/FAQ
Children's data
Who counts as a child, what verifiable parental consent requires, the tracking and advertising bans, the Fourth Schedule exemptions and disability guardians.
Who counts as a child under the DPDP Act?
Anyone who has not completed the age of eighteen years (section 2(f)). There is no lower tier, no teenager category and no separate digital age of consent: a seventeen year old is treated the same as a seven year old. Where the Data Principal is a child, the expression includes the parents or lawful guardian of that child (section 2(j)), so the rights of the child are exercised through them. The Rules define "adult" for the purpose of parental verification as an individual who has completed the age of eighteen years (rule 10(2)(a)).
Do I need parental consent before processing a child's data?
Yes. Before processing any personal data of a child, or of a person with disability who has a lawful guardian, the Data Fiduciary must obtain verifiable consent of the parent or the lawful guardian, in the manner prescribed (section 9(1)). The Act clarifies that "consent of the parent" includes the consent of a lawful guardian wherever applicable. The duty attaches before processing, not at some later checkpoint, and it applies to any personal data of the child, not only to sensitive categories. Failures here are penalised separately from ordinary breaches (the Schedule).
What does "verifiable consent" actually require?
The Rules define it as consent as specified in rule 10 or rule 11 (rule 2(1)(d)). Under rule 10(1) the Data Fiduciary must adopt appropriate technical and organisational measures to ensure verifiable parental consent is obtained before processing, and must "observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law". The check is made either against reliable identity and age details the Data Fiduciary already holds, or against identity and age details voluntarily provided by the individual, or through a virtual token mapped to those details issued by an authorised entity, which can include a Digital Locker service provider.
Can children be tracked or shown targeted advertising?
No. A Data Fiduciary "shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children" (section 9(3)). Separately, it must not undertake processing of a child's personal data "that is likely to cause any detrimental effect on the well-being of a child" (section 9(2)). The second prohibition has no exemption route at all. The first can be switched off only for the classes and purposes prescribed under section 9(4), which are set out in the Fourth Schedule.
Are there exemptions from the children's data rules?
Yes, but they are narrow and conditional. Sub-sections (1) and (3) of section 9, meaning verifiable parental consent and the tracking and advertising ban, do not apply to processing of a child's personal data by the classes of Data Fiduciaries in Part A of the Fourth Schedule, subject to the conditions in that Part (rule 12(1)), or for the purposes in Part B, again subject to the conditions there (rule 12(2)). Section 9(2), the ban on processing likely to cause a detrimental effect on a child's well being, is not exempted by either Part.
Which organisations are exempt under Part A of the Fourth Schedule?
Five classes, each with a condition attached. A clinical establishment, mental health establishment or healthcare professional, where processing is restricted to providing health services to the child to the extent necessary to protect her health. An allied healthcare professional, restricted to supporting a treatment and referral plan recommended for the child. An educational institution, restricted to tracking and behavioural monitoring for its educational activities or in the interests of the safety of children enrolled with it. An individual in whose care infants and children in a crèche or child day care centre are entrusted, restricted to tracking and behavioural monitoring in the interests of the safety of those children. And a transport provider engaged by such an institution, crèche or centre, restricted to tracking the location of children during travel to and from it (Fourth Schedule).
Which purposes are exempt under Part B of the Fourth Schedule?
Six purposes, each limited to what is necessary. Exercising a power, performing a function or discharging a duty in the interests of a child under Indian law. Providing or issuing a subsidy, benefit, service, certificate, licence or permit in the interests of a child under clause (b) of section 7. Creating a user account for communicating by email, where use of the account is limited to email. Determining the real-time location of a child, restricted to tracking in the interest of her safety, protection or security. Ensuring that information, a service or an advertisement likely to cause a detrimental effect on a child's well-being is not accessible to her. And confirming that a Data Principal is not a child, along with the due diligence under rule 10 (Fourth Schedule).
What about a person with disability who has a lawful guardian?
The same verifiable consent duty applies, and the verification is different. Before processing the personal data of a person with disability who has a lawful guardian, the Data Fiduciary must obtain the verifiable consent of that guardian (section 9(1)). Under rule 11(1) it must "observe due diligence to verify that such guardian is appointed by a court of law, or by a designated authority or by a local level committee, under the law applicable to guardianship". The Rules point to the Rights of Persons with Disabilities Act, 2016 and the National Trust Act, 1999 for who counts as a guardian, a designated authority and a local level committee.
What is the penalty for getting children's data wrong?
A breach in observance of the additional obligations in relation to children under section 9 carries a penalty that "may extend to two hundred crore rupees" (the Schedule). It sits at the same level as failing to report a personal data breach, and above the one hundred and fifty crore ceiling for Significant Data Fiduciary failures. As with every item in the Schedule, the figure is a maximum: the Board imposes a penalty only after an inquiry, only if it finds the breach significant, and only after weighing the factors in section 33(2).
Can the age threshold be relaxed for a particular company?
Only by the Central Government, and only on a finding of safety. If satisfied that a Data Fiduciary has ensured that its processing of children's personal data "is done in a manner that is verifiably safe", the Central Government may notify, for that Data Fiduciary, the age above which it is exempt from all or any of the obligations under section 9(1) and section 9(3) (section 9(5)). It is a company-by-company power, not a general lowering of the age of eighteen. No such notification appears in the official sources this wiki mirrors.
/MYND · DPDP practice
Have a question about your own situation?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.