Now a staple of our daily lives, social media platforms are raising critical legal issues, chief among them the protection of minors and their fundamental rights. Australia led the way in 2025 by becoming the first country to ban social media for under-16s. In the US, Meta reached a landmark $17 billion settlement last August to resolve a lawsuit accusing it of fueling social media addiction among children. Meanwhile in Europe, the Commission marked a major milestone on 17 September 2026, with the introduction of the EU KIDS Act, designed to restrict children’s access to social media platforms across the EU.
The Lexing® network members provide a snapshot of the current state of play worldwide.
The following countries have contributed to this issue: Belgium, France, Germany, Greece, India, Mexico, New-Zealand, South Africa, and USA.
FREDERIC FORSTER
Executive VP of Lexing® global network
South Africa does not have one law specifically regulating social media. Instead, what people and businesses do on social media platforms is governed by several existing laws.
These laws protect freedom of expression while also addressing privacy, defamation, hate speech, harassment, cybercrime and harmful online content. This means social media is not a legal free-for-all: the same rights and responsibilities that apply offline can also apply online. South Africa does not have a specific social media law but there are many laws of general application.
The Constitution
Section 16 of the Constitution of the Republic of South Africa, 1996 protects freedom of expression, including the freedom to receive and share information and ideas. Importantly, South African law refers to expressionrather than simply speech, giving the right a broad scope.
However, freedom of expression is not absolute. The Constitution excludes certain forms of expression, including propaganda for war, incitement of imminent violence and certain advocacy of hatred that constitutes incitement to cause harm. Social-media expression must also be balanced against other constitutional rights, particularly dignity, privacy and equality.
Hate speech and harassment
The Promotion of Equality and Prevention of Unfair Discrimination Act 4 of 2000 (PEPUDA) regulates hate speech based on protected grounds such as race, gender and ethnicity.
The Protection from Harassment Act also applies to electronic communications. This means people experiencing cyberstalking, threatening messages or other forms of online harassment may seek a protection order.
Defamation
South African common-law defamation principles apply to social media. A claimant must generally show that defamatory material concerning them was published. Once this is established, wrongfulness and intention are presumed, subject to defences such as truth and public benefit, protected comment and reasonable publication.
These principles apply to content published online, including social media posts, comments, reviews, blogs, videos and podcasts. However, courts must balance a person’s right to dignity and reputation against the right to freedom of expression.
Protection of Personal Information Act (POPIA)
POPIA (1) regulates how personal information is processed in South Africa. It can apply when personal information is collected, used, stored, shared or disclosed through social media.
Businesses using social media for marketing, customer engagement or other commercial purposes therefore need to consider their POPIA obligations, particularly when handling users’ personal information.
Cybercrimes Act
The Cybercrimes Act 19 of 2020 addresses more serious forms of unlawful online conduct. It creates offences relating to unlawful access to computer systems and data, cyber fraud and unlawful interference with data.
It also criminalises specified harmful communications, including certain threats of violence or damage to property, as well as certain non-consensual disclosures of intimate images. What appears to be “just posting” online can therefore sometimes carry criminal consequences.
Films and Publications Act
The Films and Publications Act 65 of 1996 extends South Africa’s content-regulation framework into the online environment. It regulates aspects of online distribution and harmful or prohibited content, with particular protections relating to children.
Electronic Communications and Transactions Act (ECTA)
The Electronic Communications and Transactions Act 25 of 2002 (ECTA) establishes conditional limitations on liability for qualifying service providers performing functions such as hosting, caching and providing information-location tools. It also contains provisions relevant to notice-and-takedown procedures.
This is important for social media because South African law distinguishes between the person who creates unlawful content and the circumstances in which an intermediary may be protected from liability for hosting or providing access to that content.
Will South Africa Ban Social Media for Children?
Unlike countries such as Australia, South Africa currently has no general social-media age ban.
Communications and Digital Technologies Minister Solly Malatsi has questioned whether age bans are the right approach for South Africa, particularly because children may misrepresent their age or bypass restrictions (2).
Instead, the Minister has supported stronger enforcement of existing online-safety laws, better digital literacy for children, parents and schools, and greater responsibility for social-media platforms. He has also raised issues such as stronger age-verification measures and labelling AI-generated content as part of the broader discussion around online safety. (3)
*****
(1) The Protection of Personal Information Act 4 of 2013. Available at: https://popia.co.za/
(2) Minister Solly Malatsi: Government Social Media Summit. Available at:
https://www.gov.za/news/speeches/minister-solly-malatsi-government-social-media-summit-09-jul-2026
(3) Further Information:
https://www.michalsons.com/blog/category/social-media-law
https://www.michalsons.com/focus-areas/social-media-law
JOHN GILES
&
TANIKA UPASANI
Germany is currently engaged in an intense debate on introducing a statutory minimum age for the use of social media. Unlike Australia, which in November 2024 introduced a ban for children under 16, Germany has so far relied on a differentiated approach combining EU law, federal law, and state (Länder) law, accompanied by a lively political and constitutional discussion.
EU Legal Framework: The Digital Services Act
The European Digital Services Act (DSA) (Regulation (EU) 2022/2065) constitutes the central legal framework. Art. 28(1) DSA requires providers of online platforms accessible to minors to take appropriate and proportionate measures to ensure a high level of privacy, safety, and protection. Art. 28(2) DSA prohibits profiling-based advertising directed at minors. The DSA is designed as a fully harmonising regulation – Member States may not, in principle, adopt stricter national rules within its scope of application.
The European Commission specified these obligations in July 2025 throughGuidelines pursuant to Art. 28(4) DSA (COM(2025) 4764 final). In addition, in April 2026 the Commission adopted Recommendation (EU) 2026/1035 establishing a common EU framework for privacy-preserving age verification technologies, promoting the use of EU-wide interoperable solutions based on the EUDI Wallet. In July 2026, an expert panel on children’s online safety recommended that unsupervised social media use should only be permitted from the age of 13 across the EU; the Commission intends to present a legislative proposal in autumn 2026.
National Law in Germany
At the national level, the protection of minors on social media is addressed by several statutes:
Section 24a of the Youth Protection Act (1) specifies Art. 28(1) DSA and sets out structural precautionary measures that platform providers must implement, including notice-and-action mechanisms, technical means of age verification, and age-appropriate default settings. The Federal Agency for the Protection of Children and Young People in the Media (2) monitors compliance and may, pursuant to Section 24b JuSchG, order specific measures where precautions are insufficient.
