France's Social Media Age Ban: a Trojan Horse for Digital Surveillance

France’s new social media age-verification law is being presented as a child protection measure, but it lays the foundations for unprecedented identity checks and state control.

France\'s new law mandates age verification on social media.

France’s new law introduces mandatory age verification, raising fears of digital surveillance, weaker anonymity and EU-controlled online IDs. Photo: Suzi Media Production/Getty Images

On 21 July 2026, French lawmakers definitively adopted a bill establishing a minimum age for accessing social media, a project that has been under consideration for nearly three years.

The bill establishes the principle of banning social media for children under 15, but the exact age will be set by decree within this upper limit to ensure compliance with European law. Under the guise of child protection, the system unfortunately foreshadows a dangerous form of control over public opinion, exercised by the state, which seeks to keep an eye “on what goes on inside people’s homes”.

Platforms will be legally responsible for verifying the age of their users before opening or maintaining an account; they will no longer be able to rely solely on a simple sworn statement.

The system will use a double-anonymity age-verification mechanism. Users will have to prove their age to a trusted third party, such as through a digital ID or an accredited service provider. That third party will issue a cryptographic token certifying only that the person is aged 15 or over.

The social media platform will receive this validation without gaining access to the user’s civil identity, while the trusted third party will not know on which platform the verification is being used. Platforms must implement at least two technical verification solutions that comply with this principle in order to balance the protection of minors with respect for privacy.

In the event of non-compliance with these obligations, platforms will face significant financial penalties, which could include a ban on operating in the French market if they refuse to implement compliant age verification.

The implementation schedule is phased: as of 1 September 2026, the ban will apply to the creation of all new accounts; as of 1 January 2027, the verification requirement will also apply to existing accounts, with a transition period of a few months to allow users to verify their age.

Final Authority in the Hands of the EU

Some web experts point out that the law is nothing more than an empty shell. Tech entrepreneur Yann Darwin points to the "digital majority" law of 7 July 2023 as a precedent. It prohibited children under 15 from registering on social media platforms without parental consent, mandated age verification and imposed a fine of up to 1% of a platform’s global revenue for failure to comply.

However, the law was never followed by implementing decrees and was, in the weeks that followed, blocked by Brussels for non-compliance with the Digital Services Act. To circumvent the predictable sanction from Brussels, the new version passed by French lawmakers is significantly watered down.

The Senate’s rapporteur for the bill admitted the day before yesterday that it was a law with “fairly limited regulatory scope”, a “landmark”, whose enforcement will depend “almost exclusively on the European Commission”.

EU Digital Identity Fuels Surveillance Fears

You might be interested EU Digital Identity Fuels Surveillance Fears

It is indeed important to note the power wielded by the European Union in this matter. It is the EU that will have the final say on the legal framework, the technical standards for age verification and part of the oversight of platforms – which represents yet another relinquishment of sovereignty over the highly symbolic issue of individual identification.

The mindset behind this law is cause for concern. As Aurore Bergé, minister for equality and the fight against discrimination, explained to the media, “what happens inside people’s homes is the state’s business”.

Finally, the planned timeline for implementing the law raises questions and concerns. The measure will apply to new accounts starting in September 2026. For existing accounts, retroactive verification will begin in January 2027 – right in the middle of the presidential campaign. Bergé had announced this as early as February: “The issue of ending anonymity on social media will arise during the 2027 presidential campaign.”

There is likely to be concern about platform overload, as well as a series of bugs that could discourage many users from taking the step of verifying their identities. This phenomenon has been documented and analyzed in the United Kingdom: identity verification processes lead to users dropping off, particularly among those over 50, who encounter more technical difficulties and are reluctant to share their personal data.

Influencer Pierre Sautarel has raised concerns about the age-based divide this could create. Identity verification risks excluding from social media a large portion of the older electorate, who are uncomfortable with these procedures and may consequently turn to the mainstream media for information, without access to alternative perspectives: “Sidelined from the online debate in the midst of a presidential campaign, this audience will return to getting their news from TF1 and France 2, which will suit the centrist bloc perfectly.”

The Hidden Cost: Fewer Voices, Less Online Debate

Erik Tégner, president of the conservative magazine Frontières – which is often subject to censorship and attacks from the left-wing press or militant progressive groups – sees another unintended consequence: the lifting of anonymity is likely to encourage organizations tasked with tracking down online hate speech, as legal action will be made much easier.

The problem is not only ideological, it is also technical and practical. The past few months have been marked by a series of data breaches affecting major public services, fueling questions about the government’s ability to ensure the security of the personal information it collects.

The most emblematic breach remains that of France Travail, which exposed the data of tens of millions of people registered over the past 20 years, including Social Security numbers, addresses, and contact information – a case that led the National Commission on Informatics and Liberties (CNIL) to impose a fine of €5m ($5.7m) on the agency.

More recently, in April 2026, France Titres (ANTS), the government agency responsible for issuing identity documents and official papers, disclosed a security incident affecting 11.7 million accounts, with the potential disclosure of personal information such as names, dates of birth, email addresses, and, in some cases, mailing addresses or phone numbers. Under the new law, any expansion of identity verification measures automatically increases the amount of sensitive data that could be compromised in the event of a security breach.

Why Meta Is Fighting Europe's Digital Rulebook

You might be interested Why Meta Is Fighting Europe's Digital Rulebook

Little Resistance in Parliament

On the right, voices are being raised on social media to denounce the parties’ lack of vigilance on this crucial issue. In the parliamentary chamber, very few voted against the measure.

In 2011, Marine Le Pen denounced the exploitation of child protection as a pretext to implement prior screening for internet access, but the majority of her party abstained during the vote. The emphasis on child protection makes the issue of identity verification acceptable to a large segment of the public, who fail to see the long-term side effects or unintended consequences of the measures set to be implemented.

The Rassemblement National’s (RN) responsibility lies in its inability to propose a credible alternative that would allow for the continued protection of children without getting caught up in the cycle of identity verification. Yet there are ways to address this. Access to smartphones for children under 15 could be regulated without compromising the protection of adults’ privacy. From notifications to algorithm settings, platforms could also be required to address the addictive mechanisms they exploit, particularly with regard to minors.

This is the view of Sarah Knafo, a MEP for Reconquête, Éric Zemmour’s party. She believes that the law on age verification on social media constitutes a disproportionate infringement on civil liberties under the guise of protecting minors.

The requirement to verify users’ ages will effectively link French citizens’ real identities to their online accounts, paving the way for a form of widespread surveillance and creating an additional risk in the event of a data breach or hacking of personal information.

Knafo also considers the measure ineffective, arguing that teenagers will be able to easily circumvent it using VPNs or other technical means.

Finally, she advocates an approach based on family responsibility: “Parental controls have never been more effective; smartphones allow for precise monitoring of usage. It is up to families to exercise their authority. And it would already be a step in the right direction if society stopped constantly undermining parents’ authority only to step in and replace them.”

In and of itself, the law passed on 21 July is merely the embryonic form of such control. Many details remain unclear regarding how this control will function, the procedures involved and its limits. But everything is already in place to enable, sooner or later, an unprecedented level of control over the population – one endorsed by both national and European institutions.

AI Can Already Control Much of Your Smartphone

You might be interested AI Can Already Control Much of Your Smartphone