news / 2026 / france + social-media A constitutional review desk with the social-media bill, privacy annotations, an age-assurance flowchart, a phone test stand, and legal binders traces the identity system the invalidated ban would have required.

news

France's Social Media Ban Died at the Identity Gate

The missing verifier became the constitutional defect: a ban aimed at children would have required every user to prove age without rules for data handling, authority, limits, or appeal.

France’s Constitutional Council struck down the country’s under-15 social-media ban on August 14, eighteen days before it was due to take effect. Article 1 failed on two linked grounds: its blanket restriction on access was disproportionate, and the age check required to enforce it carried no statutory privacy safeguards.

I wrote in July that France had enacted a ban without building the gate. The court has now turned that implementation hole into a constitutional holding. This is the new development. The missing verifier, missing scope rules, and missing parental route killed the central provision before platforms had to discover what compliance meant.

The verifier stopped being an implementation detail

The law prohibited anyone under 15 from accessing an online social-network service. That clean sentence concealed a universal checkpoint. To identify the children, services would have to ask every visitor or account holder to establish an age band. The Council’s decision says this directly: any ban on all users below a threshold necessarily requires every person, including adults, to prove age before entering.

Parliament supplied no conditions or limits for that proof. The statute did not assign responsibility for the verifier, specify acceptable evidence, restrict retention, define secondary use, establish an appeal, or explain how an adult falsely classified as a child could recover access. The court held that this omission deprived privacy of the legal guarantees required by the Constitution.

That reasoning matters outside France. Age assurance is often sold as a narrow child-safety feature. Its actual deployment creates an identity layer across the entire audience. A document check exposes adults. Face estimation processes adults. A reusable credential classifies adults. Even a privacy-preserving age token needs an issuer, audit rules, revocation, error handling, and a boundary against reuse.

The service boundary was wider than the political slogan

The law used a broad definition of online platforms where people connect, communicate, share material, and discover users or content. The Council found that access could be blocked without regard to a service’s features, content, demonstrated dangers, or existing protections.

The exemptions covered online encyclopedias, educational or scientific directories, and open-source educational project platforms. The decision points to what remained exposed: collaborative leisure, news, and mutual-aid services; communication apps; online games with marked social features; and social networks connected to education but lacking an educational purpose themselves.

This is where “ban social media” collapsed as a legal category. A political slogan suggests a short list of giant feeds. The enacted definition could reach hobby communities, game guilds, support spaces, local forums, group-chat systems, and services whose social layer is secondary to the thing people came to do.

The court also rejected the law’s treatment of every child below 15 as one condition. It offered no assessment of age, maturity, family circumstances, the nature of the service, or its specific risks. Parents and legal guardians received no route to lift, narrow, or tailor the restriction in a child’s interest.

Proportionality became systems design

The Council accepted the government’s stated goals. Protecting children from addiction, isolation, pornography, harassment, and fraud can justify limits on access. The failure came from the shape of the mechanism.

Paragraphs 11 through 18 of the decision read like a systems review conducted through constitutional law. The input category was overbroad. Risk classification was absent. Exceptions were too narrow. Parental override was absent. The same outcome applied across different services and different children. The result could not satisfy the requirement that restrictions on expression be necessary, appropriate, and proportionate.

Then paragraphs 19 through 21 follow the data path. The restriction requires an age signal. The age signal requires evidence. Evidence about identity or biometrics affects privacy. Parliament left the evidence process undefined. The legal control surface ended exactly where the technical one began.

This decision gives lawmakers a harder specification for the next attempt. A replacement will need service-level risk criteria, a defensible treatment of communication and support spaces, parental or guardian authority, and a verifier whose privacy limits live in law. The government cannot repair this by swapping in a vendor and calling the API layer implementation.

The surviving law exposes the difference between visible and hidden state

The Council reviewed Article 1 and invalidated it. Other provisions survived without an affirmative ruling on their constitutionality. According to Agence France-Presse’s report via Courthouse News, the separate high-school phone restriction remains scheduled for September 1.

That surviving rule operates inside institutions with rosters, staff, buildings, timetables, and disciplinary procedures. A phone is visible. A school can write local exceptions and hear a complaint. Social-media age sits behind an account, device, browser, credential, family relationship, or probabilistic estimate. The state has to manufacture observability before it can enforce the boundary.

The Élysée has already asked Prime Minister Sébastien Lecornu to produce a legally sound replacement quickly while accounting for the European regulatory framework. Speed will collide with the same architecture described in the July law: French authority over unlawful access, EU authority over major platform obligations, regulators interpreting child-safety duties, and private identity services proposing the gate.

A narrower statute could survive. It might classify services by features and demonstrated risk. It might preserve access to messaging, support, education-adjacent communities, and low-risk collaborative systems. It could let guardians authorize access and require age-band proof that discloses no birthday or identity. It would still need strict retention limits, independent audits, human appeals, and rules for existing accounts and stored data.

Those are legislative choices. Leaving them to product teams transfers public power into vendor defaults.

The court wrote the protocol requirements in negative space

France’s first law tried to gain simplicity by removing machinery. The Constitutional Council found the removed machinery inside the rights violation. Broad service definitions affected expression. A fixed age threshold ignored individual and service risk. Universal age proof affected privacy. Undefined verification stripped away legal guarantees.

The decision leaves the child-safety objective intact and blocks the shortcut. A future ban must describe the gate with enough precision to constrain whoever builds it. The verifier needs an authority, a data model, limits, error recovery, and a jurisdictional home. The access rule needs a service taxonomy tied to evidence rather than political shorthand.

The protocol was missing in July. In August, the Constitution noticed.