DPDP children's data

DPDP children's data rules
and verifiable parental consent.

What section 9 of the DPDP Act and Rules 10 to 12 require before you process data about anyone under eighteen, how parental consent is verified, who the Fourth Schedule exempts, and what a website has to change by 13 May 2027.

Section 9Rule 10Rule 11Rule 12Fourth Schedule

Last updated Published by TryTrustableNot legal advice

01

What does the DPDP Act say about children's data?

The DPDP Act treats everyone under eighteen as a child. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. It must not process data in a way likely to harm the child's well-being, and it must not track, behaviourally monitor or target advertising at children.

The definition is in section 2(f) of the Act: a child is an individual who has not completed the age of eighteen years. Section 9 then sets five rules:

ProvisionWhat it saysCan it be disapplied?
9(1)Verifiable consent of the parent (or lawful guardian) before processing any personal data of a child, in the manner the Rules prescribe.Yes, for the classes and purposes in the Fourth Schedule (Rule 12).
9(2)No processing that is likely to cause any detrimental effect on the well-being of a child.No. Nothing in the Act or Rules exempts anyone from 9(2).
9(3)No tracking or behavioural monitoring of children, and no targeted advertising directed at children.Yes, only for the Fourth Schedule classes and purposes, on their conditions.
9(4)The Rules may exempt classes of Data Fiduciaries or purposes from 9(1) and 9(3).This is the power Rule 12 uses.
9(5)The Government may notify an age above which a Data Fiduciary whose processing is verifiably safe is exempt from 9(1) and 9(3).We have found no such notification as of 28 September 2026.

From section 9 of the Digital Personal Data Protection Act, 2023, paraphrased. Read the text before relying on the wording.

Two consequences are easy to miss. First, parental consent does not cure 9(3): a parent cannot consent to their child being targeted with advertising. Second, nothing exempts anyone from 9(2), so even an exempt hospital or school must not process a child's data in a way likely to harm them.

03

What about persons with disability under Rule 11?

Section 9(1) also covers a person with disability who has a lawful guardian. Under Rule 11, before relying on consent from someone who says she is that guardian, the Data Fiduciary must verify that the guardian was appointed by a court, a designated authority or a local level committee under the applicable guardianship law.

The applicable law depends on the person. For long-term impairments that prevent legally binding decisions despite support, it is the Rights of Persons with Disabilities Act, 2016, where the designated authority sits under section 15. For autism, cerebral palsy, intellectual disability or multiple disabilities, it is the National Trust Act, 1999, whose local level committees appoint guardians under section 13. The practical change is a guardianship document check in your consent flow, and a record that you made it.

05

What must a website change for children's data under DPDP?

A website that children can use needs a way to identify likely minors, a parent verification flow that meets Rule 10, no advertising or behavioural tags firing for known children, and a record showing whose consent covered each child's account. It all has to work by 13 May 2027, when section 9 and Rules 10 to 12 commence.

1. Decide how you learn a user is a child. A declared date of birth, an account type, the context of the service. Write the method down, because the Board will ask how you knew, and item 6 of Part B only covers processing that is necessary for the check.

2. Build the parent step before the child's data is processed. Rule 10 puts verification before account creation, not after. Route the parent to identify herself, check her against details you already hold or a token from an authorised entity, and only then create the child's account.

3. Switch off tracking for children. Section 9(3) is a prohibition, not a consent question. For a user you know is a child, advertising pixels, retargeting tags and behavioural analytics should not load at all, whatever the banner says. Scan your site to see which trackers fire before any choice: those are the ones that will also fire for a child.

4. Record the chain. Which parent consented, how she was verified (not the document itself), which notice version and language she saw, and when. Consent by TryTrustable holds non-essential tags back until a choice is made and records every choice against the notice version and language that produced it; the parent verification step itself is yours to build or buy.

5. Keep the verification data small. A yes-or-no answer that the parent is an adult is usually enough. Storing copies of identity documents adds breach exposure under section 8(5) without adding anything Rule 10 asks for.

The ceiling for failing section 9 is ₹200 crore per instance, the same as for failing to notify a breach. The DPDP penalty calculator shows how it stacks with the other heads, and the DPDP consent notice template covers the notice the parent must see.

Related guides: cross-border data transfer, Significant Data Fiduciary duties, data retention and erasure, how the Data Protection Board works and the dated DPDP regulatory tracker. The DPDP Act and Rules 2025 guide sets out the whole timetable, and the DPDP penalty schedule what each failure can cost.

Questions

The things people ask us

What age is a child under the DPDP Act?

Anyone who has not completed eighteen years, under section 2(f). There is no lower threshold for teenagers of the kind the GDPR allows, so a seventeen-year-old is a child for every purpose of section 9. A Data Fiduciary needs verifiable parental consent before processing that person's data, unless a Fourth Schedule exemption applies.

Does the DPDP Act require age verification for every user?

No rule says every user must prove their age. Rule 10 requires verifiable consent of the parent before processing a child's data, and due diligence that the person consenting is an identifiable adult. How you find out that a user is a child is left to you, and Part B of the Fourth Schedule lets you process data to confirm someone is not a child.

Can a parent use DigiLocker to give consent under the DPDP Rules?

Yes, as one route. Rule 10 lets the parent's identity and age be checked against details or a virtual token issued by an authorised entity, and expressly includes details or tokens made available and verified by a Digital Locker service provider. The Rule names the mechanism; it does not require any particular product, and a parent already verified on your platform can rely on those details.

Can schools and edtech platforms track children under DPDP?

An educational institution may carry out tracking and behavioural monitoring for its educational activities or for the safety of enrolled children, under Part A of the Fourth Schedule, without parental consent under section 9(1). The exemption is for the institution. An edtech company selling directly to families is not an educational institution by that fact alone.

Is targeted advertising to children allowed under DPDP?

No. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children, and parental consent does not lift it. The Fourth Schedule carves out narrow cases, such as blocking harmful advertisements from reaching a child, but none of them permits targeting a child with advertising. The penalty ceiling is ₹200 crore.

When do the children's data rules apply?

Section 9 of the Act and Rules 10 to 12 come into force on 13 May 2027, eighteen months after the Rules were published. A proposal reported in January 2026 would bring some duties forward for the largest companies, but it had not been notified as of 28 September 2026.

Children's data

Find the trackers that would fire for a child.

The free scan shows every cookie, pixel and tag that loads before anyone makes a choice. Under section 9(3), those are the ones you have to be able to switch off.