Aryan Anand & Saniya Singh Raghuvanshi

Abstract: This article examines the implications of common ownership for competition in India’s increasingly oligopolistic markets. It assesses whether the existing material-influence framework adequately captures the competitive risks arising from overlapping ownership and informational linkages between rivals. By examining the interaction between market concentration, and common ownership, the article argues for a market-sensitive regulatory framework incorporating rebuttable presumptions and targeted behavioural remedies.
This piece discusses self-harm and mental health concerns, which involve minors. Reader discretion is advised.
In September 2025, a 14-year-old boy from Mohanlalganj (a locality of Lucknow) took his life after spending nearly ₹14 lakh from his father’s bank account on Free Fire (mobile game). Five months later, on February 4, 2026, a 14-year-old boy died by suicide after developing an addiction to Free Fire; ₹ 28,000 was spent on in-app purchases. These incidents show us how in-game purchase mechanisms drive addictive gaming behaviour and lead to severe psychological harm, which can cost their lives.
In its Economic Survey 2025–26, the Ministry of Finance highlighted Gaming Disorder and digital addiction as emerging mental health concerns, such as depression and anxiety for Children. The study by von der Heiden et al. (2019) reinforces this link; it found that problematic video gaming (online and offline games) involving social and action elements is associated with adverse psychological effects such as depression, anxiety and others. These vulnerabilities are intensified by Predatory monetisation mechanisms, which play a substantial role behind the digital addiction of children to online social games.
This piece argues that the Promotion and Regulation of Online Gaming Act, 2025 and Online Gaming Rules, 2026, fail to adequately regulate monetisation mechanisms in online social free-to-play games, such as loot boxes, behavioural tracking-driven in-app purchases and manipulative design features (variable reward systems and artificial scarcity). Further, these mechanisms result in psychological harm such as depression and anxiety through addictive gaming behaviour, psychological reinforcement, and behavioural manipulation. As a result, this framework does not effectively implement India’s child-protection obligations, contrary to the proactive practical necessity posed by the Digital Personal Data Protection Act, 2023. It leaves predatory monetisation in free-to-play online social games outside mandatory child protection safeguards Furthermore, this regulatory gap is inconsistent with certain provisions related to the rights of children in the digital environment under the UNCRC. The Legal framework of India, including both the Online Gaming Act, 2025 and its Rules, 2026, should follow General Comment No. 25 (2021) to meet specific provisions related to the digital environment under the UNCRC more effectively. Therefore, this piece proposes reforms to the Promotion and Regulation of Online Gaming Act, 2025 and Online Gaming Rules, 2026, to address the regulatory gap surrounding predatory monetisation and child protection in free-to-play online social games.
The scope of this piece is limited to minors (persons below 18 years) and online social free-to-play games.
To substantiate the claim, Part II states how behavioural design in monetisation mechanisms within online social free-to-play games can encourage addictive engagement, influencing minors to make in-app purchases. Part III identifies the regulatory gap in the Online Gaming Act, 2025 and its Rules, 2026, with the help of the Digital Personal Data Protection Act, 2023, in the context of child protection. Part IV discusses international child protection standards and argues that India’s Online Gaming Act, 2025, and its Rules, 2026, fail to meet them. Part V suggests comparative reforms for the Online Gaming Act, 2025, and its Rules, 2026 and reaches the conclusion.
II. Behavioural Design of In-App Purchases and Surveillance Capitalism.
India is the largest mobile games download market in the world. It has registered over 8.45 billion installations in FY 2024-25, according to Sensor Tower performance insights, 2025. However, this scale of engagement masks a growing crisis: for minors, routine play escalates into gaming addiction, marked by a complete loss of control despite severe consequences
These addiction risks are intensified by gameplay features that include in-app purchases, loot boxes, and even artificial scarcity. Spritzer et al. (2026) make this argument in their discussion of Brazil’s Digital Child and Adolescent Act of 2025. Most game elements used in modern gameplay function similarly to those of gambling games. They use techniques such as variable ratio reinforcement (players never know when they’ll get a reward) and the near miss phenomenon (players almost win the prize, prompting them to continue playing).
The fundamental architecture of the in-app purchase feature across the freemium model works through a closed-loop system. It encourages players to purchase a “virtual currency” to distance themselves from the feeling of spending real money. This currency is then spent on an in-game storefront that features a mix of visual upgrades (outfits).
