17.6 Social media restrictions and bans

Family discussing a blocked social feed and age restriction around a kitchen table.
Age-based restrictions affect whole households and require new checks.

Status reviewed 15 July 2026. The government has announced an under-16 social-media restriction and default protections for 16- and 17-year-olds. The first regulations are intended by the end of 2026 and expected to take effect in spring 2027, subject to parliamentary approval. The rules are not yet in force.

The announced UK policy

Following a March-to-May 2026 consultation, the government announced on 15 June that it intends to prevent in-scope social-media companies offering their services to under-16s. It described a targeted definition based on social interaction, user posting, and algorithmic recommendation, with expected examples including major social platforms and narrow exemptions for services such as education, e-commerce, and music streaming. Exact legal scope will depend on regulations.

The same policy programme would restrict under-16s from functions such as communicating with strangers and creating livestreams on other services, including gaming services. For 16- and 17-year-olds, government announced default restrictions, and on 15 July specified default overnight curfews from midnight to 6am and controls on engagement-maximising features. The government intends to use regulation-making powers added to the Online Safety Act, with affirmative approval by both Houses. An announcement and intended commencement date are not the same as operative law.

The Australian precedent

Much of the UK debate has been shaped by Australia, which in late 2025 brought into effect a law barring children under 16 from holding social media accounts and placing the obligation on platforms to enforce it. It is the most significant such measure attempted by a comparable democracy, and it is being watched closely around the world as a test case: whether the age limit can actually be enforced, what it costs in privacy and practicality, whether children simply route around it, and whether the promised benefits materialise. UK ministers have referred to the Australian approach with evident interest, and its perceived success or failure will heavily influence what the UK does.

The Australian experience is therefore the most useful evidence available, and it cuts both ways. Supporters point to a society-wide attempt to push back against documented harms to children. Critics note the enforcement problem: to keep under-16s off a platform, the platform must determine the age of every user, which is where the privacy difficulty arrives. Early reports of children circumventing the rules, and of the burden falling on age-assurance systems of uncertain accuracy, are exactly the issues the UK would inherit. Watching how Australia's scheme actually performs is more informative than any prediction.

The identity side-effect everyone misses

A platform must reach sufficient confidence about which users are below, near, or above a threshold. The government says companies will need stronger, highly effective age assurance and acknowledges that more adults will be asked to prove age. That does not logically require every adult to disclose a name, passport, or persistent identity: age estimation, existing account signals, mobile-network checks, reusable age tokens, and staged checks can establish an age band with different privacy costs.

The privacy risk is therefore not simply "everyone must identify themselves". It is that mainstream participation becomes conditional on an age decision, that weak systems may collect excessive identity or biometric data, and that false decisions can exclude lawful users. Pseudonymous participation can survive only if systems return a limited age attribute, avoid stable cross-service identifiers, separate verification from the platform, provide non-biometric alternatives, and offer meaningful appeal. Those safeguards should be evaluated in the eventual regulations and Ofcom guidance rather than assumed.

The genuine concern, and the trade-off

It would be dishonest to treat the underlying worry as manufactured. There is real and growing evidence of harm associated with heavy social media use by children: effects on sleep, attention, mental health, body image, and exposure to material no child should see. Many parents feel genuinely powerless against engagement-maximising designs aimed at their children, and the desire to do something is understandable and decent. A guide that dismissed these concerns would deserve to be ignored.

The policy now combines a service-level age restriction with feature regulation, defaults, education, and parental support. The right test is evidence: whether the restriction improves wellbeing and safety; how children route around it; whether harmful activity moves elsewhere; how errors and exclusion are handled; and how much data all users surrender. Device controls and safer design may complement the rule or achieve some aims with less identity processing. A proportionate assessment must count both child-safety benefit and the privacy, equality, speech, and access costs.

Platform pressure and deplatforming

Age limits are not the only way social media participation is constrained. The broader environment — shaped by the Online Safety Act, by platform terms of service, and by political and commercial pressure — already determines what may be said and who may say it, often more powerfully than any law. Accounts are suspended, content is removed or demoted, and individuals are excluded from the platforms where public conversation happens, sometimes for clear cause and sometimes through error, automation, or pressure. This is the territory of 16.3 and 16.6, and it is a restriction on participation that operates regardless of formal bans.

The practical lesson is that your presence on any single platform is conditional and revocable, and increasingly so. Building your entire public identity, audience, or livelihood on one service leaves you exposed to a single company's decisions and a single regulator's rules. The resilience principles elsewhere in this guide — keeping independent channels, owning your own means of contact, not depending wholly on platforms you do not control — apply directly here, and they matter more as the rules around participation tighten.

What to watch, and what to do

The policy direction is decided, but the legal detail is not. Watch the regulations for the service definition, exemptions, treatment of existing accounts, acceptable age-assurance methods, data retention, independent testing, equality impacts, appeal, and whether adults can obtain an unlinkable proof of age. Regulations under the announced power require parliamentary approval, so scrutiny is still meaningful.

For your own resilience, act on the things already within your control. Reduce your dependence on any single platform; keep ways to reach the people who matter to you that do not rely on a social media account, such as the encrypted messaging in 7.1; and keep sensitive or easily-misread expression off mass platforms in favour of more appropriate channels, as set out in 16.8. If age verification does come to mainstream social media, the data-minimisation guidance in 17.2 will apply there too. The consolidated steps are in 17.7.

Primary sources: the government's 15 June 2026 progress statement and 15 July 2026 policy announcement.