Key takeaways
- A "child" is an individual under 18; processing their data generally requires verifiable consent from a parent or lawful guardian.
- Tracking, behavioral monitoring and targeted advertising directed at children are prohibited.
- Certain service categories — healthcare, education, child transport — have exemptions reflecting the nature of the service.
- Violations can attract penalties up to ₹200 crore, the same tier as breach-notification failure.
Why children's data gets its own regime
Section 9 of the DPDP Act recognizes that children need additional safeguards. Where consent is the foundation of the regime, the consent of a child cannot be presumed valid — the Act requires verifiable parental consent, and it bans the practices most likely to exploit minors: tracking, behavioral monitoring and targeted advertising.
The core requirements
Verifiable parental consent
Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian. The DPDP Rules, 2025 require mechanisms to verify the identity and age of the parent or guardian — not just a checkbox, but verification appropriate to the risk of the processing.
Prohibited practices
Fiduciaries may not process children's data for tracking, behavioral monitoring or targeted advertising directed at children. These prohibitions are absolute within their scope — they are not framed as "opt-in" activities.
Exemptions
The Rules exempt certain categories from parts of the parental-consent requirement because the service itself implies guardian involvement or necessity: healthcare professionals, educational institutions, child-transport providers and similar categories notified by the Government. Exemptions are category-specific and do not remove the underlying safeguards for security and purpose limitation.
Designing age-aware products
- Age gating with purpose: determine where genuine age verification is needed versus lightweight assertions, and match the mechanism to the risk.
- Parental verification flow: design identity and age verification for the parent or guardian that is reliable without collecting more data than necessary.
- No tracking by default: exclude minors from analytics that could amount to behavioral monitoring and from ad-targeting systems.
- Consent records: version, timestamp and store parental consent evidence so it can be produced if the Board or an auditor asks.
The ₹200 crore stake
Violations of children's-data obligations sit at the top of the Schedule with breach-notification failure: up to ₹200 crore. For edtech, gaming, social, health or entertainment products that reach users under 18 — or cannot prove they do not — this is a board-level risk, not a product footnote.
Build age-aware compliance by design
KryptoMindz designs verifiable parental consent flows, age verification and minor-data safeguards for products serving children and families.
Discuss Your Children's Data Controls