Under India’s DPDP Act, anyone under 18 is a child, and you need verifiable consent from a parent or lawful guardian before processing their personal data. You also cannot track or behaviourally monitor children or show them targeted ads, even with parental consent, unless a specific exemption applies. The full compliance milestone for the Rules falls in May 2027, so now is the time to design your parental consent flow.
This article is general information, not legal advice. Check the Act, the DPDP Rules 2025 and your own facts with a qualified lawyer.
What Section 9 of the DPDP Act says about children’s data
Section 9 is the part of the Digital Personal Data Protection Act, 2023 that deals with children. It has four rules of thumb that every product team should know:
- Verifiable parental consent (Section 9(1)): obtain it before processing any personal data of a child.
- No detrimental processing (Section 9(2)): do not process data in a way likely to harm a child’s well-being.
- No tracking or targeted ads (Section 9(3)): tracking, behavioural monitoring and advertising aimed at children are barred.
- Exemptions (Sections 9(4) and 9(5)): the Central Government can exempt classes of fiduciaries or purposes, and can set an age above which the restrictions do not apply for fiduciaries that process data verifiably safely.
Note that the word “child” covers every user below 18. A 17-year-old on your app is a child for DPDP purposes, which matters for edtech, gaming, social media and e-commerce teams used to a lower age cut-off.
How Rule 10 defines verifiable parental consent
The DPDP Rules 2025 turn the principle into practice. Rule 10 asks the data fiduciary to adopt technical and organisational measures so that it obtains verifiable consent before processing a child’s data. In particular, you must exercise due diligence to confirm that the person giving consent is an adult and is the child’s parent.
Ways to check that the parent is an adult
The Rules recognise a few routes. You can rely on reliable identity and age details you already hold about that person, or on details they voluntarily provide, or on a virtual token mapped to those details that is issued by an authorised entity, including a Digital Locker service provider. The idea is that you confirm adulthood and the parent link without necessarily collecting more documents than you need.
Design tips for a parental consent flow
- Ask for the child’s age first, then trigger the parent flow only when needed.
- Prefer tokens or already-verified identities over fresh document uploads, to keep your own data collection small.
- Log the consent event and the verification method so you can show your due diligence later.
- Keep the notice simple enough that a parent can actually understand what they are agreeing to.
What you still cannot do: tracking, profiling and targeted ads
Parental consent does not unlock everything. Section 9(3) prohibits tracking or behavioural monitoring of children and targeted advertising directed at them. In practice this affects analytics SDKs, recommendation engines, ad networks and “engagement” features on any service that may be used by under-18s. Teams should audit third-party scripts on child-facing screens and switch off behavioural ad features for users identified as minors.
If you build or fine-tune AI features on this data, the same logic applies. See our post on training AI on Indian personal data under the DPDP Act for how purpose limitation and consent interact with model training.
Fourth Schedule exemptions at a glance
The Fourth Schedule to the Rules lists classes of fiduciaries and purposes that are exempt from the parental consent and tracking restrictions, but only to the extent necessary for the stated purpose. The exemption relates to consent and tracking; the other duties of the Act still apply.
| Who or what | Typical scope of the exemption |
|---|---|
| Clinical and mental health establishments, healthcare professionals | Processing needed to provide health services to the child |
| Educational institutions | Tracking or monitoring for educational activities or student safety |
| Childcare providers | Monitoring in the interest of the safety of children in their care |
| Transport providers | Location tracking during travel, in the interest of safety |
| Email-only accounts, harmful-content blocking, age verification | Processing limited to what is necessary for that purpose |
Treat this table as orientation, not a legal opinion: always read the exact wording of the Schedule before relying on an exemption.
Timeline and penalties: when does this bite?
The DPDP Rules were notified in November 2025 with a phased rollout. Industry guides describe the Data Protection Board as set up first, the consent manager framework following about a year later, and the remaining obligations, including the children’s data provisions, applying about 18 months after notification, around mid-May 2027. See our explainer on the consent manager deadline in November 2026 for the intermediate milestone. Breaching the children’s data obligations can attract a penalty of up to Rs 200 crore under the Act’s schedule, so this is one of the higher-risk areas for consumer apps.
A practical compliance checklist
- Map where you may collect data from under-18 users, including sign-up, support and analytics.
- Add an age gate and a parental consent route with a recorded verification method.
- Disable behavioural tracking and targeted advertising for minors.
- Check whether a Fourth Schedule exemption genuinely applies, and document why.
- Update your breach plan, because child data incidents are higher stakes. See DPDP breach notification and the 72-hour clock.
- For a broader roadmap, start with implementing DPDP strategies.
Frequently asked questions
Who counts as a child under the DPDP Act?
Anyone under 18 years of age. This is a higher threshold than the 13 to 16 years used in many other privacy laws.
Is parental consent always required to process a child’s data?
Section 9(1) requires verifiable parental consent, but the Fourth Schedule exempts certain classes of fiduciaries (such as clinical establishments and educational institutions) and certain purposes, only to the extent necessary and with conditions.
Can I show personalised ads to teenagers if a parent consents?
No. Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, and parental consent does not lift that bar unless a specific exemption applies.
How do I verify that someone is the parent?
Rule 10 expects reasonable due diligence that the person is an adult and the child’s parent, using identity and age details you already hold, details voluntarily provided, or a virtual token issued through a government-backed service such as DigiLocker.
What is the penalty for getting this wrong?
The DPDP Act schedule lists a penalty of up to Rs 200 crore for breaching the obligations relating to children’s personal data.
Conclusion
For any business whose users might be under 18, the DPDP Act raises the bar: verify the parent, stop behavioural tracking and ads, and use exemptions narrowly. Start with an audit of your child-facing touchpoints and a simple verification flow, and you will be far ahead before the May 2027 milestone.