Algorithmic Childhood: Can Indian Law Protect Children from Addictive Feeds?

Recommendation algorithms increasingly shape children's online experience by optimising for engagement, often at the expense of well-being.

Abstract

Recommendation algorithms increasingly shape children's online experience by optimising for engagement, often at the expense of well-being. The Digital Personal Data Protection Act, 2023 and the Information Technology Rules, 2021 offer protections for data processing and harmful content, but do not directly regulate addictive design. This article asks whether Indian law can protect children from systems built to capture and retain attention.

Keywords

Recommendation Algorithms, Children, Social Media, DPDPA, 2023, IT Rules, 2021, Indian legislative.

Introduction

Every time a child opens a social-media application, an unequal contest begins. On one side is a young user with a still-developing capacity for self-regulation. On the other is a recommendation system refined by a resource-rich platform to maximise time and attention. Pauses, clicks and scrolling behaviour become signals that teach the system what will keep the child engaged.

While this is at best a debatable issue to adults, it is practically more of an architectural flaw taken up to a mega scale for those whose brain has not yet finished functioning for children.

It is extremely accurate and extremely urgent: Whether the legislation of India can allow damages caused not by seeing content but through the decision-making which determines what content a child should be looking, at what pace and how long.

Designing for Engagement: The Problem

There are three design trends that we should pay attention to. An endless page eliminates the resting cues of previously finite page. Autoplay extends this logic to the video, removing even the decision point of choosing the next clip. Individualized streams driven by recommendation algorithms assure that whatever content a kid is most likely to watch next is geared to keep them watching instead of relaxing or feeling content.

These outcomes are not accidents of neutral design; they reflect choices that turn attention into revenue. Children may experience sleep loss, reduced concentration, social anxiety and weaker independent judgment as a platform increasingly dictates how their time is spent. A harmful video presents a content problem, but an individually optimised loop of escalating stimulation presents a design problem.

India's Existing Legal Framework

India's scheme does provide relevant protections, even if it was designed without the intent to consider Recommendation Algorithms per se. Art 21 is now extensively understood by the SC to ensure a right to life that includes protection of one's dignity and right to privacy of informational self.

DPDPA has introduced recent significant law and order under DPDP Act of India; it has restricted usage of minor's personal data under Sec 9(1) "No data fiduciary shall process the personal data of a child except with the verifiable consent of parents". Here 18 year boundary for the child is determined from the Juvenile justice act of 2015. The tracking, behavioural profiling and targeting advertising to the child of paragraph 9(3), by impacting on the data-centric profiling on which such recommendation systems rely. These section 9(3) protections cannot be waived even with parental permission - clearly, society regards a particular class of risk to children as not being bargainable over.

Rules that provide the second pillar include the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, (as amended), which lay down due diligence requirements for social media intermediaries and also set out a grievance redressal mechanism that would be supervised on appeal by Grievance Appellate Committees. These are rules intended mainly to effect removal of objectionable material and ensure traceability of their originators rather than attributing blame towards design.

Where the Framework Falls Short

The gaps are substantive, not accidental. For one, there is a lack of algorithmic transparency. No Indian legislation requires platforms to share the criteria for their recommender systems and thus regulators cannot ascertain whether a feed's design is harmful.

Second, child age verification has not been solved. The consent mechanism built into the DPA is severely weakened by lack of a reliable, privacy-preserving age verification mechanism; current suggestions will be easily circumvented by kids and place unnecessary burdens on households with low digital or text literacy.

Third, DPDPA prohibits processing, not architecture: A site could easily get around the statute with infinite scroll or autoplay without collecting or processing the same kind of data, none of which requires user profiling.

Fourth, the enforcement framework is still developing. The Data Protection Board was being constituted as child-related obligations came into operation, while parts of the IT Rules remained under constitutional challenge. Regulatory ambition has therefore moved faster than institutional capacity.

Comparative Perspective

UK's Online Safety Act, 2023 necessitates that all in-scope services assess the risks of services for children every 12 months and, where those risks are high or medium, that recommender systems filter out or downrank all harmful content from children's feeds. The European Union's Digital Services Act specifies more clearly, Article 28 for proportionate measures for minor's protection and Article 38 of the same act: "very large online platforms… must provide at least one recommender system which is not based on the processing of personal data".

Beyond that, the commission's 2025 guidelines, will "allow children to clear their feeds, to actively tell the platforms their explicit preferences, over the platform's inferred knowledge on their engagement indicators."

Conclusion

A child-focused approach to regulating recommendation algorithms needs to be more than just consent and take-down. The DPDPA and IT Rules are significant but incomplete steps in this direction.

Follow-up regulation under the DPDPA, or even the development of a design code inspired by emerging UK and EU standards for safety-by-design without requiring verification mechanisms that could harm digitally excluded children could make the difference.

Until the law addresses the architecture that captures children's attention, India will continue to regulate individual pieces of content while leaving the system that selects and amplifies them largely untouched.

Primary materials

Key primary materials: Digital Personal Data Protection Act, 2023 and subordinate legislation; Ministry of Electronics and Information Technology.

Technology and Digital RightsTechnology LawArtificial Intelligence