---
title: "DPDP Act and Children's Data: Verifiable Parental Consent"
description: "DPDP Act Section 9 treats anyone under 18 as a child. Verifiable parental consent, the tracking and targeted-ad ban, Rule 10 verification and a checklist."
url: "https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/"
image: "https://advaslam.com/og/writing/dpdp-children-data-parental-consent-guide.png"
---

[Data protection & DPDP compliance](https://advaslam.com/practice/data-protection/)

# DPDP Act and Children's Data in India: Verifiable Parental Consent, Tracking Bans and What EdTech Must Change

By [**Adv. K J Muhammed Aslam**](https://advaslam.com/profile/) · Advocate, Ernakulam (Bar Council of Kerala)

Published 1 September 2026

Under the [Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508), a child is anyone who has not completed 18 years of age — [Section 2(f)](https://indiacode.gov.in/handle/123456789/496508) — and before processing a child’s personal data a business must obtain **verifiable consent of a parent or lawful guardian** under [Section 9(1)](https://indiacode.gov.in/handle/123456789/496508), while [Section 9(2)](https://indiacode.gov.in/handle/123456789/496508) and [Section 9(3)](https://indiacode.gov.in/handle/123456789/496508) prohibit — with only narrow, notified exceptions — processing likely to cause detrimental effect on a child’s well-being, tracking, behavioural monitoring and targeted advertising directed at children. Breach of these duties carries a penalty of up to **two hundred crore rupees**.

## Why is children’s data the highest-risk DPDP obligation for most Kerala businesses?

Because the age threshold catches far more users than teams expect, and the prohibitions go to product design, not just paperwork. A business that thinks of its users as young adults — a learning app, a gaming platform, a social community, a health or counselling service — often discovers that a large share of its registered base is under 18. Under Section 9, every one of those users must be handled through parental consent, and every tracking and ad-targeting decision must be re-examined.

Kerala is not an edge case here. KSUM-backed edtech, healthtech and gaming startups in Kochi and Thiruvananthapuram, tuition centres and schools that run apps and CRMs, and consumer apps with nationwide reach all process children’s data. The startup exemption power in Section 17(3) does not extend to Section 9 at all; the relaxations are the classes and purposes prescribed under Section 9(4), set out in the Fourth Schedule to the Rules, and any age-based exemption the Central Government notifies under Section 9(5) for a fiduciary whose processing of children’s data is verifiably safe. The obligation applies in full from **14 May 2027** — the date the 18-month tranche of the [DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (G.S.R. 846(E), 13 November 2025) commences, together with the [Section 33 penalty regime](https://indiacode.gov.in/handle/123456789/496508). The Board’s powers and inquiry procedure are set by the Act itself (Sections 27 and 28) — content that treats May 2027 as distant is underestimating the engineering time an age-gating and consent redesign actually takes.

## What does verifiable parental consent mean under Rule 10?

Section 9(1) states the principle. Rule 10 of the DPDP Rules, 2025 supplies the method, and its design is deliberately more demanding than a checkbox:

-   **What must be verified:** that the person giving consent for the child’s data is actually the parent or lawful guardian, and that the child is indeed a child. The fiduciary must be able to demonstrate this verification if the Board asks.
-   **How verification is done:** by relying on identity and age details the fiduciary already holds about the parent or guardian, or on details voluntarily provided and then verified — Rule 10 contemplates checking through means such as **Digital Locker** (under the IT Act framework) or a **virtual token issued by an authorised entity**. The token approach is designed so the fiduciary does not need to collect and store a parent’s full identity document where a tokenised confirmation suffices.
-   **Parallel for persons with disabilities:** Rule 11 applies a similar verifiable-consent scheme where the Data Principal has a lawful guardian under the Rights of Persons with Disabilities Act framework.

What does not satisfy the rule: a self-declared I am 18 checkbox, a pre-ticked parental consent box, or an email link that anyone with access to the child’s email can click. The word verifiable in Section 9(1) was chosen to exclude exactly those patterns.

