Age Gating, Indian-Style

Last week, Meta announced it will shortly begin testing the voluntary addition of a date of birth for WhatsApp users in India, its biggest market (with over 600 million users). The trial forms part of an early-stage effort to explore privacy-focused ways of meeting future regulatory obligations in that country without disrupting the core WhatsApp experience. The obligations in question arise from India’s Digital Personal Data Protection (DPDP) Act of 2023, which will require social media platforms to obtain verifiable parental consent before processing personal data belonging to anyone under age 18. Implicit in this requirement is the need to ascertain (and verify) the age of any user if the platform is to comply.

In recent months, Meta has also been engaged with Indian regulators over measures to strengthen child safety across its platforms and the proposed introduction of WhatsApp usernames, which officials have reportedly asked the company to defer over concerns about impersonation and digital fraud. The social media giant has additionally faced questions over its content moderation practices across Facebook, Instagram, and WhatsApp.

The WhatsApp experience in India will be watched with interest by regulators and legislators in other jurisdictions such as Australia, the United Kingdom, France, and various US states. In America, some states have already imposed age-gating rules on social media platforms while others are considering such measures. A significant challenge for these efforts is how to verify that user-supplied age information is indeed correct. In Australia, this has proved especially problematic, with under-16s providing false information (using someone else’s details, for instance) and engaging in various subterfuges to fool photographic age detection software.

India has a significant apparent advantage in identity verification, with its sophisticated biometric identity system, Aadhaar. Originally developed to supply unique identification numbers for the delivery of government subsidies, benefits, and services, Aadhar is now administered by the Unique Identification Authority of India. It enables governments, businesses, and other parties to trust that the person they are transacting with is truly who they claim to be. Basic information about a person is collected, providing multiple channels for authentication using biometrics such as fingerprints and iris scans.

In practical terms, while the DPDP Act requires verifiable parental consent before platforms process children’s data, it does not specify a mechanism for the purpose. However, as was made clear at a recent meeting of experts on India’s child social media policy, all age verification in India effectively means using the Aadhaar system. The draft DPDP rules of 2025 propose two means of verifying children’s ages on social media: “an Aadhaar-linked DigiLocker system, in which a parent’s Aadhaar credentials are associated with their child’s account so that platforms can send a yes-or-no age query, or an electronic token system in which a government ID is converted into an encrypted credential that shares only name and age.”

The DigiLocker arrangements appear to offer superior data protection, as they enable the required verification to be achieved without the need to share any underlying personal information with the platforms. However, this system

does not eliminate metadata trail. A platform that pings DigiLocker about a user’s age now has a record that it queried India’s national identity infrastructure on behalf of that user, at that time, on that platform. At population scale—1 billion internet users—that query log is a surveillance database even if no individual Aadhaar number is stored by the platform.

So DigiLocker is by no means without ongoing concerns about data privacy. Furthermore, there are also concerns that using an Aadhaar-based system places the state as the intermediary between users and platforms and is a form of “mission creep”: a system developed for a narrow government subsidy-distribution purpose growing far beyond that original use.

The WhatsApp test of user age self-declaration, based potentially on the softer technology-enabled verification checks used in Australia, thus represents a push against the prevailing Indian trend for government-intermediated identity verification. Whether WhatsApp can satisfy strict Indian safety regulations, given high rates of bypass observed in Australia, while operating at sufficient scale remains an open question. On the other hand, the Indian experience with digital identity verification using Aadhaar may prove informative if the need to ensure child social media safety is seen to be sufficiently important to necessitate the use of state-mediated identity tools to enforce compliance—even if those tools come with potential risks to privacy.

The post Age Gating, Indian-Style appeared first on American Enterprise Institute – AEI.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *