Published on:

January 2024

in:

Author/s:

Aparajita Bharti and Nikhil Iyer

How Do We Keep Young Digital Nagriks Safe Online?

How do we keep young digital nagriks safe online? This is a critical question which will have a long lasting impact on India’s citizenry in the decades to come. Is it possible to simultaneously uphold the goals of user privacy, and access and equity on the internet, while keeping children safe?

Instinctively, there is a preference to replicate the offline world’s gatekeeper approach. Like in a bar or a movie theater – check the ID of the person and deny entry if they are below the legal age (typically 18). Yet, this approach arguably doesn’t translate to the online world, when applied to services which children are legally permitted to access, as they create unwarranted hurdles. Put differently, is it necessary to deny access to a 15 year old wishing to learn a new language or a guitar, unless they provide documentary ID proof?

Under India’s Digital Personal Data Protection Act, 2023, every person below age 18 has to provide verifiable parental consent if they wish to access any online service. To satisfy this, every data fiduciary (platforms, services, etc.) has three obligations – verify the user’s age with reasonable accuracy as being below 18, ascertain the legitimacy of the relationship between the user and the parent or guardian, and record evidence of their latter’s consent.

However, this approach is inconsistent with India’s digital reality. According to the National Sample Survey (75th round, 2021), less than 40% Indian households are reported to be digitally literate – defined generously as even one person knowing how to use a computer and the internet. Digital literacy also tends to be better in lower age groups, and reduces among older populations. In a survey conducted by Delhi Commission for Protection of Child Rights (DCPCR) and Young Leaders for Active Citizenship (YLAC), over 80% respondents said their parents take their help in navigating the internet and digital devices.

To understand how online parental consent can be applied in India, we interacted with a range of stakeholders, including elected representatives, bureaucrats, technology company representatives, and digital literacy educators. A common thread across these conversations was around circumvention and control. Not only do adolescents and teenagers regularly find roundabouts to escape constant parental oversight due to a higher sophistication in use of technology, they are also enablers in low income households for their parents, often transacting digitally on their behalf. This is especially true where a shared device is used among many family members. In fact, shared device usage is not just limited to low income households, many early adolescents between the age of 12-14 even in higher income households use their parents’ phones. Another practical consideration is the paucity of time for working parents. Hard verification of parental consent can prove to be a logistical nightmare, if parents have to share consent for every single digital service the child accesses on a daily basis coupled with frequent changes to platforms that may require fresh consent. 

We must acknowledge these realities as we start implementing the DPDP Act 2023. Globally, countries are experimenting with different approaches to ensure equity and safety for children, factoring in these practical difficulties. These include allowing data fiduciaries to use alternate age assurance methods such as facial recognition, capacity testing, existing account holder confirmation, etc., instead of solely relying on hard identity document based verification, and exploring age verification at different points in the value chain. For example, the UK recently outlined a potential role for app stores in age verification in its Online Safety Act. India must also adopt a whole-of-ecosystem approach rather than placing the responsibility solely on parents to ensure the safety of children.

To achieve these goals, under its rule-making powers, MEITY can consider publishing guidance for platforms to assess the risk their service poses to a child – and prescribe corresponding age assurance mechanisms. Apart from age assurance, the guidance can also suggest default settings for privacy, purpose limitation, guardrails around profiling tracking, data minimisation, etc.  

This may lead to two outcomes – high risk services which children are legally prohibited from accessing, such as adult media content, alcohol, etc. will continue to remain out of bounds; meanwhile, other services, such as skilling and educational platforms, gaming, social media, etc. will be able to use less intensive age assurance mechanisms corresponding to the degree of risk associated with their service specifically. As these risk assessments will be open to public scrutiny by parents, child rights groups etc., it may align the incentives of platforms to act in the best interests of the child. If any platform fails to provide adequate protection to child users in violation of MEITY’s guidance, the Data Protection Board can entertain complaints against them. 

Protecting children online is one of the thorniest problems that regulators have to contend with in internet governance. Every age assurance/verification mechanism has its pros and cons, however at the minimum we must allow for flexibility in age assurance mechanisms to ensure no child gets left behind and correspondingly create incentives for platforms to protect children’s privacy by design. 

Aparajita Bharti and Nikhil Iyer work at TQH consulting, a public policy and research consulting firm. They are co-authors of a discussion paper “Navigating Children’s Privacy and Parental Consent Under The DPDP Act 2023” by TQH

X (Twitter)
LinkedIn