You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
Banning Social Media for Minors: Why Age Verification Fails
Banning social media for minors requires verifying each user’s age, but the internet identifies connections, not people: an IP address has no ID number.
Banning social networks for minors: the ID card doesn't fit the protocol
How do you ban a minor from entering a social network if the network doesn't know who you are? That is the question that dismantles the measure before it is even approved. The premise is simple: if the State wants to stop 14-year-olds from accessing Instagram, TikTok, or YouTube, someone must verify the age of each user. And that someone does not exist in the architecture of the internet. The network is not designed to identify people, but connections: an IP can represent multiple users or devices simultaneously, changes frequently, and in many cases is shared among thousands via CG-NAT, leading to textbook identification errors.
The debate began with an uncomfortable question: if apps are banned, is web access without registration also banned? Are game chats social networks? Is Wikipedia? No one has provided an operational definition that withstands scrutiny. Because the problem isn't the list of platforms: it's that the TCP/IP protocol has no field for an ID number. And without that field, any verification is merely a patch on a pipe not built for this purpose.
What age verification really entails
The approach being discussed is not blocking websites, but requesting identification. In practice, this means, according to a participant who claims to have suffered it in other procedures, an ID number plus video verification that records facial antiestéticatures and cross-references them to prove your identity. This is not a laboratory hypothesis: some have already experienced it in other administrative processes and describe it as an intermediate step toward a permanent digital identity system. The sequence would be: first you identify, then you track, and finally you have a map of who says what.
The official argument is the protection of minors. The counterargument is that age norms already exist but are unenforced —Facebook requires users to be 18, selling violent video games to minors is prohibited— and no one has built a facial verification infrastructure to enforce them. The written law is not the applied law. Here, they are building the most expensive machinery in history to monitor something previously resolved with a click on "I am over 18."
Anonymity as the last stronghold
The core of the rejection is not technical, but political. Those who write under pseudonyms argue that anonymity protects the average citizen from the arbitrariness of power, not the incivil. The argument is that today, to identify someone, you need a complaint, a judge, and a ruling; with prior identification, the politician in charge would have direct access to who is behind each account without going through a judge. The suspicion is that a minister with a dedicated team to monitor criticism could cross-reference data and derive cases.
On the other side, the thesis is that those who have done nothing wrong have nothing to antiestéticar. It sounds reasonable until you remember that anonymity is not a privilege, it is a condition of criticism. A neighbor who discusses politics does not want their family, colleagues, or clients to read their opinions. The antiestéticar is not legal sanction: it is social sanction.
The IP is not a license plate and the MAC is not an ID card
Here, the technical analysis becomes devastating. It has been argued that it suffices to track the device's MAC address to identify the user. False: Android and iOS use random MAC addresses, and anyone can change it. Moreover, the MAC is only visible on the local network, not on the internet. Confusing the MAC with an identifiable license plate means not understanding how routing works.
Encryption adds another layer: it limits what the operator can see without breaking connections, and breaking them causes failures, latency, and services that fail to load. Frequent network changes —mobile, public Wi-Fi, roaming, VPN— would require constant re-identification. To reduce errors, the system would have to become so invasive that the cure would be worse than the disease. And all this without leaving home.
The Australian precedent and the fine print
The reference cited is Australia, the first country to approve such a system, with fines of up to 60,000 euros for non-compliant platforms. The parallel drawn is with mandatory vaccination: "You are not being forced to vaccinate, but penalizing those who do not." Translated: you are not being forced to identify yourself, but penalizing those who do not. The formula is the same, the object changes.
The doubt is whether the model is exportable. Applying a Spanish law to servers in California requires the ability to legislate extraterritorially, and here no one listens to these governments. The alternative is DNS blocking, as done with Russia, which is bypassed by changing the DNS in the browser. Cutting off the internet faucet is harder than closing a shutter.
What happens if you refuse to identify yourself
The most repeated answer is the simplest: don't enter. Millions of people are barely active on social networks, and absolutely nothing happens. For important procedures, a digital certificate already exists: labor life, SEPE, Tax Agency. A social network is not an essential service; it is entertainment. If the price of entry is the ID number, many simply stay out.
The problem for the legislator is that a norm expelling moderate users leaves the conversation in the hands of the loudest. And a norm that cannot be applied to foreign servers leaves the system in the hands of whoever complies. It is the paradox of wanting to put gates on the countryside with a ministerial order.
The question no one answers: what is a social network
If there is no definition, there is no applicable law. Are game chats social networks? Wikipedia, where anyone edits and discusses? Forums? Newspaper comments? Each affirmative answer expands the perimeter until the norm covers anything with a text box. And each negative answer opens a hole through which the minor we wanted to protect escapes.
The technical conclusion is the same as at the beginning: the internet identifies connections, not people. Any system claiming otherwise would have to rebuild the network from the ground up. And that is not done with a law, but with decades and the consent of half the planet. Meanwhile, the measure remains where it is: in the headline, not in the cable.
Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication.
Read the full discussion (145 replies).
A Spanish forum user claims he is leaving public debate due to fear of the 'hate speech' unit, highlighting a climate of self-censorship on social media.