On August 14, 2026, the French Constitutional Council (the “Constitutional Council”) struck down Article 1 of France’s Act to protect minors from the risks posed by the use of social media (the “Act”), which would have barred minors under the age of fifteen from accessing online social media services. The Constitutional Council held that the prohibition infringed on the freedom of expression and communication in a manner that was not appropriate, necessary, or proportionate to the objective pursued and, separately, that the legislature failed to provide the legal safeguards required to protect the right to respect for private life in connection with the age verification process that the ban would, by necessity, have entailed.

We summarise key aspects of the decision below.

Background—the Constitutional Framework

The Constitutional Council’s decision begins with Article 11 of the Declaration of the Rights of Man and of the Citizen of 1789 (the “1789 Declaration”), which protects the free communication of thoughts and opinions. Consistent with well-established case law on online communications, the Constitutional Council held that this right entails the freedom to access online public communication services and to express oneself through them.

The Constitutional Council then confirmed that Article 34 of the Constitution empowers the legislature to lay down rules governing the exercise of freedom of expression, including provisions aimed at ending abuses that undermine public order or the rights of third parties. However, because the right to free expression is a precondition of democracy and a safeguard for other rights, any restriction must be appropriate, necessary, and proportionate to the objective pursued.

Applying that framework, the Constitutional Council accepted that the legislature had sought to protect minors from risks including addiction, isolation, and exposure to pornography, harassment, and fraud, and that, in doing so, it was pursuing the constitutional requirement to protect the best interests of the child and the constitutionally recognised objective of preventing breaches of public order. The decision to strike down the Act turned on proportionality.

Ground 1: A Prohibition Untethered from Risk

The scope of the prohibition turned on the scope of services caught by the ban, which encompassed any “online social networking service” (as defined by Art. 2(7) of the EU Digital Markets Act (the “DMA”)) offered by an “online platform” (as defined by Art. 3(i) of the EU Digital Services Act (the “DSA”)). This meant that the ban extended to any online platform enabling end-users to log in and communicate with one another, share content, and discover other users and other content. It did not distinguish between the types of features or content offered, the risks of those features to users, or the adequacy of any safeguards provided by the service.

The Constitutional Council acknowledged the Act’s exceptions—e.g., online encyclopaedias, educational or scientific directories, and platforms for the development and sharing of free software or open-source digital projects for educational purposes—but found them too limited. In particular, the Constitutional Council identified three categories potentially left within the ban’s scope: (i) collaborative services for sharing leisure content, information, or mutual support; (ii) online communication applications and online games with significant collaborative and social features; and (iii) online social networks that are created in connection with educational activities. The ban therefore risked applying to online services whose risk to the health and safety of minors had not yet been established.

Ground 2: No Role for Individual Assessment

The Constitutional Council’s second objection concerned the absence of individuation. All minors under fifteen years of age would have been denied free access, without the ability for the minor’s parents or legal representative to lift the ban, limit its scope, or authorise access to particular services (having been informed of the risks and safeguards associated with the services concerned). The prohibition accordingly did not permit consideration of the specific risks to individual minors with respect to their age, level of maturity, family circumstances, or the nature of the service in question.

Ground 3: Age Verification without Legislative Framing of Safeguards

The Constitutional Council observed that prohibiting under-fifteens from accessing certain online services necessarily requires all users—including adults—to prove their age before gaining access to those services. As a result, the Constitutional Council concluded that in failing to specify the conditions and limits within which such proof must be furnished, the legislature had not provided the legal safeguards necessary to ensure compliance with the constitutional right to respect for private life (Article 2, 1789 Declaration).

Looking Ahead

As an immediate consequence of the decision, Article 1 of the legislation (i.e., the provision introducing the ban on social media access for minors under 15) cannot be promulgated and will not enter into force. The French government responded immediately, indicating that a replacement text would be prepared as quickly as possible, taking into account both the Constitutional Council’s decision and the EU framework. They still aim to achieve some form of the legislation, a flagship initiative of President Macron, by spring 2027.

Photo of Jadzia Pierce Jadzia Pierce

Jadzia Pierce advises clients developing and deploying technology on a range of regulatory matters, including the intersection of AI governance and data protection. Jadzia draws on her experience in senior in house leadership roles and extensive, hands on engagement with regulators worldwide. Prior…

Jadzia Pierce advises clients developing and deploying technology on a range of regulatory matters, including the intersection of AI governance and data protection. Jadzia draws on her experience in senior in house leadership roles and extensive, hands on engagement with regulators worldwide. Prior to rejoining Covington in 2026, Jadzia served as Global Data Protection Officer at Microsoft, where she oversaw and advised on the company’s GDPR/UK GDPR program and acted as a primary point of contact for supervisory authorities on matters including AI, children’s data, advertising, and data subject rights.

Jadzia previously was Director of Microsoft’s Global Privacy Policy function and served as Associate General Counsel for Cybersecurity at McKinsey & Company. She began her career at Covington, advising Fortune 100 companies on privacy, cybersecurity, incident preparedness and response, investigations, and data driven transactions.

At Covington, Jadzia helps clients operationalize defensible, scalable approaches to AI enabled products and services, aligning privacy and security obligations with rapidly evolving regulatory frameworks across jurisdictions—with a particular focus on anticipating enforcement trends and navigating inter regulator dynamics.

Photo of Virginie de France Virginie de France

Virginie de France is an associate in the Data Privacy and Cybersecurity Practice Group. She advises clients on the full range of EU technology, data protection, and digital regulatory matters. Virginie supports clients with data protection compliance projects, assisting with investigations led by…

Virginie de France is an associate in the Data Privacy and Cybersecurity Practice Group. She advises clients on the full range of EU technology, data protection, and digital regulatory matters. Virginie supports clients with data protection compliance projects, assisting with investigations led by national authorities, and acting in litigation. She also has substantial experience helping organizations meet European and national cybersecurity obligations.