Summary

  • The Digital Personal Data Protection (DPDP) Act and Rules mandate verifiable parental or guardian consent for processing a child's personal data.
  • Verification of the user's age, the guardian's identity is required under the Act.
  • Data processing for age verification purposes to confirm whether a user is a minor is explicitly permitted under the Rules.
  • The Rules explicitly prohibit processing activities detrimental to children's well-being, such as exposure to inappropriate content, tracking, behavioral monitoring, and targeted advertising.
  • Specific exemptions apply to healthcare providers, educational institutions, and public authorities when processing children’s data for essential purposes like health, education, or public welfare.
Close Button

Parental Consent: DPDP Law on Children’s Data

Avisha Khatri

Product Content Strategist
September 7, 2026

Summary

  • The Digital Personal Data Protection (DPDP) Act and Rules mandate verifiable parental or guardian consent for processing a child's personal data.
  • Verification of the user's age, the guardian's identity is required under the Act.
  • Data processing for age verification purposes to confirm whether a user is a minor is explicitly permitted under the Rules.
  • The Rules explicitly prohibit processing activities detrimental to children's well-being, such as exposure to inappropriate content, tracking, behavioral monitoring, and targeted advertising.
  • Specific exemptions apply to healthcare providers, educational institutions, and public authorities when processing children’s data for essential purposes like health, education, or public welfare.

Summary

  • The Digital Personal Data Protection (DPDP) Act and Rules mandate verifiable parental or guardian consent for processing a child's personal data.
  • Verification of the user's age, the guardian's identity is required under the Act.
  • Data processing for age verification purposes to confirm whether a user is a minor is explicitly permitted under the Rules.
  • The Rules explicitly prohibit processing activities detrimental to children's well-being, such as exposure to inappropriate content, tracking, behavioral monitoring, and targeted advertising.
  • Specific exemptions apply to healthcare providers, educational institutions, and public authorities when processing children’s data for essential purposes like health, education, or public welfare.

More children and young adults are online than ever, and more of their data is getting collected, stored, and processed by the same apps and platforms adults use. The DPDP Act doesn't treat that data the same way it treats an adult's. Businesses that process it have to rework their systems and policies to account for it.

Here's what the law actually requires.

Who is a child?

Under Section 2(f) of the DPDP Act, a child is anyone below 18. There's no lower threshold, and no distinction between a 17-year-old and a 7-year-old — the same rules apply to both.

What does the DPDP Act say about children's data?

Section 9 of the Act sets out three things a Data Fiduciary must do, or not do, when it processes a child's data:

  • Verifiable consent: A child's personal data can't be processed without verifiable consent from the child's parent or lawful guardian. (Section 9(1))
  • Children's rights under DPDP: You can't track or behaviourally monitor a child, serve them targeted ads, or carry out processing likely to harm a child's well-being. (Section 9(3))
  • Exceptions: The government can exempt specific classes of Data Fiduciaries, or specific purposes, from some of the above. (Section 9(4))

Verifiable Consent

Section 9(1) says that before you process the personal data of a child, or a person with a disability who has a lawful guardian, you need verifiable consent from that child's parent or lawful guardian.

How do you collect verifiable parental/guardian consent?

To collect verifiable consent, you need to verify the identity of the parent — not just take their word for it. 

Here's how that typically plays out: Either the child declares themselves through their date of birth and names a parent or guardian, or the parent identifies themselves upfront and shares the child's data directly.

You need to have measures in place and exercise due diligence, to confirm that the person identifying as the parent is an identifiable adult. A checkbox asking "Are you the parent?" with no verification behind it doesn't meet this standard.

If you already hold verified details for that parent, a consent notice can be sent straight to them. If you don't, their identity has to be confirmed first. This can be done either by having them supply their details directly, or by checking them through a service like DigiLocker.

Once identity is confirmed, the consent notice goes out: on the same device if the parent is physically present, or over email, WhatsApp, or SMS if they're not. Their consent, given on the child's behalf, is what creates the consent record.

You can do this by checking identity and age details you already hold for her, by checking details issued by an entity the law or government has entrusted with maintaining them, or via a virtual token mapped to those details — in practice, furnished through a Digital Locker service provider like DigiLocker.

