
MPs attend a parliamentary debate on legislative process for a social media ban on under-15s at the Assemblee Nationale, France’s lower house Parliament in Paris on January 26, 2026.
Ludovic MARIN/AFP via Getty Images
France’s highest constitutional authority struck down the country’s under-15 social media ban on Friday, ruling that a law designed to protect children had done so through a mechanism that unconstitutionally subjected every adult in France to mandatory age surveillance — and that lawmakers had failed to specify what legal safeguards would govern the resulting data collection. The ruling, Decision No. 2026-911 DC, issued by the Conseil Constitutionnel on August 14, arrives six weeks before the ban’s September 1 enforcement date and creates the European Union’s first court-articulated constitutional test for what a child-protection social media law must contain to survive legal challenge. According to France’s Constitutional Council ruling, the provisions disproportionately infringed upon freedom of expression and communication while failing to provide legal safeguards necessary to protect the right to private life.
Every government in Europe now drafting equivalent legislation — the United Kingdom, Canada, Denmark, and the EU Commission itself, which is expected to present a bloc-wide proposal in September — faces the same three constitutional requirements the French law failed to meet: a parental override mechanism, platform-by-platform differentiation based on documented risk, and a statutory specification of the privacy-preserving conditions under which age verification must occur.
What the Court Actually Said — Three Grounds, Not One
Media coverage of the ruling has focused on the single headline finding — the ban was “disproportionate.” The Constitutional Council’s reasoning was more specific than that, and its specificity is what gives the decision its weight as a forward-looking legal standard. According to an analysis of the decision’s three grounds, the ruling converts legislative gaps into binding constitutional limits.
Ground One: Overbreadth and the absence of parental override. The Council found that parliament had prohibited access across a broad category of online services without distinguishing between platforms based on their functions, content, audience, or demonstrated risks to children. The exceptions — online encyclopedias, educational and scientific directories, and platforms for open-source software development — were not adequate. The law did not cover collaborative entertainment services, mutual-aid networks, information services, communications applications, games with social functions, or networks connected to education. More critically, it gave parents no legal mechanism to authorize access for their own child based on that child’s individual age, maturity, family circumstances, or the specific platform’s risk profile.
That last point is not a technicality. The Council explicitly recognized that freedom of expression and communication under Article 11 of France’s 1789 Declaration of the Rights of Man and of the Citizen applies to children as well as adults — even where government has a legitimate protective purpose. A blanket ban that offers no route for a parent to say “my child is mature enough for this specific platform” treats every 14-year-old identically, regardless of individual circumstances. The Council found this structure was not “necessary, adapted and proportionate.” According to the Library of Congress French law guide, Article 11 describes the free communication of ideas and opinions as “one of the most precious rights of man” — a protection the Council found applied to children’s access to online services.
Ground Two: Adult privacy — the verification cascade. This is the ruling’s most significant contribution to EU digital law. The Council stated directly: “by prohibiting minors under the age of fifteen from accessing certain online services, the law inherently requires every person, even an adult, to prove their age before accessing them. However, by failing to specify the conditions and limits under which such proof must be provided, the legislature has not established the legal safeguards necessary to ensure compliance with these requirements.” That direct quote from the court’s decision has since been reported across wire services as the ruling’s central passage.
Translation: the law’s child-protection mechanism made all French adults subject to mandatory identity surveillance, and lawmakers provided no legal framework for what that surveillance could collect, how long it could be retained, who could process it, or how errors would be remedied. The stated beneficiary of the law was children. The primary operative burden fell on every French adult with a social media account. The Council treated that operative burden as a rights violation requiring its own constitutional justification — and found none.
Ground Three: Platform scope without differentiation. The Council concluded that the ban’s reach extended to services “where risks to minors have not been proven.” Child welfare — protection from addiction, isolation, pornography, harassment, and fraud — can legitimately restrict communication rights. But the mechanism must target the actual documented risks, not sweep all social media platforms with the same prohibition regardless of whether each specific platform poses the harms the law invokes. The full EU Today analysis notes that the Council’s standard requires laws to be specific, differentiated, and built on a verified constitutional architecture.
What the Ruling Means for Age Verification Technology
The Council’s privacy holding draws a direct line between child-protection legislation and the technical architecture of age verification — and it is the first ruling by an EU constitutional court to do so. As TechTimes reported on France’s enforcement gap, parliament had stripped the age-verification enforcement provisions from the bill during the final joint committee session, leaving the law with an operative ban but no operative compliance pathway.