The Interstate Treaty on the Protection of Minors in the Media (3), concluded among the federal states, supplements this system: Section 5 JMStV obliges providers of content that may impair the development of minors to implement technical access restrictions (age thresholds: 6, 12, 16, and 18 years). The Sixth Interstate Treaty Amending Media Law (4), signed in March 2025, strengthens the interconnection of existing youth protection systems.
However, due to the country-of-origin principle (Art. 3(2) of Directive 2000/31/EC; Section 3(2) of the Digital Services Act Implementation Act, (5)), the JMStV has virtually no effect on foreign platform providers – i.e. Facebook, Instagram, TikTok, and YouTube (all established in Ireland). National youth protection measures that go beyond the DSA therefore remain largely ineffective vis-à-vis the market-dominant platforms.
The Legal Debate: Constitutional Concerns
A blanket social media ban for specific age groups faces significant constitutional hurdles in Germany:
6(2) of the Basic Law (Grundgesetz, (6) guarantees the primacy of parental upbringing over state regulation. The Basic Law assigns to the State merely a supervisory role (7), not the authority to decide on a blanket basis which media children may use. Constitutional scholars emphasise that the parents’ fundamental freedom to determine their children’s upbringing must not be undermined by sweeping state prohibitions.
5(1) GG (freedom of expression and information) is also seen as a limit: a general ban on social networks for minors would deprive them of their primary digital communication space and constitute a significant interference with their right to form and express opinions. The principle of proportionality requires that less restrictive means – such as promoting media literacy and more consistent enforcement of existing rules – are not available before resorting to an outright ban.
These concerns are counterbalanced by weighty child welfare arguments: the addictive potential, manipulative design elements (dark patterns), and harmful content often originate from the platform operators themselves. Existing protective duties are widely regarded as de facto
Political Developments
In March 2026, the SPD proposed a three-tier model: a complete ban for children under 14, a youth version of platforms for the 14–16 age group, and an opt-in model from age 16. Federal Chancellor Friedrich Merz and Family Minister Karin Prien have also signalled openness to stricter rules. Both sides, however, favour a European solution, as the EU Commission holds primary legislative competence over the regulation of large platforms.
Conclusion
Germany is currently not pursuing a national go-it-alone approach. The existing regulatory framework rests on Art. 28 DSA, the Youth Protection Act (JuSchG), and the Interstate Treaty on the Protection of Minors in the Media (JMStV). A general statutory minimum age is presently precluded by the full harmonisation effect of the DSA, the country-of-origin principle, and constitutional concerns. The debate therefore focuses on more consistent enforcement of existing EU law and on a potential expansion of the DSA by the European Commission.
*****
(1) Jugendschutzgesetz (JuSchG)
(2) Bundeszentrale für Kinder- und Jugendmedienschutz (BzKJ)
(3) Jugendmedienschutz-Staatsvertrag (JMStV)
(4) 6. MÄStV
(5) Digitale-Dienste-Gesetz (DDG)
(6) Grundgesetz (GG)
(7) Wächteramt
SINA BADER
germany@lexing.network
In Belgium, minors’ use of social media is not subject to a general prohibition based on a minimum age, comparable to the measures adopted or contemplated in certain other countries, such as Australia. The protection of young users instead relies on a combination of directly applicable European rules, Belgian data protection provisions and supervisory mechanisms entrusted to several authorities. Recent political and parliamentary initiatives nevertheless indicate that Belgium is also considering the introduction of a “digital age of majority” and the strengthening of age-verification requirements.
The principal applicable framework is the Digital Services Act, or “DSA”. This EU regulation applies, among other things, to social media platforms and requires platforms accessible to minors to implement appropriate and proportionate measures to ensure a high level of privacy, safety and security for minors. It also prohibits the display of advertising based on profiling where the platform is aware with reasonable certainty that the user is a minor.
The implementation of the DSA reflects the allocation of powers within Belgium. The Belgian Institute for Postal Services and Telecommunications — the BIPT — has been designated as Belgium’s Digital Services Coordinator. It acts in cooperation with the Conseil supérieur de l’audiovisuel for the French Community, the Vlaamse Regulator voor de Media for the Flemish Community and the Medienrat for the German-speaking Community. These authorities may receive complaints, conduct investigations and, within the limits of their respective powers, impose corrective measures or sanctions. In relation to very large online platforms, the European Commission retains a central supervisory role, in cooperation with the national coordinators.
The GDPR complements this framework. Belgium has set the relevant age at thirteen, from which a minor may, subject to the conditions laid down in Article 8 of the GDPR, consent independently to the processing of his or her personal data in connection with an information society service offered directly to that minor. This threshold of thirteen is, however, frequently misunderstood. It does not constitute a general “digital age of majority”, nor does it confer an automatic right to open an account on every social media platform. It relates solely to the validity of consent as a legal basis for the processing of personal data in a particular situation.
The political debate has nevertheless shifted towards stricter access rules. In July 2025, the Government of the Wallonia-Brussels Federation expressed its support for the introduction of an age limit harmonised at EU level, effective age-verification mechanisms and standards requiring interfaces that are safer, less addictive and respectful of privacy. This position also emphasises the role of media literacy and the support and guidance provided to young people. Several proposals for resolutions have also been tabled in the Belgian House of Representatives. These concern, in particular, effective age checks for access to social media and, more broadly, the use of social media by children and adolescents.
Pending the enactment of legislation giving effect to these debates, the absence of a general prohibition does not mean that operators active in Belgium are not subject to legal obligations. Platforms must determine whether their services are accessible to minors, assess the resulting risks, apply protective settings, refrain from advertising profiling of young users and be able to demonstrate the effectiveness of the measures adopted. Any age-verification mechanism must also comply with the principles of necessity, proportionality and data minimisation.
ALEXANDRE CASSART
belgium@lexing.network
Protecting young minors without sacrificing their fundamental freedoms: this is the complex equation facing French lawmakers. Striking a balance between child protection, privacy, and freedom of expression makes the digital regulation of minors a intricate legal and political challenge. While the Constitutional Council struck down the blanket social media ban for under-15s in its decision of 14 August 2026 (1)—objecting not to its underlying principle, but to the method chosen—the start of the new school year is marked by the expansion of the mobile phone ban to high schools. A French debate that fits into a broader European and international context, marked in particular by the European Commission’s adoption on 17 September 2026, of the EU KIDS Act (2)—a proposed regulation aimed at restricting access of social media platforms to children in the EU. Below is a breakdown of the key issues, legal constraints, and the roadmap set out for lawmakers to reconcile youth safety with fundamental rights.
