New Zealand has become the latest country to propose a social media minimum age of 16. But its new Online Safety (Minimum Age and Child Safety Risk Assessment) Bill does more than copy Australia.
National, the largest party in New Zealand’s governing coalition, has introduced a Government Bill which appears to have learnt some important lessons from Australia’s first few months of implementation.
The proposed law extends beyond conventional social media to AI companion services designed primarily to simulate social, emotional or personal relationships. It also introduces broader online safety duties already seen in other jurisdictions, requiring regulated platforms to assess annually the risks their services pose to all children under 18 and again before making significant changes to their services.
Importantly, those assessments must include the number of children using the platform, broken down by age, and explain the methodology used to calculate those figures. That could prove extremely important if New Zealand is to avoid the challenges in enforcement evident across the Tasman Sea.
Age assurance without prescribing one technology
Like Australia, New Zealand would require platforms to take “reasonable steps” to prevent under-16s from holding accounts. It remains technology neutral but is more explicit about what will not be enough to achieve compliance.
Simply asking someone to enter their age or date of birth cannot constitute a reasonable step. Nor can a platform satisfy the obligation only by requiring either formal proof of age or only by using a digital identity service.
Platforms can instead combine approaches including age verification, age estimation and age inference. That leaves room for privacy-preserving third-party age checks, facial age estimation, existing account information, behavioural signals, device signals and other evidence. As in Australia, the regulator will write guidance, but this will be non-statutory, so influential but not binding on the courts. But there are further powers to direct regulated services to implement specific technologies to address deficiencies, that can tip the balance in the regulator’s favour.
The Bill also contains strong privacy safeguards. Personal information collected for complying with the minimum-age duty may only be used or disclosed for that purpose and cannot be retained longer than necessary. Breaching those restrictions is expressly treated as an interference with privacy as well as exposing the platform to enforcement under the new law.
Learning from Australia
Australia has demonstrated why the words “reasonable steps” need effective regulatory scrutiny behind them.
Three months after Australia's minimum age came into force, eSafety found that most under-16s who previously had social media accounts had either retained them or created new ones. It subsequently opened investigations into several platforms and has been using legally enforceable information-gathering notices, user testing and other evidence to establish what those platforms actually did.
New Zealand is in a position to start with that lesson already learnt.
Its regulator would have broad powers to compel information it considers necessary or desirable. A notice could require a platform to test any feature, functionality, system or process and provide the results. The regulator could require a live demonstration, interviews and regular reporting. Failure knowingly to comply with an information request, or knowingly supplying materially false or misleading information, can itself be a criminal offence, echoing the strongest aspect of the UK’s enforcement regime which applies to disclosures to the regulator. That should allow the regulator to get behind broad claims about proprietary age assurance.
- If a platform says it uses facial age estimation, the regulator can ask how the threshold is configured, whether it applies a buffer around age 16, what liveness checks are in place and what testing demonstrates the effectiveness of that configuration.
- If a platform says its existing behavioural inference technology identifies likely children, the regulator can ask what signals it uses, how quickly it identifies an underage account, how reliably it works and what its testing shows.
And because platforms must separately report how many children of each age they believe are using their services, the regulator can compare the claimed effectiveness of those systems with their actual outcomes. They can no longer say, “We cannot count underage users because we remove them as soon as we discover them.”
That is a significant second-mover advantage.
Strong enforcement if reasonable steps are not reasonable
The enforcement architecture also has features familiar from the UK Online Safety Act.
The most serious breaches can attract penalties of 10% of relevant global turnover. The regulator can also seek court orders restricting services supporting a non-compliant platform and ultimately require app stores, internet access providers and the platform itself to prevent access in New Zealand. The UK's Online Safety Act similarly combines penalties of up to 10% of worldwide revenue with business disruption measures.
So “reasonable steps” does not have to mean platforms marking their own homework. The regulator is being given the tools to establish whether those steps are genuinely reasonable and effective.
VPNs are not the obstacle some suggest
The Bill does not currently have the support of either of National's smaller coalition partners, ACT or New Zealand First. New Zealand First has argued that the restriction cannot work without either digital ID or banning VPNs, describing Australia's experience as evidence of that problem. But we would advise them, if asked, that this presents a false choice.
As AVPA has previously explained here, in evidence we sent to a New Zealand Parliamentary inquiry and in discussions with ACT, a VPN disguises the user’s real location but it does not inevitably defeat age assurance. Platforms can already use combinations of device information such as currency and time-zone, behavioural signals and other evidence to determine both likely location and likely age. Australia's own regulatory guidance tells platforms to detect VPN use and use additional signals where necessary rather than treating a VPN as an automatic route around the law. So, there is no need to ban VPNs or even prevent children from using them – just to scrutinize VPN traffic more carefully for flags that it may come from someone under 16 in New Zealand.
So, has New Zealand written perfect law?
It is too early to say if this new legislation will withstand the efforts of platforms and their legal teams to find ways to avoid implementing the policy, if it is passed by a newly elected Parliament after the forthcoming general election. But it is clear that those who drafted it have paid close attention to the experience of other jurisdictions. While many were studying Australia to learn if limiting access to social media would be a positive or negative step, others were also watching carefully how the design of the regulation worked out.