To verify that a user is 15 or older, a platform has five main options. Self-declaration — typing a birthdate into a form — is what most platforms use today and is documented as trivially ineffective; minors simply enter false dates. Credit-card-based verification relies on the assumption that cardholders are adults and can be circumvented with a parent’s card. Government ID or document scan is the most reliable method for actual identity confirmation; it is also the most privacy-invasive, requiring users to submit a passport, driver’s license, or national identity card to a private third-party verification company. Facial age estimation using machine learning analyzes a selfie to estimate age without storing government documents — Meta deployed this technology across the EU, Brazil, and US Facebook in May 2026 — but it raises accuracy and bias concerns. Zero-knowledge proofs (ZKP) are the technical approach that avoids the privacy trade-off entirely: a trusted credential issuer (a government or bank) certifies that a person clears an age threshold, and the platform receives only a cryptographic proof of that fact — not a name, not a document scan, not a date of birth. The EFF’s AU10TIX breach analysis describes such systems as “surveillance systems” in which data breaches are “not a hypothetical concern.”
The risks of document-scan verification became concrete in June 2024, when researchers discovered that AU10TIX — an Israeli identity verification firm serving TikTok, Uber, and X — had left administrative credentials exposed online for more than 18 months. During that window, a logging platform containing users’ names, dates of birth, nationalities, ID numbers, and facial images of identity documents was potentially accessible to anyone who found the credentials, which had been posted to a public Telegram channel in March 2023. The EFF documented this case as a direct illustration of why mandatory age-verification laws create risks that fall on all users, not just children.
The European Data Protection Board’s Guidelines 3/2025, adopted in September 2025, explicitly favor the ZKP model: providers should not permanently store the age or age range of the recipient but should instead record only qualification status for service access. The EU Commission’s own age-verification application, described in July 2025 documentation, uses this architecture. France’s law did not require platforms to use privacy-preserving approaches and did not prohibit document-scan approaches that concentrate sensitive identity records at a single vendor. The Constitutional Council’s ruling converts that legislative gap into a constitutional failure: if a law requires age verification without specifying the conditions under which it must be conducted, it violates the right to respect for private life. This analysis of the ruling’s constitutional implications concludes that the decision is a setback for this law, not for the policy itself.
The practical implication: any replacement French law, and any EU-level proposal, will need to name the technical standard — or at minimum define the privacy conditions — that age verification must meet. The Council has not specified ZKP by name. But it has ruled that leaving the choice to platforms without statutory guardrails is unconstitutional. That constraint points toward either mandating privacy-preserving approaches or establishing a regulatory specification process with constitutional-level data protection requirements.
Why Adult Age Checks for Child-Protection Laws Are a Structural Design Problem
The Constitutional Council’s ruling articulates what digital rights researchers and privacy advocates have argued since the first child-protection platform bans were proposed: a law that protects children by requiring all adults to prove their identity to private companies is not protecting children at a bargain — it is trading one population’s rights for another’s. As TechTimes coverage of Dutch minister’s warning documented, this infrastructure risk extends beyond age verification into surveillance of political dissidents.
French Digital Minister Anne Le Henanff said aloud, while defending the law before the final July 21 vote, what the Council later ruled unconstitutional: “For four months, all of us in France will have to prove our age.” She framed it as a temporary inconvenience. The Council treated it as a constitutional problem without a statutory solution. That quote, confirmed in France 24’s vote coverage, has since become the ruling’s shorthand summary.
The same structural tension exists in every similar law now under development. The UK’s Online Safety Act brought mandatory age assurance for adult content into force in July 2025 — and triggered a 1,400-percent surge in VPN signups, according to Proton VPN data, as users bypassed the checks. Australia’s Online Safety Amendment (Social Media Minimum Age) Act 2024 required platforms to take “reasonable steps” to keep under-16s off their services — a standard that a longitudinal evaluation by the eSafety Commissioner, published July 31, 2026, found had produced only modest declines in restricted platform use: account ownership dropped from 52.4 percent to 42.1 percent, while 81.5 percent of the target population still actively used at least one restricted platform. The children were still online. The adults had been asked to prove who they were.
Australia’s law named the covered platforms and specified its penalties — up to AUD $49.5 million (approximately $35 million USD) per violation, now proposed to double to AUD $99 million (approximately $70 million USD). France’s law, after parliament stripped its enforcement provisions in the final joint committee session, named no penalties and specified no verification procedure. The result was a law that imposed an operative burden on all adults without providing the constitutional architecture to justify it. TechTimes coverage of Australia’s enforcement escalation detailed how even a more specific law struggled to reduce actual platform use among children.
How Did the Ruling’s Logic Apply to Children’s Own Rights?
A detail the draft coverage of the ruling has underweighted: the Constitutional Council did not strike down the law because it was too aggressive toward children’s freedom. It struck it down in part because it was insufficiently protective of children as rights-bearing individuals with varying circumstances.
