Featured Article : UK Decides Against Restricting VPNs

The UK government has decided against restricting virtual private networks (VPNs) after its own research found that most children use them for privacy rather than to bypass age checks, with ministers instead placing greater responsibility on online platforms to enforce age assurance.

Why VPNs Came Under Scrutiny

The issue arose as the UK rolled out tougher online safety rules requiring websites and apps hosting adult content to introduce stronger age verification. Some campaigners argued that children could simply use VPNs to disguise their location or identity and bypass those checks, prompting calls for restrictions on VPN services themselves.

However, the government decided to investigate how children were actually circumventing age restrictions before introducing any new controls, commissioning research to understand how VPNs were being used in practice.

Why The Government Changed Course

The decision follows research commissioned by the Department for Science, Innovation and Technology (DSIT) into how children use VPNs and attempt to bypass online age restrictions. The findings challenged one of the key assumptions behind proposals to limit VPN use.

The nationally representative study of more than 2,000 children aged 11 to 17 found that around a quarter (26 per cent) had used a VPN. However, privacy was the most common reason for doing so, with 30 per cent of VPN users saying they used one to keep their online activity private. Just 22 per cent of VPN users, equivalent to around 7 per cent of all children surveyed, said they used a VPN specifically to access age-restricted websites, apps or games.

By comparison, the research found that pretending to be older was a far more common way of bypassing age checks. Among children who had successfully circumvented age verification, 63 per cent said they had done so by posing as someone older, most commonly by entering a false date of birth.

Privacy Versus Circumvention

The findings appear to have played a significant role in shaping government policy. Online Safety Minister Kanishka Narayan confirmed the decision while speaking on BBC Breakfast, saying: “We decided not to limit VPNs.”

Technology Secretary Liz Kendall reinforced that position in a written ministerial statement, explaining that VPNs have “legitimate privacy and security uses” and confirming that the government would not seek to age-gate or restrict access to them.

The research also highlighted how widely privacy is valued by younger internet users. Overall, 86 per cent of children surveyed said it was important that their online activity remained private, while 81 per cent of VPN users said using one made them feel safer online.

Responsibility Moves To Online Platforms

Rather than restricting privacy tools themselves, the government has decided that online platforms should bear greater responsibility for preventing children from getting around age assurance requirements.

Under the new approach, platforms will be expected to take “robust steps” to detect and prevent under-age users circumventing age checks. Ofcom has been asked to report by October on what robust age assurance should look like for older teenagers, while Ofcom and the Information Commissioner’s Office will also examine how platforms can better identify attempts to use VPNs to bypass age restrictions.

The government has also said it intends to engage directly with VPN providers about possible voluntary measures while keeping the issue under review.

A Win For Privacy Campaigners

The decision has been widely welcomed by digital rights organisations and cyber security experts, many of whom had argued that restricting VPNs would have created far wider problems than it solved.

VPNs are widely used by businesses to secure remote access to company systems, protect sensitive communications, encrypt internet traffic on public Wi-Fi and help safeguard employees travelling internationally. They are also commonly used by journalists, activists, researchers and individuals seeking greater online privacy.

The government’s own research supports that broader picture. Many children reported using VPNs for reasons unrelated to age-restricted content, including accessing services available in other countries, protecting their personal information and improving online privacy.

The findings suggest that attempting to restrict VPNs would have affected many legitimate users while doing relatively little to prevent children bypassing online age restrictions.

What Does This Mean For Your Business?

For businesses, the government’s decision provides welcome certainty that VPNs continue to be recognised as legitimate cyber security tools rather than technologies primarily associated with bypassing online controls.

The wider lesson extends beyond VPNs themselves. As governments introduce new AI, online safety and digital regulation, there is growing recognition that effective policy needs to be evidence-led rather than based on assumptions about how technology is used. In this case, the government’s own research showed that privacy, not circumvention, was the main reason children were using VPNs.

Organisations should therefore continue encouraging the appropriate use of VPNs as part of a wider cyber security strategy, particularly for remote working and secure communications. At the same time, businesses that provide online services should expect increasing scrutiny over how they verify users’ ages and prevent circumvention, as regulators place greater responsibility on platforms rather than on the privacy technologies that many legitimate users rely upon.

Tech News : UK Plans New Social Media Restrictions For Under-16s

Social media restrictions for under-16s are moving closer to reality in the UK as ministers commit to action following a major consultation, signalling a significant change in how young people access digital platforms.