The theory of surveillance capitalism was introduced by sociologist Shoshana Zuboff. It states that technology companies treat human experience as a source of raw data, which is collected as “behavioural surplus” and processed through machine-learning systems to predict and influence users’ future behaviour. Applying this theory, contemporary digital games operate under an economic model that relies on translating gamers’ behaviour into data. It is then employed to predict and manipulate players in terms of influencing their purchasing patterns for commercial purposes.
Similarly, in-game purchasing, loot boxes, and similar game mechanics are not just means of entertaining players, but rather commercial practices based on behavioural psychology that track move of theirs in the virtual world. Further, the data-collection and analysis systems inside online social free-to-play games collect players’ behavioural data so that loot boxes and similar game mechanisms can adjust their commercial practices, designed on behavioural psychology, to exploit players’ vulnerabilities and maximise in-app spending.
The behavioural mechanism of in-app purchases demonstrates the need to examine whether India’s existing legal framework (legislative framework and regulatory framework) addresses their impact on minors. Part III examines this regulatory gap under the Online Gaming Act, 2025, Online Gaming Rules, 2026, and with the help of the Digital Personal Data Protection Act, 2023.
III. India’s Regulatory Gaps in Child Protection
The Online Gaming Act, 2025, regulates real-money games such as gambling while leaving free-to-play games only under Sections 3 and 4. These provisions are promotional and developmental in nature. Section 3 focuses on the recognition and development of e-sports through measures including training academies, research centres, incentive schemes, awareness campaigns, and support for technological innovation. Similarly, Section 4 facilitates the development of online social games through registration mechanisms, public-awareness programmes, increased access to gaming content, and coordination with educational and recreational institutions. Notably, neither provision imposes mandatory obligations relating to child safety, addictive design, spending limits, age verification, or behavioural manipulation. This indicates that the legislative focus is on sectoral growth and promotion rather than user protection.
Examining both the Act and the Rules reveals the existing regulatory gap and identifies the legislative and administrative reforms. The Online Gaming Rules, 2026, are constituted under Section 19 of this Act and subject to its statutory limits. It should operationalise the Act through detailed and enforceable safeguards.
The Online Gaming Rules, 2026, rely on post-harm grievance redressal and discretionary regulatory intervention. It doesn’t mandate the implementation of safety features, nor does it address addictive design and in-app purchases such as spending limits. They prescribe neither screen time limits nor age-based restrictions, and imposes no child-protection obligations on online game service providers. Rule 21 empowers the designated Authority to investigate complaints and impose penalties. However, enforcement is triggered only after alleged non-compliance is identified. As a result, the protection of children from harm remains largely discretionary and reactive rather than mandatory and preventive. This indirect relationship between review and enforcement not only can weaken deterrence but also can allow harmful practices to persist until complaints are formally raised. Rule 20 mandates that all online game service providers implement and keep in place an operational system for the resolution of consumer complaints. However, it mitigates the harm that has already occurred when a problem arises.
The regulatory gap is concerning when viewed alongside the Digital Personal Data Protection Act, 2023. Sections 9(2) and 9(3) of this Act prohibit harmful processing of children’s personal data and ban behavioural tracking of minors. However, this Act is limited to data processing and does not regulate game design or monetisation mechanisms.
In online social free-to-play games (stated in part II), behavioural data is recorded through a child’s gameplay, interactions, and spending patterns, or inferred by combining such activity with other data points, including device and contextual information, it is then used to shape, the game-design and monetisation mechanisms, this is why its processing is inseparable from the design and monetisation mechanisms that personalise engagement and drive continued play and in-app purchases. Therefore, behavioural data cannot be effectively regulated in isolation. Section 38 makes this Act operate in addition to other laws and does not replace or override other related laws until it directly conflicts with the Act.
Section 9 is not in active enforcement until May 13, 2027, which doesn’t create a present practical necessity until 2027. However, by failing to include the game design and monetisation mechanism in the gaming framework, gaming companies will face binding child-protection obligations with no sector-specific implementation guidance and no clear regulatory mechanism through which compliance can be fully achieved. It creates a proactive practical necessity to address the concern before its operationalised. Further, before it produces a regulatory vacuum, the government must operationalise through the sector-specific framework, which includes the Online Gaming Act, 2025, and Online Gaming Rules, 2026.
Beyond the domestic failures, India’s regulatory silence also raises concerns under its voluntarily accepted international obligations. It will be discussed in a later section.
