EdTech DPDP compliance
children's data, verifiable consent, no tracking.
Section 9 is the hardest provision in the DPDP Act, and edtech carries most of it. Parental consent that can be verified, an age line at eighteen, and a ban on tracking and targeted advertising that no consent can lift.
Which rules apply to edtech and children's services?
There is no edtech regulator for data. The DPDP Act and the DPDP Rules 2025 carry the weight: section 9 and Rule 10 on children, the Fourth Schedule exemptions, and the ordinary duties of notice, consent, security and erasure. Consumer protection law applies to how courses are sold.
| Rule | What it requires | Notes |
|---|---|---|
| DPDP s.2(f) | A child is anyone under eighteen | Higher than COPPA (13) and GDPR (13–16) |
| DPDP s.9(1) | Verifiable consent of a parent or lawful guardian before processing a child's data | Also applies to persons with disabilities who have a lawful guardian |
| DPDP s.9(2) | No processing likely to cause a detrimental effect on a child's well-being | A standard, not a consent question |
| DPDP s.9(3) | No tracking, behavioural monitoring or targeted advertising directed at children | A prohibition; consent does not lift it |
| Rule 10 | Measures to check that the consenting parent is an identifiable adult | Using details already held, or a virtual token or DigiLocker-type service |
| Fourth Schedule | Narrow exemptions from s.9(1) and s.9(3) | Educational institutions, healthcare, creches, child transport; specified purposes such as safety and age verification |
| Consumer Protection Act 2019 | Unfair trade practices in selling courses, including dark patterns | See the e-commerce page |
The obligation edtech gets wrong: parental consent does not unlock advertising
Edtech teams usually build a parental consent flow and assume it permits everything behind it. It does not. Section 9(3) bans tracking, behavioural monitoring and targeted advertising directed at children outright. If your product profiles under-18 users for ads, the fix is removing that processing for them, not a better checkbox.
In practice the prohibition reaches further than the ad server. A product analytics SDK that builds per-user behavioural profiles, a retargeting pixel on the course catalogue, and a recommendation engine trained on a child's viewing to push paid upgrades are all candidates. Aggregate, non-profiling analytics and pedagogical personalisation sit in a greyer zone: the Fourth Schedule lets an educational institution track and monitor behaviour for its educational activities or for safety, which suggests the line is drawn at purpose rather than technique.
The catch for most edtech companies is that exemption's scope. The Rules define an educational institution as an institution of learning that imparts education, including vocational education. A school clearly qualifies. A subscription app selling test preparation to families may or may not, and nobody has tested it yet. The prudent reading is that the exemption helps schools using your product, not your own marketing to their pupils.
How do you verify a parent's consent?
Rule 10 requires a Data Fiduciary to take appropriate technical and organisational measures to confirm that the person consenting for a child is an identifiable adult. It can rely on reliable identity and age details it already holds, or on details provided voluntarily or verified through a virtual token such as a DigiLocker-type service.
Two design consequences. First, you need to know which users are children before you can do any of this, and self-declared age is weak: a sign-up form that defaults to an adult birth year, or accepts any date without friction, invites the Board to conclude you chose not to know. Second, the parent's verification is itself personal data, processed for a specified purpose that the Fourth Schedule recognises, and should be kept only as long as that purpose needs.
Schools buying your product add a third party. Where the school is the Data Fiduciary and you process for it, the school's consent flow and exemptions govern, and your contract should say so. Where you also market directly to the same students, you are a Data Fiduciary in your own right for that relationship, with no exemption. The DPDP children's data guide goes deeper into both.
Proctoring, attention tracking and learning analytics
Online proctoring records a student's face, voice, screen and keystrokes, and some products score attention during live classes. For under-18 users this is behavioural monitoring in the plainest sense. It is lawful only where an exemption covers it, and the product must collect no more than the exam or lesson needs.
Where a school runs the exam through your product, its educational-activities exemption is the natural home for proctoring, and the school's contract with you should say so. Where you run the exam yourself for a paying family, rely on the exemption only if you are confident you are an educational institution, and otherwise treat the monitoring as needing a clear parental decision with a real alternative. In both cases the recordings are high-harm data: short retention, restricted review, and no reuse for training a model or marketing a course.
What the eighteen-year line means for a global product
A product built for the US treats thirteen-year-olds as adults under COPPA, and one built for Europe chooses an age between thirteen and sixteen. In India every user under eighteen is a child. A global edtech product therefore needs an India-specific age gate, consent flow and advertising configuration.
The configuration is usually the harder part. The same app build ships to every market, and the advertising and analytics SDKs inside it are configured by region or not at all. For Indian users under eighteen, those SDKs need to be off, or reduced to non-profiling modes, before the first screen loads. The two-pass scan shows what a web property does before and after consent; the same test is worth running on a child account in the app.
EdTech control checklist
The controls that separate a defensible children's product from one that relies on a checkbox.
| Control | Why | Evidence to hold |
|---|---|---|
| Age established at sign-up, with friction proportionate to risk | DPDP s.9 | Age-gate design and conversion data showing it works |
| Parental identity and age verified before processing a child's data | DPDP s.9(1); Rule 10 | Verification record per child account |
| No advertising, retargeting or profiling SDKs for under-18s | DPDP s.9(3) | SDK inventory by audience; scan of a child session |
| Written position on whether the Fourth Schedule exemption applies to you | Fourth Schedule | Legal note, reviewed annually |
| School contracts stating who is the Data Fiduciary for pupil data | DPDP s.8(1)–(2) | Contract clause per school customer |
| Separate consent for marketing to parents | DPDP s.6(1) | Consent record per purpose |
| Erasure when a child's account closes or goes inactive | DPDP s.8(7) | Deletion logs |
Where to go next
The children's data guide covers section 9 in full, and the penalties guide explains the ₹200 crore cap. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.
The things people ask us
What age counts as a child under the DPDP Act?
Under eighteen. Section 2(f) defines a child as an individual who has not completed eighteen years. That is higher than COPPA's thirteen and higher than any age a GDPR member state may set, so a product built to a US or EU children's standard will treat many Indian users as adults when the Act treats them as children.
Can a parent consent to targeted advertising to their child?
No. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children outright. It is not a consent question, so no parental consent makes it lawful. The only relief is the narrow set of exemptions in the Fourth Schedule to the DPDP Rules, which do not cover advertising.
Is an edtech company an educational institution under the DPDP Rules?
Possibly not. The Fourth Schedule exempts an educational institution's tracking and behavioural monitoring for educational activities or safety, and defines the term as an institution of learning that imparts education, including vocational education. Whether an app qualifies has not been tested. Plan on the basis that you do not.
How do you verify parental consent under the DPDP Rules?
Rule 10 requires the Data Fiduciary to take appropriate technical and organisational measures to confirm that the person consenting is an identifiable adult, using reliable identity and age details it already holds or that are provided or verified through a virtual token or a DigiLocker-type service. A tick box stating "I am a parent" is unlikely to be enough.
What is the penalty for breaching the children's data rules?
Up to ₹200 crore for failing to meet the additional obligations in relation to children under section 9, under the Schedule to the DPDP Act. It is the second-highest cap in the Act, below only failure to take reasonable security safeguards. The Board sets the actual amount by gravity, duration and mitigation.
Find the trackers that fire on a child's session.
Scan the pages your students land on, then see how the platform records parental consent per purpose and keeps the notice version each family saw.