France's parliament voted 279 to 81 on 21 July 2026 to ban social media accounts for anyone under 15, the first law of its kind passed by any country in the European Union. New accounts will be blocked starting in September 2026 and every existing account by January 2027. Two days on, the read is straightforward: Europe's biggest holdout on child online safety just passed its toughest law yet, and the country that wrote it becomes the regulatory frontier other governments watch.

It is worth slowing down on that. France's threshold is 15. India's is 18, and it has been law for nearly three years. Section 9 of India's Digital Personal Data Protection Act, 2023 requires any data fiduciary to obtain verifiable parental consent before processing the personal data of a child, defined in the Act as anyone under 18, with penalties for breaching that duty running as high as Rs 200 crore under the Act's own Schedule. On paper, India asks more of a platform, and covers three more years of childhood, than the law France just passed.

The number that matters is not 18. It is May 2027.

Section 9 is not yet in force: the government's own commencement notification defers it, along with the rest of the Act's operative machinery, to eighteen months after the gazette was published on 13 November 2025, which puts the date at roughly 13 May 2027. No Indian platform is currently required to verify a parent's consent for anything. The strictest child-consent law among the five regimes compared here is also the only one not yet binding on a single company.

The rule that isn't a rule yet

The DPDP Rules, 2025 spell out exactly how that verification is meant to work, and the mechanism is more demanding than anything France, the EU, the UK or the US requires. Rule 10 requires platforms to check a parent's consent against a Digital Locker-verified identity and age token, tying consent to India's national digital-identity infrastructure rather than a checkbox or a birth-year field. But Rule 10 is itself among the provisions deferred for eighteen months after the 13 November 2025 notification. The rule that would make Section 9 real is written down. It is simply switched off.

India's threshold is 18, the highest of the five regimes here, and the only one not yet enforceable.

JurisdictionThresholdInstrument
IndiaUnder 18DPDP Act, Sec. 9 (verifiable parental consent)
EU (default)Under 16GDPR, Art. 8 (member states may lower to 13)
FranceUnder 152026 law (outright account ban)
UKUnder 13UK GDPR, Art. 8 (verifiable parental consent)
USUnder 13COPPA (verifiable parental consent)

Sources: DPDP Act 2023, Sec. 9, via MeitY; CBS News on France's law; EU Agency for Fundamental Rights on GDPR Article 8; FTC on COPPA; ICO on UK GDPR.

Horizontal bar chart showing the consent or ban age threshold in five jurisdictions: India 18, the EU default 16, France 15, the UK 13 and the US 13, with India highlighted as the highest.

Two years to write, eighteen months to start

The gap between India's statute and India's practice was not built by a single delay. MeitY first released the draft DPDP Rules for public consultation on 3 January 2025, nearly seventeen months after the Act itself was passed in August 2023, with comments due by 18 February 2025. The final Rules were notified on 14 November 2025, more than two years after the Act was passed, in a release calling it the "full operationalisation" of the DPDP Act. Full operationalisation, in this case, is the start of an eighteen-month countdown before the child-consent rule actually applies.

France went from vote to a total ban on existing accounts in about five and a half months. India's own consent rule needs eighteen, and the clock only started running in November 2025.

Horizontal bar chart comparing the months from a law's final legal step to binding every existing user: India's DPDP consent rule needs 18 months, France's ban needs about five and a half months, with India highlighted.

Sources: France's timeline is per CBS News; India's eighteen-month deferral is per MeitY's commencement notification. The five-and-a-half-month figure for France is The Signal's calculation from the vote and compliance dates.

France passed its law on 21 July 2026 and reaches every existing under-15 account by January 2027, about five and a half months, our calculation from the vote date and the law's own compliance deadline. India's Rule 10, once notified, needs more than three times as long before it can be enforced against a single platform, and unlike France's law, which targets one product category, India's consent regime applies to every data fiduciary that processes a child's data at all: banks, schools, gaming apps and every social platform at once.

The honest objection

The strongest case for India's slower timeline is that it is building a harder thing. France's ban is a blunt instrument: an age gate a platform can implement with a birth-year field and an appeals process. Rule 10's Digital Locker verification ties consent to a government-backed identity system that has to work across every data fiduciary in the country, not one sector, and has to avoid locking out the many households where a parent has no Digital Locker account yet. An eighteen-month runway to build and test that infrastructure is a defensible, even responsible, choice next to a ban a legislature can flip on by decree.

That case holds up to a point, but it does not explain why writing the Rules took so long in the first place. MeitY did not publish a draft for public comment until 3 January 2025, nearly seventeen months after the Act was passed in August 2023. Building Digital Locker integration during an eighteen-month implementation window is one kind of delay, but taking close to a year and a half just to produce a draft, before that window even starts, is another matter. It is not engineering time. It is queue time.

The Signal

France's ban will be tested within months: it works, it is watered down in court, or it is quietly ignored the way age gates usually are. India's law will not face that test until 2027 at the earliest, and under the Act's own commencement schedule, the government could defer it again. Until Section 9 and Rule 10 actually bind a platform, the DPDP Act's under-18 threshold is a number in a gazette, not a control on any product a child uses today. Watch 13 May 2027, the date the deferral clock runs out, the way you would watch a bill come due: what matters is not whether India wrote the strictest rule on paper, but whether anyone is actually checking a Digital Locker token by the time it arrives.

Reporting basis: the DPDP Act's Section 9 consent requirement and its Schedule penalty are per the Act's own text, published by the Ministry of Electronics and Information Technology (MeitY). The commencement deferral and the DPDP Rules, 2025's Rule 10 deferral are per MeitY's own gazette notifications. The draft Rules' consultation timeline and the November 2025 notification announcement are per Press Information Bureau releases. France's vote count, threshold and compliance dates are per CBS News's account of the parliamentary vote. The EU's GDPR Article 8 default age is per the EU Agency for Fundamental Rights' mapping of the regulation; the US COPPA threshold is per the Federal Trade Commission's own rule page; the UK threshold is per the Information Commissioner's Office's guidance, quoting the UK GDPR directly. The month count from France's vote to full compliance, and the comparison of timelines across jurisdictions, are The Signal's calculations from those dates.