## What is banned outright — and what falls in the narrow exemptions?

Two prohibitions in Section 9 apply in addition to the parental-consent requirement, and they apply even where parental consent for general processing has been obtained:

-   **Section 9(2)** — no processing of personal data of a child that is likely to cause any **detrimental effect on the well-being** of the child. Detriment is not defined exhaustively in the Act and will be shaped by the Board and by sectoral guidance, but the plain meaning covers physical, mental and social well-being.
-   **Section 9(3)** — no **tracking or behavioural monitoring** of children, and no **targeted advertising directed at children**. This is an absolute bar on the product patterns most consumer apps monetise: profiling for ad targeting, recommendation engines that track a child’s behaviour across sessions, and personalised ad delivery to children.

The **Fourth Schedule**, read with **Rule 12**, then carves out a small set of exempted classes of fiduciaries and purposes — Part A covers clinical establishments, mental health establishments and healthcare professionals (health services only), allied healthcare professionals, educational institutions (tracking/behavioural monitoring for educational activities or child safety only), crèche or child day-care carers, and transport engaged by such institutions; Part B covers purposes such as legal duties in the interests of the child, subsidies/benefits under Section 7(b), email-account creation, real-time location for safety, filtering detrimental content from children, and age-confirmation/Rule 10 due diligence — each purpose-bound and class-bound. The key point for most businesses: the exemption is purpose-bound and class-bound. An edtech that processes a child’s data to deliver a lesson may fall within the educational purpose in its teaching function, but that does not exempt the same company’s ad network from the Section 9(3) ban on targeted advertising to children on the same app. Each processing purpose must be tested separately.

## What must a Kerala school, college, edtech or consumer app actually build?

The practical work is product and data-architecture work, not just a policy update. A realistic implementation sequence for a team starting in late 2026:

1.  **Map where children are.** Identify every flow where an individual under 18 can be a Data Principal — registration, marketing lists, analytics, support tickets, payment flows. If age is not collected today, that is itself the gap — you cannot route children through parental consent if you do not know who they are.
2.  **Design age-gating.** Build a verification step at registration or at the point data is first collected that determines age in a verifiable way. For mixed-age apps, this means a neutral age gate before any personal data beyond the gate itself is processed, with under-18 users diverted to the parental-consent flow rather than the standard onboarding.
3.  **Build the parental-consent flow under Rule 10.** Implement the verification against identity details already held or against voluntarily provided details checked via Digital Locker or an authorised virtual token. Log the consent with the particulars Section 6(10) requires the fiduciary to be able to prove — who consented, when, on what notice, for what purposes.
4.  **Strip tracking and targeted ads for children.** Audit every SDK, analytics event and ad call that fires for a child user. Disable behavioural monitoring and targeted advertising for children entirely unless the specific processing falls within a Fourth Schedule / Rule 12 exemption and has been documented as such with legal review.
5.  **Rewrite the notice for parents.** The [Section 5 notice](https://indiacode.gov.in/handle/123456789/496508) — itemised, in clear language, available in English and the Eighth Schedule languages the parent chooses, including Malayalam — must precede the consent request. A privacy policy link does not satisfy Section 5.
6.  **Set retention and erasure.** Section 8(7) requires erasure once consent is withdrawn or the specified purpose is no longer served, unless retention is required by law. For large e-commerce, gaming and social media intermediaries with thresholds in the Third Schedule, Rule 8 adds a three-year inactivity clock. Build the deletion job, not just the written retention schedule.
7.  **Train support.** A parent who writes in to withdraw consent under Section 6(4) — withdrawing must be as easy as giving it — must have that withdrawal honoured and logged, and a child who contacts support must not be social-engineered around the gate.

