justices Joymalya Bagchi and V Mohana pressed the Centre to put child-safety duties into binding law. Solicitor General Tushar Mehta told the court that the government would amend the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules so that stopping under-18s from opening social media accounts becomes a statutory obligation for intermediaries, according to MediaNama's reporting. "Guidelines are mere guidelines. It should be in some statutory format," Justice Bagchi said.
The strongest case for the court's instinct
The case for acting is real. The petition, filed by the NGO Just Rights for Children Alliance, notes that platforms such as Facebook and Snapchat let users open accounts from age 13, while Indian law treats anyone under 18 as a minor. Its lawyers argue that a minor cannot form a valid contract under Section 11 of the Indian Contract Act, so a terms-of-service click-through by a 14-year-old is legally hollow. The petition also lists grooming, sextortion and exploitation as harms that weak age verification leaves open. When a mismatch like that is left to voluntary platform policy, guidelines really are weak. The bench is right that a duty needs a statutory footing.
The petition itself asks for something narrower than a ban. It seeks age verification, parental consent and "prevention by design" safeguards, and does not seek to block minors from the internet. The solicitor general's undertaking goes further, to a hard bar on account creation, with parental consent only for educational sites.
Where the proposal outruns the evidence
The first problem is that India has already legislated a consent model. The Digital Personal Data Protection Act, 2023 defines a child as anyone under 18 and requires verifiable parental consent before processing a child's data. PRS Legislative Research summarises the penalty ceiling for breaching children's obligations as up to Rs 200 crore. The DPDP Rules, notified in November 2025, put the operational duty in Rule 10, which requires platforms to check that the person giving consent is an adult, using reliable identity details or a government-authorised token. That rule does not take effect until May 13, 2027.
So Parliament and MeitY chose parental consent, with a phase-in period so that industry and the state could build the verification plumbing. An IT Rules amendment that forbids under-18 accounts outright overrides that choice before it has been tested. Two overlapping regimes, one that says "consent of a parent" and one that says "no account at all", will leave platforms guessing which one governs. Compliance uncertainty like that falls hardest on smaller Indian services, which cannot absorb legal ambiguity the way a large multinational can.
The second problem is enforcement. A ban is only as good as age assurance, and age assurance is where the evidence is weakest. The MediaNama report cites Australia removing 4.7 million accounts in the first month of its under-16 law, which came into force on December 10, 2025 under the Online Safety Amendment (Social Media Minimum Age) Act 2024. It also cites a Reuters test in which platforms asked for no age proof on 50 test accounts, and a UK figure of 39% of children bypassing age checks. Account removals measure compliance activity, not children made safer. Whether teenagers moved to unregulated services, or simply lied about their age, is not settled.
The third problem is the price paid by everyone else. Reliable age gating of under-18s means verifying the age of every user. PRS notes that this could reduce digital anonymity for all users. In a country where the state has broad takedown powers over online speech, building an identity checkpoint at the front door of every social platform is a cost to adult speech, not just a burden on companies. It also risks cutting off older teenagers from news, civic groups, and support communities. Sixteen and seventeen-year-olds have speech interests that a blanket bar treats as nil.
A proportionate path for the Centre
The court has given the government a chance to legislate carefully, and it should use it. Four design choices would keep the child-safety goal while limiting collateral damage:
- Tier by age and risk. Set stricter defaults for under-13s, and default safety settings (private accounts, restricted contact from strangers, no targeted ads) for 13 to 17, rather than one cliff at 18.
- Align with Rule 10, don't duplicate it. Use the DPDP verifiable-consent architecture as the single legal pathway, so platforms comply with one regime.
- Require privacy-preserving age assurance. Accept government-authorised tokens that confirm "over 18" or "under 18" without disclosing identity, and bar platforms from keeping the underlying documents.
- Consult and then measure. Publish the draft amendment, take comments, and commit to a review with published data on circumvention and harm reduction.
The solicitor general said the government will act. The question is whether it acts on a fully drafted, consulted rule or on a courtroom undertaking. The DPDP Rules were shaped by consultations across seven cities before they were notified. A rule that reshapes how every Indian teenager reaches the internet deserves at least as much process.
Protecting children online is a legitimate, urgent goal. The strongest version of it is a targeted, well-enforced, privacy-preserving regime. A blanket age-18 gate, imposed before the DPDP consent rules have even taken effect, is a weaker and riskier answer.