Family Vlogs to Deepfakes: Why India Needs a Digital Child Rights Law
- Shekhar Patil
- 2 days ago
- 7 min read
*Shekhar Patil
Introduction
The child protection laws were formulated to address tangible dangers that children face, such as abusive homes. However, in today’s digital world, gadgets like smartphones make use of algorithms to turn a child’s personal emotions into monetary gains without the consent of the minor. There are child protection laws in India, namely the POCSO Act of 2012, the IT Act of 2000, and the DPDP Act of 2023. But none of these laws talk about the commercialization and exposure of children in online spaces deliberately built to get the attention of users. To bridge this gap, India requires a Digital Child Rights Law which will ensure that children are not just considered the consumers of technology, but as independent right holders entitled to privacy, dignity, and digital freedom under Article 21 of the Indian Constitution.
Children as Content, the Commercialization of Childhood
Modern social media has transformed the situation, creating a virtual space whereby childhood itself becomes public media. Caregivers or parents, as channel managers, document the daily activities as well as the emotional turmoil of the child and publish edited content to maximize audience engagement. In this digital economy, human attention is treated as currency, converting personal moments into public spectacles without the minor’s consent. The legal question that emerges here is: when does "featuring" a child in family content cross the line into digital child labour?
In cases where income is generated by a social media platform due to the consistent presence of the child, the performances the child gives on screen, or the ability to retain the attention of the viewers, there is a generation of economic value. From a constitutional viewpoint, Article 24 ensures that the child is protected from exploitation, while Directive Principles in Articles 39(e) and 39(f) ensure that childhood is preserved from any kind of moral or material abandonment. In the case of M.C. Mehta v. State of Tamil Nadu (1996), the Supreme Court has stated that children should not be exploited economically in a way that their healthy upbringing is denied.
Nevertheless, current statutory safeguards do not consider digital workplaces. Children can assist in "family businesses" under the Child and Adolescent Labour (Prohibition and Regulation) Act, 1986, if the child is not involved in any kind of work that will interfere with school education. Monetized family vlogging takes advantage of this family exemption. Furthermore, unlike child actors who have the legal safeguards of working hours, trust funds, and compulsory schooling, child influencers on the Internet do not have any form of statutory protection. Minors bear the long-term psychological burden of a persistent digital footprint.
Deepfakes & Synthetic Abuse, Where Realness Is No Longer a Prerequisite for Harm
While commercial family vlogging demonstrates how exploitative childhood can be, the proliferation of generative artificial intelligence and synthetic media represents a structural danger of non-consensual digital abuse of a child. Deepfake technology allows the offender to exploit the likeness of a minor, a child’s voice, or biometric characteristics for generating sexually explicit, defamatory, or abusive imagery without physical contact. Synthetic media abuse is a violation of the basic right to personal dignity and bodily integrity, which is guaranteed by Article 21 of the Constitution of India. The right to informational self-determination was recognized in K.S. Puttaswamy v. Union of India (2017).
Moreover, in the case of Subhranshu Rout v. State of Odisha, the court emphasised that disseminating non-consensual explicit digital media amounts to an assault on one’s digital dignity. Traditional torts and crimes jurisprudence relies on establishing physical damage and identifiable physical offenders. However, deepfakes challenge this traditional approach since, in accordance with the procedures provided by Section 65B of the Indian Evidence Act of 1872 (now Section 63 Bharatiya Sakshya Adhiniyam, 2023), which requires strict electronic chain of custody certification, tracking the source of the artificial media presents enormous procedural difficulty. To resolve this, a special Digital Child Rights law must be passed to impose strict liability on those who host such synthetic media.
Why Existing Indian Laws Are Failing
India’s current child protection laws work well for traditional crimes, but the implementation in cases of algorithmic crimes shows some limitations.
1. The Protection of Children from Sexual Offenses (POCSO) Act, 2012
POCSO Act 2012 is designed to protect children against sexual abuse and exposure to pornographic material. In accordance with sections 13, 14 and 15, the law makes it an offense to produce, possess, and distribute child sexual abuse material (CSAM), including digitally represented material. However, the legal regime of POCSO operates based on identifiable acts of sexual exploitation. The law does not have the requisite legal flexibilities to regulate non-sexual exploitation of children commercially, such as the systematic exploitation of a child through the commercialization of the child’s daily activities by parents or guardians. Where parental oversharing or commercial vlogging involves minors' psychological distress, POCSO provides no administrative remedies.
