On 10 December 2025, Australia became the first country in the world to require social media platforms to keep under-16s off their services. The Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) inserted Part 4A into the Online Safety Act 2021, and most of the coverage since has been about the big names — the ten platforms the eSafety Commissioner has publicly assessed as age-restricted: Facebook, Instagram, Threads, TikTok, Snapchat, YouTube, X, Reddit, Kick and Twitch. Founders reading that list and concluding the regime is someone else’s problem are making a category error. The obligation attaches to a statutory definition, not a list — and any Australian consumer product with social features needs to work out which side of that definition it sits on, because the obligation that follows carries a maximum civil penalty of $54.6 million for a body corporate, and eSafety expects providers to self-assess rather than wait to be told.
Are You an “Age-Restricted Social Media Platform”?
Section 63C of the Online Safety Act defines an age-restricted social media platform as an electronic service where the sole purpose, or a significant purpose, is to enable online social interaction between two or more end-users, users can link to or interact with some or all other users, and users can post material on the service. Read literally, that language sweeps in a startling range of consumer products — community features in a fitness app, a creator marketplace with comments, a forum bolted onto a SaaS product.
Two instruments cut it back. The Online Safety (Age-Restricted Social Media Platforms) Rules 2025 exclude eight classes of service: those whose sole or primary purpose is messaging, email, voice or video calling; enabling users to play online games; enabling users to share information about products or services (reviews, technical support and the like); professional networking and professional development; or supporting users’ education or health — plus services with a significant purpose of facilitating communication between educational institutions and students or their families, or between health care providers and the people in their care. That is why WhatsApp, Messenger Kids, LinkedIn, Roblox and YouTube Kids sit outside the regime while their siblings sit inside it. Then the Amendment Rules that took effect on 26 March 2026 narrowed the definition further: a service is only age-restricted if it also has a recommender feature — defined widely as a feature that selects material for a user by reference to any information the service has associated with their account, which catches personalised surfaces well beyond the classic “For You” feed — or a logged-in feature — an endless feed, engagement or follower feedback shown to posters, or disappearing time-limited content, where at least one is gated behind holding an account. The stated target is services “purposefully designed to maintain persistent engagement”, not every product where users happen to talk to each other.
Three things founders should take from that structure:
- The exclusions are purpose-based, and purpose can drift. A game with chat is excluded as gaming; a game that ships a social feed, follower graphs and an algorithmic content stream may not stay excluded. Every significant social feature you add is a moment to re-run the analysis. Roblox is instructive — outside the minimum age obligation as a gaming service, but put on notice by eSafety in February 2026 over child grooming concerns and then issued legally enforceable transparency notices in April 2026, alongside Minecraft, Fortnite and Steam. Exclusion from Part 4A is not exclusion from the Online Safety Act.
- eSafety’s list of ten is expressly non-exhaustive. The Commissioner’s regulatory guidance puts the onus on providers to assess their own services against section 63C and the Rules. A startup that has never done the analysis has no answer when the letter arrives.
- The compliance burden falls on the platform alone. Under-16s who hold accounts commit no offence, and neither do their parents. There is no obligation on app stores. If your service is in scope, the problem is entirely yours.
What “Reasonable Steps” Actually Requires
The core obligation, in section 63D, is that a provider of an age-restricted platform must take reasonable steps to prevent age-restricted users — Australian children under 16 — from having accounts. Section 63D itself carries a civil penalty of 30,000 penalty units; the five-times multiplier for bodies corporate under the Regulatory Powers (Standard Provisions) Act 2014 takes that to 150,000 penalty units — $54.6 million at the $364 penalty unit value applying to conduct from 1 July 2026 ($49.5 million for earlier conduct).
“Reasonable steps” is deliberately technology-neutral, but eSafety’s September 2025 regulatory guidance and its March 2026 compliance update give it real shape. The Commissioner expects a layered, documented age assurance system — a “waterfall” in which low-friction methods (age inference from behavioural and account signals) escalate to more robust ones (facial age estimation, ID-backed verification) where signals conflict. Some markers from the guidance and the first nine months of enforcement practice:
- Self-declaration alone is not reasonable steps. An unverified date-of-birth field at sign-up, on its own, fails.
