KryptoMindz Technologies

KryptoMindz Insight · DPDP Act

DPDP Act Children's Data and Verifiable Parental Consent

Processing a child's data under the DPDP Act requires verifiable parental consent — with prohibitions on tracking, behavioral monitoring and targeted advertising for minors, and a ₹200 crore penalty tier behind it.

By 11 min read Reviewed August 7, 2026

Key takeaways

  • A "child" is an individual under 18; processing their data generally requires verifiable consent from a parent or lawful guardian.
  • Tracking, behavioral monitoring and targeted advertising directed at children are prohibited.
  • Certain service categories — healthcare, education, child transport — have exemptions reflecting the nature of the service.
  • Violations can attract penalties up to ₹200 crore, the same tier as breach-notification failure.

Why children's data gets its own regime

Section 9 of the DPDP Act recognizes that children need additional safeguards. Where consent is the foundation of the regime, the consent of a child cannot be presumed valid — the Act requires verifiable parental consent, and it bans the practices most likely to exploit minors: tracking, behavioral monitoring and targeted advertising.

The core requirements

Verifiable parental consent

Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian. The DPDP Rules, 2025 require mechanisms to verify the identity and age of the parent or guardian — not just a checkbox, but verification appropriate to the risk of the processing.

Prohibited practices

Fiduciaries may not process children's data for tracking, behavioral monitoring or targeted advertising directed at children. These prohibitions are absolute within their scope — they are not framed as "opt-in" activities.

Exemptions

The Rules exempt certain categories from parts of the parental-consent requirement because the service itself implies guardian involvement or necessity: healthcare professionals, educational institutions, child-transport providers and similar categories notified by the Government. Exemptions are category-specific and do not remove the underlying safeguards for security and purpose limitation.

Designing age-aware products

The ₹200 crore stake

Violations of children's-data obligations sit at the top of the Schedule with breach-notification failure: up to ₹200 crore. For edtech, gaming, social, health or entertainment products that reach users under 18 — or cannot prove they do not — this is a board-level risk, not a product footnote.

Build age-aware compliance by design

KryptoMindz designs verifiable parental consent flows, age verification and minor-data safeguards for products serving children and families.

Discuss Your Children's Data Controls

Go deeper