1. The Constitutional Council’s Decision on Banning Social Media for Minors Under 15
The Constitutional Council does not view restricting minors’ access to social media as inherently illegitimate (3). On the contrary, it explicitly acknowledges that protecting the best interests of the child can justify certain limitations. However, it sets out a clear requirement for the French legislature: the broader the restriction, the greater the burden to prove that it is necessary, proportionate to the identified risk, and backed by adequate safeguards.
The Council’s partial invalidation rests on two complementary sets of considerations:
- first, the overly general and disproportionate nature of the ban in light of the freedom of expression and communication; and
- second, the lack of sufficient safeguards surrounding age verification processes with respect to the right to privacy.
This aligns closely with the European approach. The European Commission’s guidelines adopted under the Digital Services Act (DSA) (4) favor a risk-based logic, tailoring requirements according to the nature of the services and the specific harms involved. Rather than imposing a blanket solution on all services accessible to minors, they advocate for targeted interventions focusing on recommendation algorithms, autoplay functions, push notifications, and design features that foster excessive usage.
Consequently, a general ban is not legally impossible in all circumstances, but the Constitutional Council’s decision shows that it will be significantly harder to justify than a targeted regime. The Council specifically criticized the French mechanism for sweeping broadly over platforms that allow users to communicate or share content, without drawing sufficient distinctions based on features, content, service-specific risks, or existing protective measures. Any future French legislation would therefore be well-advised to differentiate more clearly based on the age of minors, the nature of the service, and, above all, high-risk functionalities.
In other words, the Council is not challenging the objective of protecting minors; it is challenging how the legislature chose to achieve it. This is a crucial distinction, as it leaves the door open for a new framework that is more targeted and better regulated.
Introducing parental opt-outs can enhance a framework’s proportionality by introducing a degree of individualization that accounts for the child’s specific situation and the exercise of parental authority. However, parental consent alone does not resolve all issues. A ban targeting vastly different services indiscriminately could still be deemed excessive, and parental opt-outs do not address the privacy concerns tied to age verification.
Regarding age verification, stringent safeguards are critical: data minimisation, strict separation between identity data and proof of age, purpose limitation, minimal retention periods (or no retention wherever possible), robust security, independent oversight, and effective appeal mechanisms.
The model developed at the European level is particularly compelling in this regard because it relies on a simple premise: the platform does not need to know the user’s identity or exact age; it only needs to know whether they meet the required age threshold. A trusted third party can verify the user’s age and pass only that confirmation to the platform.
While AI-based age estimation can reduce reliance on IDs, it shifts the problem rather than eliminating it. It raises concerns regarding accuracy, false positives, algorithmic bias, and—depending on the technology used—potentially intrusive processing of physical or biometric data. As a result, providing an alternative verification method and a functional remedy in case of errors is mandatory.
Ultimately, regulating specific functionalities appears legally sounder than banning an application in its entirety, provided the causal link between the feature and the risk is demonstrated. Rules targeting specific recommendation systems, autoplay features, persistent notifications, or other engagement-maximizing design mechanisms are far more directly connected to the harms lawmakers seek to prevent.
More broadly, this decision does not establish an absolute constitutional right for minors to access all social media platforms. Instead, it should be read as a roadmap for legislators: identify risks precisely, target specific services or features, proportion measures according to age, and embed robust safeguards for age verification and privacy protection directly into the text of the law.
While the French Constitutional Council’s ruling carries no direct legal authority over foreign courts, its reasoning could easily be echoed internationally. The competing rights at play are not unique to France: freedom of expression, privacy, personal data protection, and children’s rights are all anchored in the EU Charter of Fundamental Rights (5), while Articles 8 and 10 of the European Convention on Human Rights (ECHR) (6) similarly protect privacy and freedom of expression. The Council’s test—namely assessing the necessity and proportionality of the interference with fundamental rights—is broadly transferable, even if foreign jurisdictions apply it within their own distinct legal frameworks.
2. Banning Mobile Phones in High Schools
Law No. 2026-813 of 24 August 2026 (7), published on 24 August, extends the ban on mobile phones and other electronic communication equipment to high schools starting in the 2026–2027 academic year.
Previously, Article L. 511-5 of the French Education Code (8) mandated this prohibition in primary and middle schools, while high schools were left to decide whether to implement it through their internal rules. Going forward, the prohibition applies universally to high schools.
However, individual schools retain significant operational flexibility: their internal rules must define the practical procedures for enforcing the ban, as well as exceptions (e.g., for educational purposes). The law also explicitly maintains the right to use necessary devices for students with disabilities or debilitating health conditions. Additionally, specific rules may be set out by internal regulations for students enrolled in higher education programs hosted within high schools (such as BTS or preparatory classes for Grandes Écoles).
It is worth noting that this specific provision was not explicitly declared compliant with the Constitution through dedicated judicial review. The Constitutional Council was petitioned specifically regarding Article 1 (the social media ban for under-15s) and did not raise ex officio issues regarding the law’s remaining provisions. Thus, while the high school phone ban was not struck down, it has not undergone formal constitutional vetting either.
Finally, the administrative circular of 2 July 2 2026, preparing the rollout of this ban was challenged before the Conseil d’État in emergency proceedings. In an order dated 21 July 2026, the summary judge declined to suspend its execution, finding that the legal condition of urgency was not met. However, this procedural ruling does not settle the case on its merits and does not prejudge any future assessment regarding the legality of the measure.