IV. The Framework of International Law
The General Comment No. 25 (2021) of the UNCRC is relevant to digital games because it addresses the rights, health, welfare of the child, and their right to play. It requires States to regulate digital design and address unhealthy interactions with digital games and social media. This can protect the development and rights of children.
India ratified the UNCRC on December 11, 1992. Such ratification makes the protection of the rights of children in the digital environment obligatory as per its provisions. In fairness, General Comment No. 25 (2021) is not per se justiciable or legally binding within the domestic laws of India. The significance of General Comment No. 25 (2021) becomes clearer when its institutional status is understood. General Comments are interpretive guidance issued by the Committee on the Rights of the Child (‘Committee’). They provide authoritative interpretation of the treaty, i.e. official interpretation by the Committee in the form of general recommendations of how the UNCRC’s existing provisions should be understood and applied, which the ratified states have an option (not a legal obligation) to follow. Further, Article 43 of the UNCRC established the Committee as the official body of independent experts, which is then mandated to monitor and interpret the treaty. This Committee derives its authority to issue General Comments from Article 45(d) as an authoritative interpretation of the treaty through suggestions and general recommendations.
At the domestic level, the obligation remains a policy and legislative commitment. Further, failure to make progress in following the provisions of UNCRC related to the rights of children in the digital environment as per General Comment No. 25 (2021) can result in recommendations during periodic reviews by the UN Committee on the Rights of the Child, which can lead to international scrutiny. In Salil Bali vs Union of India & Anr, 2013, the Supreme Court recognises that international obligations such as the UNCRC acquire enforceable legal effect through incorporation into domestic legislation rather than by ratification alone. Nevertheless, the UNCRC remain an international legally binding convention once ratified to follow through enforcement. This can be done by making the legal framework to comply with the UNCRC, with the help of a focus on protecting children from emerging forms of harm in the digital environment.
If a state ignores General Comment No. 25 (2021), then it can be difficult to comply with the UNCRC, as General Comments serve as the official authoritative interpretation and operational manual for the treaty. It offers substantive guidance necessary to address complex, contemporary violations.
The Online Gaming Act, 2025, and Online Gaming Rules, 2026 discussed in Part III leave significant gaps in protecting children from psychological harm on children through addiction by in-app purchase mechanisms associated with free-to-play online social games, as they do not regulate in-app purchases, spending limits, addictive or manipulative game-design features, age-based safeguards, age verification, or screen-time limits. This legislative framework doesn’t follow those obligatory provisions related to the rights of children in the digital environment under the UNCRC and the general recommendations of the General Comment No. 25 (2021), which are relevant to the topic and issue discussed in Part I.
These identified gaps in India’s regulatory framework as also discussed in part III doesn’t follow obligation highlighted in Article 3 (best interests of the child), and also needs to follow the general recommendation in para 12 to 13, 28 and 38 to 41 of General Comment No. 25 (2021) which require the child’s best interests to guide digital regulation, legislation and business practices and regulate businesses through child-rights due diligence to protect children in the digital environment. Further, the identified regulatory gaps in the legislative framework go against Article 6 (right to life, survival and development) and Article 16 (no unlawful interference to privacy of children) and also need to follow the recommendations in paras 14, 80 to 82 and 96, which require states to protect children from digital violence, exploitation and mental or physical health risks, including harmful game designs and unhealthy engagement with digital games. Moreover, the identified gaps also go contrary to the obligations of Article 19 (protection from physical or mental violence, injury or abuse, neglect or negligent treatment, maltreatment or exploitation) and Article 36 (protection from other forms of exploitation), which needs to follow the recommendation to address the gaps and fulfil the specific provisions of UNCRC, given in para 35 to 39 and 112 to 114 of General Comment No. 25 (2021), related to regulation of businesses to respect children’s rights and prevent digital harms, and effective remedies and protection from economic, and other forms of exploitation.
The legal framework of India discussed in Part III doesn’t fulfil the requirements (domestic and international). It demands legislative and judicial reforms to regulate in-app purchases of online social free-to-play games to protect minors from psychological harm. This is outlined in the concluding section.
V. Comparative Reforms and Conclusion
The Online Gaming Act, 2025, should be amended to impose mandatory child-protection obligations on online free-to-play social games. Sections 3 and 4 must be expanded beyond their promotional focus to require preventive safeguards against predatory monetisation and harmful game design, including mandatory age verification, commercial advertisements targeting minors for in-app purchases, spending limits for minors, restrictions on loot boxes, and safeguards against algorithmic profiling over behavioural data.
