DPDP children's data rules
and verifiable parental consent.
What section 9 of the DPDP Act and Rules 10 to 12 require before you process data about anyone under eighteen, how parental consent is verified, who the Fourth Schedule exempts, and what a website has to change by 13 May 2027.
Last updated Published by TryTrustableNot legal advice
What does the DPDP Act say about children's data?
The DPDP Act treats everyone under eighteen as a child. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. It must not process data in a way likely to harm the child's well-being, and it must not track, behaviourally monitor or target advertising at children.
The definition is in section 2(f) of the Act: a child is an individual who has not completed the age of eighteen years. Section 9 then sets five rules:
| Provision | What it says | Can it be disapplied? |
|---|---|---|
| 9(1) | Verifiable consent of the parent (or lawful guardian) before processing any personal data of a child, in the manner the Rules prescribe. | Yes, for the classes and purposes in the Fourth Schedule (Rule 12). |
| 9(2) | No processing that is likely to cause any detrimental effect on the well-being of a child. | No. Nothing in the Act or Rules exempts anyone from 9(2). |
| 9(3) | No tracking or behavioural monitoring of children, and no targeted advertising directed at children. | Yes, only for the Fourth Schedule classes and purposes, on their conditions. |
| 9(4) | The Rules may exempt classes of Data Fiduciaries or purposes from 9(1) and 9(3). | This is the power Rule 12 uses. |
| 9(5) | The Government may notify an age above which a Data Fiduciary whose processing is verifiably safe is exempt from 9(1) and 9(3). | We have found no such notification as of 28 September 2026. |
From section 9 of the Digital Personal Data Protection Act, 2023, paraphrased. Read the text before relying on the wording.
Two consequences are easy to miss. First, parental consent does not cure 9(3): a parent cannot consent to their child being targeted with advertising. Second, nothing exempts anyone from 9(2), so even an exempt hospital or school must not process a child's data in a way likely to harm them.
How does verifiable parental consent work under Rule 10?
Under Rule 10 of the DPDP Rules 2025, a Data Fiduciary must use technical and organisational measures to obtain the parent's verifiable consent before processing a child's data. It must check that the person claiming to be the parent is an identifiable adult, using identity and age details it already holds or details or a virtual token from an authorised entity.
Rule 10(1) gives two sources for that check:
- Reliable details already with you. Identity and age details of the parent that the Data Fiduciary already holds and can rely on, typically because the parent is a verified user
- Details provided voluntarily. Either by the individual, or through a virtual token mapped to identity and age details and issued by an authorised entity
An adult is someone who has completed eighteen years. An authorised entity is a body entrusted by law or by the Central or a State Government with issuing identity and age details or a mapped token, or someone it appoints or permits to do so, and the definition expressly includes details or tokens made available and verified by a Digital Locker service provider. That is the DigiLocker-style route: the parent proves she is an adult without handing you a document you then have to store.
The Rule comes with four illustrations. They vary on two questions: who starts the process, and whether the parent is already known to you.
| Case | Who starts | Is the parent your user? | What you check before creating the child's account |
|---|---|---|---|
| 1 | The child, who says she is a child and names her parent | Yes, with identity and age details already given | That you hold reliable identity and age details for the parent and that she is an identifiable adult. |
| 2 | The child, who names her parent | No | The parent's adulthood, by reference to identity and age details from an entity entrusted by law or the Government, or a virtual token mapped to them. The parent may use a Digital Locker service provider. |
| 3 | The parent, opening an account for the child | Yes | As in case 1. |
| 4 | The parent, opening an account for the child | No | As in case 2. |
Summarised from the illustration to Rule 10 of the DPDP Rules 2025.
In every case you enable the parent to identify herself through your website, app or another appropriate means. What the Rule does not do is tell you how to establish that the user is a child in the first place. That judgement is yours, and item 6 of Part B of the Fourth Schedule lets you process personal data to the extent necessary to confirm that a user is not a child.
What about persons with disability under Rule 11?
Section 9(1) also covers a person with disability who has a lawful guardian. Under Rule 11, before relying on consent from someone who says she is that guardian, the Data Fiduciary must verify that the guardian was appointed by a court, a designated authority or a local level committee under the applicable guardianship law.
The applicable law depends on the person. For long-term impairments that prevent legally binding decisions despite support, it is the Rights of Persons with Disabilities Act, 2016, where the designated authority sits under section 15. For autism, cerebral palsy, intellectual disability or multiple disabilities, it is the National Trust Act, 1999, whose local level committees appoint guardians under section 13. The practical change is a guardianship document check in your consent flow, and a record that you made it.
Which organisations are exempt from parental consent?
Rule 12 and the Fourth Schedule exempt five classes of Data Fiduciary and six purposes from section 9(1) and 9(3), each only on a stated condition. Healthcare providers, educational institutions, crèches and school transport operators are covered for defined health and safety processing. None is exempt from the prohibition on harmful processing in 9(2).
