Infosek
INFOSEK

Children's Data Under DPDP and Verifiable Parental Consent

This is the strictest part of the framework and it carries a two hundred crore rupee penalty head. It also applies to any product a child can reach, not only products built for children.

Children's Data Under DPDP and Verifiable Parental Consent

Three separate obligations

Section 9 imposes duties that do not depend on each other:

How Rule 10 says to verify

Rule 10(1) requires appropriate technical and organisational measures to ensure verifiable parental consent, and due diligence to check that the person identifying as the parent is an adult, identifiable if required under any law in force in India, by reference to either:

An authorised entity means one entrusted by law or by the Central or a State Government with issuing such details or tokens, or a person it appoints or permits, and expressly includes details made available and verified by a Digital Locker Service Provider.

The trap in general-audience products

Section 9 does not apply only to products for children. It applies to the processing of a child's personal data. A general consumer app with no age gate is processing children's data the moment a fifteen-year-old signs up, whatever the terms of service claim.

Since section 9(3) then bars behavioural monitoring and targeted advertising for those users, an analytics and ads stack applied uniformly across the user base is already non-compliant for that segment.

“Our terms say you must be eighteen” is not an age assurance measure. It is a disclaimer, and the Rules ask for measures.

Infosek Team

Exemptions exist but are conditional

Section 9(4) allows sub-sections (1) and (3) to be disapplied for prescribed classes of Data Fiduciaries or purposes, subject to conditions, and Rule 12 gives effect to this by reference to Part A and Part B of the Fourth Schedule. Section 9(5) separately allows the Central Government to notify a lower age threshold for a Data Fiduciary that has ensured its processing of children's data is verifiably safe.

Both are conditional routes, not general relief. Confirm your class or purpose is actually covered before relying on either.

What to build

Common questions

What is verifiable parental consent under DPDP?

Under Rule 10, a Data Fiduciary must adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before processing a child's personal data, and must observe due diligence to check that the individual identifying herself as the parent is an adult who is identifiable if required under law, by reference to reliable identity and age details already held, or details voluntarily provided, including through a virtual token issued by an authorised entity such as a Digital Locker Service Provider.

Can you show targeted advertising to children under the DPDP Act?

No. Section 9(3) prohibits a Data Fiduciary from undertaking tracking or behavioural monitoring of children, or targeted advertising directed at children.

Product reachable by under-18s?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment