
Important: This article provides general compliance information and not legal advice. The official English versions of UAE legislation state that the original Arabic text prevails in the event of a conflict. Platforms should obtain UAE legal advice for final interpretation, scope and implementation deadlines.
The UAE now has a dedicated child online-safety framework built around two important instruments.
The Federal Decree-Law Regarding Child Digital Safety entered into force on 1 January 2026.
It establishes the broader framework for protecting people under 18 in digital environments. Its scope includes websites, search engines, applications, messaging services, forums, gaming platforms, social media, live-streaming services, podcasts, streaming platforms, on-demand video services and e-commerce platforms.
The law introduces requirements relating to:
Entities already subject to the law were given up to one year from its entry into force to regularise their position, unless that period is extended by Cabinet Resolution.
The Cabinet Resolution Regarding the Regulation of Children’s Access to Social Media Platforms was issued on 17 June 2026.
It adds considerably more prescriptive requirements for services that fall within the definition of a social media platform. The most visible change is a minimum age of 15 for personal social media accounts.
However, the Resolution is not simply an age ban. It also establishes detailed requirements for:
The Resolution enters into force on the day following its publication in the Official Gazette. Platforms then receive a 12-month transition period from that effective date.
Businesses should therefore confirm the Official Gazette publication date before calculating their precise compliance deadline rather than treating 17 June 2026 automatically as the start of the transition period.
The federal law applies to digital platforms and internet service providers that:
The scope is not limited to companies incorporated, licensed or physically established in the UAE. A foreign platform may be covered where its service is directed at UAE users and children use the platform or are exposed to its services or content.
Indicators that a service may be directed at UAE users can include:
The legislation does not yet provide a complete test for when a foreign service is considered “directed” at users in the UAE. Platforms should document their scope analysis instead of assuming that the absence of a UAE office removes them from the regime.
The 2026 Resolution defines a social media platform broadly. It covers a service that does one or more of the following:
The definition applies regardless of whether the service is free or paid, where the provider is established, its business model or the infrastructure used to operate it.
This creates a classification question for hybrid services.
A platform does not necessarily avoid the Resolution because it describes itself as a game, marketplace, forum, streaming service or collaboration tool. Features such as public profiles, user posts, followers, comments, group channels, recommendation feeds or creator communities may bring part or all of the service within scope.
Examples requiring closer assessment include:
The correct analysis should focus on product functionality, not the marketing category assigned to the service.
The new framework cannot be implemented with one generic “minor” flag.
Platforms need to distinguish at least four operational age groups.
Under the federal law, platforms are generally prohibited from collecting, processing, publishing or sharing the personal data of children under 13 unless a set of conditions is satisfied.
These conditions include:
Further Cabinet rules are expected to specify which data may be collected and how parental consent must be obtained and verified. Education and health platforms may receive specific exemptions through a Cabinet Resolution, subject to safeguards.
For social media services, this parental-consent route does not override the separate under-15 account restriction.
A parent cannot authorise an under-15 child to open a personal social media account merely because the parent has consented to data processing.
These users are above the federal law’s under-13 privacy threshold but below the social-media account threshold.
They therefore cannot create, use or operate personal accounts on services covered by the social-media Resolution.
Platforms must also prevent them from accessing full social features, including:
Caregiver consent cannot remove this restriction.
Fifteen-year-olds may access social media, but their accounts must be placed in a specially protected mode.
Platforms must apply measures such as:
The Resolution specifically identifies unrestricted private messaging, open live streaming and intensive algorithmic recommendation systems as elevated-risk functions that may need to be restricted, disabled or supported by additional safeguards.
The special 15-to-16 controls in the 2026 Resolution no longer apply in exactly the same way once the user turns 16.
However, users aged 16 and 17 remain children under the broader Child Digital Safety Law. Platforms must therefore continue to apply appropriate child privacy, safety, content, advertising and age-based controls.
Turning 16 should not automatically convert the account into an unrestricted adult account.
The new rules require product architecture changes, not just new terms and conditions.
The standard onboarding pattern of asking users to enter their date of birth is not sufficient for social media platforms.
The onboarding flow needs to:
The account state should be determined before the user obtains access to restricted functionality.
A platform should not create a fully active account and attempt to verify age afterwards.
Product teams need a central policy layer capable of applying restrictions by age group.
The platform should be able to determine whether a user may:
A scattered collection of feature flags maintained independently by different product teams will be difficult to audit and more likely to produce inconsistent outcomes.
A centralised age-policy service is generally more defensible.
The Resolution prohibits under-15 personal social media accounts and access to full social functionality.
It does not necessarily mean that every form of unauthenticated, non-interactive viewing must be blocked in all circumstances. The precise limits may depend on the service, content and future regulatory guidance.
Where appropriate, a platform might provide an under-15 experience that:
This approach should be validated against the platform’s actual functionality and UAE legal advice.
The rules do not apply only to new registrations.
Social media platforms must identify personal accounts belonging to underage children and take immediate measures to suspend or disable them. They must also adopt measures to prevent circumvention.
