Published On: 14th August 2026
Authored By: Ayesha Salma Yusoof
Middlesex University Dubai
Introduction
For decades, digital protection laws for children have operated through content regulation, which focused on controlling the content that children can see. On 1st January 2026, the Federal Decree-Law No. 26 of 2025 Regarding Child Digital Safety took effect, establishing the United Arab Emirates’ first comprehensive statutory framework focusing on the digital safety protection for children.[1] Six months later, on 18th June 2026, the Cabinet Resolution No. 106 of 2026 Regarding the Regulation of Children’s Access to Social Media Platforms fixed the age of fifteen as the minimum age to have a social media account and imposed safeguards for users aged fifteen to under sixteen. [2]
The status regulation element, which in this case determines a child’s presence on a digital platform based solely on age, is reflective of the pivotal development surrounding the restrictions taken towards social media access for minors across multiple nations. These measures not only reflect growing concerns over the childhood of minors from digital addiction but are reflective of protecting children from gaining exposure to inappropriate content, online exploitation and unsafe interaction, which could put them in a vulnerable position. Consequently, the central question lies as to whether the UAE’s sound two-tier structure, encompassing a federal statute supported by a specific Cabinet Resolution, could potentially achieve the ultimate aim of digital protection for children.
The Two-Tier Framework
The Child Digital Safety Law is seen to lay down the broad principles to support the implementation of future regulations. This framework applies to any digital platform operating in or directed to UAE users abroad, internet service providers licensed under the UAE telecommunication laws and the custodians of children under eighteen.[3] Consequently, this establishes obligations like requirements to implement an age-verification mechanism, calibrating a forthcoming risk-classification system, content moderation, prohibiting children from accessing commercial online gaming, gambling and associated advertising, restrictions on processing personal data of children under the age of thirteen without custodial consent, periodic reporting duties, and notice-and-takedown obligations, particularly relating to child sexual abuse material.[4]
Additionally, custodians (including parents or guardians) are highlighted as a contributing factor in this framework, where they bear a set of duties that include supervising digital use, refraining from enabling the circumvention of these regulations, preventing social media exploitation and reporting harmful content.[5] The oversight of this framework sits with the Telecommunications and Digital Government Regulatory Authority, alongside the support of the Child Digital Safety Council, which is chaired by the Ministry of Family.[6] Currently, the statute grants a one-year grace period, meaning that full enforceability arrives in January 2027.[7] With non-compliance likely to trigger blockings and administrative sanctions, the effectiveness of this framework would likely depend on the implementation of the regulations to uphold the vision outlined in the framework.
Alternatively, the Cabinet Resolution, which outright bars children under fifteen from posting, commenting and participating on open social media platforms, reflects a translation of the general age-verification principle in the Child Digital Safety law into becoming a specific numerical rule.[8] As for the fifteen to under sixteen category, gaining access is possible, but limited through stricter parental control and age-appropriate algorithm filters.[9] With a twelve-month transition period, the Resolution highlights that self-declaration of age alone is legally insufficient.[10] This consequently forces platforms to consider methods like ID-based checks, biometric and AI-supported age estimations or licenced third-party verification providers as alternative verification solutions that go beyond self-declaration.[11]
Assumptions on Enforcement
With the statute outlining the social media framework and institutional authority, alongside the Cabinet Resolution operationalising the age verification principle, this doctrine is theoretically legally sound. The difficulty arises when having to determine if the restricted age verification is reliable and practically achievable at scale.
This hypothesis can be observed in Australia’s Online Safety Amendment Act 2024, which came into force in December 2025, requiring age-restricted platforms to take reasonable steps to prevent users under sixteen from having access to or creating social media accounts.[12] Research observation noted by BMJ found that more than 85% of individuals under sixteen continued to use their social media accounts three months after the ban took effect.[13] This consequently highlighted that the current age verification methods, which still encompassed an element of age self-declaration, were suboptimal. Consequently, the Australian government’s response of imposing heavy penalties of up to AUD 49.5 million on the relevant platforms or providers illustrates that increasing penalties alone are unlikely to bridge the verification gap.[14] Additionally, the study also highlighted that the regulation alone is likely to be ineffective if the enforcement strategy remains unconvincing and weak.
With the Cabinet Resolution having already taken into account that self-declaration is inadequate, this suggests that the UAE’s model may have a structural advantage since the Telecommunications and Digital Government Regulatory Authority, operating as a regulatory body to oversee internet service providers, allows the regulator to block access at an infrastructural level rather than having to rely on the platforms policing themselves. Therefore, whether the advantage is real entirely depends on the consistent implementation of regulation by the key stakeholders (government, internet service providers, social media platforms and custodians) to achieve the mechanism stated in the Resolution and support the successful implementation of the Child Digital Safety laws.