The legislative framework of China is the Law on the Protection of Minors, 2020. It mandates age verification under Article 75 and spending limits by setting up spending management under Article 76. China’s 2022 minor protection report found that 75.49% of minors played games fewer than three hours per week, compared with 67.76% in 2021. It also highlights the regulation of age verification; nearly 30% reduced their game-related spending, while unauthorised payments by minors without parental permission fell from 28.61% to 15.43%. Meanwhile, Standard 12 of the UK’s Age Appropriate Design Code, 2020, regulates algorithmic profiling based on children’s behavioural data. It requires profiling to be off by default unless justified by the child’s best interests. Children and Screens’ independent impact assessment of UK documented 91 platform and policy changes tied to this Code, including restricting the downloadability of minors’ content and preventing minors from being tagged by non-followers. Though limited to social media platforms, its success in this domain can raise similar impact within the online social gaming sector. Moreover, specific in-game monetisation tactics, such as loot boxes and surprise mechanics, are regulated by Article 2, which defines probabilistic items under the Game Industry Promotion Act, 2006, of South Korea. The study by Xiao, L. Y. Park, S. (2025) analysed the 100 highest-grossing iPhone games in South Korea. They found that 90% of these titles utilised paid loot boxes, with 84.4% successfully disclosing their probabilities. This highlights that enforced legal mandates outperform industry self-regulation.
Online Gaming Rules, 2026, should operationalise the statutory obligations of its parent act by introducing safeguards including strict age verification, screen time limits, and regulation of addictive design features. These design features include loot boxes and pay-to-win systems. China’s Notice on Minors’ Addiction to Online Games (2021) restricts users under 18 to one hour of online gaming per day from Friday to Sunday, statutory holidays, and are prohibited other days.
Further, it must impose spending caps and prior approval for in-app purchases for minors and make user safety obligations binding. Moreover, it should restrict behavioural tracking and profiling of children, and should not rely solely on post-harm grievance mechanisms but also shift to preventive measures including design standards. The UK’s Design Code, 2020 implements post-harm and preventive measures mechanisms. Meanwhile, violations must attract mandatory penalties, which will allow it to regulate “permissible” gaming, i.e., free-to-play games.
The Dutch Civil Code (Book 6) of the Netherlands treats the non-disclosure of loot-box probabilities as a misleading omission (Art. 6:193d BW), requiring developers to disclose the odds before purchase, and prevents developers from concealing the real-money price of loot boxes solely through virtual currencies. It also protects minors by prohibiting aggressive commercial practices, including advertisements (Art. 6:193i BW) that make children purchase loot boxes or in-game items. Moreover, the Consumer Protection Enforcement Act, 2006 imposes a penalty of up to €900,000 per violation for failure to comply with consumer protection rules under Book 6 of the Dutch Civil Code.
A study (Xiao, 2025) evaluated top-grossing mobile games in the Netherlands against consumer guidelines. It demonstrated a failure of the regulations as compliance was virtually non-existent: only 2% displayed Euro pricing, and under 10% disclosed loot box odds. Regulators failed to actively enforce guidelines against international developers. The Dutch experience demonstrates that India must combine clear statutory safeguards for in-game monetisation and effective enforcement with a regulator that can actively detect, investigate, and penalise non-compliance.
The Supreme Court’s willingness to entertain the PIL in Dr K.A. Paul @ Kilari Paul v. Union of India, 2026 (first and second paragraph) supports that online gaming raises constitutional concerns, also under Article 21. The court needs to capitalise on this opportunity by expanding the scope of Article 21, which would oblige the legislative framework to regulate in-app purchase design harming minors. The Constitution of Brazil, 1988 (Article 227) provides the right to protect minors from exploitation, neglect, systemic harm, and violence. Brazil enforces these protections through its Digital Child and Adolescent Statute. In June 2026, a Brazilian court ordered gaming companies to pay $51.5 million over exploitative paid loot boxes involving minors. The decision highlights the effectiveness of Brazil’s constitutional right under Article 227.
Children are susceptible to harm where the regulatory framework fails to regulate the online gaming environment. It must be noted that there will be a gap in India’s regulatory framework until the Government adopts sufficient measures regarding the following: (a) in-app purchases; (b) addictive designs; and (c) child safety within the online gaming space.
Aryan Anand is a 4th year, B.A. LL.B. student at Chandigarh University, Punjab
Saniya Singh Raghuvanshi is a 4th year, B.A. LL.B. student at Chandigarh University, Punjab
Categories: Law & Economics
