Shubhi Agarwal & Anamika Jaiswal are students at Maharashtra National Law University, Mumbai
Are Algorithms Rewiring Young Minds?
In March 2026, a Los Angeles Superior Court jury, in coordinated state proceedings against Meta (JCCP 5255), returned a verdict which expanded the scope of intermediary liability from content-based to even design-based. The plaintiffs herein argue against the design of such platforms which has been engineered to engage and actively produce harm on children. Other countries have started recognising this concern however their approach is different, for instance Australia has adopted a more preventive stance by completely restricting access to children under 16 years of age. It, thus, becomes imperative to examine a similar legal framework in India. A study revealed that excessive social media use is significantly correlated with heightened stress, anxiety, and depression in children. Yet, Indian laws are currently anchored in a content-centric liability model, completely disregarding how platforms are designed to capture, retain and amplify user attention, often normalising addictive engagement patterns inimical to children’s mental health and cognitive development.
Against this background, this blog analyses and suggests if and how Indian laws can adopt design-liability: first as product liability under CPA, 2019; second by reimagining US models under DPDPA, 2023.
Reconceptualising Design Liability Under CPA
The plaintiffs in K.G.M v. Meta et al alleged negligence-based product liability against social media intermediaries for the engineered architecture i.e. the design features of the platform. In the US, the Federal Trade Commission (“FTC”) statute broadly prohibits unfair or deceptive acts or practices affecting consumers. As per Section 5(n) of FTC Act, liability is triggered when a business practice causes substantial consumer injury that is not reasonably avoidable by consumers and lacks countervailing benefits to consumers. Crucially, the services need not be paid for users to be ‘consumers’, making free digital services fall within the protective scope of the Act.
In India, conversely, consideration is a prerequisite for the provisions of CPA, 2019 to apply. This effectively excludes users from initiating claims against intermediaries for algorithmic harm, given that such services are ostensibly offered free of cost. However, this is now being judicially reviewed and reinterpreted in Amitabh Thakur v. WhatsApp. In the mentioned case, the Uttar Pradesh State Commission has advanced a nuanced interpretation, holding that users do furnish valuable consideration in the form of personal data, making WhatsApp a service provider falling within the purview of CPA. The commission acknowledges that, notwithstanding the absence of monetary consideration, users of WhatsApp part with data that carries significant economic value due to its monetisation through targeted advertisements. Therefore, the service cannot be characterised as truly gratuitous in nature.
That said, the matter remains unresolved due to Allahabad HC’s stay on further proceedings pursuant to an appeal filed by WhatsApp. The Commission’s findings, however, become crucial for the present discourse as it would provide a direct remedy to users against platforms for app designs. However, such a change cannot emanate from a ruling and has to come from legislative policy via amendments to the Act.
US Models Through the Lens of the DPDP
The US, at state level, has recently introduced two Acts: South Carolina’s Stop Harm from Addictive Social Media (SHASM Act), and Illinois’ Children’s Social Media Safety Act, both of which have been passed by the respective legislative chambers but provide for future effective dates. Both the Acts hold social media platforms liable for their design, especially in the context of children. Although their objective is common, their approach differs.
SHASM relies on a probabilistic age-estimation model where platforms must estimate the age of the users by using their own technology and available data. This means that on specified dates, the intermediaries are required to develop a probability of users being over the age of 15. If they cannot reach 80% confidence that a user is over 15, they must treat them as a child. On the other hand, Illinois’ bill primarily revolves around Operating Software (“OS”) level age signalling. It requires OS providers to collect the age of users at device setup and then transmit a signal conveying the age bracket to any app that requests it. Apps must then use this to apply design options accordingly. However, in situations where the platform, through internal ‘clear and convincing information’, believes that the user’s age is not in accordance with the signal, it can recategorize that user.
At the federal level, the Kids Online Safety Act (“KOSA”) creates a duty of care for platforms. It entitles social media platforms with the responsibility to reduce risks for users they know or should know are minors. But, in contrast to its states’ bills, the federal bill calls for coordinated efforts between the Federal Communications Commission and FTC to conduct a study on the most technologically feasible methods and options of age checks. Although the Senate Committee on Commerce, Science, and Transportation ordered the bill to be reported with an amendment in the nature of substitute on August 5, 2026, the Bill continues to harbour the above-mentioned provisions.
