France’s Constitutional Council struck Article 1 of the July social-media law, the provision carrying the under-15 access prohibition, while leaving the rest of the statute outside that operative result [E1]. It accepted protection of children and prevention of public-order harms as legitimate aims, so the judgment did not reject the policy objective itself [E1]. The constitutional failure came from the breadth and construction of the restriction imposed to pursue those aims [E1]. Independent coverage likewise described the decision as blocking the under-15 ban on constitutional-freedom grounds [E6].
Article 1 supplied neither a parental route nor an individualized channel capable of changing the prohibition’s application, making the restriction insufficiently targeted [E1]. More revealingly, enforcing the threshold necessarily required “toute personne, même majeure” to prove age: the minor’s gate had become an adult credential checkpoint [E1]. Parliament had not written the conditions, limits or privacy safeguards governing that proof [E1]. A short prohibition had therefore acquired an unexpectedly large paperwork department.
The Council did not declare age verification unconstitutional, abolish an age threshold, forbid parental controls or rule out a privacy-preserving third-party credential [E1]. Nor did the surviving provisions receive an affirmative constitutional blessing: the Council said it did not examine them [E1]. That jurisdictional distinction matters because continued presence in the statute is different from adjudication on the merits [E1]. The ruling leaves lawmakers room to redesign the gate, while giving them no warrant to treat untouched language as pre-cleared.
Legislative history makes the defect less mysterious. The Senate’s 20 July joint-committee report described the proposed drafting as “minimaliste,” an economy of text that preceded the constitutional challenge [E2]. Article 1 identified whom services were supposed to exclude while leaving the proof machinery required for that exclusion largely unwritten [E1]. Once adults also had to establish age, the missing machinery stopped looking ancillary and became part of the rights burden itself [E1].
The Élysée responded by calling for “une rédaction juridiquement robuste tenant compte de la décision,” preserving the political project while conceding that the legal instrument needs another pass [E3]. European privacy work already supplies one possible technical direction: age assurance should use the least intrusive method possible [E4]. The Commission has separately promoted threshold verification that can work without revealing exact age, identity or other personal details [E5]. Those materials do not guarantee that a French successor will survive review, but they show that universal identity disclosure is not the only available architecture [E4][E5].
A successor law therefore faces several concrete choices: who performs the check, what fact reaches the platform, how long any evidence persists, what happens when proof is refused or wrong, and who bears responsibility for that error [E1][E4][E5]. Those are design requirements inferred from the holding’s adult-proof problem; the Council itself did not prescribe a technical architecture [E1]. A threshold-only credential could answer the disclosure question by telling a service only whether the legal age condition is met [E5]. Retention, refusal and error handling would still require legislation or implementing rules consistent with the least-intrusive principle [E4].
The government’s strongest counter-case remains substantial: the Council accepted the protective aims, and its decision left age-assurance tools available for a narrower statute [E1]. European work offers a plausible route in which a verifier discloses an eligibility result while withholding identity and exact age [E4][E5]. The constitutional danger returns if lawmakers again outsource the hard questions to platforms while every adult quietly acquires a duty to present credentials [E1]. France can still write fifteen into the login; this time, Parliament has to write what the login is allowed to know.