Privacy-related Concerns
The Child Digital Safety law states that processing children’s personal data must be done with the custodian’s consent.[15] However, the verification data, which may include biometrics, government records and ID checks, is relatively a more sensitive form of data as compared to the social media data being restricted. Consequently, this conflicts with the notion of verification being “accurate, proportionate, privacy-conscious and limited to the minimum data necessary” because biometric matching and estimations are more data-intensive models as compared to the self-declaration model being replaced.[16] With neither instrument explicitly specifying the data retention periods and third- party data sharing limits applicable to licensed verification providers, the standard of safeguards and regulators’ enforcement decisions is a domain yet to be resolved before the regulation is fully operational after the 12-month transitional period.[17]
Supporting Authority
Federal Law No. 3 of 2016 on Child Rights (commonly known as Wadeema’s Law): The general principle of Wadeema’s law establishes that the state and the child’s guardians bear a duty to protect the child from all forms of neglect, abuse and exploitation.[18] Therefore, Wadeema’s law can be read as an extension of the protective duty relating to cybercrime legislation and preventing children from being exposed or directly put at risk when using online platforms. With Wadeema’s law reflecting the state’s protective duty towards children, the Child Digital Safety Law and the Cabinet Resolution reflect a preventative measure taken to deter the likelihood of potential harm.
Federal Decree-Law No. 45 of 2021 on Personal Data Protection: Establishes the general principle that processing of any personal data, including the collection of data to verify a user’s age, has certain requirements and obligations to be met, thereby limiting such data to a specific purpose which must not exceed its necessary limit.[19] Therefore, verification platforms collecting data to process age-verification as per the Cabinet Resolution must satisfy the purpose, limitation and data minimisation standard to ensure compliance with the personal data protection legislation.[20]
Conclusion
Overall, the UAE’s Child Digital Safety framework is a legally well-constricted outline when paired alongside the operational and design aspects of the regulations in the Cabinet Resolution. Despite the implementation of age-verification technology at a large scale not yet proven reliable in Australia, the twelve-month transitional period will be a crucial timeframe for the UAE to experiment with the accuracy of age-verification systems, a periodic reporting mechanism that ensures compliance and the explicit regulatory infrastructural changes (like the blocking powers towards internet service providers). Apart from these technical factors that are yet to be addressed, the UAE’s framework proves to be a well-designed framework that comes at a much-needed moment because mitigating the potential harm of social media, particularly targeting children, is a critical policy issue that needs to be addressed rather than postponed further.
References
[1] Baker McKenzie, ‘United Arab Emirates issues new Child Digital Safety law’ (8 January 2026) < United Arab Emirates issues new Child Digital Safety law | Insight | Baker McKenzie > accessed 14 July 2026.
[2] Ministry of Family, ‘Cabinet Resolution Regarding Regulating Children’s Access to Social Media Platform’ (19 June 2026) < Cabinet Resolution Regarding Regulating Children’s Access to Social Media Platform – Ministry of Family > accessed 14 July 2026.
[3] United Arab Emirates issues new Child Digital Safety law (n.1).
[4] Ibid.
[5] Ibid.
[6] Ibid
[7] Federal Decree-Law No (26) of 2025 Regarding Child Digital Safety, art 18.
[8] Cabinet Resolution Regarding Regulating Children’s Access to Social Media Platform (n.2).
[9] Ibid.
[10]Ibid.
[11]Ibid.
[12] Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) No 127 of 2024.
[13] Courtney Barnes and others, ‘Assessing Early Effects of Australia’s Social Media Minimum Age Act on Adolescents’ Social Media Use: Observational Study’ (2026) 393 BMJ e363695 < Assessing early effects of Australia’s Social Media Minimum Age Act on adolescents’ social media use: observational study> accessed 14 July 2026.
[14] Ibid.
[15] Federal Decree-Law No (26) of 2025 Regarding Child Digital Safety, art 7.
[16] Cabinet Resolution Regarding Regulating Children’s Access to Social Media Platform (n.2).
[17] Ibid.
[18] Federal Law No (3) of 2016 on Child Rights Law (Wadeema).
[19] Federal Decree-Law No. 45 of 2021 on Personal Data Protection, art 5.
[20] Donovan Vanderbilt, ‘UAE Data Protection Law: PDPL Compliance Guide and Requirements’ (WE THE UAE 2031, 22 February 2026) < UAE Data Protection Law: PDPL Compliance Guide and Requirements — WE THE UAE 2031 > accessed 14 July 2026.