You're also allowed to process data for the specific purpose of confirming whether a user is a minor, as per Fourth Schedule Part B of the DPDP Rules.

Does the child's self-declaration need to be verified too? No. The DPDP Act doesn't require you to verify whether the person who declares themselves a minor actually is one — a DOB checkbox on the child's side is legally sufficient. The verification obligation sits entirely on the parent's side: their identity and age must be confirmed when they give consent.

Children's Rights

Three protections apply to a child, regardless of whether valid consent exists.

No processing likely to cause detrimental effect

The Act prohibits any processing likely to cause a detrimental effect on a child's well-being. "Detrimental effect" isn't defined in the law, but it's understood to cover anything that could compromise a child's privacy, security, or mental and emotional health.

Examples include exposure to violent or explicit content, which can hurt a child's development and psychological well-being. 

No tracking or behavioural monitoring of children

The Act also bans tracking or behavioural monitoring of children. This term isn't defined either, so its exact scope is a bit open — but it's understood to cover sustained monitoring of a child's online activity and preferences over time. Think of it as the kind of profiling that builds a behavioural picture of a child across sessions, not a one-off interaction.

For instance if a gaming app analyses a child's level progression or in-app purchase patterns to build a profile of their habits, this will be restricted under the Act

No targeted advertising directed at children

The Act also bans targeted advertising directed at children. Where the previous restriction covers the act of monitoring, this one covers using that data to personalise what a child sees.

In the earlier example if the behavioural profile is then used to tailor the ads a child sees based on her habits, that's independently prohibited too. Google and YouTube were fined $170 million for tracking children's online activity without consent and using it to serve them personalised ads.

Exceptions

Under Section 9(4) of the Act and Rule 12 of the Rules, the government can exempt specific classes of Data Fiduciaries, or specific purposes, from two obligations: obtaining verifiable consent (Section 9(1)), and not tracking or targeting children with ads (Section 9(3)).

Exemptions by class of Data Fiduciary

These obligations won't apply to:

  • Clinical establishments, mental health establishments, and healthcare professionals but only to the extent necessary to provide health services and protect the child's health.
  • Allied healthcare professionals for supporting a treatment or referral plan already recommended for the child.
  • Educational institutions  for educational activities, or the safety of children enrolled with them
  • Individuals running a crèche or day care centre if processing is for the safety of the children in their care.
  • Entities transporting children to and from a school, crèche, or day care for the purpose of tracking a child's location for her safety during that journey.

Exemptions by purpose

These obligations also won't apply to processing carried out to:

  • Exercise a power, perform a function, or discharge a duty in a child's interest under law.
  • Issue a subsidy, benefit, certificate, licence, or permit in a child's interest, under a law, government policy, or publicly funded scheme.
  • Create a user account strictly for email communication.
  • Determine a child's real-time location, where restricted to her safety, protection, or security.
  • Prevent a child from accessing content, a service, or an advertisement likely to cause her detrimental effect — the "content safety" exception.
  • Confirm whether a Data Principal is a child in the first place — the age-verification step covered earlier in this piece.

Exception for specific Data Fiduciaries

Separately, under Section 9(5), the government can notify a specific, named Data Fiduciary as exempt from all or some of the Section 9(1) and 9(3) obligations, above an age threshold the notification specifies — if it's satisfied that fiduciary processes children's data in a verifiably safe manner.

So far, the government hasn't issued any such notification.

One thing worth flagging: none of these exemptions ever cover Section 9(2) — processing likely to cause a detrimental effect on a child. That protection stands regardless, reflecting the law's core policy of the child's best interest.

Path Forward

  • Add age verification to every new account signup.
  • Pick your method for confirming the identity of a parent: an Aadhaar-based check, a DigiLocker token, or another due-diligence-backed method.
  • Build a parent-verification flow for accounts flagged as minors.
  • Turn off tracking, profiling, and targeted ads for any account flagged as a minor. 
  • Check if any part of your business fits an exemption (healthcare, education, childcare, school transport). If it does, keep that processing limited to just the exempted purpose.
  • Remember: no exemption ever covers processing that could harm a child.
  • Keep records of every parental consent including who consented, how you verified them, and when.

Want to protect your children's data? Get in touch with us to know how

Schedule a Demo Call

Compliance Deadline:

0 weeks away