*****
(1) Conseil constitutionnel, Decision No°2026-911 DC of 14 August 2026: https://www.conseil-constitutionnel.fr/sites/default/files/as/root/bank_mm/decisions/2026911dc/2026911dc.pdf
(2) Press release from the European Commission Representation in Franc, 17 Sept. 2026, EU KIDS Act: Commission proposes to restrict access of social media platforms to children in the EU: https://france.representation.ec.europa.eu/informations-et-evenements/informations/eu-kids-act-la-commission-propose-de-restreindre-lacces-des-plateformes-de-medias-sociaux-aux-2026-09-17_fr?prefLang=en&etrans=en ; Proposal for a Regulation of the European Parliament and of the Council, EU KIDS ACT – ‘EU Keeping Internet Digital Spaces Accountable and Trustworthy, 17 Sept. 2026, COM(2026) 681 final: https://digital-strategy.ec.europa.eu/en/library/proposal-eu-kids-act-eu-keeping-internet-digital-spaces-accountable-and-trustworthy
(3) Virginie Bensoussan-Brulé, Réseaux sociaux et mineurs : la décision du Conseil constitutionnel trace une feuille de route pour les législateurs européens, www.lexing.law, 8 August 2026, https://www.lexing.law/avocats/reseaux-sociaux-et-mineurs-la-decision-du-conseil-constitutionnel/2026/08/18/
(4) Guidelines on measures to ensure a high level of privacy, safety and security for minors
online, pursuant to Article 28(4) of Regulation (EU) 2022/2065, https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-protection-minors
(5) Charter of Fundamental Rights of the European Union, 2012/C 326/02, https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:12012P/TXT
(6) Convention for the Protection of Human Rights and Fundamental Freedoms as amended by Protocol No. 15, https://rm.coe.int/1680a2353d
(7) Law No. 2026-813 of 24 August 2026 aiming to protect minors from the risks associated with social media use, https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000054743001
(8) Article L. 511-5 of the Education Code, https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000037286581
VIRGINIE BENSOUSSAN-BRULÉ
france@lexing.network
Social media in Greece are not governed by a single legislative instrument. Their regulation results from the combined application of EU and national rules concerning digital services, audiovisual content, the protection of minors, advertising and consumer protection. Data protection, intellectual property and civil or criminal liability remain relevant but cannot be examined comprehensively within this brief overview.
The principal framework governing social media platforms is the Digital Services Act (1). The DSA does not itself determine which content is illegal. Instead, it requires platforms to provide mechanisms through which illegal content may be reported, explain decisions restricting content or accounts and offer internal complaint-handling procedures (2).
Very large online platforms are subject to additional obligations to assess and mitigate systemic risks arising from, among other matters, illegal content, adverse effects on fundamental rights and threats to the protection of minors (3).
Where social media services include a significant audiovisual element, Law 4779/2021 also applies. Video-sharing platforms under Greek jurisdiction must adopt appropriate measures to protect minors from content that may impair their physical, mental or moral development. Such measures may include age-verification systems, parental controls and reporting or complaint-handling mechanisms, under the supervision of the NCRTV (4).
Further to the above, advertising on social media must be readily identifiable. The DSA prohibits deceptive or manipulative interface designs (“dark patterns”) and requires platforms to identify advertisements and the persons on whose behalf they are displayed (5). It also restricts profiling-based advertising using sensitive data and advertising directed at minors (6).
Influencers and advertisers are separately required to disclose sponsored posts, affiliate arrangements, gifts and other commercial relationships clearly and prominently. Concealing the commercial purpose of content may amount to an unfair commercial practice or misleading omission (7). Additional restrictions apply in regulated sectors, including tobacco, gambling and medicinal products. For example, advertising prescription-only medicinal products to the general public is prohibited (8).
*****
(1) Regulation (EU) 2022/2065 – DSA
(2) Articles 16, 17 and 20 DSA
(3) Articles 33–35 DSA
(4) Article 32, Law 4779/2021
(5) Articles 25–26 DSA
(6) Articles 26(3) and 28(2) DSA
(7) Articles 9c–9e and Annex, point 11, Law 2251/1994
(8) Article 120(1)(a), Joint Ministerial Decision D.YG3a/G.P. 32221/2013
GEORGE BALLAS
&
NIKOLAOS PAPADOPOULOS
Social media regulation in India is based on a conditional safe harbour framework.
The Information Technology Act, 2000 (the “IT Act”) originally provided intermediaries broad immunity, requiring platforms only to remain neutral and respond when notified. This regime was built in times when intermediaries tended to operate like “pipes” carrying content.
As the nature and role of intermediaries evolved, and with the fast spread and penetration of social media channels, regulatory focus moved from the role played by the intermediary to the harms, or potential harms, caused.
Now, immunity for intermediaries, and particularly social media intermediaries, is qualified and conditional. There are due diligence mandates, compliance and grievance redressal requirements, frameworks around synthetic media, AI-generated content and misinformation-related duties, and expanded takedown and information-seeking powers granted to governmental authorities.
Statutory Foundation: The Information Technology Act, 2000
The IT Act defines an “intermediary” to encompass any person or entity that, with respect to any electronic record, receives, stores, or transmits that record or provides any service with respect to that record on behalf of another person. This definition covers network service providers, internet service providers, web-hosting services, search engines, and, most importantly, social media platforms.
Intermediary safe harbour is provided under Section 79 of the IT Act. Section 79 provides that an intermediary shall not be liable for any third-party information, data, or communication link hosted or made available on its network. It applies only where three (3) conditions are jointly satisfied (1): the intermediary’s function is limited to providing access to a communication system over which third-party information is transmitted, stored, or hosted; the intermediary does not initiate the transmission, select the receiver, or select or modify the information transmitted; and the intermediary observes such due diligence as the Central Government may prescribe. Under Section 79(3), safe harbour protection is expressly forfeited if the intermediary conspires, abets, or aids in the commission of an unlawful act, or if, upon receiving actual knowledge or notification of unlawful material, it fails to expeditiously remove or disable access to that content.
Judicial Interpretation: The Landmark Shreya Singhal Ruling
The scope and enforceability of the intermediary safe harbour were authoritatively settled by the Supreme Court of India in the landmark ruling of Shreya Singhal v. Union of India. (2) The Supreme Court, while striking down Section 66A of the IT Act, also read down Section 79(3) to ensure that intermediaries are not forced into the role of private censors determining the illegality of speech; rather, the ‘knowledge’ referenced in the provision requires a court order or an official notification from the appropriate government or its authorised agency.
The Information Technology Rules, 2021: A Tiered Governance Framework
Subsequently, the Central Government notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (the “Intermediary Rules. The Intermediary Rules introduced a differentiated classification of digital platforms based on functionality and user base:
- Social Media Intermediary (“SMI”): These are intermediaries that primarily or solely enable online interaction between two or (2) more users, and allow them to create, upload, share, disseminate, modify, or access information using their services; and
- Significant Social Media Intermediary (“SSMI”): These are social media intermediaries having registered Indian users above a specified threshold, currently prescribed at five (5) million registered users. (3)
Baseline Due Diligence for All Intermediaries (Rule 3)
To maintain safe harbour immunity, all intermediaries, including SSMIs, must comply with the baseline due diligence obligations set out in Rule 3:
- User Terms and Content Prohibitions: Intermediaries must prominently publish terms of use, privacy policies, and user agreements informing users not to host, upload, or share prohibited content, including content which is defamatory, obscene, invasive of privacy, infringing, or harmful to minors material;
- Grievance Redressal Mechanism: Platforms must appoint a Resident Grievance Officer, acknowledge user complaints within twenty four (24) hours, and dispose of grievances within fifteen (15) days (or specified expedited timelines for urgent categories);
- Expedited Removal of Non-Consensual Intimate Content: Platforms must remove or disable access to non-consensual sexually explicit content, nudity, or impersonation within twenty four (24) hours of receipt of a complaint;
- Mandatory Takedown on Court or Government Order: Content identified under lawful court orders or government directions must be taken down within thirty six (36) hours; and
- Data Preservation: Intermediaries are obligated to preserve information and associated user records for at least one hundred and eighty (180) days following removal for investigatory and evidentiary purposes.
