Children today face unprecedented risks online. While the internet opens doors to learning and creativity, it also exposes minors to harmful content, exploitation, and privacy violations. Governments around the world have responded with varying legislative approaches to protect young users. The United States, United Kingdom, and India each bring distinct legal frameworks to this challenge, reflecting their unique cultural, legal, and technological landscapes.
Table of Contents
United States: building privacy protections layer by layer
The U.S. approach to online child protection centers primarily on privacy and data collection rather than content regulation. The cornerstone of American legislation is the Children’s Online Privacy Protection Act (COPPA), enacted in 1998 and implemented in 2000. COPPA requires websites and online services directed at children under 13 to obtain verifiable parental consent before collecting personal information.
Under COPPA, operators must post clear privacy policies, provide parents with access to their children’s information, and maintain reasonable security measures. The Federal Trade Commission (FTC) enforces the law, with violations carrying civil penalties. Recent updates expanded the definition of personal information to include biometric identifiers and mobile phone numbers, adapting to technological changes.
However, COPPA has faced criticism for being outdated. Many experts argue that the age limit of 13 is too low, given that teenagers face significant online risks. In response, lawmakers introduced COPPA 2.0, which would extend protections to minors under 17, ban targeted advertising to children and teens, and create an “eraser button” allowing parents and teens to delete personal information. The Senate overwhelmingly passed COPPA 2.0 in July 2024, though it awaits House approval and presidential signature.
Beyond federal legislation, several U.S. states have enacted their own child online safety laws. California, Connecticut, Florida, Georgia, Louisiana, New York, Tennessee, and Utah have passed legislation regulating how companies collect and use children’s data, particularly on social media platforms. This patchwork of state laws creates complexity for companies operating nationwide but reflects growing concern about children’s digital safety.
United Kingdom: the comprehensive Online Safety Act
The UK took a different approach with its Online Safety Act 2023, which received Royal Assent in October 2023. Unlike the U.S. focus on privacy, the UK legislation establishes a broad “duty of care” framework requiring platforms to protect users from both illegal content and content harmful to children.
The Act designates Ofcom, the UK’s communications regulator, as the online safety regulator with extensive enforcement powers. Companies face fines up to 10% of global revenue or ยฃ18 million, whichever is greater, for non-compliance. In the most serious cases, Ofcom can block services from being accessed in the UK.
The Online Safety Act requires platforms likely to be accessed by children to conduct risk assessments and implement age-appropriate protections. Services must prevent children from accessing harmful content including pornography, self-harm promotion, eating disorder content, bullying, and material encouraging dangerous activities. Platforms must use “highly effective” age assurance measures, which can include photo identification, banking information verification, or facial age estimation.
Implementation follows a phased approach. As of July 2025, the child safety regime became fully operational, with platforms required to complete children’s risk assessments and implement appropriate safety measures. The Act also introduced new criminal offenses including cyberflashing, encouraging serious self-harm, and intimate image abuse, targeting individual perpetrators rather than just platforms.
The legislation has sparked debate about freedom of expression and privacy. Critics argue that mandatory age verification threatens user privacy and creates barriers to accessing information. Following implementation, VPN apps became the most downloaded on UK app stores as users sought to circumvent age checks. Nevertheless, supporters maintain that strong protections are necessary to safeguard children from online harm.
India: criminal law meets cyber regulation
India’s approach to protecting children online relies heavily on criminal law provisions combined with cyber regulations. The primary legal framework consists of the Information Technology Act, 2000 (IT Act) and the Protection of Children from Sexual Offences Act, 2012 (POCSO Act).
Section 67B of the IT Act specifically criminalizes publishing, transmitting, browsing, or collecting child sexual abuse material (CSAM). The provision covers not just distribution but also viewing and possession, with first offenses punishable by up to five years imprisonment and fines up to โน10 lakh. Subsequent offenses carry up to seven years imprisonment. This strict stance reflects India’s alignment with global norms on child protection.
Section 67A targets sexually explicit content involving adults, while Section 67 addresses general obscenity in electronic form. These provisions work alongside the Indian Penal Code’s Section 293, which prohibits selling or distributing obscene materials to persons under 20 years of age.