However, the question that remains is whether and how these legislations can be incorporated in India. The Illinois model, without any verification system, would likely be ineffective as it offers no method to deal with children misrepresenting their age, a common and recognized phenomenon. With respect to other models, India’s DPDPA lays the foundation for accommodating their elements, while exposing fundamental gaps that need to be addressed.
Social media platforms act as Data Fiduciaries under Section 2(i) of the Act due to their collection and processing of personal data. Section 9(2) prohibits such Fiduciaries from any data processing which may be detrimental to the well-being of a child. Additionally, Section 9(3) prevents behavioural monitoring and targeted advertisements directed at children. These provisions can penalise addictive design choices like infinite scrolling, algorithmic feeds, etc., which platforms have themselves acknowledged are engineered to encourage compulsive engagement, often at the cost of mental health.
However, exceptions to this exist under the Fourth Schedule of DPDP Rules, 2025, which lists certain purposes which do not attract any liability under Section 9(1) and 9(3), thereby creating space for accommodating US-like solutions. Exception 6 under Part B allows Data Fiduciaries to use data, limited to the extent “necessary”, to confirm whether a user is a child. Moreover, Exception 5 permits data processing to prevent access to services or advertisements likely to harm children. Together, these exceptions allow Data Fiduciaries to overcome misrepresentation of age by enabling age-verification checks and behavioural tracking. It thereby combines KOSA’s duty-of-care mechanism with SHASM’s age-estimation model in an effort to counter design-based harm.
However, this flexibility is not without critical loopholes. As mentioned, data processing is only limited by an ambiguous standard of “to the extent necessary”. No clear limits as to duration, volume or type of data to be processed has been defined. Without such specifications, platforms can easily justify prolonged user tracking under the guise of age estimations. Additionally, it also risks creating false positives where adults may be categorized as children or vice versa. These exemptions, therefore, risk undermining the principle of data minimisation.
This is further compounded by the recent Dutch judgment in Stichting Bits of Freedom v. Meta Platforms Ireland Limited and Ors., which has directed Meta to let users opt-out of algorithmic recommended content, in an effort to allow users to make autonomous choices and limit behavioural tracking. Yet, in India, in cases where a user has opted out of such design features, platforms can still monitor their behaviour under the Fourth Schedule to “determine their age.” Thus, this effectively turns the age-verification mechanism into a surveillance tool applicable to all users and not merely children, raising detrimental consent-based privacy concerns. In conclusion, KOSA, thus, offers the best alternative since it provides space to legislators to first understand the above-mentioned loopholes and then act on it.
The Way Forward
Although this piece does not purport to offer a comprehensive solution, the authors do offer a few suggestions-
- Expansion of CPA: The Act has not been able to keep up with evolving digital services. As it stands currently, users who surrender their data, in exchange for a nominally free service have limited recourse when that exchange causes them harm. An amendment to related definitions like consideration, consumer, etc, recognising data and behavioural engagement as valid forms of considerations, can encourage purposive reinterpretation by the Central Consumer Protection Authority within the fold of consumer law.
- A Mandated Institutional Study on Device-Level age verification: Rather than rushing toward a verification mandate whose technical parameters remain marred with loopholes it is more prudent for the MeitY in coordination with TRAI and CCPA to conduct a time bound study on the feasibility methods or OS-level age verification. This is in line with Section 107 of KOSA. Unlike KOSA, however India need not study device-level integration from a blank slate as Rule 10 of the DPDP Rules already contemplates verification of reliable identity and age details through a virtual token issued by an authorised entity, including a Digital Locker service provider. The proposed study should therefore build on the same focusing more on the operational feasibility of a OS/device level, privacy risks which arise in implementing it at scale, accessibility implications for users on low-cost devices and other competitive consequences for the domestic startups.
Conclusion
The authors merely propose certain coordinates for a fuller discussion on the subject and the need for the legislature to act upon it. Transposing U.S. models is neither realistic nor entirely desirable. However, a cross-jurisdictional view does reveal the tendencies of legal systems confronting similar concerns and the methods that may be gathered to counter increasingly capitalistic models of engagement that drive consumption at the cost of the growth and development of children at a very tender age.
It risks opening a floodgate of litigation, an outcome already visible in the U.S, where the proliferation of social media addiction claims has led courts to frame select suits as bellwether trials to manage and signal outcomes for the larger pool. However, the harm being immediate and potentially irreversible must be materially looked into and countered, not by the courts through piecemeal adjudication, but by Parliament at the earliest.