The 1789 Declaration’s Article 11 protects free communication of ideas and opinions for everyone — including people under 15. The Council recognized online platforms as important for democratic participation and expression. This means a child has a constitutional interest in accessing online information and communication that the legislature cannot extinguish with a blanket rule that ignores individual circumstances. A 14-year-old using a platform to communicate with school friends or access educational materials has a different constitutional position than a 14-year-old using a platform to access self-harm content. France’s law treated them identically. The Council’s solution is not to remove child protection — it is to require that child protection be achieved through a mechanism that accounts for individual variation, which a parental override system can provide. According to France’s constitutional framework on free expression, this tradition of proportionality review runs through all French constitutional jurisprudence.
The ruling is therefore also a ruling about parental authority: the law stripped parents of the right to make the judgment call that their specific child, at their specific stage of maturity, could access a specific platform with a specific risk profile. French courts have a long jurisprudential tradition of protecting parental authority in educational and developmental decisions. The Council extended that tradition to the digital context.
How Does the French Ruling Apply to the EU Commission’s September Proposal?
The timing is pointed. The Constitutional Council issued its ruling six weeks before the September 1 enforcement date France had set for the ban — and approximately six weeks before the European Commission is expected to present its own proposal for bloc-wide social media restrictions on minors. The two events are now linked.
Von der Leyen has called for EU-wide restrictions. An EU expert panel has recommended prohibiting access for under-13s pending platform safety certification. The Commission’s September proposal — whatever form it takes — must now contend with a constitutional standard set not by an advocacy organization or a parliamentary debate, but by the highest constitutional court of the EU’s founding member state and second-largest economy.
That standard has three components: a mechanism to limit access to documented-risk platforms rather than all social media; a parental override mechanism tied to individual assessment; and a statutory specification of how age verification will be conducted in a privacy-preserving manner. A proposal that omits any of these three elements will face immediate challenge in French courts — and will face the same challenge in Germany, Spain, and any other member state whose constitutional framework applies proportionality review to legislation restricting fundamental rights. That is most of them. The EU Today analysis concludes that the ruling defines constitutional boundaries within which France must continue its policy — and that those boundaries now apply EU-wide.
The ruling also gives the Commission an opportunity it did not have before Friday: a concrete judicial specification of what a constitutionally robust child-protection law requires, issued by a court in a country that attempted the policy in good faith and whose legislature is explicitly committed to trying again. Jessica Galissaire, a senior policy researcher at the Interface who analyzed the French ban for TechPolicy.Press, had framed the question before the ruling as whether the Commission would adopt a “product safety approach” — targeting addictive design features like infinite scroll and algorithmic amplification — rather than a blanket age ban. The Council’s ruling does not require the product-safety approach, but it does require that any access-restriction approach be specific, differentiated, and built on a verified constitutional architecture. That analysis is now available via TechPolicy.Press on France’s EU implications.
What Questions Must France Answer Before Legislating Again?
The Élysée’s response on August 14 was unequivocal: President Macron has instructed Prime Minister Sébastien Lecornu to begin work immediately on revised legislation that addresses the Council’s objections and aligns with the European legal framework, with the aim of bringing a compliant law into force before the end of Macron’s current presidential term — spring 2027. That gives the government roughly seven months to redesign a law that three years of effort have not produced in constitutionally compliant form. According to France 24’s ruling day coverage, Macron was determined the reform take effect before spring 2027, when France holds a presidential election and he cannot run for a third term.
The replacement legislation must answer at least three questions that the struck-down law left open.
First, which platforms are covered and why? The law must be able to demonstrate, for each platform included in its scope, that there is documented evidence of harm to minors on that specific platform. A blanket definition covering all “social network services” cannot survive proportionality review if it sweeps in platforms whose risk to the target age group has not been established. This may require a tiered or risk-based categorization, with different obligations for different platform types — precisely the kind of regulatory complexity the parliament sought to avoid by passing a simple blanket rule.
Second, how will parental override work? The Council did not say parents must be able to override the ban for every platform — it said the law must provide some mechanism for parents or legal representatives to authorize access for a specific child based on that child’s individual circumstances. Designing that mechanism requires addressing verification of the parent’s identity, the operational cost of platform-level parental authorization at scale, and the risk that such a mechanism becomes the primary circumvention pathway.
Third, what age verification standard must platforms meet? This is the technically hardest question. France cannot simply say “platforms must verify age” — the Council has ruled that is constitutionally insufficient. The new law must specify, at the statutory level, the conditions under which age verification must be conducted: what data may be collected, what may be retained, who may process it, how errors must be remediated. Mandating privacy-preserving methods (ZKP-based systems) or prohibiting the riskiest approaches (unregulated document scans to third-party commercial vendors) is not just a policy preference — it is now a constitutional requirement.
