By sector · EdTech

EdTech DPDP compliance
children's data, verifiable consent, no tracking.

Section 9 is the hardest provision in the DPDP Act, and edtech carries most of it. Parental consent that can be verified, an age line at eighteen, and a ban on tracking and targeted advertising that no consent can lift.

DPDP s.9Rule 10Fourth Schedule₹200 crore cap
01

Which rules apply to edtech and children's services?

There is no edtech regulator for data. The DPDP Act and the DPDP Rules 2025 carry the weight: section 9 and Rule 10 on children, the Fourth Schedule exemptions, and the ordinary duties of notice, consent, security and erasure. Consumer protection law applies to how courses are sold.

RuleWhat it requiresNotes
DPDP s.2(f)A child is anyone under eighteenHigher than COPPA (13) and GDPR (13–16)
DPDP s.9(1)Verifiable consent of a parent or lawful guardian before processing a child's dataAlso applies to persons with disabilities who have a lawful guardian
DPDP s.9(2)No processing likely to cause a detrimental effect on a child's well-beingA standard, not a consent question
DPDP s.9(3)No tracking, behavioural monitoring or targeted advertising directed at childrenA prohibition; consent does not lift it
Rule 10Measures to check that the consenting parent is an identifiable adultUsing details already held, or a virtual token or DigiLocker-type service
Fourth ScheduleNarrow exemptions from s.9(1) and s.9(3)Educational institutions, healthcare, creches, child transport; specified purposes such as safety and age verification
Consumer Protection Act 2019Unfair trade practices in selling courses, including dark patternsSee the e-commerce page
04

Proctoring, attention tracking and learning analytics

Online proctoring records a student's face, voice, screen and keystrokes, and some products score attention during live classes. For under-18 users this is behavioural monitoring in the plainest sense. It is lawful only where an exemption covers it, and the product must collect no more than the exam or lesson needs.

Where a school runs the exam through your product, its educational-activities exemption is the natural home for proctoring, and the school's contract with you should say so. Where you run the exam yourself for a paying family, rely on the exemption only if you are confident you are an educational institution, and otherwise treat the monitoring as needing a clear parental decision with a real alternative. In both cases the recordings are high-harm data: short retention, restricted review, and no reuse for training a model or marketing a course.

05

What the eighteen-year line means for a global product

A product built for the US treats thirteen-year-olds as adults under COPPA, and one built for Europe chooses an age between thirteen and sixteen. In India every user under eighteen is a child. A global edtech product therefore needs an India-specific age gate, consent flow and advertising configuration.

The configuration is usually the harder part. The same app build ships to every market, and the advertising and analytics SDKs inside it are configured by region or not at all. For Indian users under eighteen, those SDKs need to be off, or reduced to non-profiling modes, before the first screen loads. The two-pass scan shows what a web property does before and after consent; the same test is worth running on a child account in the app.

06

EdTech control checklist

The controls that separate a defensible children's product from one that relies on a checkbox.

ControlWhyEvidence to hold
Age established at sign-up, with friction proportionate to riskDPDP s.9Age-gate design and conversion data showing it works
Parental identity and age verified before processing a child's dataDPDP s.9(1); Rule 10Verification record per child account
No advertising, retargeting or profiling SDKs for under-18sDPDP s.9(3)SDK inventory by audience; scan of a child session
Written position on whether the Fourth Schedule exemption applies to youFourth ScheduleLegal note, reviewed annually
School contracts stating who is the Data Fiduciary for pupil dataDPDP s.8(1)–(2)Contract clause per school customer
Separate consent for marketing to parentsDPDP s.6(1)Consent record per purpose
Erasure when a child's account closes or goes inactiveDPDP s.8(7)Deletion logs
07

Where to go next

The children's data guide covers section 9 in full, and the penalties guide explains the ₹200 crore cap. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.

Questions

The things people ask us

What age counts as a child under the DPDP Act?

Under eighteen. Section 2(f) defines a child as an individual who has not completed eighteen years. That is higher than COPPA's thirteen and higher than any age a GDPR member state may set, so a product built to a US or EU children's standard will treat many Indian users as adults when the Act treats them as children.

Can a parent consent to targeted advertising to their child?

No. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children outright. It is not a consent question, so no parental consent makes it lawful. The only relief is the narrow set of exemptions in the Fourth Schedule to the DPDP Rules, which do not cover advertising.

Is an edtech company an educational institution under the DPDP Rules?

Possibly not. The Fourth Schedule exempts an educational institution's tracking and behavioural monitoring for educational activities or safety, and defines the term as an institution of learning that imparts education, including vocational education. Whether an app qualifies has not been tested. Plan on the basis that you do not.

How do you verify parental consent under the DPDP Rules?

Rule 10 requires the Data Fiduciary to take appropriate technical and organisational measures to confirm that the person consenting is an identifiable adult, using reliable identity and age details it already holds or that are provided or verified through a virtual token or a DigiLocker-type service. A tick box stating "I am a parent" is unlikely to be enough.

What is the penalty for breaching the children's data rules?

Up to ₹200 crore for failing to meet the additional obligations in relation to children under section 9, under the Schedule to the DPDP Act. It is the second-highest cap in the Act, below only failure to take reasonable security safeguards. The Board sets the actual amount by gravity, duration and mitigation.

Children's data

Find the trackers that fire on a child's session.

Scan the pages your students land on, then see how the platform records parental consent per purpose and keeps the notice version each family saw.