
Masaar and the Egyptian Initiative for Personal Rights (EIPR) call on the Supreme Council for Media Regulation and the National Telecom Regulatory Authority (NTRA) to publish the full text of their joint decision on children’s social media accounts, and to set out its legal basis and safeguards governing its implementation. The two regulators announced the decision on 17 September without making its full text available. The two organizations stress that protecting children from exploitation, harassment, blackmail and other forms of online harm must include addressing risks arising from platform design, while safeguarding children’s privacy and their rights to expression, access to knowledge and participation.
According to the official announcement, the decision applies to users under 15. It prohibits platforms from allowing independent personal accounts to children under 13, while allowing them for users who are at least 13 but not yet 15, with an automatically activated mandatory safe-use mode that cannot be disabled by the child alone. It also requires reviewing existing accounts that reliable mechanisms identify as belonging to, or likely to belong to, users under 15, with a means to challenge the outcome and correct age information. Platforms must submit implementation plans within 30 days of the publication and their notification of the decision, and comply within three months of its entry into force.
Last April, in their paper “No Trade-offs: Towards Protecting Children Online While Respecting Their Rights”, the two organizations addressed platforms’ responsibility for features that expose children to harm. This position is grounded in the Convention on the Rights of the Child, which Egypt has ratified, and the Committee on the Rights of the Child’s interpretation in General Comment No. 25 on the digital environment. The comment links protection from violence and exploitation to children’s best interests, evolving capacities, and rights to privacy, access to knowledge and expression. On this basis, the two organizations evaluated restrictions imposed to protect children using the tests of necessity and proportionality, to safeguard their rights without delaying responses to existing reports of harm.
Masaar and EIPR stress that restrictions on creating accounts are insufficient to protect children if risks arising from platform design remain. Children’s safety also depends on what “safe mode” entails, which settings are activated automatically and the limits on changing them according to age, as well as who can message children’s accounts and which accounts and content the service recommends. These risks also extend to location and image sharing, live streaming, advertising targeted at children, commercial profiling and in-app purchases.
Protection after harm depends on a reporting process that is easy to use and confidential, enables children to preserve evidence, follow up on reports and get help, responds swiftly to serious cases, and prevents the perpetrator from re-establishing contact through other accounts. In some cases, disclosing report details to a child’s family may expose the child to further danger, making confidentiality in support procedures part of their safety. The number of reports alone cannot measure the effectiveness of this process: protection also depends on how quickly reports are addressed and whether reporting has actually stopped the harm and prevented it from recurring.
These safeguards remain incomplete without a clear definition of the decision’s scope. The available announcement does not specify whether it covers online games with chat features or services that combine posting and messaging, even though UNICEF research found that 14% of the cases it examined occurred in games with communication features. This figure must not be generalized to Egypt. The announcement is also limited to children under 15, leaving unspecified the measures to protect adolescents aged 15 to 17 and the ways in which children under 13 can access information and safe assistance without needing an independent account.
Dividing users into age groups and reviewing existing accounts make age verification central to implementing the decision. The official announcement requires effective and proportionate age-verification methods and minimizing the data collected, but does not specify which methods will be adopted or the rules governing their operation. Evaluating these mechanisms depends on how much data is required, who will process it, how long it will be retained, and how far it is possible to establish only that a user is above a specified age threshold without disclosing their identity.
The two organizations stress that age-verification methods may create new risks unless they are designed and used under clear rules. Verification data or results may be reused for marketing or profiling, or to link a user’s identity to their activity across different services beyond the specified purpose. Some verification methods may also exclude people who lack the necessary documents, devices or connectivity, while reliance on biometric data adds risks to privacy and access to services. This highlights the need for clear rules on processing age data and for the Personal Data Protection Center to act within its legal limits, in coordination with regulators, to ensure the methods adopted comply with those rules.
The possibility of using methods based on analyzing user behavior makes these safeguards all the more necessary. Al Mal newspaper reported comments by the NTRA’s deputy head about the possibility of inferring age from how users write, interact, and use their accounts, as one of the potential technical methods. This does not establish that any particular method has been adopted. Assessing the effects of these methods includes examining how much data they require, whether it can be linked to the account or to advertising, and their accuracy across different groups, including the possibility of errors affecting children with disabilities.