What Happens to French Law as of Today?
The immediate practical consequence is that the September 1 enforcement date is dead. The Constitutional Council’s ruling blocks Article 1 of the law — the core ban — from taking effect. Children under 15 in France remain subject to the existing regime: France’s 2023 law requiring platforms to obtain parental consent for under-15s to create new accounts, a rule that has been largely unenforced due to technical and legal obstacles since its passage. The high school mobile phone ban — a separate provision of the struck-down bill — was not challenged by the Council and is understood to remain in effect. According to France 24’s coverage of the ruling, the ruling does not prohibit France from legislating again or invalidate every other provision in the wider law.
For the major platforms — TikTok, Meta’s Instagram and Facebook, Snap, and Google’s YouTube — the ruling provides a reprieve. It does not close the regulatory file. French law is in active revision, the government has publicly committed to a tighter replacement, and the EU Commission’s September proposal creates a parallel track that could impose bloc-level obligations regardless of what France’s domestic legislation ultimately says. Platforms that have been complying in good faith with France’s 2023 parental-consent framework — which is to say, most of them incompletely — remain in that legal limbo while the redesign proceeds.
The Constitutional Council has not said that France cannot legislate on social media and children. It has said, with precision specific enough to serve as a legislative drafting guide, how not to legislate. Whether the government can meet the spring 2027 deadline with a law that satisfies all three constitutional grounds in the ruling — while simultaneously navigating GDPR constraints, DSA harmonization requirements, and the EU Commission’s own forthcoming framework — is the question that will define the next chapter of European digital policy for children.
Frequently Asked QuestionsWhy did France’s Constitutional Council strike down the social media ban?
The Council identified three constitutional failures. The ban was overbroad: it swept all social media platforms without distinguishing between those with documented risks to minors and those where such risks have not been established, and it provided no mechanism for parents to authorize access for their specific child based on individual circumstances. It violated adult privacy: any system that blocks children requires all adults to prove their age, and the law specified no legal framework governing how that verification would work — what data could be collected, retained, or processed. And it failed proportionality: the specific measure chosen was not the least restrictive means available to achieve the child-protection goal. All three failures together meant the law could not withstand review under France’s 1789 Declaration of the Rights of Man, which protects free communication of ideas and opinions.
What must France do differently in the replacement law?
At minimum, the new legislation must: (1) scope coverage to platforms where harm to minors has been specifically documented, rather than all services meeting a broad “social network” definition; (2) include a mechanism for parental or guardian authorization of access for a specific child based on that child’s individual maturity and circumstances; and (3) specify in statutory text the privacy conditions governing any age-verification requirement — including what data may be collected, how it must be protected, and what privacy-preserving technical standards must be met. The Council has not specified zero-knowledge proof systems by name, but its ruling requires that the verification mechanism be defined in law, not left to platform discretion. A replacement law that mandates ZKP-based verification would address the constitutional failure; one that simply restates the ban without specifying the verification architecture would not.
What does the French ruling mean for the UK and Canada, which have similar laws in progress?
The ruling establishes that a child-protection social media ban that forces all adults to verify their age — without statutory guardrails on how that verification is conducted — fails constitutional proportionality review. The UK’s Online Safety Act brought mandatory age assurance into force in July 2025, though its child social media ban component targets under-16s and has not yet been implemented. Canada’s Bill C-34 is pending. Both laws face the same structural design problem the French Council identified: the mechanism that protects children requires everyone else to surrender privacy. The French ruling does not bind UK or Canadian courts, but it is the most detailed constitutional analysis of this design tension from a major democratic institution, and it will be cited in legal challenges to both laws. The EU Commission’s expected September 2026 bloc-wide proposal must also account for it.
What age verification method satisfies both the privacy requirement and the child protection goal?
Zero-knowledge proof (ZKP) systems are the only currently available approach that can answer “is this user over 15?” without transmitting identity data to the platform. Under ZKP-based verification, a trusted issuer — a government agency, a national ID authority, or a bank — certifies that a user clears an age threshold, and the platform receives only a cryptographic proof of that fact. No name, no document scan, no date of birth leaves the verification chain. The European Data Protection Board’s Guidelines 3/2025 explicitly favor this model. The European Commission’s own age-verification app uses this architecture, as described in July 2025 documentation. Document-scan verification — where users upload a passport or national ID card to a private third-party company — is the most technically reliable alternative, but concentration of identity documents at a single commercial vendor creates breach risks that the 2024 AU10TIX incident illustrated: the firm serving TikTok, Uber, and X left credentials exposed for 18 months, potentially exposing users’ identity documents to anyone who found the credentials on a public Telegram channel.