Additional Due Diligence for Significant Social Media Intermediaries (Rule 4)
Recognising their substantial market reach and potential impact on public discourse, Rule 4 imposes stringent additional compliance mandates upon SSMIs:
- Resident Key Personnel: SSMIs must appoint three (3) dedicated personnel who are Indian citizens and residents: a Chief Compliance Officer responsible for ensuring statutory compliance, a Nodal Contact Person available 24×7 for law enforcement coordination, and a Resident Grievance Officer;
- Monthly Compliance Reports: SSMIs must publish periodic compliance reports every month detailing the particulars of complaints received, action taken, and proactive monitoring and removal actions undertaken by the platform; and
- First Originator Traceability (3) SSMIs providing messaging services must enable the identification of the first originator of information within India pursuant to a judicial order or a lawful direction issued under Section 69 of the IT Act. This provision has been challenged in court on the ground that it is irreconcilable with end-to-end encryption and undermines user privacy, and the challenge remains pending.
Key Amendments and Emerging Regulatory Directives
Fact-Checking Mechanism and Judicial Scrutiny (2023 Amendment). In April 2023, the Ministry of Electronics and Information Technology (MeitY) amended Rule 3(1)(b)(v) of the Intermediary Rules to oblige intermediaries not to host or publish information in respect of any business of the Central Government identified as fake, false, or misleading by an officially notified Fact Check Unit. The constitutional validity of this amendment was challenged before the High Court of Bombay in Kunal Kamra & Ors. v. Union of India, where the provision was struck down as unconstitutional for violating the right to freedom of speech and expression and exceeding statutory rule-making authority under Section 79. The Union of India has appealed this ruling to the Supreme Court, which has issued notice but declined to stay the Bombay High Court’s judgment; the appeal remains pending.
Synthetically Generated Information and Deepfakes (2026 Amendment). On February 10, 2026, MeitY notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (the “2026 Amendment”). The 2026 Amendment introduces a tiered compliance framework regulating “Synthetically Generated Information” (“SGI”), including artificial intelligence-generated audio-visual content and deepfakes:
- All intermediaries that host, create, or enable the creation of SGI must implement baseline technical safeguards, including embedding permanent metadata and identifiers, prohibiting user tampering with SGI labels, and deploying reasonable technical measures to prevent the generation and dissemination of unlawful synthetic content (such as non-consensual sexually explicit deepfakes or child sexual abuse material); and
- SSMIs are subject to mandatory affirmative obligations, including integrating pre-upload user declarations for synthetic content, deploying automated technical verification and AI detection mechanisms to verify such declarations, and prominently labelling verified synthetic content prior to publication.
Conclusion
Social media regulation in India has moved from a passive safe harbour doctrine to a comprehensive, multi-tiered compliance regime, distinguishing ordinary from significant intermediaries, imposing time-bound grievance redressal, and now reaching into synthetic media.
*****
(1) Section 79(2), IT Act.
(2) Shreya Singhal v. Union of India, [2015] 5 S.C.R. 963
(3) Rule 4(2), Intermediary Rules.
(4) Kunal Kamra v. Union of India, 2024 SCC OnLine Bom 3086.
HARINI SUDERSAN
&
SATYAJIT NAIR
Mexico is moving from debate to policy design on the use of social media by children and adolescents, with the Federal Government preparing a proposal for Congress while international courts and governments increasingly scrutinize how digital platforms are designed (1).
Mexico is currently evaluating legislative and public policy measures aimed at strengthening the protection of children and adolescents in digital environments. The proposals under discussion focus on social media access by minors, age verification mechanisms, parental controls, protection from harmful content, cyberbullying prevention and enhanced safeguards for privacy and mental health.
The debate (2) regarding the regulation of social media for minors in Mexico involves a broad range of stakeholders. Members of the Mexican Federal Congress, particularly within the Senate and the Chamber of Deputies, have introduced and discussed legislative initiatives aimed at strengthening the protection of children and adolescents in digital environments. Technology companies operating social media platforms are also central actors, as prospective regulations may require them to implement age-verification systems, parental controls and additional safety measures. Parents, educational institutions, child protection authorities and civil society organizations likewise play an important role in shaping the discussion.
The current legislative debate intensified during 2026 through various congressional initiatives and reforms concerning digital environments and child protection. At the same time, the Mexican government announced a broader public discussion concerning artificial intelligence (3) and digital platform regulation, which includes social media and online protection of minors among its key subjects. These developments indicate that social media regulation is becoming an important component of Mexico’s evolving digital policy agenda (4).
The regulatory discussion is taking place at the federal level through Mexico’s legislative and policy-making institutions. Any eventual legal reforms would apply throughout the country and affect social media providers operating within the Mexican market. As a result, both domestic and international technology companies offering services to Mexican users could be subject to new compliance obligations.
The debate is driven by growing concerns regarding:
- Cyberbullying and online harassment.
- Exposure of minors to harmful or inappropriate content.
- Excessive use of social media and potential mental health implications.
- Protection of Personal Data and Privacy.
- Digital violence and online exploitation risks.
These concerns mirror developments observed in jurisdictions such as France, Australia and the United Kingdom, where governments have increasingly explored age-based restrictions and online safety obligations.
The proposals under discussion contemplate several possible regulatory mechanisms, including:
- Age-verification requirements.
- Parental consent systems.
- Enhanced parental controls.
- Digital safety obligations for platforms.
- Measures designed to prevent dissemination of harmful content affecting minors.
- Strengthened protection of children’s privacy and identity online.
Importantly, the scope and final content of any future regulation remain subject to the legislative process.
The overall objective is to create safer digital environments for children and adolescents while attempting to preserve legitimate rights such as freedom of speech (expression), access to information and participation in digital life.
