State Social Media Bans for Children Face Constitutional Firewall: Jurisdiction, Enforcement, and Age Verification
Andhra Pradesh and Karnataka announced bans on social media use for children — Andhra for under-13 and Karnataka for under-16 — triggering immediate debate about whether states have the constitutional authority to regulate internet platforms.
Legal experts pointed out that internet and telecommunications regulation falls exclusively under the Union List (Entry 31, Seventh Schedule), placing such regulation outside state legislative competence.
Questions were also raised about technical enforceability: age verification systems are imperfect, easily circumvented, and involve tradeoffs between child safety and user privacy.
The Union Minister for Electronics and IT stated the central government was already discussing age-based restrictions — implying the Centre, not states, is the appropriate regulatory actor.
Social media platforms like Instagram, YouTube, and Snapchat operate under central regulation (IT Act, 2000 and IT Rules, 2021) and respond to central government orders — not state government notifications.
Centre-State Legislative Relations: Article 246 and the Seventh Schedule
The constitutional division of legislative powers is the primary obstacle to state-level internet regulation.
Even if Karnataka or Andhra Pradesh enacts a state law mandating social media platforms to ban under-age users, such a law would be ultra vires the Constitution — platforms have no obligation to comply with state mandates on internet regulation, only with central government orders under the IT Act.
IT Act 2000: Section 69A and Blocking Powers (Central Government Only)
The architecture of India's internet regulation framework concentrates regulatory power entirely in the central government.
State governments cannot order platforms to block under-age users. Any enforceable mechanism — such as platform-level age gates or access restrictions — would require the Centre to issue directions under Section 69A or through an amendment to the IT Rules.
Age Verification: Technical Challenges and Privacy Tradeoffs
Even if legislative competence existed, technically enforcing an age-based social media ban raises significant practical and rights-based challenges.
Key Details
- Age assurance methods range from self-declaration (weakest; easily bypassed) to document-based identity verification (strongest; raises data privacy concerns) to inferred age estimation via facial recognition or behavioural patterns (emerging; accuracy disputed).
- The DPDP Act, 2023 (Section 9) mandates "verifiable parental consent" for processing children's data, but does not specify the verification method — leaving the technical standard to be determined by DPDP Rules, 2025.
- DPDP Rules, 2025 require platforms to implement age verification mechanisms but do not mandate a specific technology — giving platforms flexibility while creating an accountability obligation.
- Privacy concern: Document-based age verification (e.g., Aadhaar-based) creates large databases of user identity linked to platform use — raising surveillance and data breach risks.
- Children can bypass age verification by lying, using a sibling or parent's account, or using VPNs — technical measures alone cannot guarantee compliance.
- Australia's approach: placed legal obligation on platforms (not users) to ensure age compliance, with platforms facing fines; shifted responsibility from individuals to corporations.
The "ban first, figure it out later" criticism reflects a genuine policy sequencing problem — without a robust, privacy-respecting age verification infrastructure, even a constitutionally valid central law would struggle with enforcement. States announcing bans face this challenge amplified by their lack of legal authority over platforms.
Digital Personal Data Protection Act, 2023: Section 9 and Children's Data
The DPDP Act provides the existing national framework most directly relevant to children's social media safety.
The DPDP Act already mandates parental consent for all under-18s — a stronger protection than what Karnataka (16) or AP (13) propose. The state bans are partly addressing a gap in enforcement, but enforcement of the DPDP Act itself lies exclusively with the central DPBI. States proposing their own parallel bans risk constitutional invalidity while the central framework remains underenforced.
- Article 246(1): Exclusive Parliamentary competence over Union List subjects — state laws on Union List = void.
- Entry 31, Union List: "Posts and telegraphs; telephones, wireless, broadcasting and other like forms of communication" — includes internet.
- IT Act, 2000: Section 69A — central government blocking power (upheld in Shreya Singhal v. Union of India, 2015).
- IT Rules, 2021: Govern Significant Social Media Intermediaries (50 lakh+ users); no state-equivalent rules.
- DPDP Act, 2023: Section 9 — parental consent for processing children's (under-18) data; no targeted advertising of children.
- DPDP Rules, 2025: Age verification and parental consent workflow obligations on platforms.
- Telecommunications Act, 2023: Replaced the Indian Telegraph Act, 1885; governs telecom under Entry 31.
- Karnataka proposed ban: under-16 years; announced by CM Siddaramaiah (2026 state budget).
- Andhra Pradesh proposed ban: under-13 within 90 days; 13–16 under consideration.
- Australia's ban: under-16 (national legislation, 2025); fines up to AUD 49.5 million for platforms.
- MeitY: confirmed Centre is examining age-based restrictions at national level (March 2026).
- Data Protection Board of India (DPBI): central enforcement body under DPDP Act.