## How does this interact with other laws schools and apps already follow?

DPDP Section 9 sits on top of, not instead of, existing duties:

-   **IT Act and intermediary duties.** A platform that hosts user-generated content is also subject to the [IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021](https://indiacode.gov.in/handle/123456789/510236) as amended on 10 February 2026, which accelerates takedown for CSAM and non-consensual intimate imagery involving children to two hours on a complaint under Rule 3(2)(b) (previously twenty-four hours). DPDP verifiable consent and IT Act takedown are cumulative.
-   **Education-specific regulation.** School and college data handling is also shaped by affiliation-board and state guidelines, but none of those displaces the DPDP requirement — a CBSE or Kerala state-board affiliation does not exempt an institution from being a Data Fiduciary for the digital personal data it processes.
-   **BSA evidence.** Consent logs that prove verifiable parental consent was obtained will, if disputed, be electronic records that need a [Section 63 BSA certificate](https://indiacode.gov.in/handle/123456789/496549) (new 65B) to be admissible. Design the log with hash and dual-signature certification in mind from the start — see the [electronic evidence guide](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/).

## Primary sources

-   [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(f), 5, 6, 8, 9, 10, 33 and the Schedule)
-   [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rules 3, 6, 7, 8, 10, 11, 12, 14, First, Third and Fourth Schedules)
-   [PIB backgrounder and press release on notification of the DPDP Rules (14 and 17 November 2025)](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)
-   [IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), 10 February 2026) — Gazette of India](https://egazette.gov.in/WriteReadData/2026/269993.pdf) (Rules 3(1)(d), 3(2) — two-hour takedown for CSAM and non-consensual imagery)
-   [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) (Section 63 on electronic evidence certificates)

FAQ

## Common questions

**Who is a child under the DPDP Act, 2023?**

Anyone under 18 years of age. Section 2(f) of the DPDP Act, 2023 defines a child as an individual who has not completed 18 years. This is stricter than the GDPR, where a child can be 13 to 16 depending on the member state, and the US COPPA, where a child is under 13. Indian businesses must apply the 18-year threshold for all DPDP purposes.

**What is verifiable parental consent under the DPDP Act?**

Section 9(1) requires a Data Fiduciary to obtain verifiable consent of the parent or lawful guardian before processing any personal data of a child. Rule 10 of the DPDP Rules, 2025 prescribes the verification manner: the fiduciary must rely on identity and age details it already holds, or on details voluntarily provided and checked through means such as Digital Locker or a virtual token issued by an authorised entity, so that the person giving consent is actually the parent or guardian.

**Can a business track children or show them targeted ads under the DPDP Act?**

No, except within narrow, notified exemptions. Section 9(2) prohibits processing likely to cause detrimental effect on the well-being of a child. Section 9(3) prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. The Fourth Schedule, read with Rule 12, exempts only limited classes and purposes such as healthcare, education, childcare and real-time safety — not general commercial targeting.

**What is the penalty for violating children's data obligations?**

Up to two hundred crore rupees per breach under the Schedule to the DPDP Act, read with Section 33, imposed by the Data Protection Board after inquiry and hearing weighing factors under Section 33(2). This is one of the highest penalty bands in the Act, alongside the penalty for failing to maintain reasonable security safeguards.

**Does an edtech app need parental consent if the user says they are 18?**

The Act requires the fiduciary to actually verify, not merely ask. Relying on a self-declared checkbox that the user is 18, without a verifiable parental-consent step where the user is in fact a child, does not satisfy Section 9(1) read with Rule 10. The business needs an age-gating design that checks age in a verifiable way and routes under-18 users through parental consent before any processing.

**A note on this article.** It is general legal information, not legal advice. The law may have changed since the date shown; before acting on anything here, take advice on your specific situation from an advocate of your choice.

Keep reading

Data protection & DPDP compliance

### DPDP Compliance Guide for Kerala Businesses to May 2027

DPDP readiness for Kerala SMEs: phased timeline to May 2027, notices, safeguards, breach response, rights, children, SDF, transfer, contracts, penalties.