The challenge for Mexican lawmakers will be finding an appropriate balance between protecting minors and avoiding disproportionate restrictions on digital rights, innovation and technological development. As in many jurisdictions worldwide, the key policy question is not whether children should be protected online, but how to achieve that protection effectively and proportionately.
Mexico is not yet among the jurisdictions that have enacted comprehensive social media bans for minors. However, current legislative proposals and public policy discussions demonstrate a clear movement toward stronger regulation of digital platforms and enhanced protection of children and adolescents online.
The coming years will determine whether Mexico follows the more restrictive approaches adopted in certain countries or develops a more balanced model centered on risk management, parental involvement and platform accountability. The regulatory framework remains under legislative discussion and some proposals referred to herein have not yet completed the legislative process. Therefore, this contribution reflects the current status of the debate rather than enacted law.
*****
(1) Why Should Mexico Have to Regulate Social Media?: https://mexicobusiness.news/tech/news/why-should-mexico-have-regulate-social-media
(2) Presidenta anuncia foros para crear propuesta de regulación del uso de plataformas digitales y redes sociales en niñas, niños y adolescentes | Presidencia de la República | Gobierno | gob.mx: https://www.gob.mx/presidencia/prensa/presidenta-anuncia-foros-para-crear-propuesta-de-regulacion-del-uso-de-plataformas-digitales-y-redes-sociales-en-ninas-ninos-y-adolescentes
(3) Coordinación de Comunicación Social – Senado recibe minuta con proyecto de decreto para tipificar creación de contenido íntimo con inteligencia artificial: https://comunicacionsocial.senado.gob.mx/informacion/comunicados/16046-senado-recibe-minuta-con-proyecto-de-decreto-para-tipificar-creacion-de-contenido-intimo-con-inteligencia-artificial
(4) CCE y Congreso crean Alianza Nacional Digital, buscan mejorar regulación de IA y ciberseguridad: https://www.eluniversal.com.mx/cartera/cce-y-congreso-lanzan-alianza-nacional-digital-buscan-mejorar-regulacion-de-inteligencia-artificial-y-ciberseguridad/
ENRIQUE OCHOA
DE GONZÁLEZ ARGUELLES
The Social Media (Age-Restricted Users) Bill is currently before Parliament. It was introduced on 23 October 2025 but has not yet proceeded to its first reading.
If enacted, the Bill would require providers of designated age-restricted social media platforms to take all reasonable steps to prevent persons under the age of 16 from holding accounts on those platforms. (1) A breach of this core duty could expose providers to a civil pecuniary penalty of up to $2 million. (2)
The intention of the Bill is to reduce online harm to children by placing greater responsibility on social media platform providers. It is intended to address concerns about cyberbullying, exposure to harmful content, online exploitation, and misuse of children’s personal information. Similar age-restriction regimes have recently been introduced overseas, reflecting a broader international trend toward regulating children’s access to social media.
What the Bill would do
Core obligation
If enacted, the Bill would require providers of designated age-restricted social media platforms to take all reasonable steps to prevent persons under the age of 16 from holding accounts on these platforms. The obligation is directed at account holding rather than passive viewing.
Platforms within scope
A platform would only be subject to the Bill if both of the following criteria are met:
- it must fall within the Bill’s concept of a “social media platform”; and
- it must be designated by regulations as an “age-restricted social media platform”.
The Bill defines a “social media platform” as an electronic platform where the “sole or primary purpose” is to enable online social interaction between two or more end users, and where users can interact with each other and post material. The Bill also clarifies that online social interaction includes sharing material for social purposes, and that advertising and revenue-generating activities are to be disregarded when assessing a platform’s “sole or primary purpose”. (3)
Age assurance
The Bill does not prescribe a particular method of age verification. Instead, it requires providers to take all reasonable steps to prevent persons under the age of 16 from holding accounts. Whether a provider has taken reasonable steps depends on what it was reasonably able to do at the relevant time, including:
- the privacy of the person under the age of 16; and
- the reliability of the method used to satisfy the provider that the person is not under the age of 16. (4)
Enforcement
The Bill provides for a civil enforcement regime, with proceedings determined on the balance of probabilities. A provider that breaches its core obligation may be liable to a civil pecuniary penalty of up to $2 million. In determining whether to impose a penalty, and the amount of any penalty, the court must have regard to matters including the nature of the breach, the provider’s conduct, and any steps taken to prevent or mitigate the breach. (5) The Bill also provides a statutory defence where the provider reasonably relied on information supplied by the person under the age of 16 in determining that they were not under the age of 16. (6)
Why the Bill matters
Social media platforms play a significant role in the lives of many young people. Policymakers have, however, expressed increasing concern about the potential risks associated with children’s use of social media, including exposure to harmful content, cyberbullying, and misuse of personal data.
The Bill forms part of a broader policy focus on strengthening protections for children online, including in relation to privacy. In parallel with the Bill, the Office of the Privacy Commissioner is progressing its Children’s Privacy Project, which is examining how digital services collect, use and disclose children’s personal information. Similar issues have also been considered by the Education and Workforce Committee in its inquiry into online harm affecting young New Zealanders.
Key takeaway
If enacted, the Bill would require designated age-restricted social media platforms to take all reasonable steps to prevent persons under the age of 16 from holding accounts. Businesses that operate interactive digital platforms or services should monitor the Bill’s progress, assess whether their services could fall within its scope, and consider what age assurance and compliance measures may be required if the Bill becomes law.
*****
(1) Social Media (Age-Restricted Users) Bill
(2) Social Media (Age-Restricted Users) Bill, section 10
(3) Social Media (Age-Restricted Users) Bill, section 5(3)(a) and (b)
(4) Social Media (Age-Restricted Users) Bill, sections 7 and 8
(5) Social Media (Age-Restricted Users) Bill, section 11
(6) Social Media (Age-Restricted Users) Bill, section 12
DAVID ALIZADE
While US consumer-protection law reaches deceptive conduct by advertisers and influencers, American courts routinely rejected claims for social media providers’ own liability, invoking statutory immunity. A recent $17.1 billion landmark settlement between Meta and 47 US states demonstrates that this shield of immunity is not impenetrable. With Congress deadlocked, states and courts — not Washington — are where the next chapter of social media regulation is most likely to be written in the United States.
This multi-billion-dollar settlement will force Meta to change the core of its business model, including changes to its platform, granting an independent auditor broad access to information, and enjoining Meta from making future false or misleading public statements regarding the efficacy of its safety features. The case tentatively settled mid-trial and still requires the trial court’s approval. Meta also seeks to condition part of its payment of damages on whether other social media titans agree to settle with states and make similar platform changes. That won’t end the litigation: In addition to this Meta trial, thousands of individual plaintiffs and hundreds of school districts’ claims are currently outstanding.
