News By/Courtesy: PARAM SAKET SARANG | 13 Jul 2026 22:32pm IST

HIGHLIGHTS

  • India's DPDP Act mandates verifiable parental consent before processing personal data of individuals below 18 years, strengthening privacy protection for children.
  • The law imposes an absolute ban on tracking, behavioural monitoring, and targeted advertising directed at children, regardless of parental consent.
  • Businesses must comply with the DPDP Rules by May 14, 2027, or face penalties of up to ?200 crore for violations involving children's personal data.

Children's Personal Data under India's DPDP Act, 2023: Key Compliance Requirements

India's rapidly growing digital economy is increasingly driven by young internet users who engage with social media, online gaming, OTT platforms, e-learning applications, and e-commerce services. As businesses collect and process personal information from these users, protecting children's privacy has become a major legal priority. To address this, the Digital Personal Data Protection (DPDP) Act, 2023, along with the DPDP Rules, 2025, establishes a comprehensive framework for processing children's personal data.

The DPDP Act received Presidential assent on 11 August 2023, while the draft Rules were released for public consultation in January 2025. The final Rules were notified on 13 November 2025, with substantive provisions—including those relating to children's data—scheduled to come into force on 14 May 2027, giving businesses time to prepare for compliance.

Definition of a Child and Data Fiduciary

The DPDP Act defines a child as any individual who has not completed eighteen years of age. Since minors generally cannot provide legally valid consent, the law recognises the parent or lawful guardian as the person authorised to provide consent on the child's behalf.

A Data Fiduciary refers to any person, company, platform, or organisation that determines the purpose and means of processing personal data. This includes social media companies, educational technology providers, gaming platforms, healthcare institutions, OTT services, and online retailers.

Section 9: Three Core Obligations

Section 9 of the DPDP Act introduces three important obligations for Data Fiduciaries processing children's personal data.

First, before collecting or processing any personal data relating to a child, the Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian. This consent is a mandatory legal requirement and serves as the basis for lawful processing.

Second, Data Fiduciaries must not process children's personal data in any manner that is likely to have a detrimental effect on the child's well-being. This obligation applies irrespective of whether parental consent has been obtained.

Third, the Act imposes an absolute prohibition on tracking, behavioural monitoring, and targeted advertising directed at children. Unlike ordinary consent requirements, these restrictions cannot be waived through parental approval.

Verifiable Parental Consent

The requirement of verifiable parental consent is more stringent than the consent framework applicable to adults. Obtaining a simple declaration from an individual claiming to be a parent is insufficient.

Under Rule 10 of the DPDP Rules, 2025, a Data Fiduciary must verify both the identity of the parent or lawful guardian and confirm that the individual is an adult before relying on the consent provided.

The Rules recognise three methods for verification:

  • Using identity and age information already reliably available with the Data Fiduciary.
  • Relying on identity and age details voluntarily submitted by the parent.
  • Using a government-authorised virtual token, including one issued through Digital Locker or similar government-recognised systems.

These mechanisms aim to ensure that parental consent is genuine while minimising the risk of unauthorised processing.

Business Implications

The DPDP framework significantly impacts businesses that provide digital services to children or have under-18 users among their customer base.

Platforms can no longer rely on behavioural profiling or personalised advertising for child users. Recommendation algorithms, advertising systems, analytics tools, and tracking technologies must be redesigned to distinguish between adult and child accounts. Businesses must ensure that tracking scripts and profiling mechanisms are disabled for children.

Where Data Fiduciaries engage third-party Data Processors, they remain legally responsible for compliance. Accordingly, contracts with processors should clearly prohibit behavioural tracking, profiling, or targeted advertising involving children's personal data and require compliance with the DPDP framework.

Exemptions

The DPDP Act empowers the Central Government to prescribe limited exemptions for specified Data Fiduciaries and processing activities. The DPDP Rules provide exemptions primarily for educational institutions, healthcare providers, subsidy delivery, account creation, and child-safety purposes. These exemptions are narrowly interpreted and do not permit commercial profiling or targeted advertising involving children.

Penalties

The DPDP Act prescribes substantial financial penalties for non-compliance. Violations relating to children's personal data—including failure to obtain verifiable parental consent or engaging in prohibited tracking or targeted advertising—can attract penalties of up to INR 200 crore. Failure to notify personal data breaches may also attract penalties up to INR 200 crore, while failure to implement reasonable security safeguards can result in penalties up to INR 250 crore.

These penalties are imposed by the Data Protection Board of India, with appeals lying before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

Conclusion

India's DPDP Act marks a significant shift in the regulation of children's online privacy. By requiring verifiable parental consent, prohibiting behavioural monitoring and targeted advertising, and imposing substantial penalties for violations, the legislation seeks to create a safer digital environment for children. With the substantive provisions becoming enforceable from 14 May 2027, organisations have a limited window to update their privacy policies, redesign technical systems, strengthen contractual safeguards with Data Processors, and establish robust compliance mechanisms. Businesses that prepare early will not only reduce legal risk but also foster greater trust among users and demonstrate responsible data governance in India's evolving digital ecosystem.

Section Editor: Kadam Hans | 13 Jul 2026 22:35pm IST


Tags : International Legal Article

Latest News







Copyright A unit of White Code Global Consulting Pvt Ltd. All rights reserved. Unless otherwise indicated, all materials on these pages are copyrighted by A unit of White Code Global Consulting Pvt Ltd. All rights reserved. No part of these pages, either text or image may be used for any purpose. By continuing past this page, you agree to our Terms of Service, Cookie Policy, Privacy Policy and Content Policies.