The New Privacy Paradox of Social Media: Are We Protecting Children by Creating Bigger Digital Identity Risks?
The social media industry is entering a new phase of digital identity verification, For years, platforms such as Instagram, Facebook, LinkedIn and X allowed users to create accounts primarily through email addresses, mobile numbers and self-declared information. Today, that model is changing rapidly. Governments, regulators, parents and technology companies are demanding stronger age assurance, parental controls and identity verification—particularly for children and teenagers. At first glance, this appears to be a positive development. Parents want greater control over what their children see online. Governments want platforms to prevent minors from accessing inappropriate content. Social media companies want to demonstrate that they are taking online safety seriously. But there is another side to this development that deserves significantly more attention: If proving that a person is a child or an adult requires government-issued identity documents, who ultimately holds that identity data—and what happens if that data is compromised? This is where the debate moves beyond social media safety and becomes a question of national cybersecurity, digital identity security, privacy and critical data governance. India Is Moving Toward Stronger Digital Personal Data Protection India’s regulatory environment has already moved substantially in this direction. The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes India’s framework for processing digital personal data and specifically defines a child as an individual who has not completed 18 years of age. The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology on 14 November 2025, creating the operational framework around the Act. This is important because the digital economy increasingly depends on personal information. A modern online identity may include: Name Date of birth Mobile number Email address Government identification information Location Device information IP address Photographs Facial information Employment information Education information Online behaviour Social connections Browsing and engagement patterns Purchase and advertising activity The problem is not necessarily that a company collects one piece of information. The problem is aggregation. A government identity document combined with a person’s face, phone number, professional profile, social-media activity, location and behavioural history creates an extraordinarily valuable digital identity profile. That profile becomes an attractive target for cybercriminals, fraudsters, hostile insiders, data brokers and sophisticated social-engineering campaigns. The Child-Safety Paradox Consider the objective behind parental controls. A 15-year-old creates an Instagram account. The platform needs to determine whether the user is actually 15. If the user claims to be 25, the platform may attempt to identify the account as belonging to a teenager and place it into a more restrictive experience. Meta has been publicly expanding its Teen Accounts and age-assurance systems. Instagram’s Teen Accounts were introduced in India with restrictions around messaging, sensitive content, account privacy and parental supervision. Meta has subsequently described AI-based systems designed to identify suspected teenagers even when an account lists an adult birthday. The objective is understandable. But consider the security question: How much personal information should a social-media company need to determine whether somebody is 15, 17 or 25? Does the platform need a complete Aadhaar card? Does it need a PAN card? Does it need a passport? Does it need a driving licence? Does it need a photograph? Does it need facial recognition? Does it need a parent’s identity? Does it need a relationship between the child’s identity and the parent’s identity? And most importantly: Does the company actually need to retain any of that information after the age has been established? That last question should become central to the privacy debate. The Identity Verification Problem There is a major difference between: “Verify that this person is above 18.” and “Upload your government identity document so that a private technology company or its verification partner can establish your identity.” The first is an age-assurance requirement. The second can become an identity-data collection exercise. Technically, these are not the same thing. An ideal privacy-preserving system should be capable of answering: “Is this person above the required age?” without necessarily revealing: “Here is the person’s complete government identity document, document number, photograph, date of birth and other information.” India’s Aadhaar authentication ecosystem itself demonstrates an important principle: identity authentication can be performed through an authentication mechanism rather than simply handing a complete identity document to every service provider. UIDAI states that requesting entities must obtain consent for authentication and that Aadhaar authentication involves verification against the Central Identities Data Repository. That raises an important policy question: Why should every social-media platform become a repository—or even a processor—of high-value identity documents when the actual requirement may only be age assurance? LinkedIn’s Identity Verification Raises Another Question This issue is not limited to children. LinkedIn already uses identity verification mechanisms through third-party providers such as Persona. According to LinkedIn’s own documentation, users whose accounts are restricted or inaccessible may be asked to verify their identity using a government-issued ID, driving licence or passport. LinkedIn states that Persona collects the personal data required for the verification process. LinkedIn also describes its Persona-based verification process, including government ID verification and, in certain cases, facial matching. LinkedIn says that some information from the verification process is shared with LinkedIn while biometric data and certain ID details are not received by LinkedIn in the described process. This distinction is extremely important. It demonstrates that the question is not simply: “Does LinkedIn store my Aadhaar?” The better cybersecurity questions are: Who processes the document? Which company receives it? What information is extracted? How long is it retained? Where is it processed? Which employees can access it? Which vendors can access it? Can it be used for another purpose? What happens if the verification provider is breached? What happens when the verification relationship ends? The security boundary therefore extends beyond the social-media platform itself. It includes the entire identity-verification supply chain. X Is Moving in the Same Direction X has also publicly documented its age-assurance mechanisms. According to X’s own policy documentation, the platform can use existing account signals, email and phone information, facial age estimation and government-issued ID verification to determine whether a […]