While this Meta settlement may be limited to liability for social media platforms, US law is not. For any websites that collect children’s data, biometric data, use addictive algorithmic-feed design — or make privacy, safety, or endorsement marketing claims that are not substantiated by hard data — many of the concepts discussed in this article may serve as a warning of expanding liability emerging in the United States. Recommendations on how best to protect against liability are summarized at the end of the article.
1. U.S. Federal Regulation of Social Media
Liability of Advertisers, Influencers, and Creators of Online Content: The FTC Act § 5 prohibits unfair or deceptive acts or practices. Aside from some states’ privacy and other consumer-based statutes, this is the principal hook for privacy misrepresentations, dark patterns, undisclosed endorsements, and safety claims. (1)
Provider Immunity: Federal publisher immunity has long shielded platform social media providers and publishers (“providers”) from liability for content posted by third-party users. (2) Pursuant to § 230, providers were generally viewed as publishers shielded from liability for good-faith hosting and moderation of social media websites that contain objectionable content or conduct arising from user-created posts. Predicated on free speech, this statutory immunity had long been impenetrable, subject only to express statutory exclusions providing narrow exceptions. (3) With the landmark Meta settlement, there can be no doubt that this immunity does not shield providers for their own design choices in operating their platforms.
Liability for Children’s Online Usage: The federal Children’s Online Privacy Protection Act (COPPA) regulates the collection, use, and disclosure of personal information from children under 13. (4) Statutory immunity is not a complete shield for online platform providers, who are still required to obtain verifiable parental consent before collecting personal information from pre-teen children, but only if the online services are either specifically directed at children or if the provider has actual knowledge of users under 13. In August 2026, the U.S. Department of Justice settled a $400 million claim against TikTok to resolve a COPPA claim. (5) While considerable, that settlement pales in comparison to the tentative $17.1 billion settlement announced by Meta just a week later. In addition to payment of penalties, Meta agreed to make material changes to its business model, including:
- a. Platform Changes:
- Mandatory safety updates will be implemented for all teenage users on Facebook and Instagram.
- Endless scrolling will be interrupted by a two-hour daily usage limit.
- Elimination of features that psychologists link to negative social comparisons, such as tallying the “like” button clicks.
- Age-verification tools and parental controls will be implemented.
- Usage limits from 12:00 a.m. to 6:00 a.m. and silence notifications from 10:00 p.m. to 7:00 a.m.
- b. Oversight: Appointment of an independent auditor with broad access to information and direct lines of communication to states’ attorneys general.
- c. Injunction: Meta is barred from making false or misleading public statements regarding the effectiveness of its safety features.
- d. Payment: Meta will initially pay $12 billion. It will pay an additional $5 billion if other social media providers Snap, TikTok, and YouTube also settle with the states with financial penalties and product changes. (6)
2. Tort-Based Design Defect and Failure to Warn Litigation
What was different about the Meta case that triggered a billion-dollar settlement tacitly acknowledging the expansion of liability, despite the statutory § 230 immunity? Relying on traditional tort theories of negligent design and failure to warn, together with the federal COPPA statute, a coalition of the majority of US states sued Meta in federal court, testing whether design-based claims can establish social media addiction. (7) “Social media addiction” involves claims of a compulsive, dopamine-driven urge that keeps users scrolling apps like Instagram — and crowds out schoolwork and relationships, particularly among children.
A. The Bellwether Meta Trial and Proposed Settlement
Opening statements began August 18, 2026, before Northern District of California U.S. District Judge Yvonne Gonzalez Rogers (“Judge Rogers”). The tentative settlement occurred after just two weeks of trial testimony. The eight-person jury was advisory only, with Judge Rogers retaining the power to make the ultimate determination, including the current issue of whether to approve the pending $17.1 billion settlement.
Advancing traditional tort theories of product design defect and failure to warn, the states argued Meta violated COPPA by collecting children’s data without consent. (8) California’s lead counsel told the jury that Meta’s business model could be summed up as: “hook the users, hold them for as long as they can, harvest their data, and then hide the truth from the public.” (9) Meta responded that the same internal research shows it was studying — not creating — the problem, pointing to its safety investments, under-13 removal efforts, and parental controls. (10)
B. Other Design-Defect Litigation
The Meta settlement may bring an end to other states’ litigation, but it is not the end of the potential liability exposure faced by Meta and other providers: Over 10,000 individual plaintiffs and over 800 school districts have also sued under similar design-defect and failure-to-warn theories. The cases are largely consolidated in multidistrict litigation in the Northern District of California, before Judge Rogers, the same court and judge as the bellwether trial. (11)
The first such case to reach a jury, K.G.M. v. Meta Platforms, Inc., produced a landmark verdict in Los Angeles in March 2026. The plaintiff alleged that infinite scroll, algorithmic recommendations, and autoplay were engineered to make her interact compulsively from childhood, causing anxiety and depression. Meta and Google argued they were immune for their curation choices and that any failure-to-warn claim failed because neither the plaintiff nor her mother had read the terms of use. The jury disagreed, finding that Meta and Google knew of the danger to children posed by their design features and failed in their duty to warn of such dangers. $6 million in total damages were awarded, in the first verdict holding platforms liable for addictive design. (12) Both companies are appealing.