A defensible remediation process should cover:
Automated detection should not be the only control. False positives may affect legitimate users, while false negatives can leave underage accounts active.
Platforms need an appeal and human-review process.
For 15-year-old users, the platform should review:
Possible safeguards include:
The Resolution identifies intensive algorithmic recommendation systems as a potentially high-risk feature for 15-year-old users.
This means recommender-system compliance should be treated as part of child safety, not merely an artificial-intelligence governance project.
Platforms should assess:
A child-safety mode may require different ranking objectives rather than simply removing a short list of prohibited content.
Platforms must provide tools for regulating permitted access periods and restricting daily or night-time use for the 15-to-16 age group.
Detailed standards may still be issued by the Child Digital Safety Council and TDRA.
Product teams should nevertheless prepare the underlying capabilities now:
The federal law also refers more broadly to time limits and mandatory rest and disconnection periods as child-protection controls.
Age assurance creates a difficult privacy trade-off.
A platform must collect enough information to distinguish adults from children, while avoiding the creation of a new high-risk identity database.
The data inventory should identify:
The inventory should show which systems, vendors, teams and jurisdictions receive each category.
Where technically possible, the main platform should receive an age result rather than a complete copy of the user’s identity document.
For example, the age-assurance component could return:
under_15age_15age_16_to_17adultverification_failedmanual_review_requiredThe platform may still need evidence of the method, time and outcome. However, it should avoid retaining passport images, Emirates ID copies, facial images or biometric templates where an auditable age token would be sufficient.
This separation reduces breach impact and makes purpose limitation easier to demonstrate.
The 2026 Resolution requires non-retention of biometric data and official documents except to the extent and for the duration necessary to complete age verification and in accordance with applicable legislation.
The retention schedule should distinguish between:
“Delete after verification” should be translated into a technical deletion workflow with logs and vendor confirmation, not left as a general policy statement.
The age-verification notice should explain:
The explanation must be understandable to the relevant user, not written solely for lawyers.
For younger users, a layered notice may be appropriate:
Using a vendor does not remove the platform’s responsibility.
Vendor due diligence should examine:
Contracts should prevent the vendor from using age-verification data for unrelated analytics, model training or commercial profiling unless clearly lawful and authorised.
The Resolution permits several types of age-verification mechanisms, provided they satisfy the required standards.
Potential methods include:
Self-declaration of age is expressly insufficient for social media platforms.
The mechanism must:
A practical architecture may use different levels of assurance depending on risk.
Possible controls may include:
Possible controls may include:
Stronger verification may be appropriate before enabling:
The final method must still meet any UAE approval requirements. A risk-based ladder should not be used to justify an unapproved mechanism where the Resolution requires approval.
An age-estimation model may perform differently depending on image quality, disability, device type, ethnicity or other factors.
Because the Resolution prohibits unjustified discrimination and technical exclusion, platforms should provide alternatives such as:
Users should not permanently lose access because one biometric method produced an uncertain result.
The platform should be able to demonstrate:
Auditability does not require retaining all raw identity information.
It requires preserving enough evidence to show that the process worked as designed.
The 2026 Resolution prohibits social media platforms from:
The Resolution permits:
The review should cover more than the visible advertisement.
It should assess:
A child account should not be passed into adult advertising workflows simply because an ad partner’s own terms claim that its service is not intended for minors.
Platforms should define the distinction internally.
Contextual advertising may use information such as:
Behavioural advertising may rely on:
Advertising systems should be configured so that child accounts cannot silently move from contextual to behavioural targeting.
The federal law requires platforms to provide clear, user-friendly tools for immediately reporting harmful content and harmful behaviour affecting children.
Platforms must also use their technical capabilities, including artificial intelligence and machine-learning systems, for proactive detection, removal or reporting.
The law separately requires immediate reporting of specified child sexual-abuse material and harmful content to the relevant authorities, together with information requested for investigation. Platforms must also implement removal and reporting orders issued by competent authorities.
A generic abuse form hidden behind several menus may not be enough.
Children should be able to report:
The reporting interface should explain:
The platform should define different workflows for:
The process should identify the responsible team, response time, evidence-preservation requirements and authority-contact route.
A platform may have technically strong controls but still struggle to demonstrate compliance if responsibilities and records are fragmented.
A cross-functional programme should include:
One senior owner should be accountable for the UAE child digital safety programme.
The social-media Resolution expressly requires periodic assessments of digital-safety risks relating to children.
The assessment should consider:
The assessment should lead to prioritised remediation actions rather than becoming a one-time compliance report.
The evidence pack should contain:
Under the Resolution:
The authorities may apply measures including warnings, closure, partial blocking, total blocking and administrative penalties, subject to the applicable framework and graduality principle.
The legislation reviewed for this article does not yet provide a complete published schedule of child-digital-safety fine amounts.
Platforms should not rely on unverified penalty figures. The more immediate operational risks already identified in the legislation include warnings, service restrictions and blocking.
Waiting for every technical standard to be finalised is risky. Core obligations are already sufficiently clear to begin architecture and governance work.
The main obligations concern product functionality, access control and safety operations. Updating legal text without changing the platform will not address the central requirements.
