Children's Data Under The DPDP Act Age Verification And Parental Consent In Practice

POSTED ON AUGUST 27, 2026 BY DATA SECURE
AUTHOR NAME: Haider M, Data Privacy Intern
breach

Introduction

A gaming platform in India signs up a new user who says she is sixteen. Under most privacy laws that would already be a straightforward case: get consent, move on. Under the DPDP Act it is not straightforward at all, because a sixteen-year-old is not treated as capable of giving that consent herself, and the platform now must go find, and verify, an adult who can give it on her behalf.

India drew its line for childhood in data law at eighteen, not thirteen, not sixteen, and did it without exceptions for mature minors or emancipated teenagers. That single choice, more than almost any other provision in the Act, is why children's data compliance in India looks so different from what most global platforms have already built for GDPR or COPPA. A consent flow designed around a thirteen-year-old threshold does not just need tweaking to work here. It needs rebuilding.

This piece works through what Section 9 of the DPDP Act actually requires, how the Rules expect verifiable consent to work in practice, which prohibitions survive even when a parent says yes, where the exemptions carved out for schools and hospitals create real operating room, and the uncomfortable trade-off sitting underneath the entire regime: verifying that someone is a child, reliably, tends to require collecting more data, not less.

What Section 9 Actually Requires

Section 2(f) of the Act defines a child as an individual who has not completed eighteen years of age. That is the whole test. India did not build in a lower threshold for a mature sixteen-year-old, and it does not have anything like the sliding “digital age of consent” that GDPR leaves member states free to set somewhere between thirteen and sixteen. The number is fixed by statute, and it lines up with the age of majority under the Indian Contract Act and the Juvenile Justice Act rather than with anything specific to data protection. A platform used to treat thirteen as the cutoff, because that is what COPPA and most GDPR implementations use, is not looking at a stricter version of the same rule. It is looking at a different rule entirely, one that pulls millions of Indian teenagers who would count as adults everywhere else back into the parental consent regime.

Section 9(1) does the actual work: a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing any personal data belonging to a child. The word doing the heavy lifting there is verifiable, and the Act does not leave it to a company's imagination.

How “Verifiable” Consent Is Supposed to Work in Practice

Rule 10 of the DPDP Rules, 2025 sets out what verifiable is supposed to mean in practice, and it points toward a specific mechanism rather than a general standard. The Rule defines an authorised entity as one that has been entrusted with issuing proof of identity and age, or a virtual token confirming those details, and it names Digital Locker service providers explicitly as a route through which that verification can happen. Read plainly, the Rule is steering companies toward using DigiLocker, or an equivalent government-recognised identity system, to confirm that the person clicking consent is actually an adult and the child's parent or guardian, rather than accepting a checkbox or a self-declared birthdate.

It is a meaningfully higher bar than what most consent flows built for other markets are used to clearing. A credit card check or an email confirmation, both common verification shortcuts elsewhere, would struggle against a standard built around authoritative, government-linked identity credentials.

The Absolute Prohibitions That Consent Cannot Override

Section 9(3) sits apart from the consent machinery entirely, and it is worth understanding why. It prohibits a Data Fiduciary from tracking or behaviourally monitoring children, or directing targeted advertising at them, and unlike almost everything else in the Act, this prohibition does not bend to consent. A parent saying yes to a child's account does not unlock behavioural profiling or targeted ads for that child. The two obligations run on separate tracks: Section 9(1) is about permission; Section 9(3) is a line that permission cannot move.

That distinction has a real design consequence. A platform can have its consent side fully in order, a verified parent, a documented approval, a clean audit trail, and still be in breach if its ad engine or its recommendation system is quietly profiling every user regardless of age. Consent compliance and Section 9(3) compliance must be engineered and audited as two separate problems. Getting one right says nothing about the other.

Where the Exemptions Create Room, and Room for Dispute

breach

None of this is absolute, and Section 9(4) is where the Act builds in room to breathe. It allows the government to exempt specified classes of Data Fiduciaries, or specified purposes, from both the consent requirement and the anti-tracking prohibition, subject to conditions. Rule 12, read with Part A of the Fourth Schedule to the DPDP Rules, is where those exemptions actually get named. Clinical establishments, mental health establishments, and healthcare professionals can process a child's data without the full consent regime when the processing is limited to delivering health services. Educational institutions get relief for tracking and monitoring tied to academic activity or student safety. Crèches and childcare centres get similar room for safety-related monitoring, and transport providers engaged by any 9(of these institutions can track a child's location for the narrow purpose of getting them there and back safely.

There is a separate mechanism, Section 9(5), that works differently from the fixed exemptions. It lets the government grant a specific Data Fiduciary permission to treat children above a certain age as adults for consent purposes, if that Fiduciary can demonstrate its processing is verifiably safe. As of mid-2026, the Central Government has not notified any exemptions or lowered the age threshold for any classes of Data Fiduciaries under Section 9(5). It functions as an incentive sitting in reserve rather than a live pathway any company can rely on today.

The exemptions sound narrow when you read the categories in isolation. Healthcare. Education. Child safety. In practice, legal commentators have already flagged that the drafting is broader than it looks. While commercial ed-tech platforms may attempt to claim relief under broad sectoral categories, doing so to run ad-supported behavioural tracking carries severe regulatory risk, as Fourth Schedule exemptions remain strictly conditioned on academic activity and student safety.

