Meta Faces Legal Challenge in Oakland as Data Privacy Laws Differ Between the US and India
This week, a significant legal case against Meta began in Oakland, focusing on the company’s practices concerning user data and children. In the United States, the case is grounded in a law from 1998 designed to protect children under 13. Conversely, India’s data protection laws extend the definition of a child to anyone under 18, enforcing stricter guidelines, including the requirement for verified parental consent before any data processing occurs.
While the US case investigates whether Meta allowed children under 13 to use its platforms, the Indian law proactively restricts tracking, behavioral monitoring, and targeted advertising aimed at minors. This means that India already has legislation in place that addresses many of the concerns currently being debated in a US courtroom.
Understanding the Difference in Child Protection Laws
The Children’s Online Privacy Protection Act (COPPA) in the US applies only to individuals younger than 13. Once a child turns 14, they lose these protections under this law. Therefore, the recent allegations against Meta revolve around allowing unauthorized access to younger users and the potentially harmful design elements aimed at teenagers, which are being scrutinized under state consumer protection laws.
On the other hand, India’s Digital Personal Data Protection Act (DPDP) defines a child as anyone under 18. It mandates that any processing of personal data requires verifiable consent from a parent, with measures in place to validate the parent’s identity and age. The law also explicitly prohibits the tracking and targeted advertising of children.
The Implications of Stricter Regulations
If the Indian standards were applied to Meta, many features that are currently subject to legal scrutiny in the US—like recommendation algorithms and content designed to keep users engaged—would violate the DPDP. The DPDP’s straightforward nature makes it easier to determine if a child’s data has been misused, as it focuses on the child’s age and whether their behavior was monitored without parental consent.
Meanwhile, the case in Oakland must prove that Meta’s design choices were unfair or misleading. This process is more complicated compared to the Indian regulations, which could lead to clearer enforcement.
One reason behind the lack of equivalent actions in India is that while the DPDP Act was established in 2023, the regulations required to enforce it are still being developed. This includes the essential feature of confirming that a consenting adult is indeed the parent of the child, a task that poses significant challenges without becoming a surveillance mechanism itself.
What This Means Moving Forward
Earlier this year, discussions were held by Indian authorities, exploring how to establish age-based controls for children on social media platforms. Currently, India has strong laws but lacks the administrative framework for their enforcement. The DPDP largely relies on a Data Protection Board for enforcement, which is fundamentally different from the US system where state attorneys general can initiate lawsuits.
This situation highlights a contrast in regulatory approaches between the two countries. The US, with its ongoing legal actions, is producing vital evidence that could inform regulations elsewhere, including in India. Internal documents from Meta are being reviewed, and high-ranking officials from the company may need to testify, creating a public record that could serve as a reference point for future regulation in India.
In conclusion, while both nations strive to safeguard the interests of young users, the ongoing case in Oakland could ultimately lead to insights that may help in the effective application of India’s newly implemented data protection laws. The world will be watching as this case unfolds, possibly shaping the future of child data protection laws globally.