Alongside measures relating to children’s accounts and age verification, protection tools have been introduced that operate outside the platforms themselves, at the level of internet access. The launch of the mobile services “Etamen” and “Etamen 3ala El A5er” was announced in July. They allow the owner of a mobile line to subscribe to content filtering; the latter service also blocks access to social media websites and applications. This form of protection differs from safeguards applied within children’s accounts: it controls access to services at the connection level. It does not, in itself, address risks arising from platform design or operation. Filtering internet access therefore cannot replace platforms’ responsibility to reduce exploitation and respond to children’s reports.
In light of the above, Masaar and the Egyptian Initiative for Personal Rights call for the following:
- Publish the decision and ensure transparency in its implementation: The Supreme Council for Media Regulation and the NTRA must publish the signed decision, its number, legal basis and annexes, and specify the dates of publication, notification and entry into force from which implementation deadlines are calculated. The two organizations also call on the regulators to identify the authority responsible for reviewing compliance plans, disclose the criteria for approving them, and publish summaries of the plans and regulatory decisions insofar as doing so does not put children’s safety or data at risk.
- Clarify the decision’s scope and the age groups it covers: Specify whether the decision covers online games with chat features and services that combine posting and messaging, while ensuring that adolescents aged 15 to 17 have effective ways to report harm and obtain help when they experience it. This must not mean extending restrictions on creating or using accounts to this age group. Platforms should also provide appropriate ways for children under 13 to access information and assistance without needing an independent account.
- Require platforms to provide effective safeguards within their services: specify what “safe mode” includes, which settings activate automatically, and the limits on changing them based on the child’s age. Reduce opportunities for harmful contact by restricting messages from unknown adults and the recommendation of children’s accounts to those adults; limit recommendations that lead to harmful content or unwanted contact; set controls on location and image sharing and live streaming; and set clear restrictions on advertising targeted at children, commercial profiling and in-app purchases.
- Provide a safe and effective process for reporting harm: Enable children to report harm easily and confidentially, preserve evidence, follow up on reports and obtain help, with an urgent response to serious cases and measures to prevent the perpetrator from renewing contact through other accounts. Support procedures must protect the child’s confidentiality where informing their family could expose them to further danger, without delaying responses to existing reports of harm.
- Establish clear safeguards for age verification and data protection: Disclose the data required for age verification, who will process it and how long it will be retained, and limit verification to the minimum information necessary wherever possible. The two organizations also call for a ban on using verification data or results for marketing, profiling or linking a user’s identity to their activity across different services beyond the specified purpose. Alternatives must be available for people who lack the necessary documents, devices or connectivity, and providing biometric data must not become a general requirement for using services.
- Assess age-verification methods before wider deployment: Publish descriptions of proposed age-verification or age-estimation methods and identify their providers. Conduct a public assessment of their effects on privacy and access to services, and of age-estimation errors, including those that may affect children with disabilities. The two organizations also call on the Personal Data Protection Center to issue clear guidance, within its legal remit, on processing age data, and to coordinate with the regulators to ensure that the methods adopted comply with these rules.
- Ensure participation and independent oversight of implementation: Disclose the consultations held on the measures, involve children and adolescents of different ages and backgrounds in evaluating them through safe processes. Enable independent assessment and make periodic findings available on the speed of responses to reports of grooming and harassment, ease of access to help, age-estimation errors, the outcomes of appeals, and unintended effects on access to knowledge.
- Publish evaluation criteria and review the measures regularly: The Supreme Council for Media Regulation and the NTRA must announce evaluation metrics and review dates from the start of implementation, and revise measures shown to restrict rights or fail to protect children.
- Subject any subsequent legislation to public consultation: The government and parliament must publish any draft law subsequently proposed on this issue and consult affected groups before its adoption, in a way that ensures children’s safety, privacy and ability to learn, express themselves and participate.