Self-declaration is not accepted as sufficient age verification under the social-media Resolution.
Caregiver consent cannot authorise an under-15 personal social media account or remove mandatory protections for 15-year-old users.
The rules emphasise minimisation, purpose limitation and limited retention. Indefinite storage of documents or biometric data creates additional privacy and security risk.
A platform must actively prevent behavioural advertising and commercial profiling of children where prohibited. A written policy is insufficient if advertising identifiers continue to flow to adtech vendors.
Platforms must identify and address underage accounts already in the system. Controls limited to new registration leave a major compliance gap.
The 15-to-16 bracket has specific mandatory protections. Sixteen- and seventeen-year-olds remain children under the broader federal law, but the control model is not identical.
A marketplace, game, streaming service or application may contain social-media functionality. Scope must be assessed feature by feature.
Live streaming, generative AI, public discovery, group chat, gifting and recommendation changes can materially alter the platform’s risk classification.
Use this checklist to translate the UAE child digital safety requirements into practical product, privacy, advertising and governance actions.
| Area | Minimum practical action | Evidence to retain |
|---|---|---|
| Scope |
Identify UAE-facing and UAE-directed services.
|
Written applicability assessment |
| Classification |
Assess social, gaming, streaming and marketplace features.
|
Product-function inventory |
| Age bands |
Configure under-13, 13–14, age 15, 16–17 and adult account states.
|
Approved age-policy matrix |
| Verification |
Implement an effective and legally supportable age-assurance method.
|
Vendor records and test results |
| Data minimisation |
Collect only the information needed to determine the appropriate age band.
|
Data-flow and minimisation review |
| Retention |
Delete identity documents and biometric data when they are no longer necessary.
|
Deletion logs and vendor evidence |
| Under-15 accounts |
Prevent prohibited account creation and identify existing underage accounts.
|
Detection and suspension records |
| Age 15 controls |
Restrict content, unknown-user contact, public sharing, live streaming and intensive recommendations.
|
Feature-configuration evidence |
| Privacy defaults |
Apply the highest appropriate privacy settings automatically.
|
Configuration records and test screenshots |
| Advertising |
Disable tracking-based targeted advertising and commercial profiling for children.
|
Adtech configuration and data-flow tests |
| Parental controls |
Provide understandable controls without allowing mandatory protections to be weakened.
|
Product documentation and quality-assurance results |
| Time controls |
Support daily limits, night-time restrictions and disconnection periods.
|
Functional test evidence |
| Reporting |
Provide simple, visible and child-appropriate reporting channels.
|
Reporting workflow and response metrics |
| Moderation |
Establish urgent child-safety escalation and authority-reporting procedures.
|
Incident and escalation matrix |
| Risk assessment |
Assess child-safety risks periodically and before launching material product changes.
|
Approved assessment reports |
| Regulatory readiness |
Prepare the statistics, records and compliance information required for regulatory review.
|
Reporting pack and control dashboard |
| Governance |
Assign accountable product, privacy, engineering and trust-and-safety owners.
|
Responsibility matrix and management approvals |
This checklist provides general compliance information and is not legal advice. Final interpretation and implementation should be confirmed with qualified UAE legal counsel.
No. The Resolution applies to social media platforms whose services are made available in the UAE or directed at UAE users, regardless of the provider’s place of establishment.
The broader federal law also has extraterritorial reach where platforms direct services at UAE users.
No.
The specific under-15 personal-account restriction applies to services that fall within the Resolution’s definition of a social media platform.
Other digital platforms remain subject to the broader Child Digital Safety Law, including age verification, privacy, harmful-content and child-protection obligations.
Hybrid products require careful classification.
Not under the 2026 Resolution.
Caregiver consent does not create an exception to the under-15 social-media account prohibition.
Not as their recognised age-verification method for the social-media rules.
The Resolution states that self-declaration of age is not sufficient. Platforms need an effective and reliable method that meets the prescribed standards.
Not necessarily.
The Resolution permits document-based methods but also requires data minimisation and limited retention. A platform should assess whether it can receive and retain only an age result or verification token rather than a full identity-document copy.
No.
It is one permitted category of mechanism, provided the applicable standards are satisfied. Other options include digital government identity, official-document verification and approved licensed age-verification providers.
The Resolution specifically prohibits targeted advertisements based on tracking and behavioural profiling and commercial exploitation of data based on tracking children’s digital activities.
General contextual advertising that does not rely on profiling or privacy intrusion is expressly distinguished from prohibited behavioural targeting.
A social media account may become permissible, but it must operate under enhanced safeguards until the child turns 16.
The transition should activate the protected account state rather than automatically providing unrestricted access.
The specific 15-to-16 controls may change, but the user remains a child under the broader federal framework until age 18.
Privacy, content, advertising and safety protections should therefore continue to apply as appropriate.
The federal law provides for a separate administrative-penalties framework.
The instruments reviewed for this article identify possible measures including warnings, closure, partial blocking and total blocking, but do not yet provide a complete child-digital-safety fine schedule.
Businesses should verify later Cabinet instruments and regulator guidance rather than relying on unofficial fine figures.