Iran Draft Would Make Serving Anonymous Users a Punishable Offense
A draft framework for governing Iran's internet would make serving users without identity verification a punishable violation.
A draft framework for governing Iran’s internet lists “failure to authenticate users before providing services” as a punishable violation, according to a copy of the text obtained by Digiato. It is a proposal, not enforceable law, and faces a long approval path.
The clause sits in Article 5, which requires authentication to follow what the text calls the “valid identity system in cyberspace.” Article 6 would let digital services reach anyone under 16 only after their age is verified against the National Identity Database of Natural Persons, Iran’s state register of citizens.
Together the clauses would turn identity verification from a per-service policy choice into a legal obligation with a penalty attached. The plan names the Supreme Council of Cyberspace, the state body that sets Iran’s internet policy, as the only authority competent to issue binding rules - placing it above the Ministry of Information and Communications Technology, the country’s telecom regulator. If it passes, it is a formal legal move toward ending anonymous access to digital services in Iran, beyond what is enforced in practice today.
Fines Scale With Revenue
Article 5 attaches a graduated penalty ladder: public declaration of the violation, operating restrictions, a ban on signing up new users, a fine of 1% to 10% of revenue, and licence suspension.
The new-user ban runs up to three months, advertising restrictions up to three years, and licence suspension or revocation up to three years. Article 5 defines seven categories of violation and eight penalties, in a plan of eight articles.
Enforcement would not sit with the ordinary courts. Cases would go to a three-member tribunal - a judge chosen by the head of the judiciary, a deputy from the National Cyberspace Center, and a specialist nominated by Iran’s national union of online businesses - whose majority rulings bind, with appeals running only to the Court of Administrative Justice, which hears complaints against Iranian state bodies, according to Digiato.
A Firewall Inside the Age Check
The age-verification clause carries a limit that cuts the other way. The text says an age check must not give the service provider access to a person’s identity information, and that the national database may be used only to verify or query age - a line between establishing who a user is and confirming how old they are, with both routed through state identity infrastructure.
Age checks for minors are law elsewhere too. Britain’s Online Safety Act requires services to use age assurance before showing certain content, and Australia has set a minimum age of 16 for social media accounts. Those regimes lean on commercial age-assurance vendors rather than a government identity register.