Why The UK Is Moving Towards Social Media Restrictions

The UK government has made it clear that some form of restriction on social media use for under-16s will be introduced, even if a full ban is not adopted, with ministers now focused on deciding how those measures should work in practice.

This change comes after growing concern about the impact of social media on children’s mental health, behaviour, and safety, alongside mounting political pressure from campaigners, parents, and members of Parliament. The Children’s Wellbeing and Schools Bill is central to this process, as it gives ministers the power to introduce restrictions through regulation rather than requiring entirely new legislation.

The consultation, which closes later this month, is designed to gather evidence on what combination of measures would be most effective, with ministers emphasising that the objective is not simply to act quickly but to ensure that any changes are workable and enforceable at scale, and that the approach should be “evidence-led, with input from independent experts” .

What Type Of Restrictions Are Being Considered?

Rather than focusing solely on an outright ban, the government is currently exploring a range of targeted interventions aimed at reducing harm while preserving some level of access.

One key area is the design of platforms themselves, with proposals to limit or remove features that encourage prolonged use, such as infinite scrolling, autoplay, and algorithm-driven content feeds. These features have come under increasing scrutiny for keeping users engaged for extended periods, often without clear stopping points.

Age verification is another major focus, with stronger enforcement expected to play a central role in any future framework, particularly given evidence that many children already bypass existing age limits by registering with false dates of birth.

The consultation is also examining the potential for time-based controls, including overnight curfews, as well as restrictions on access to AI chatbots and other emerging technologies that may expose children to inappropriate or harmful interactions, as part of a broader effort “to examine the most effective ways to ensure that children have ‘healthy online experiences’” .

Taken together, these measures point to a more granular approach, where specific features and behaviours are regulated rather than applying a single blanket rule across all platforms.

The Evidence Driving The Debate

The policy push is underpinned by a growing body of data and research highlighting both the scale of social media use among young people and the risks associated with it.

For example, recent figures show that social media use is nearly universal among teenagers, with around 95 per cent of 13 to 15-year-olds actively using platforms and the vast majority holding their own accounts. At the same time, a significant proportion of children report exposure to harmful or distressing content, including material linked to self-harm, bullying, and unrealistic body image expectations.

The Online Safety Act 2023 already requires platforms to take steps to protect children from harmful content, including enforcing age limits and removing illegal material. However, ongoing enforcement actions and investigations suggest that compliance has been uneven and that further intervention may be needed to achieve meaningful improvements.

Concerns have also been raised about the underlying design of platforms, particularly features that drive prolonged engagement, with policymakers pointing to risks from “design features that encourage them to spend more time on screens, while also serving up content that can harm their health and wellbeing” .

How Other Countries Are Approaching The Issue

Several countries have already introduced or are actively considering similar restrictions to the ones the UK is now considering.

For example, Australia has taken the most direct approach, introducing a nationwide ban on social media access for under-16s, with platforms required to take reasonable steps to prevent children from creating or maintaining accounts. Early enforcement efforts led to millions of accounts being removed, demonstrating that large-scale intervention is technically possible, although questions remain about long-term effectiveness and circumvention.

Spain has signalled its intention to follow a similar path, while France has already introduced measures requiring parental consent for younger users and is exploring tighter controls. Across the European Union, regulators have also focused on platform design, with actions taken against companies over addictive features and insufficient child protection measures.

These international examples highlight how governments are increasingly willing to intervene directly in platform access, and how enforcement and user behaviour remain challenging, particularly where young people find alternative routes to access services.

What Challenges Still Need To Be Addressed

Implementing effective restrictions is likely to prove complex, particularly given the global nature of social media platforms and the ease with which users can bypass controls.

Age verification remains one of the most difficult issues, as systems must be robust enough to prevent misuse while also protecting user privacy and remaining practical for widespread adoption. Even with improved verification methods, there is a risk that children will migrate to less regulated platforms or use shared accounts to maintain access.

There are also broader questions about how restrictions might affect positive uses of social media, including communication, education, and community building, particularly for young people who rely on online spaces for support and connection.

These competing factors explain why the government has opted for a consultation-led approach, aiming to balance safety, practicality, and unintended consequences before finalising its strategy.

What Does This Mean For Your Business?

For UK businesses, the immediate impact will depend on how directly they interact with younger audiences, but the broader implications extend well beyond youth-focused platforms.