- Existing accounts count. The obligation is to prevent under-16s having accounts, not merely opening them — platforms are expected to detect and deactivate existing underage accounts and to stop deactivated users simply re-registering. eSafety has specifically called out letting previously self-declared under-16 users “age up” by editing their birthdate.
- You don’t have to verify everyone. The guidance is explicit that verifying every user’s age is not required, and that measures which wrongly exclude large numbers of compliant adult users cut against reasonableness. Proportionality to your service’s risk profile is the organising principle.
- Users need a way to contest errors. Accessible review mechanisms for people wrongly flagged as under 16 — and reporting pathways parents can actually use — are part of the expected architecture.
Enforcement is no longer hypothetical: eSafety’s March 2026 update disclosed 23 compulsory information-gathering notices and active investigations into five of the ten named platforms, with a toolkit running from enforceable undertakings and infringement notices up to court-imposed civil penalties.
The Age Assurance Data You Collect Is Its Own Legal Risk
Part 4A comes with a privacy regime that startups building age assurance should treat as a design constraint, not an afterthought. Under section 63DB, a platform must not collect government-issued identification material, or use an accredited service within the meaning of the Digital ID Act 2024 — a category that includes private-sector identity providers, not just the government’s own system — for age assurance, unless it offers users reasonable alternative means of proving their age. And under section 63F, personal information collected for age assurance may only be used or disclosed for that purpose (with narrow exceptions, including with the individual’s consent) and must be destroyed once that purpose is spent; non-compliance is treated as an interference with privacy under the Privacy Act 1988, which puts the OAIC alongside eSafety as a regulator of your age gate. The OAIC has published dedicated Part 4A privacy guidance, and its expectations run in the familiar grooves: minimise what you collect, prefer estimation over identification where risk allows, and never repurpose age assurance data for advertising or profiling. With a statutory tort of serious invasion of privacy now available to plaintiffs, an over-collecting age gate is a litigation surface as well as a compliance failure.
A Practical Playbook
- Run the section 63C analysis now, and write it down. Map your features against the definition, the exclusions and the March 2026 recommender/engagement criteria. A dated, reasoned self-assessment is your first exhibit if eSafety ever asks.
- Re-assess on every roadmap change. Feeds, follows, DMs opened to strangers, recommender algorithms — each can move you across the line. Make the analysis a standing item in product review.
- If you’re in scope, build layered age assurance, not a checkbox. Signals-based inference backed by escalation, deactivation and re-registration controls, plus a review pathway. Document why your chosen stack is proportionate to your risk profile.
- Design the data handling with sections 63DB and 63F in front of you. Offer reasonable alternatives to government ID and accredited digital ID services, ringfence age assurance data, and build the destruction step into the pipeline — not a manual clean-up you’ll forget.
- Watch the perimeter. The Rules can be amended, eSafety’s list can grow, and gaming and messaging exclusions are under sustained political pressure. Treat today’s exclusion as a position to monitor, alongside the rest of your privacy reform tracking.
The Bottom Line
The Social Media Minimum Age regime is drafted around a definition broad enough to reach well beyond the ten platforms in the headlines, then trimmed by purpose-based exclusions and engagement-feature criteria that reward products designed with restraint. For consumer tech startups the work is less about buying age verification software than about knowing, with documented reasons, whether Part 4A applies to you — and re-checking every time the product grows a new social limb. If you’re in scope, eSafety’s guidance describes a defensible system: layered, proportionate, privacy-minimising, documented. If you’re out of scope, the analysis that proves it is cheap insurance against a $54.6 million question.
This article is general information only, not legal advice — whether Part 4A applies turns on your service’s specific features and purposes, and the Rules and guidance continue to evolve. Viridian Lawyers advises Australian consumer tech and social product startups on online safety regulation, age assurance design and privacy compliance. If your product has social features and no section 63C self-assessment on file, get in touch.