BRICS split on child online safety tests
India's BRICS chairship confronts divergent national approaches to child online safety, from Brazil's guardian-linked accounts to China's service curfews

India's chairship of the BRICS grouping faces a fundamental split over how to protect children online. New Delhi hosts the 18th BRICS Summit on September 12 and 13, where children's digital safety is on the agenda, according to a MediaNama report drawing on a closed-door discussion. The regulatory detail is from the public record.
Four distinct regulatory theories are in play across the member states, placing duties in different places. The instruments have almost nothing in common.
Four theories of protection
The child is seen as a data subject in India and South Africa, where the primary harm is unlawful data processing. Brazil and Indonesia treat the child as a user the platform must design for, focusing on age assurance and guardian linkage. China, with Russia's older framework closest to it, views the child as someone whose consumption the state must supervise, leading to content curfews and blocking. The United Arab Emirates imposes duties across an entire regulated industry through its 2025 decree-law.
These frameworks ask different questions. A data protection regime asks if a platform had a lawful basis for processing. A duty-of-care regime asks if the platform knew a user was 14.
Brazil's comprehensive duty-of-care law
Brazil's Law No. 15,211 of 2025, known as the ECA Digital, imposes specific obligations. Its grace period ended on March 17, 2026.
Providers must run reliable age verification, where self-declaration alone is not enough. Accounts held by users under 16 must be linked to a legal guardian. Platforms must supply parental supervision tools, apply protective settings by default, not profile minors for advertising, remove manipulative design patterns, and run impact assessments on minor users.
Enforcement sits with the autonomous data protection authority, the ANPD, restructured in April 2026. Penalties can reach 10% of an economic group's revenue in Brazil, with suspension and prohibition from operating also available. Administrative sanctions begin in November 2026, and formal compliance verification starts in January 2027.
The law's scope is wide, reaching any provider offering a service with probable access by minors.
Indonesia's tiered access rule
Indonesia's Government Regulation No. 17 of 2025, known as PP Tunas, sets access by age band against platform risk level, not a flat ban. It lets a 14-year-old onto a low-risk platform with parental consent, but not a high-risk one.
| Age Band | Permitted Access | Condition |
|---|---|---|
| Under 13 | Low-risk products designed for children | With parental permission |
| 13 to 16 | Low-risk products and features | With parental consent |
| 16 to 18 | Account holding | With parental consent |
Platforms must verify age, provide parental controls, filter harmful content, run risk assessments, restrict commercial use of children's data, and offer reporting tools. Sanctions are administrative. The regulation took effect in April 2025, with enforcement phasing in from March 28, 2026. MediaNama notes accounts differ on whether subsequent steps hardened the tiers into a flatter bar.
China's layered controls and AI ban
China's minor mode framework caps daily app use at one hour for under-16s and two hours for 16 and 17-year-olds, and switches services off between 10pm and 6am. The newer layer is the Interim Measures for the Management of AI Human-Like Interaction Services, published on April 10, 2026, which took effect on July 15, 2026.
For minors, these impose an absolute prohibition on virtual intimate relationship services. Other AI companion services need parental consent for children under 14. Providers must offer a minor mode with reality reminders, usage time limits, and parental controls. The design assumes parental consent cannot cure the harm of certain services.
India's unsettled position
India's position is the least settled of the large members. The Digital Personal Data Protection Act, 2023 requires verifiable parental consent for every user under 18, and draws no distinction at all between a nine-year-old and a 17-year-old. It bars tracking and targeted advertising at children. Rule 10 of the DPDP Rules sets out consent confirmation methods. Both take effect on May 13, 2027.
A separate children's social media law has been under discussion. MediaNama reported in March 2026 on a proposed three-tier structure resembling Indonesia's banding. A government official quoted then said the reasoning was that "we do not believe in very harsh measures such as a ban."
A government-led consultation concluded earlier in August 2026 that "a complete social media ban for children would not be effective." It involved the National Commission for Protection of Child Rights, MeitY and the Department of Telecom. The consultation turned to age-gating, platform design duties and a code of conduct. It also recorded an intent to treat children as rights-bearers.
Internally, India is not uniform. Karnataka's chief minister proposed an under-16 social media ban in March 2026, an instrument the union government has declined.
**Other BRICS members' approaches**
Russia's protections rest largely on a 2010 law on information harmful to children, with content blocking. Lawmakers raised age verification proposals in late 2025. MediaNama could not confirm an enacted platform-duty or age-assurance regime is in force in Russia.
South Africa relies on data protection through the POPI Act, prohibiting processing children's personal information except in defined circumstances. There is no age-gating or duty-of-care statute equivalent to Brazil's.
The four newer members - Egypt, Ethiopia, Iran and Saudi Arabia - have no comparable framework in force. For more on global regulatory standings, see our standings page. To understand how different rules might apply to specific platforms, our fixtures analysis provides context.





