
What France's under-15 social media ban actually does
France is the first EU country to ban social media for under-15s. Starting September 2026, no new accounts can be created for that group; from January 2027, existing accounts get shut down unless users can prove they are over 15. To make that possible, every social media user in France will have to pass an age check approved by the French data-protection regulator.
The scope is much broader than classic social networks: games with chat, messengers with social feeds, adult sites — mirroring Australia's under-16 ban and similar UK proposals.
Under the banner of child protection, a permanent identity and surveillance infrastructure is being wired up that links every family member's ID documents, biometrics and usage patterns to every major platform — potentially for life.
Age verification is a privacy problem, not just a safety tool
On paper, showing an ID or a selfie sounds harmless. In practice, age checks are less about your age than about the companies that collect, store and potentially leak your most sensitive data: passport scans, biometric face matching, behavioural and device-level signals.
In 2025 a contractor Discord used for age-verification appeals was breached: at least 70,000 government ID photos, names, emails and IP addresses were exposed. Passwords can be changed; your face and your passport number cannot. For parents helping a child through an age check, that means trusting family-level identity data to a web of unknown subcontractors just so kids can stay in a homework group chat.
When the price of entry is permanent biometric exposure, this stops being a neutral "safety tool" and becomes a structural threat to family privacy.
Enforcement collects more data than the platforms it regulates
Central paradox: the systems meant to police platforms end up collecting more sensitive data than the platforms themselves. France is leaning on "double anonymity" — a third party checks your ID or face and hands the platform only an age token.
Elegant on paper, less so in practice: verification providers become new centralised stores of ID scans and biometrics. Platforms still log the timing and location of every check, and Arcom can demand data, impose fines and order services blocked — an incentive to collect "just in case." The enforcement stack ends up knowing more about your family than TikTok or Instagram ever did.
The bans are easy to bypass — but families carry the risk
Australia, the first country to impose an under-16 ban, offers a sobering preview: about 70% of affected teens still access social media, and a BMJ study found more than 85% keep using restricted platforms — often through their own accounts, no fancy circumvention needed.
Kids route around; adults comply. French teens told Le Monde the checks are "easy to get around" and are more worried about handing over ID than losing access. Families are left with bad options: submit to invasive checks, or push conversations into less visible, less safe spaces.
What this means for parents and digital rights
Parents are quietly turned into enforcers of a system they never asked for: share their own IDs and biometrics, trust opaque vendors and accept that leaks are inevitable — with no way to "reset" a face or passport number.
Meanwhile, infinite scroll, engagement algorithms and weak moderation remain untouched. Normalising ID checks for everyday speech also paves the way for broader "chat control" regimes — see our deep-dive on the EU Chat Control saga — and erodes the anonymity that vulnerable users (LGBTQIA+ teens, abuse victims) depend on.
There's a better way to protect kids online
Protecting children from grooming, harassment and toxic design is essential — but identity-heavy age verification is neither the only nor the best tool. A balanced approach would prioritise:
- Design-based regulation: target infinite scroll, engagement algorithms and opaque recommendation systems.
- Platform accountability: safe defaults, transparent moderation and independent audits.
- Family-first tools: privacy-respecting parental controls, media literacy, device-level protections.
- Privacy-preserving age assurance: decentralised open standards that never store raw IDs or biometrics.
Take action: defend your family's right to private communication
Chat-Control.eu exists because we believe in safety without surveillance. While lawmakers argue, you can already shrink your household's attack surface:
- Move to EU-based encrypted email instead of Big Tech inboxes.
- Switch to secure, end-to-end encrypted cloud storage for family documents.
- Use a privacy-respecting VPN to cut back on profiling.
- Adopt a password manager to stop chain-reaction breaches.
- Follow the EU Chat Control saga and write to your representatives.
- Read our deep-dive on why your ISP knows more about you than Google — it's the same network layer that any age-verification scheme will lean on.
Let's build an internet where kids are safer because platforms are less toxic — not because families are forced to surrender their most intimate data.