3. State Laws
State efforts to regulate children’s social media use remain inconsistent, and courts previously struck down many such statutes on free speech or § 230 immunity grounds. California’s Age-Appropriate Design Code illustrates the volatility: a March 2026 Ninth Circuit ruling lifted the injunction on most of the law while leaving its data-use and “dark patterns” provisions blocked as unconstitutionally vague. Remanded for further proceedings, its ultimate reach remains unsettled. (13) Two other enacted California statutes also remain in litigation limbo: California’s Digital Age Assurance Act would require device operating systems to collect age information at setup and share an age-bracket signal with apps starting in 2027. (14) California’s SB 976, the Protecting Our Kids from Social Media Addiction Act, requires parental consent before minors receive algorithmically personalized feeds, key provisions having taken effect since January 2025. (15)
The Meta settlement is not the only billion-dollar recovery against Meta for privacy abuses. In 2024, Texas’ state attorney general obtained a $1.4 billion settlement in a biometric and cross-device data case premised on a failure to obtain users’ requisite consent and acknowledge purpose limits. (16)
In March 2026, a New Mexico jury found Meta liable for $375 million under the state’s Unfair Practices Act for misrepresenting platform safety and enabling child exploitation, and a judge added a further $567 million abatement award in August 2026 — bringing Meta’s total New Mexico exposure to $942 million and requiring years of court-supervised platform changes. (17)
4. Legislative Outlook at the Federal and State Level
Congress remains gridlocked: the House passed its Kids Internet and Digital Safety Act in June 2026 without the “duty of care” standard that Senate sponsors of the Kids Online Safety Act consider essential. With few legislative days left before November’s midterm elections, a compromise this year looks unlikely. (18) States are filling the vacuum: more than 300 bills touching age verification, design codes, and minor-account controls were introduced across 40 states and Puerto Rico in 2026 alone. (19) New York’s SAFE for Kids Act, with final rules effective January 25, 2027, will likewise require verifiable parental consent for addictive feeds and bar overnight notifications to minors absent consent. (20) While litigation is pending that will blunt the effect of these state statutes, the Meta settlement may chill opposition to the groundswell, forcing these changes with or without additional state protections.
5. Recommendations
- A. Make the platform changes to websites consistent with the platform changes to which Meta has already agreed, as outlined above.
- B. Treat age data as sensitive rather than as marketing inventory.
- C. Rebuild the children’s-data stack around COPPA, with separate consent for third-party disclosure, defined retention limits, and a genuine “actual knowledge” escalation process.
- D. Track state-by-state design-code and high-risk-processing obligations, since compliance now varies sharply by jurisdiction and courts continue to redraw the boundaries.
- E. Substantiate every safety claim before it is made public; the FTC Act reaches promises about monitoring or moderation a provider cannot actually deliver. (21)
- F. Handle biometric and cross-device data with documented consent and purpose limits.
- G. Build an incident-and-litigation protocol that preserves design decisions and consent logs. (22)
*****
(1) 1.15 U.S.C. § 45(a)
(2) 47 U.S.C. § 230(c)(1) and (c) (2)
(3) Cf. Anderson v. TikTok, Inc., 116 F.4th 180, 183–84 (3d Cir. 2024) (holding a platform’s own algorithmic curation may be outside § 230’s scope)
(4) 15 U.S.C. §§ 6501–6506; 16 C.F.R. pt. 312 (FTC Children’s Online Privacy Protection Rule)
(5) Press Release, U.S. Dep’t of Justice (Aug. 21, 2026), https://www.justice.gov/opa/pr/justice-department-secures-400m-settlement-tiktok-and-bytedance-resolve-childrens-privacy
(6) John Ruwitch, Meta, States Agree to $17 Billion Settlement in Child Safety Trial, NPR (Aug. 26, 2026), https://www.npr.org/2026/08/26/nx-s1-5944781/meta-settlement-child-safety-lawsuit
(7) Kenrick Cai, Meta Faces 29-State Trial That Could Reshape Instagram, Facebook, Reuters (Aug. 18, 2026), https://www.reuters.com/world/us/meta-faces-29-state-trial-that-could-reshape-instagram-facebook-2026-08-18
(8) ‘Profits Won.’ The Child Safety Trial Against Meta Kicks Off in Federal Court, NPR (Aug. 18, 2026), https://www.npr.org/2026/08/18/nx-s1-5935458/meta-child-safety-social-media-addiction-trial-opening
(9) Supra note 8 (quoting Cal. Deputy Att’y Gen. Megan O’Neill’s Aug. 18, 2026 opening statement)
(10) Supra note 8 (summarizing Meta’s defenses)
(11) AAJ Statement on Verdict in First California Social Media Addiction Bellwether Case (Mar. 25, 2026), https://www.justice.org/resources/press-center/aaj-statement-on-verdict-in-first-california-social-media-addiction-bellwether-case
(12) Meta and YouTube Found Liable in First Social Media Addiction Trial, NPR (Mar. 25, 2026), https://www.npr.org/2026/03/25/nx-s1-5746125/meta-youtube-social-media-trial-verdict
(13) NetChoice, LLC v. Bonta, No. 25-2366, slip op. (9th Cir. Mar. 12, 2026), https://cdn.ca9.uscourts.gov/datastore/opinions/2026/03/12/25-2366.pdf
(14) A.B. 1043, 2025–2026 Leg., Reg. Sess. (Cal. 2025) (Digital Age Assurance Act, enacted Oct. 13, 2025, eff. Jan. 1, 2027)
(15) S.B. 976, 2023–2024 Leg., Reg. Sess. (Cal. 2024) (Protecting Our Kids from Social Media Addiction Act, partly effective since Jan. 1, 2025); see NetChoice, LLC v. Bonta, supra note 13
(16) Press Release, Office of the Tex. Att’y Gen., (July 30, 2024) https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-14-billion-settlement-meta-over-its-unauthorized-capture
(17) Meta Ordered to Pay $942 Million to Address Harm to Kids from Social Media, Wall St. J. (Aug. 7, 2026), https://www.wsj.com/tech/meta-ordered-to-pay-942-million-to-address-harm-to-kids-from-social-media-8ba5aab7
(18) Axios, House Vote, Senate Clash on Kids Online Safety Bills (June 29, 2026), https://www.axios.com/2026/06/29/house-vote-senate-clash-kids-online-safety; Politico, Senate Panel’s Vote for Kids Safety Rules Throws Gauntlet to House (Aug. 5, 2026), https://www.politico.com/news/2026/08/05/senate-panels-vote-for-kids-safety-rules-throws-gauntlet-to-house-01025574
(19) Nat’l Conf. of State Legislatures, Social Media and Children: 2026 Legislation (2026), https://www.ncsl.org/technology-and-communication/social-media-and-children-2026-legislation
(20) Press Release, N.Y. Governor Kathy Hochul & Att’y Gen. Letitia James, (July 29, 2026), https://www.governor.ny.gov/news/governor-hochul-and-attorney-general-james-announce-final-safe-kids-act-rules-protect-children
(21) 15 U.S.C. § 45(a); 16 C.F.R. pt. 255 (FTC Guides Concerning the Use of Endorsements and Testimonials in Advertising).
(22) Press Release, Utah Div. of Consumer Prot. & Fed. Trade Comm’n, (Sept. 3, 2025), https://commerce.utah.gov/2025/09/03/press-release-utah-division-of-consumer-protection-and-ftc-secure-landmark-settlement-with-aylo-over-unconscionable-and-deceptive-practices/
JANICE F. MULLIGAN
