DPDP Wiki Talk to us

/The Act · Chapter II · Obligations of Data Fiduciary

Section 9: Processing of personal data of children

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) G.S.R. 843(E)Chapter II: Obligations of Data Fiduciary
Provision
Section 9 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
Rules made under it
Rule 10Rule 11Rule 12
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 9. Processing of personal data of children

Verbatim from the Gazette of India
(1)

The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed.

Explanation.—

For the purpose of this sub-section, the expression “consent of the parent” includes the consent of lawful guardian, wherever applicable.

(2)

A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child.

(3)

A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

(4)

The provisions of sub-sections (1) and (3) shall not be applicable to processing of personal data of a child by such classes of Data Fiduciaries or for such purposes, and subject to such conditions, as may be prescribed.

(5)

The Central Government may, if satisfied that a Data Fiduciary has ensured that its processing of personal data of children is done in a manner that is verifiably safe, notify for such processing by such Data Fiduciary the age above which that Data Fiduciary shall be exempt from the applicability of all or any of the obligations under sub-sections (1) and (3) in respect of processing by that Data Fiduciary as the notification may specify.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryChildren and parentsCentral Government

Before a Data Fiduciary (an entity that determines the purpose and means of processing data) processes the personal data of a child, it must obtain verifiable consent from the child's parent. This rule also applies to a person with a disability who has a lawful guardian, requiring the guardian's verifiable consent. The exact manner of verifying this consent will be prescribed in future rules.

The law places strict limits on how children's data can be used. A Data Fiduciary is prohibited from processing personal data in any way that is likely to cause a detrimental effect on a child's well-being. Additionally, a Data Fiduciary cannot track children, monitor their behavior, or direct targeted advertising at them.

There are exceptions to these strict rules. The government may prescribe certain classes of Data Fiduciaries, or specific purposes, that are exempt from the parental consent and tracking restrictions. Furthermore, if the Central Government is satisfied that a particular Data Fiduciary processes children's data in a verifiably safe manner, it can issue a notification. This notification can specify an age above which that specific Data Fiduciary is exempt from the parental consent and tracking rules.

Key points

  • A Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing the personal data of a child or a person with a disability who has a lawful guardian (1).
  • A Data Fiduciary cannot process personal data in a way that is likely to cause a detrimental effect on a child's well-being (2).
  • Tracking, behavioral monitoring, and targeted advertising directed at children are strictly prohibited (3).
  • The government may prescribe exemptions from the consent and tracking rules for certain classes of Data Fiduciaries or specific purposes (4).
  • The Central Government can lower the age limit for the consent and tracking rules for a specific Data Fiduciary if it is satisfied their processing is verifiably safe (5).

Common misreadings

  • Assuming the ban on tracking and targeted advertising has no exceptions; the government can prescribe exemptions for certain Data Fiduciaries or purposes.
  • Believing the age limit for parental consent is entirely fixed; the Central Government can notify a lower age threshold for specific Data Fiduciaries that operate in a verifiably safe manner.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.