Apple removed roughly 3,400 apps from the Indian App Store on Wednesday for failing to implement age verification required under amendments to India's Information Technology Rules that took effect August 1. The affected apps span dating, gaming with real money elements, social networking, and a broad category the rules describe as content unsuitable for minors. Google carried out a comparable removal on Play, though it has not published a number. Developers describe a compressed timeline: the technical specification for acceptable verification methods was published on June 18, giving six weeks to implement, test, and pass review.
What the rules require
The amendment requires apps in specified categories to verify that a user is above eighteen through one of four methods: a government digital identity check through the Aadhaar-based verification service, a bank or payment credential associated with an adult account, a credit-referenced check through an approved bureau, or a device-level attestation from the operating system vendor. Self-declared age is explicitly insufficient, which is the change from the previous framework.
The rules also require that verification data not be retained beyond the verification event, with an auditable record of the check but not of the underlying identity data. That is a reasonable privacy provision and it complicates implementation, because the standard approach of storing a verification result against a user identifier requires careful design to satisfy both requirements.
Why so many apps failed
Six weeks is not long to integrate an identity verification flow, and the approved provider list was published later still, on July 3. Developers we spoke with described a queue at the verification providers, several of whom could not onboard new customers before the deadline. A dating app operator in Mumbai said his integration was complete on July 26 and his provider's compliance review had not finished when the deadline passed.
The category definitions also caused confusion. The rules list categories broadly enough that many developers were unsure whether they applied. A social app with user-generated content might or might not fall under the content provision depending on moderation. Several developers said they sought clarification from the Ministry of Electronics and Information Technology and received no response before the deadline, then were removed.
The story is rarely the launch. It is what breaks, what ships, and who owns the mess at 2 a.m.
The device-level option
The fourth verification method, operating system attestation, would let Apple or Google assert a user's age to an app without the app touching identity data. That is the privacy-preserving approach and the one most developers want. Apple has a declared age range API that shipped for other jurisdictions, and Google has a similar capability. Neither has been approved as compliant under the Indian rules, because the approval process requires the verification method itself to meet the standard and neither company has submitted the underlying age determination for review.
That leaves a situation where the best technical option is unavailable and developers must integrate a third-party identity check. Apple's position, stated in a developer communication, is that it is working with the ministry on recognition of its API. Privacy advocates in India have argued that platform-level attestation concentrates sensitive determination in two American companies, which is a fair objection and a different one from the practical developer complaint.
The pattern across jurisdictions
Age assurance requirements are arriving everywhere. The United Kingdom's Online Safety Act obligations took effect in 2025 and produced a similar round of removals and traffic collapses for affected services. Several American states have laws with varying requirements and ongoing constitutional litigation. Australia's social media minimum age law took effect in December 2025. The European Union has a draft approach built on a digital identity wallet.
The technical fragmentation is the underlying problem. An app operating in twelve markets faces twelve different verification requirements with different approved methods and different data handling rules. Standards work exists, notably an ISO specification and a technical group at the World Wide Web Consortium, and neither has produced anything regulators have adopted. Until they do, compliance cost scales with the number of markets, which advantages large companies and pushes small developers out of jurisdictions.
What happens to the removed apps
Restoration requires completing verification integration and passing review, which Apple says it is prioritizing. Several developers reported restoration within 48 hours of submitting a compliant build. For an app whose Indian user base is a meaningful share of revenue, a week of unavailability is damaging and survivable. For a small developer, it can be terminal.
The larger effect will be on which apps serve India at all. India is the second largest app market by downloads and far smaller by revenue per user, which means compliance cost is weighed against modest returns. Two European developers told us they will simply geo-block India rather than implement verification, which is the rational individual decision and, aggregated, is a worse outcome for Indian users than the rules intended.
Indian developers have a different complaint and a fair one. The verification providers charge between eight and twenty rupees per check depending on method and volume, which for an app with a large free user base and small revenue per user is a cost that scales with usage and produces no revenue. Two Indian gaming studios told us they will verify only users who attempt a monetized action, which is a defensible reading of the rules and one the ministry has not confirmed. Clarity on that single point would change the compliance cost for a large share of the affected apps.
Skarvonix will keep following this beat with reporting grounded in how systems behave outside the launch keynote.
- Privacy