Part A: classes of Data Fiduciary
| # | Who | Exempt only where processing is restricted to |
|---|---|---|
| 1 | A clinical establishment, mental health establishment or healthcare professional | Providing health services to the child, to the extent necessary to protect her health. |
| 2 | An allied healthcare professional | Supporting a healthcare treatment and referral plan recommended by such a professional for the child, to the extent necessary to protect her health. |
| 3 | An educational institution | Tracking and behavioural monitoring for its educational activities, or in the interests of the safety of children enrolled with it. |
| 4 | An individual to whom infants and children in a crèche or child day care centre are entrusted | Tracking and behavioural monitoring in the interests of the safety of those children. |
| 5 | Someone engaged by an educational institution, crèche or child care centre to transport its children | Tracking the children's location, for their safety, while travelling to and from it. |
Part B: purposes
| # | Purpose | Condition |
|---|---|---|
| 1 | Exercising a power, function or duty in the interests of a child under any law in India | Only to the extent necessary. |
| 2 | Providing a subsidy, benefit, service, certificate, licence or permit in the child's interests under section 7(b) | Only to the extent necessary. |
| 3 | Creating a user account for communicating by email | Only to the extent necessary to create an account whose use is limited to email. |
| 4 | Determining a child's real-time location | Only tracking real-time location, for her safety, protection or security. |
| 5 | Making sure information, services or advertisements likely to harm a child are not accessible to her | Only to the extent necessary to keep them away from the child. |
| 6 | Confirming that a Data Principal is not a child, and doing the Rule 10 due diligence | Only to the extent necessary for that confirmation. |
From the Fourth Schedule to the DPDP Rules 2025. Terms such as clinical establishment and allied healthcare professional take their meaning from the statutes the Schedule's note cites.
Read the conditions narrowly. The educational institution exemption covers the institution's own tracking for education or safety. It does not make an analytics vendor on a school's website exempt for its own purposes, and a consumer edtech app is not a school because children learn on it. The edtech compliance guide works through that line in more detail.
What must a website change for children's data under DPDP?
A website that children can use needs a way to identify likely minors, a parent verification flow that meets Rule 10, no advertising or behavioural tags firing for known children, and a record showing whose consent covered each child's account. It all has to work by 13 May 2027, when section 9 and Rules 10 to 12 commence.
1. Decide how you learn a user is a child. A declared date of birth, an account type, the context of the service. Write the method down, because the Board will ask how you knew, and item 6 of Part B only covers processing that is necessary for the check.
2. Build the parent step before the child's data is processed. Rule 10 puts verification before account creation, not after. Route the parent to identify herself, check her against details you already hold or a token from an authorised entity, and only then create the child's account.
3. Switch off tracking for children. Section 9(3) is a prohibition, not a consent question. For a user you know is a child, advertising pixels, retargeting tags and behavioural analytics should not load at all, whatever the banner says. Scan your site to see which trackers fire before any choice: those are the ones that will also fire for a child.
4. Record the chain. Which parent consented, how she was verified (not the document itself), which notice version and language she saw, and when. Consent by TryTrustable holds non-essential tags back until a choice is made and records every choice against the notice version and language that produced it; the parent verification step itself is yours to build or buy.
5. Keep the verification data small. A yes-or-no answer that the parent is an adult is usually enough. Storing copies of identity documents adds breach exposure under section 8(5) without adding anything Rule 10 asks for.
The ceiling for failing section 9 is ₹200 crore per instance, the same as for failing to notify a breach. The DPDP penalty calculator shows how it stacks with the other heads, and the DPDP consent notice template covers the notice the parent must see.
Related guides: cross-border data transfer, Significant Data Fiduciary duties, data retention and erasure, how the Data Protection Board works and the dated DPDP regulatory tracker. The DPDP Act and Rules 2025 guide sets out the whole timetable, and the DPDP penalty schedule what each failure can cost.
The things people ask us
What age is a child under the DPDP Act?
Anyone who has not completed eighteen years, under section 2(f). There is no lower threshold for teenagers of the kind the GDPR allows, so a seventeen-year-old is a child for every purpose of section 9. A Data Fiduciary needs verifiable parental consent before processing that person's data, unless a Fourth Schedule exemption applies.
Does the DPDP Act require age verification for every user?
No rule says every user must prove their age. Rule 10 requires verifiable consent of the parent before processing a child's data, and due diligence that the person consenting is an identifiable adult. How you find out that a user is a child is left to you, and Part B of the Fourth Schedule lets you process data to confirm someone is not a child.
Can a parent use DigiLocker to give consent under the DPDP Rules?
Yes, as one route. Rule 10 lets the parent's identity and age be checked against details or a virtual token issued by an authorised entity, and expressly includes details or tokens made available and verified by a Digital Locker service provider. The Rule names the mechanism; it does not require any particular product, and a parent already verified on your platform can rely on those details.
Can schools and edtech platforms track children under DPDP?
An educational institution may carry out tracking and behavioural monitoring for its educational activities or for the safety of enrolled children, under Part A of the Fourth Schedule, without parental consent under section 9(1). The exemption is for the institution. An edtech company selling directly to families is not an educational institution by that fact alone.
Is targeted advertising to children allowed under DPDP?
No. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children, and parental consent does not lift it. The Fourth Schedule carves out narrow cases, such as blocking harmful advertisements from reaching a child, but none of them permits targeting a child with advertising. The penalty ceiling is ₹200 crore.
When do the children's data rules apply?
Section 9 of the Act and Rules 10 to 12 come into force on 13 May 2027, eighteen months after the Rules were published. A proposal reported in January 2026 would bring some duties forward for the largest companies, but it had not been notified as of 28 September 2026.
Find the trackers that would fire for a child.
The free scan shows every cookie, pixel and tag that loads before anyone makes a choice. Under section 9(3), those are the ones you have to be able to switch off.