25 Sept 2026

[DPDP Compliance Guide for Kerala Businesses to May 2027](https://advaslam.com/writing/dpdp-compliance-guide-kerala-businesses/)

Data protection & DPDP compliance

### Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act

Company leaked your Aadhaar, phone or health data? DPDP Sections 11-14 rights, Board complaint, IT Act 43A compensation, consumer and civil remedies.

6 Sept 2026

[Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act](https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"BlogPosting","@id":"https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/#article","isPartOf":{"@id":"https://advaslam.com/#website"},"headline":"DPDP Act and Children's Data in India: Verifiable Parental Consent, Tracking Bans and What EdTech Must Change","description":"DPDP Act Section 9 treats anyone under 18 as a child. Verifiable parental consent, the tracking and targeted-ad ban, Rule 10 verification and a checklist.","url":"https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/","mainEntityOfPage":"https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/","datePublished":"2026-09-01T00:00:00.000Z","dateModified":"2026-09-01T00:00:00.000Z","keywords":"DPDP Act children data, verifiable parental consent India, DPDP Section 9 child, tracking children banned DPDP, edtech DPDP compliance children, Rule 10 DPDP parental consent","inLanguage":"en-IN","author":{"@id":"https://advaslam.com/#person"},"publisher":{"@id":"https://advaslam.com/#person"},"image":"https://advaslam.com/og/writing/dpdp-children-data-parental-consent-guide.png","about":{"@type":"Service","@id":"https://advaslam.com/practice/data-protection/#service","name":"Data protection & DPDP compliance","url":"https://advaslam.com/practice/data-protection/","provider":{"@id":"https://advaslam.com/#practice"}}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Articles","item":"https://advaslam.com/writing/"},{"@type":"ListItem","position":3,"name":"DPDP Act and Children's Data in India: Verifiable Parental Consent, Tracking Bans and What EdTech Must Change","item":"https://advaslam.com/writing/dpdp-children-data-parental-consent-guide/"}]},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"Who is a child under the DPDP Act, 2023?","acceptedAnswer":{"@type":"Answer","text":"Anyone under 18 years of age. Section 2(f) of the DPDP Act, 2023 defines a child as an individual who has not completed 18 years. This is stricter than the GDPR, where a child can be 13 to 16 depending on the member state, and the US COPPA, where a child is under 13. Indian businesses must apply the 18-year threshold for all DPDP purposes."}},{"@type":"Question","name":"What is verifiable parental consent under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"Section 9(1) requires a Data Fiduciary to obtain verifiable consent of the parent or lawful guardian before processing any personal data of a child. Rule 10 of the DPDP Rules, 2025 prescribes the verification manner: the fiduciary must rely on identity and age details it already holds, or on details voluntarily provided and checked through means such as Digital Locker or a virtual token issued by an authorised entity, so that the person giving consent is actually the parent or guardian."}},{"@type":"Question","name":"Can a business track children or show them targeted ads under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"No, except within narrow, notified exemptions. Section 9(2) prohibits processing likely to cause detrimental effect on the well-being of a child. Section 9(3) prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. The Fourth Schedule, read with Rule 12, exempts only limited classes and purposes such as healthcare, education, childcare and real-time safety — not general commercial targeting."}},{"@type":"Question","name":"What is the penalty for violating children's data obligations?","acceptedAnswer":{"@type":"Answer","text":"Up to two hundred crore rupees per breach under the Schedule to the DPDP Act, read with Section 33, imposed by the Data Protection Board after inquiry and hearing weighing factors under Section 33(2). This is one of the highest penalty bands in the Act, alongside the penalty for failing to maintain reasonable security safeguards."}},{"@type":"Question","name":"Does an edtech app need parental consent if the user says they are 18?","acceptedAnswer":{"@type":"Answer","text":"The Act requires the fiduciary to actually verify, not merely ask. Relying on a self-declared checkbox that the user is 18, without a verifiable parental-consent step where the user is in fact a child, does not satisfy Section 9(1) read with Rule 10. The business needs an age-gating design that checks age in a verifiable way and routes under-18 users through parental consent before any processing."}}]}]}
```
