The United Arab Emirates has enacted landmark digital regulations that fundamentally change how tech companies manage young users. Under Cabinet Resolution No. 106 of 2026, social media platforms face strict age rules.The law bans children under fifteen from holding personal social media accounts.It applies to all platforms accessible within the country, regardless of where the platform owner is located.Tech platforms must upgrade systems, block unauthorized users, and implement secure verification tools to avoid severe penalties or platform blocks.
The core framework enforces UAE child digital safety through a clear two-tier structure.Children under fifteen years old cannot create, run, or use personal profiles.They cannot post comments, share files, join group chats, or use interactive spaces.Parents cannot waive or override these rules.For teenagers aged fifteen to sixteen, platforms may allow restricted accounts.These accounts require mandatory privacy protections, limited public sharing, restrictions on direct messaging with strangers, and built-in screen time controls.
Digital platforms must replace simple birthdate checks with certified age checks. Self-declared ages are no longer valid under the law.Platforms must use official digital ID systems, national document scans paired with facial verification, or approved artificial intelligence age estimation tools.These verification methods must protect user data privacy.Systems cannot retain biometric records or identity documents longer than needed to complete the verification check.
Tech firms face important obligations under the rule. Companies must build tools that continuously scan for and disable unauthorized accounts created by young children.Platforms cannot target children with behavioral advertising based on personal profile tracking or web history.General contextual ads remain permitted, but personalized ad tracking for minors is prohibited.Tech companies must also add safe design features, offer clear parental control panels, and submit detailed compliance reports to regulators.
Government authorities share oversight responsibilities.The National Media Authority monitors digital media content to protect children from harmful material. The Telecommunications and Digital Government Regulatory Authority oversees technical systems, system security, and age verification tools. Meanwhile, the Child Digital Safety Council oversees overall risk assessments and issues technical guidance. Non-compliant platforms face major administrative penalties, heavy fines, or complete service blockages across the nation.
The law offers a twelve-month grace period running from June 30, 2026, to June 30, 2027. During this year, tech services must update software, review existing user accounts, remove underage profiles, and update parental tools. Global firms without local headquarters are fully subject to the rules. If offshore services ignore the mandate, government regulators can block platform access for local internet users.
This initiative aligns the region with international child protection trends. Global regulators are moving away from passive warnings toward active technological barriers. Lawmakers emphasize that preventing young children from using unregulated social platforms reduces exposure to online bullying, cyber extortion, data tracking, and predatory behavior. Tech providers must prioritize safety design immediately to secure compliance before the final deadline arrives.
