← All guides

Families & young people

A parent's guide to teenagers and social media

Age rules, what parental controls can and cannot do, the risks that actually matter versus the ones that get headlines, and how to have conversations that keep a teenager talking to you.

By Stephanie BenackUpdated 2026-08-12 min read

Advice for parents about teenagers online tends to arrive in two unhelpful forms: alarmed coverage of the latest app, and technical instructions for controls that a motivated fifteen-year-old will route around in an afternoon.

This guide tries to be more useful — about which risks actually warrant attention, what the tooling genuinely achieves, and why the conversational approach outperforms the technical one over time.

Start with the actual risks

Public attention and real prevalence are poorly aligned. Roughly in order of how often they affect ordinary teenagers:

Peer-to-peer harm. Exclusion, rumours, group chats formed to mock someone, screenshots recirculated. Overwhelmingly the most common harm, almost always involving people the child already knows from school. It rarely produces headlines and it is what most affected teenagers are actually dealing with.

Sleep displacement. Not a dramatic risk, but a pervasive one, and it amplifies everything else. A phone in the bedroom overnight predicts poorer sleep, and poor sleep predicts worse mood, worse school performance, and reduced resilience.

Content that is legal but corrosive. Material on body image, self-harm, eating, and extreme ideology — not usually sought out, but delivered by recommendation systems that respond to engagement signals a distressed teenager generates.

Sextortion. This has changed in character and deserves specific attention. The current pattern is financially motivated, often targets boys aged roughly 14–17, and moves fast: a stranger poses as a peer, establishes contact, moves to a private channel, obtains an intimate image, then immediately threatens to send it to the victim's contacts unless paid. The speed and the shame are the mechanism. A teenager who knows in advance that this exists, and that their parents will not be angry, is far better protected than one relying on any filter.

Contact from adults with sexual intent. Real and serious, though less common than coverage implies. Grooming typically involves sustained relationship-building, secrecy, and moving the conversation to a private channel.

Scams. Teenagers are frequently targeted for account takeover, gaming currency fraud, and increasingly as money mules — an offence with lasting consequences that many do not recognise as criminal.

Note where the balance falls. Most of the harm comes from people the child knows and from systems optimised for engagement — neither of which a stranger-danger framing addresses.

What the rules actually are

Most major platforms set a minimum age of 13. This derives largely from the US Children's Online Privacy Protection Act, which imposes strict requirements on services knowingly collecting data from under-13s. It is a data protection threshold, not a judgement that a service is appropriate at 13.

In much of the EU the threshold for consent to data processing is higher, between 13 and 16 depending on the member state.

Age assurance is being tightened in many jurisdictions, with online-safety legislation in the UK, EU, Australia and several US states pushing platforms towards stronger verification. In practice, self-declared ages remain easy to falsify and a large number of under-13s hold accounts.

Most platforms also apply stricter defaults to known minors: private-by-default accounts, restricted messaging from adults, limits on targeted advertising, and reduced discoverability. These protections depend on the platform knowing the user is a minor — which is a concrete argument for a teenager's account carrying their real age.

What parental controls can and cannot do

Genuinely useful:

  • Device-level screen time and downtime, especially overnight. Blunt but effective, and the sleep benefit is well-supported.
  • Purchase controls. Preventing surprise spending is straightforward and non-contentious.
  • Age ratings on app stores, which stop casual installation of clearly inappropriate apps.
  • Platform family tools linking a parent account for visibility over time spent and, on some services, who can message the child.
  • DNS-level filtering at the home router for the crudest categories of content.

Limited or counterproductive:

  • Content filtering in general. It fails in both directions — blocking legitimate health, sexuality and support information while missing much of what it targets. Filters are weakest against exactly the "legal but harmful" content that matters most.
  • Covert monitoring. Reading a teenager's messages without their knowledge is the fastest way to guarantee that, when something goes badly wrong, they will not come to you. The cost is paid at the worst possible moment.
  • Anything relying on the child not being technical. VPNs, browser profiles, secondary devices, and borrowed friends' phones are all trivially available. Controls treated as a wall become a game.

The realistic framing: controls buy time and structure for a younger child, and their value declines steadily through the teenage years. They do not substitute for the child's own judgement, which is the thing you are actually trying to build.

Conversations that work

The evidence consistently favours engaged, communicative parenting over restrictive monitoring, and the mechanism is simple: it keeps the channel open.

Establish the no-blame rule explicitly, and repeat it. The single most protective sentence available to you is some version of: "If anything happens online that frightens you, you can tell me and you will not be in trouble — even if you broke a rule to get there." Sextortion, grooming, and scams all depend on the victim being too ashamed to tell an adult. Removing that shame in advance defeats the mechanism. Say it before anything happens, and say it more than once.

Ask about the social situation, not the software. "Who's being annoying in the group chat?" gets further than "What apps are you using?" You are trying to understand the social environment, which is where the risk lives.

Be specific about the patterns. Teenagers respond well to concrete mechanics: that a stranger who moves quickly to a private app and asks for photos is running a known script; that someone claiming to be their age with a thin profile probably is not; that a request to keep a friendship secret is itself the warning sign.

Discuss permanence honestly, without catastrophising. Screenshots exist, and things resurface. Equally, an overstated "this will ruin your life" message is not credible and gets discounted along with everything else you said.

Negotiate rules rather than imposing them, and revise them as the child gets older. Rules a teenager helped set are ones they are more likely to keep when you are not there — which is the only test that matters.

Practical settings worth making

A short list with a good effort-to-benefit ratio:

  1. Phones out of bedrooms overnight, charging elsewhere. The highest-value single rule.
  2. Accounts set to private, with follower requests reviewed.
  3. Location sharing off in posts and profiles; check individual apps, not just the phone-level toggle.
  4. Messaging restricted so people they do not follow cannot initiate contact.
  5. Correct date of birth on the account, so minor protections apply.
  6. Two-factor authentication enabled — teenage accounts get stolen frequently.
  7. Comment and keyword filters turned on where offered.
  8. Know where the report and block buttons are, together, before they are needed.

If something goes wrong

Sextortion. Do not pay — payment reliably leads to further demands. Do not delete the account or the messages; capture evidence including the profile and URLs. Block, report to the platform, and report to the police or the national reporting body. Specialist services can have intimate images of minors removed across platforms, including tools that work from an image hash so nothing has to be sent to anyone. Above all, make clear to the child that they are not in trouble; the fear of the parent's reaction is what the offender is counting on.

Bullying. Document with screenshots and URLs before blocking. Report to the platform, and — where it involves classmates — to the school, which usually has both a duty and a process. Our guide on responding to online harassment covers the documentation in detail.

Contact from an adult. Preserve everything, do not confront the person, and report to the police and the platform.

Compromised account. Change the password, check for altered recovery details, and review connected apps. See our guide to social engineering.

The overall shape

The parents who navigate this well tend to do a small number of things consistently: they protect sleep, they keep the conversation open, they explain mechanics rather than issuing prohibitions, and they make it unambiguous that the child can come to them without fear.

Technical controls are supporting infrastructure for a relationship, not a substitute for one. A teenager who will tell you when something goes wrong is better protected than any configuration will make them.

Related guides