India children online safety age verification

New York's Kid-Safe Feed Rules Land as India's States Reach for Blunter Tools

NY's SAFE for Kids rules require age checks and default chronological feeds for minors; Karnataka and Andhra Pradesh are instead weighing outright bans.

Two Models for Protecting Kids Online People of Internet Research · India $5,000 Max penalty per violation NY's SAFE for Kids Act civil penal… Jan 25, 2027 NY rules take effect 180 days after State Register publ… 20% Time-on-feed defines coverage Threshold share of time on algorit… Under-16 Karnataka's proposed ban age Announced in the state's 2026-27 b… peopleofinternet.com
Two Models for Protecting Kids Online People of Internet Research · India $5,000 Max penalty per violation Jan 25, 2027 NY rules take effect 20% Time-on-feed defines coverage Under-16 Karnataka's proposed ban age peopleofinternet.com

Key Takeaways

New York Attorney General Letitia James and Governor Kathy Hochul on July 28, 2026 released final implementing rules for the SAFE for Kids Act, to be published in the State Register on July 29, 2026 and effective January 25, 2027. The rules require "Addictive Online Platforms" — defined as services where users spend at least 20% of their time on algorithmically personalized feeds — to verify a user's age, default minors to chronological (not algorithmically personalized) feeds, and block push notifications between midnight and 6 a.m., all unless a verified parent consents otherwise. Violations carry civil penalties of up to $5,000 per occurrence.

India has no equivalent statute yet, but the debate has arrived. On July 31, MediaNama convenes policymakers, child psychiatrists and civil society in Delhi specifically to examine "proposals by Karnataka, Andhra Pradesh, Goa, and the Centre" on age-based restrictions for children online. The timing invites an obvious comparison: New York regulates platform design for minors already using these services. India's loudest state-level proposals so far aim to bar them from the services altogether.

The case for intervention, stated fairly

The concern behind both approaches is legitimate. Recommendation engines are built to maximize watch time, and there is a growing evidence base that engagement-optimized feeds correlate with sleep disruption and compulsive use in adolescents — the exact harms New York's rules target with defaults rather than bans. In India, the scale is larger and the guardrails thinner: crores of children carry smartphones with essentially no enforced minimum age on major platforms, and parents often lack the technical means to monitor algorithmic exposure even when they want to. Karnataka Chief Minister Siddaramaiah invoked exactly this when he told the state assembly, during the 2026-27 budget presentation on March 6, 2026, that social media would be barred for under-16s to prevent "adverse effects on children from the use of mobile phones." Andhra Pradesh has floated a similar bar for under-13s. Neither government is wrong that the status quo is inadequate.

Where the state-ban approach breaks down

The trouble is implementation, and it is not a minor detail — it is the whole policy. Karnataka's announcement, by the state government's own admission, came with no consultation of platforms and no disclosed enforcement mechanism; legal commentators have since questioned whether a state even has the constitutional authority to regulate an inherently cross-border service this way, since "social media" sits uneasily within any state's police-power lane and platforms operate nationally. Andhra Pradesh's under-13 threshold and Karnataka's under-16 threshold are also simply incompatible: a single national platform cannot geofence a 13-year-old differently in Vijayawada than a 15-year-old in Bengaluru without a verification layer neither state has specified.

That verification layer is where India's parallel framework — the Digital Personal Data Protection Act, 2023, whose provisions on children's data Parliament's own research wing has summarized in detail — already offers a more defensible model than an outright ban. Section 9 of the DPDPA requires verifiable parental consent before a platform may process a child's personal data at all, and the DPDP Rules notified by MeitY build out a consent architecture rather than an access bar. That is the right instinct: reduce processing and exposure risk through consent and design defaults, not through switching off the service. New York's rules follow the same logic — verify age, restrict the feed and the 3 a.m. notification, but preserve access — and pair it with a genuine privacy safeguard the state proposals currently lack: age-verification data must be deleted immediately after use, and platforms must offer at least one non-government-ID method to prove age.

Why the design-default model travels better to India

An outright state-level ban invites two failure modes a design mandate avoids. First, it pushes enforcement toward exactly the identity-verification infrastructure India's own privacy law is trying to make optional — a hard age gate all but requires checking a government ID or Aadhaar-linked credential for every user, a far larger surveillance footprint than a consent-and-default regime that only kicks in once a platform meets an engagement threshold. Second, a ban that is unenforceable in practice — and neither Karnataka nor Andhra Pradesh has published how it would verify age at scale — trains an entire cohort of teenagers to route around it via VPNs or borrowed accounts, which is worse for child safety than a working consent flow, not better. It also invites the state to intervene again later with a stricter, less workable rule once the symbolic ban predictably fails to change behavior.

The more defensible path

India does not need to copy New York's statute wholesale — a state attorney general's rulemaking power and a central Parliament's are different instruments, and India's does not yet have a dedicated child-online-safety statute the way New York now does. But the underlying design choice is worth borrowing before the Delhi roundtable's proposals harden into law: regulate the algorithmic feed and the notification, verify age with privacy-preserving methods and immediate data deletion, and leave general access alone. That gives regulators a mechanism proportionate to the actual harm — compulsive, engagement-optimized use — without asking every Indian teenager to first prove their identity to a platform, or every state to invent an unenforceable ban a national service has no realistic way to comply with on a state-by-state basis.

Sources & Citations

  1. NY AG James: Final SAFE for Kids Act Rules
  2. NY Attorney General: Final SAFE for Kids Act Rules Released
  3. PRS Legislative Research: Digital Personal Data Protection Bill 2023 Summary
  4. TechCrunch: Karnataka Signals Intent to Ban Social Media for Under-16s
  5. MediaNama: Age Verification and Restricting Social Media for Children (Delhi, 31 July)