While WhatsApp's move to test age declaration is a nod to the DPDP Act, critics argue that self-declaration is a fundamentally flawed method for verifying age. Relying on users to simply state their age does little to stop minors from bypassing restrictions, as children can easily provide false information. Without robust, third-party verification or document-based checks, these prompts may serve more as a 'check-the-box' exercise for legal compliance rather than a genuine safety measure.
There is also a significant concern regarding the privacy implications of collecting more data. To truly verify age, platforms might eventually require government IDs or other sensitive documents, which creates a new set of risks. If a platform is forced to store such sensitive information to prove compliance, it becomes a more attractive target for data breaches. The irony is that the very law designed to protect personal data could lead to the collection of even more sensitive identity data by private corporations.
Furthermore, the implementation of these checks could lead to a fragmented user experience, where access to essential communication tools becomes gated by bureaucratic hurdles. For a platform as ubiquitous as WhatsApp, which is used for everything from personal chats to business transactions, any barrier to entry could disproportionately affect users who lack easy access to digital identity documentation. This creates a digital divide where certain populations may be excluded from the platform.
Finally, the government and the company must be held accountable for the efficacy of these measures. If the goal is to protect children, the methods used must be proven to work. If these tests result in a system that is easily circumvented, it fails the public interest. Regulators should ensure that companies are not just performing compliance theater but are instead implementing meaningful, privacy-preserving solutions that actually achieve the objectives of the DPDP Act.