The POCSO Act complements the IT Act by focusing on the subject rather than the object of exploitation. Section 14 criminalizes using children for pornographic purposes, whether showing sexual organs, depicting children in obscene contexts, or involving them in simulated or real sexual acts. Section 11 addresses sexual harassment, including showing pornographic material to children.
India has also launched initiatives to strengthen enforcement. The SAHYOG portal, launched in 2024, provides a centralized platform for reporting CSAM and issuing takedown orders to intermediaries. The National Commission for Protection of Child Rights (NCPCR) actively issues takedown requests and awareness programs. However, challenges remain, including the subjective definition of “obscenity” rooted in pre-digital morality and inconsistent enforcement timelines.
The proposed Digital India Act aims to address gaps in the current framework by introducing age-gating requirements, prohibiting targeted advertising to children, and establishing clearer duties for online intermediaries. The legislation would specifically tackle cyber-bullying, doxing, and cyber-flashing while requiring platforms to implement age verification systems.
Comparing the three approaches
These three jurisdictions demonstrate fundamentally different regulatory philosophies. The United States emphasizes parental control and data privacy through COPPA, placing responsibility on parents to monitor and consent to their children’s online activities. This approach respects freedom of expression but may not adequately address content-based harms that children encounter.
The United Kingdom adopts a comprehensive duty-of-care model through its Online Safety Act, requiring platforms to proactively identify and mitigate risks to children. This regulatory approach places primary responsibility on service providers rather than parents, reflecting a view that platforms have greater capacity to implement systemic protections. However, the extensive age verification requirements raise privacy concerns and implementation challenges.
India takes a criminal justice approach, using penal provisions to deter harmful conduct and punish offenders. The IT Act and POCSO Act establish clear criminal liability for creating, distributing, and possessing CSAM, with enforcement through traditional law enforcement channels. This approach sends strong deterrent signals but may struggle with the scale and anonymity of online violations.
Each system faces enforcement challenges. COPPA’s age verification requirements are easily circumvented by children who lie about their age, and many platforms simply ban users under 13 rather than implementing parental consent mechanisms. The UK’s age verification mandates face similar circumvention issues, with users employing VPNs to access restricted content. India’s criminal law approach encounters underreporting and difficulties prosecuting cross-border offenses.
The effectiveness of these frameworks also depends on international cooperation. Online platforms operate globally, meaning that content prohibited in one jurisdiction remains accessible through servers in other countries. The UK’s Online Safety Act applies to foreign companies serving UK users, creating potential jurisdictional conflicts. India collaborates with international bodies like the National Centre for Missing & Exploited Children (NCMEC) for reporting, but recent court decisions emphasize that foreign reporting cannot substitute for local compliance.
Despite these differences, common themes emerge. All three jurisdictions recognize that protecting children online requires updated legal frameworks responsive to technological change. All struggle with balancing child safety against privacy rights and freedom of expression. And all acknowledge that legislation alone cannot solve the problem without industry cooperation, parental engagement, and digital literacy education.
What do you think? Should governments prioritize privacy-focused approaches like COPPA, comprehensive duty-of-care models like the UK’s Online Safety Act, or criminal law frameworks like India’s IT Act? How can countries balance protecting children online with preserving privacy and free expression for all users?
References
- https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa
- https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy
- https://www.commerce.senate.gov/index.php/2024/7/senate-overwhelmingly-passes-children-s-online-privacy-legislation
- https://www.gov.uk/government/collections/online-safety-act
- https://www.whitecase.com/insight-alert/uk-online-safety-act-protection-children-codes-come-force
- https://www.eff.org/deeplinks/2025/08/no-uks-online-safety-act-doesnt-make-children-safer-online
- https://legal.bihar.in/section-67a-67b-it-act-punishment-for-obscene-and-csam-content/
- https://www.asvlawoffices.com/protection-of-children-from-online-harm-assessing-legal-measures-under-the-it-act-and-pocso-act/
Leave a Reply