2. The Information Technology Act, 2000, and Intermediary Guidelines
The IT Act, 2000 read alongside the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, establishes framework for platform liability and content removal. Under Rule 3(1)(b), intermediaries are required to exercise due diligence and remove unlawful or non-consensual explicit content upon receiving actual knowledge or court orders. But, in practice, these measures face obstacles in the form of compliance delays. For a minor victim of deepfakes or non-consensual imagery, the removal period under the law, ranging from 24 to 36 hours, is inadequate to curb the dissemination process, as it happens in real time on different platforms. Moreover, the provisions of the IT Act deal with cybercrimes in general and do not acknowledge the specific duty of care that platforms have towards minor users.
3. The Digital Personal Data Protection (DPDP) Act, 2023
The enactment of the DPDP Act, 2023, was an important step in formulating the framework of data protection in India. Under Section 9(1), it is clearly stated that the data fiduciaries must obtain the consent of the parent or legal guardian for processing any personal data of the child. Similarly, under Section 9(3), the platforms cannot engage in the behavioural tracking of children or targeted advertising.
Despite these protections, the DPDP Act suffers from three major statutory flaws. Firstly, the Act fails to recognise evolving capacities. According to Section 2(f) of DPDP Act, a child is defined as a person below 18 years of age. By treating a child at the age of five the same way as a seventeen year old child in terms of consent requirement, the law fails to recognize the principle of evolving capabilities of Article 5 of the UN Convention on the Rights of the child (UNCRC). Secondly, an adolescent privacy paradox arises, in contrast with Article 8 of GDPR of the European Union, wherein each Member State is allowed to provide adolescents, ranging from 13 to 16 years old, with digital consent autonomy, the DPDP Act requires that such adolescents remain under complete parental control until age 18. Hence, the law creates a paradox wherein an adolescent desiring privacy, advice regarding reproductive issues, or mental health information is denied access to it without parental consent. Thirdly, the blind eye towards 'Sharenting', under the legislative framework of mandatory parental consent, the law makes a presumption that the parents would act only in the best financial interest of the child. In case the parents themselves are the data fiduciaries of the child's sensitive data, and they themselves make use of it commercially, then there is no mechanism through which the child can object.
Looking Beyond India: What Other Legal Systems Are Starting to Recognise
Globally, there is a growing recognition that laws must be child-specific to protect children, considering modern digital realities.
Firstly, France (Child Influencer Law, 2020): In France, the government passed Law No. 2020-1266 concerning children who are featured in videos on online platforms. Under the law, the money earned by the children will be kept in a protected bank account until the child attains legal age. They also have the ‘right to be forgotten’, allowing them to request the removal of their content without the need for parental consent.
Secondly, the United Kingdom (Age-Appropriate Design Code): The Design Code, formulated under the UK Data Protection Act 2018, requires online platforms to design their services in a way that incorporates child safety and high levels of privacy by default and prioritizes the best interests of the child at the center of its policies.
A Way Forward: Imagining a Digital Child Rights Law for India
Addressing this gap needs focused legislation that should be based on some guiding principles. First, the most basic requirement of this law should be based on the right to privacy and on Article 3 of the UN Convention on the Rights of the Child (UNCRC), which mandates that any processing of digital data with respect to children shall take into consideration their best interests. Second, there is a need for children to have a right to digital erasure, which allows them to have the ability to delete material uploaded about them in their childhood once they grow up and have digital capability, despite the parental permission given at that time. Third, there must be clear regulations governing the commercial aspect of family vlogging, where the channel generates profit from child-centered content, a specific percentage of these earnings must be deposited into a protected trust fund for the child’s benefit, rather than be left completely at the parents’ discretion. Fourth, the deepfakes and synthetic photos of minors call for swift takedown policies that ensure the content is taken down immediately upon receiving reports about it, without going through lengthy processes associated with the usual cybercrime legislation. Finally, there must be mandatory privacy settings provided by the digital service provider for underage users.
Conclusion
The central challenge is the technologies themselves, but about the slow adaptation of the laws in comparison to the development of new innovations. Disregarding violations of privacy rights as insignificant issues deprives a whole generation of effective legal protection. India must take proactive actions to formulate a Digital Child Rights Law that safeguards children’s fundamental rights to privacy and dignity in the digital age.



Comments