|
India's rapidly growing digital economy is increasingly driven by young internet users who engage with social media, online gaming, OTT platforms, e-learning applications, and e-commerce services. As businesses collect and process personal information from these users, protecting children's privacy has become a major legal priority. To address this, the Digital Personal Data Protection (DPDP) Act, 2023, along with the DPDP Rules, 2025, establishes a comprehensive framework for processing children's personal data.
The DPDP Act received Presidential assent on 11 August 2023, while the draft Rules were released for public consultation in January 2025. The final Rules were notified on 13 November 2025, with substantive provisions—including those relating to children's data—scheduled to come into force on 14 May 2027, giving businesses time to prepare for compliance.
Definition of a Child and Data Fiduciary
The DPDP Act defines a child as any individual who has not completed eighteen years of age. Since minors generally cannot provide legally valid consent, the law recognises the parent or lawful guardian as the person authorised to provide consent on the child's behalf.
A Data Fiduciary refers to any person, company, platform, or organisation that determines the purpose and means of processing personal data. This includes social media companies, educational technology providers, gaming platforms, healthcare institutions, OTT services, and online retailers.
Section 9: Three Core Obligations
Section 9 of the DPDP Act introduces three important obligations for Data Fiduciaries processing children's personal data.
First, before collecting or processing any personal data relating to a child, the Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian. This consent is a mandatory legal requirement and serves as the basis for lawful processing.
Second, Data Fiduciaries must not process children's personal data in any manner that is likely to have a detrimental effect on the child's well-being. This obligation applies irrespective of whether parental consent has been obtained.
Third, the Act imposes an absolute prohibition on tracking, behavioural monitoring, and targeted advertising directed at children. Unlike ordinary consent requirements, these restrictions cannot be waived through parental approval.
Verifiable Parental Consent
The requirement of verifiable parental consent is more stringent than the consent framework applicable to adults. Obtaining a simple declaration from an individual claiming to be a parent is insufficient.
Under Rule 10 of the DPDP Rules, 2025, a Data Fiduciary must verify both the identity of the parent or lawful guardian and confirm that the individual is an adult before relying on the consent provided.
The Rules recognise three methods for verification:
These mechanisms aim to ensure that parental consent is genuine while minimising the risk of unauthorised processing.
Business Implications
The DPDP framework significantly impacts businesses that provide digital services to children or have under-18 users among their customer base.
Platforms can no longer rely on behavioural profiling or personalised advertising for child users. Recommendation algorithms, advertising systems, analytics tools, and tracking technologies must be redesigned to distinguish between adult and child accounts. Businesses must ensure that tracking scripts and profiling mechanisms are disabled for children.
Where Data Fiduciaries engage third-party Data Processors, they remain legally responsible for compliance. Accordingly, contracts with processors should clearly prohibit behavioural tracking, profiling, or targeted advertising involving children's personal data and require compliance with the DPDP framework.
Exemptions
The DPDP Act empowers the Central Government to prescribe limited exemptions for specified Data Fiduciaries and processing activities. The DPDP Rules provide exemptions primarily for educational institutions, healthcare providers, subsidy delivery, account creation, and child-safety purposes. These exemptions are narrowly interpreted and do not permit commercial profiling or targeted advertising involving children.
Penalties
The DPDP Act prescribes substantial financial penalties for non-compliance. Violations relating to children's personal data—including failure to obtain verifiable parental consent or engaging in prohibited tracking or targeted advertising—can attract penalties of up to INR 200 crore. Failure to notify personal data breaches may also attract penalties up to INR 200 crore, while failure to implement reasonable security safeguards can result in penalties up to INR 250 crore.
These penalties are imposed by the Data Protection Board of India, with appeals lying before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Conclusion
India's DPDP Act marks a significant shift in the regulation of children's online privacy. By requiring verifiable parental consent, prohibiting behavioural monitoring and targeted advertising, and imposing substantial penalties for violations, the legislation seeks to create a safer digital environment for children. With the substantive provisions becoming enforceable from 14 May 2027, organisations have a limited window to update their privacy policies, redesign technical systems, strengthen contractual safeguards with Data Processors, and establish robust compliance mechanisms. Businesses that prepare early will not only reduce legal risk but also foster greater trust among users and demonstrate responsible data governance in India's evolving digital ecosystem.
Tags : International Legal Article
Copyright A unit of White Code Global Consulting Pvt Ltd. All rights reserved. Unless otherwise indicated, all materials on these pages are copyrighted by A unit of White Code Global Consulting Pvt Ltd. All rights reserved. No part of these pages, either text or image may be used for any purpose. By continuing past this page, you agree to our Terms of Service, Cookie Policy, Privacy Policy and Content Policies.