Regulating Online Speech: Aadhaar Checks and an Autonomous Body
The Supreme Courts recent suggestions for an autonomous online regulator and Aadhaar-based age checks reopen tensions between free speech, intermediary duties and privacy. This analysis examines the constitutional, statutory and jurisprudential issues and outlines a path for lawful reform.
Introduction
On 27 November 2025 the Supreme Court of India, during hearings over complaints concerning allegedly obscene online commentary, suggested the creation of an autonomous regulator for social media and floated the idea of Aadhaar-based age verification to prevent minors accessing certain content. The Courts observations came in the context of petitions by online content creators challenging FIRs for allegedly obscene speech on livestreamed shows. The remarks signal a judicial impatience with current self-regulatory mechanisms and invite immediate constitutional and statutory scrutiny.
This development is legally important because it brings into sharp relief tensions between freedom of expression, intermediary liability, data protection and privacy. The suggestions touch on settled constitutional guarantees (Articles 19(1)(a) and 21), the Information Technology Act 2000 and its rules, and the jurisprudence that balances free speech with reasonable restrictions and the States interest in protecting minors.
Legal Background
At stake are three core legal regimes: (1) the constitutional right to free speech under Article 19(1)(a) and permissible restrictions under Article 19(2); (2) the right to privacy and personal data protection recognised in Justice K.S. Puttaswamy v. Union of India (2017); and (3) intermediary liability and online regulation under the Information Technology Act 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
The Supreme Courts 2015 decision in Shreya Singhal v. Union of India is the leading authority on online speech and intermediaries: the Court struck down Section 66A (over-broad criminalisation of online speech) while recognising a limited role for intermediary regulation and the need for procedural safeguards. Puttaswamy established privacy as a fundamental right, requiring any interference to satisfy legality, necessity, and proportionality. At the transnational level, the European Court of Human Rights judgment in Delfi AS v. Estonia (2015) upheld the possibility of holding an intermediary liable for user comments where internal moderation failed, a ruling often cited in debates about intermediary duties.
Critical Analysis
The Courts core proposals — an autonomous regulator and Aadhaar age-verification — raise discrete but overlapping legal questions.
First, an autonomous regulator. The idea answers a legitimate policy gap: self-regulation by platforms and industry codes have demonstrably struggled to police harmful content and enforce grievance redress effectively. However, an independent regulator must be designed to respect Article 19(2) and procedural fairness. Prior judgments (Shreya Singhal and subsequent High Court orders) emphasise that content moderation and takedown decisions must not amount to prior restraint without clear statutory mandate and safeguards. Absent detailed enabling legislation, a regulator operating by executive fiat risks being struck down as an impermissible prior restraint or delegation lacking intelligible principles (see A.K. Roy v. Union of India and others on delegation principles).
Second, Aadhaar-based age verification. The Courts suggestion is pragmatic — verifying that an online user is an adult before exposing them to adult content is an attractive harm-minimising measure. But Puttaswamys proportionality framework raises serious objections. Mandatory linkage of online accounts to Aadhaar invites mass collection of biometric or identity data, heightening risks of surveillance, mission-creep and data breaches. The Supreme Court in Puttaswamy and in subsequent Aadhaar judgments (e.g., Justice K.S. Puttaswamy (II) on the validity of Aadhaar) stressed safeguards where Aadhaar is used; compulsory usage outside statutorily specified contexts is constitutionally fraught. Less intrusive alternatives — age-verification through certified third-party age attestations, anonymised tokenisation, or certified identity-vouchers — would better fit the necessity and least-restrictive-means tests.
Third, intermediary liability. Strengthening regulation often translates to expanded duties on intermediaries to trace originators or remove content. The IT Rules 2021 already impose onerous compliance duties (grievance officers, compliance officers, content takedown timelines) that courts have been urged to scrutinise against constitutional guarantees. Delfi and related European precedents provide foreign support for limited intermediary accountability but under fact-specific circumstances; they do not license blanket obligations that undermine anonymity or legitimate speech.
Finally, procedural safeguards matter. Any regulator or verification regime must include independent oversight, judicial reviewability, clear standards for takedown, transparency obligations and data protection guarantees. In the absence of a comprehensive Personal Data Protection Act in force with strong ex-ante safeguards, the Courts proposal risks solving one problem (harmful content) by creating another (privacy and surveillance harms).
Opinion & Outlook
Practically, the Supreme Court is likely to invite Parliament to legislate rather than create permanent regulatory architecture by judicial fiat. The Courts observations work as a corrective to industry self-regulation and a nudge to the legislature to enact a calibrated framework that reconciles free speech, child protection and data privacy. A well-drafted law would: (a) define harmful online content narrowly and with objective criteria; (b) create an independent regulator with statutory powers, limited adjudicatory functions, and robust appellate and judicial review mechanisms; (c) mandate privacy-preserving age-verification methods rather than compulsory Aadhaar linkage; and (d) integrate safeguards from Puttaswamy and international best practice (e.g., data minimisation, purpose limitation, independent audits).
Absent legislative steps, any attempt to implement Aadhaar linkage or expanded intermediary duties via rulemaking or executive direction will be vulnerable to constitutional challenge. Litigants will rely on Shreya Singhal for free speech protections and on Puttaswamy to contest intrusive identity-linking schemes. The balance will likely be guided by a proportionality analysis: is the interference necessary to protect minors and public order, and is there a less intrusive means? Court precedents suggest high judicial scepticism of sweeping measures without statutory scaffolding.
Conclusion
The Supreme Courts call for tougher rules and Aadhaar age-checks highlights an urgent policy problem: protecting citizens, especially minors, online while upholding fundamental rights. The legally sustainable path is legislative reform: a narrowly tailored statutory regulator, privacy-preserving age-verification mechanisms, clear intermediary duties and meaningful procedural safeguards consistent with Shreya Singhal and Puttaswamy. Until then, piecemeal or ad hoc measures risk constitutional challenge and unintended harms.
Related Cases
Published by Anrak Legal Intelligence