Changes to social media regulation are likely to influence how digital platforms operate more widely, particularly in areas such as content moderation, user verification, and the design of engagement features. Businesses that rely on social media for marketing, customer engagement, or recruitment may see shifts in platform behaviour, audience reach, and compliance requirements over time.

Stronger age verification and feature restrictions could also affect advertising strategies, especially where campaigns currently reach mixed-age audiences, requiring more careful targeting and clearer segmentation.

There is also a wider regulatory signal that digital products are increasingly being judged not just on functionality and growth, but on their impact on users, particularly vulnerable groups. This trend is already visible in areas such as data protection and online safety, and it is likely to extend further as governments respond to public concern about digital harms.

Organisations involved in technology, digital services, education, or safeguarding should be paying close attention, as the outcome of this consultation will help shape the next phase of UK digital regulation. Businesses that understand how these changes affect platform design, user behaviour, and compliance expectations will be better placed to adapt as new rules are introduced and enforced.

Tech News : Millions Defy WhatsApp Bans

In a recent BBC World Service interview, Head of WhatsApp, Will Cathcart, claimed that tens of millions of people in countries where WhatsApp has been banned continue to use it.

Where Is WhatsApp Banned And Why? 

WhatsApp is banned Iran and North Korea, has been blocked at times in Syria, Senegal, and Guinea, and recently China banned iPhone users from downloading the app. Also, Qatar, Egypt, Jordan and the United Arab Emirates restrict certain features of the app.

WhatsApp faces bans and restrictions in these countries mainly due to concerns regarding its end-to-end encryption, which prevents governments from monitoring or intercepting messages sent through the platform. The encryption feature undermines authorities’ abilities to surveil communications for security purposes, potentially allowing for the spread of dissent or undesirable information. Also, WhatsApp’s widespread popularity makes it a powerful tool for activities such as organising protests or disseminating information, posing challenges to governments seeking to control the flow of information and maintain societal order. Consequently, countries with authoritarian regimes or strict censorship laws are opting to ban or restrict WhatsApp to maintain control over communication channels and uphold state authority.

Evidence of Tens of Millions Still Using It 

Mr Cathcart says the fact that WhatsApp can see the registered phone numbers of users, plus anecdotal reports of people using WhatsApp, have enabled WhatsApp to: “look at some of the countries where we’re seeing blocking and still see tens of millions of people connecting to WhatsApp”.  

Apple 

In the interview, Mr Cathcart highlighted how China ordered Apple to block Chinese iPhone users from downloading WhatsApp from the AppStore in April was a “choice Apple has made” but stressed that Android users there can still download it without going through official shops.

China has also banned another end-to-end encrypted app, Telegram, and has asked Apple to remove microblogging app Threads from its app store due to political content that mentions the Chinese president.

VPNs 

Mr Cathcart also pointed the role that virtual private networks (VPNs) and WhatsApp’s proxy service have had in keeping WhatsApp accessible.

Free Internet Battle 

Mr Cathcart also highlighted how the UK government’s battle over several years to ban end-to-end encryption in apps like WhatsApp to allow police to read criminals’ messages, and the US forcing TikTok to be sold or banned (for national security reasons) are indicators of the growing battle for a free Internet.

What Does This Mean For Your Business? 

For businesses, the ongoing saga surrounding end-to-end encrypted apps like WhatsApp has implications for operations, security, and ethics. As highlighted by Will Cathcart, the widespread use of WhatsApp in countries with authoritarian regimes shows its critical role as a secure communication platform for individuals facing oppressive surveillance and censorship. In such environments, where privacy and freedom of expression are under constant threat, encrypted apps serve as a lifeline for both personal and professional interactions.

However, the bans and restrictions imposed by these governments highlight the tension between security and freedom in the digital age. By targeting encrypted platforms, governments essentially seek to exert control over information flow and suppress dissent, often at the expense of individual liberties and privacy rights. For businesses operating in (or collaborating with partners in) such regions, these restrictions pose significant challenges, potentially jeopardising the confidentiality of sensitive communications and data.

Also, the battle over end-to-end encryption extends beyond geopolitical borders, shaping the broader landscape of internet freedom and digital rights. Efforts by governments like the UK’s to undermine encryption in the name of law enforcement raise serious questions about the balance between security measures and civil liberties. Any compromise to encryption standards not only undermines the privacy and security of users but also sets a dangerous precedent that threatens the integrity of the digital ecosystem.