On September 14, Family and Social Services Minister Mahinur Özdemir Göktaş said Turkey is building an online age-verification system on e-Devlet, the national government-services portal, to enforce the country's new ban on social media for children under 15. Turkish Minute reports that the system is meant to confirm a user's age without disclosing their underlying identity information to the platforms. The ban takes effect on November 1, 2026.
The strongest case for the law
The case for acting is serious. Göktaş justified the ban on health grounds, saying children spend more than three and a half hours a day on social media on average and linking heavy use to disrupted sleep, anxiety and depression. Parliament passed the measure on April 22, 2026, as Law No. 7578, and the TBMM legislative record shows it was published in the Official Gazette on May 1 (Issue 33240). The Next Web reports it followed a school shooting about a week earlier, and that President Erdoğan blamed digital platforms for it. Parents who cannot supervise every app have a fair claim that platforms built around engagement should carry some duty toward minors. A six-month transition period also gives companies time to prepare, which is better than a surprise cutoff.
What the law actually does
The legislation is not a standalone "gaming law". The TBMM bill record shows it is an omnibus Social Services amendment bill, which also covers parental leave and foster care, with a child-protection-in-digital-spaces component. As the law firm Gün + Partners summarises it, the digital provisions amend Internet Law No. 5651. Social media providers must stop serving under-15s and verify age. The regulator, BTK, gains new sanctions: it can bar advertisers from dealing with non-compliant platforms and can restrict traffic bandwidth. BTK is also to issue secondary regulations covering age classifications, parental controls and platform obligations. Those regulations will decide most of what the ban means in practice.
Platforms must also give 15-to-17-year-olds age-differentiated services with parental controls over account settings, purchases and usage time. Foreign gaming platforms with more than 100,000 daily Turkish visitors must appoint a local representative.
Where the design is better than most
The e-Devlet approach deserves credit on privacy. Most age-assurance regimes push platforms toward facial scans, ID uploads or third-party data brokers. The result is a honeypot of sensitive data, a risk the Electronic Frontier Foundation has highlighted in its analysis of Meta's US settlement, where it warned that mandatory age assurance "seriously threatens online anonymity and privacy for everyone". A state-run token that says "over 15" and passes nothing else to the platform is a narrower design. Bianet describes a model in which users can keep nicknames and their ID numbers are not shared with platforms.
The question is whether that promise holds. The verifier is the state itself. Even if the platform never sees an identity, the government's portal can log every verification request. Bianet reports that freedom-of-expression groups have already raised "mass surveillance" concerns about the identity system. Whether e-Devlet retains request logs, and for how long, is a question the BTK regulations should answer in writing before November 1. Unwritten assurances are not a safeguard in a country where anonymous speech has legal consequences.
The enforcement toolkit is the real risk
The privacy design does not address the second problem: what the state can do to platforms that fall short. Bandwidth throttling and advertiser bans are blunt tools. They hit every user, adult or child, on a platform at once. The Next Web notes that Turkey has previously blocked Instagram and restricted platforms during the 2025 protests that followed the jailing of Istanbul mayor Ekrem İmamoğlu. It says the new law "expands and formalises" the infrastructure through which the government controls what people can access. That is the analyst's judgment rather than a finding of fact, but the precedent is documented.
A child-safety rule that can be enforced by degrading a service for millions of adults invites use as a political lever. The CHP, the main opposition party, voted against the measure, arguing children should be protected "not with bans but with rights-based policies", according to the same report.
What proportionate implementation looks like
The ban itself is a blunt instrument, and the evidence that a flat age cut-off improves teen wellbeing is contested. But it is now law, so the useful question is how to narrow its harms. Three steps would help:
- Publish the e-Devlet privacy terms. BTK's regulations should state that verification logs are not retained beyond the transaction, are not linkable to the platform or account, and cannot be used for other purposes.
- Make sanctions graduated and reviewable. Throttling should come only after notice, a chance to cure, and a court-reviewable decision, and should be targeted at the non-compliant service rather than open-ended.
- Keep the 15-to-17 tier light. Age-differentiated services should not become a licence for platforms to over-remove lawful content about health, sexuality or politics for teenagers out of fear of penalties.
Turkey has chosen a privacy-preserving verification architecture over a data-hoarding one, which is a real point in its favour. The remaining test is procedural: whether the secondary regulations keep the state's own hands out of users' data and enforcement proportionate. If the regulations leave both open, the design credit will not offset the enforcement risk.