The Verification Paradox Nobody Has Fully Solved

Here is the tension sitting underneath the entire framework, and it rarely gets named directly. Verifying that someone is genuinely an adult, and genuinely the parent of a specific child, is not something a company can do with less data. It needs something stronger than a self-declared birthdate can offer, which in practice means a government ID or a DigiLocker token or some other credential that counts as verifiable rather than just declared. So, a regime built to protect children's data ends up asking platforms to collect a parent's identity documents to prove the child deserves protection from data collection in the first place. That is not really a flaw in the design. It is closer to an unavoidable cost of taking verification seriously, and not many organizations have worked out how to explain that trade-off to a parent who is, reasonably, wary of uploading a government ID just to let their kid play a game.

The Readiness Gap: What Most Organizations Are Missing

breach

Most Indian companies serving anyone under eighteen know, in general terms, that parental consent is required. Considerably fewer have rebuilt their systems around what the Act specifically demands, and the gaps tend to cluster in a few places.

Age gates that ask instead of verifying

A self-declared birthdate is still the most common age check in the market, and it satisfies nothing under Rule 10. A child who wants access will simply enter an adult birthdate, and the platform has no verifiable consent trail to show if a regulator ever asks for one.

Ad and analytics systems never separated from the consent flow.

Marketing and product teams frequently run one behavioural tracking stack across the entire user base, adults, and children together, because building a separate, non-tracking experience for under-eighteen users is expensive. Section 9(3) does not care how expensive it is to build.

Exemption claims made without documentation

A platform that believes it qualifies under Part A of the Fourth Schedule needs to be able to show, specifically, how its processing stays within the conditions attached to that exemption. Assuming the exemption applies is not the same as being able to prove it does.

No plan for the verification-versus-minimisation trade-off

Very few consent flows have a clear answer to what happens to the parent's identity document once verification is done, how long it sits on file, or why keeping it around is proportionate. A data principal, or a regulator, is entitled to ask exactly that.

Way Forward

A few concrete steps are worth taking now:

  • Replace self-declared age gates with a verification flow that produces a verifiable record using DigiLocker or an equivalent authorized entity, rather than an honesty-based checkbox.
  • Separate tracking, profiling, and ad-targeting systems by age band, so that a Section 9(3) violation in the adult product does not automatically become a violation in the under-eighteen experience, and vice versa.
  • Document, in writing, exactly which Fourth Schedule exemption a service is relying on and why its specific processing falls within the stated conditions, rather than assuming a sector label is enough.
  • Build a clear, minimal retention policy for the identity documents collected during parental verification itself, ensuring strict alignment with purpose-limitation and data-minimization obligations under Section 8 of the Act.
  • Brief product and marketing teams specifically on the fact that Section 9(3)'s prohibitions do not lift with parental consent, since that is the single most common misunderstanding in how the section gets implemented.
  • Watch for any Section 9(5) age-flexibility notifications once the government begins issuing them, since being an early applicant could meaningfully ease the compliance burden for services with a strong existing safety record.

Conclusion

India's choice to set the bar at eighteen, with no sliding scale and only narrow, conditional room to manoeuvre, was a deliberate one. It reflects a view that children cannot be expected to consent meaningfully to data processing, and that the burden of proving otherwise sits with the business, not the child.

That is a harder standard to build for than most global platforms are used to, and it is not going to get easier by waiting. The organizations that treat verifiable consent as a genuine engineering problem, not a checkbox to add later, will be the ones that are not scrambling to explain their age gate the first time the Board asks to see it.

We at Data Secure (Data Privacy Automation Solution) DATA SECURE - Data Privacy Automation Solution  can help you to understand Privacy and Trust while lawfully processing the personal data and provide Privacy Training and Awareness sessions in order to increase the privacy quotient of the organisation.

We can design and implement RoPA, DPIA and PIA assessments for meeting compliance and mitigating risks as per the requirement of legal and regulatory frameworks on privacy regulations across the globe especially conforming to GDPR, UK DPA 2018, CCPA, India Digital Personal Data Protection Act 2023. For more details, kindly visit DPO India – Your outsourced DPO Partner in 2025 (dpo-india.com).

For any demo/presentation of solutions on Data Privacy and Privacy Management as per EU GDPR, CCPA, CPRA or India DPDP Act 2023 and Secure Email transmission, kindly write to us at info@datasecure.ind.in or dpo@dpo-india.com.

For downloading the various Global Privacy Laws kindly visit the Resources page of DPO India - Your Outsourced DPO Partner in 2025

We serve as a comprehensive resource on the Digital Personal Data Protection Act, 2023 (Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025), India's landmark legislation on digital personal data protection. It provides access to the full text of the Act, the Draft DPDP Rules 2025, and detailed breakdowns of each chapter, covering topics such as data fiduciary obligations, rights of data principals, and the establishment of the Data Protection Board of India. For more details, kindly visit DPDP Act 2023 – Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025

We provide in-depth solutions and content on AI Risk Assessment and compliance, privacy regulations, and emerging industry trends. Our goal is to establish a credible platform that keeps businesses and professionals informed while also paving the way for future services in AI and privacy assessments. To Know More, Kindly Visit – Your Trusted Partner in AI Risk Assessment and Privacy Compliance | AI-Nexus