DPDP Wiki Talk to us

/Guides · Product & compliance teams

Children's data and persons with disability under the DPDP Act

Verifiable parental consent, the ban on tracking and targeted advertising at children, guardian verification, and the exemptions in the Fourth Schedule.

Interpretation · not legal adviceUpdated 9 September 20267 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

The Act treats children and persons with disability who have a lawful guardian as one protected group and puts three duties on anyone processing their personal data. The Rules set out how consent is verified in each case, and list the situations where two of the three duties fall away.

Who counts as a child#

A "child" is an individual who has not completed the age of eighteen years (section 2(f)). Where the individual is a child, the Data Principal includes her parents or lawful guardian; where she is a person with disability, it includes her lawful guardian acting on her behalf (section 2(j)).

Three duties#

Before processing the personal data of a child, or of a person with disability who has a lawful guardian, a Data Fiduciary must obtain the "verifiable consent" of the parent or lawful guardian, in the prescribed manner. "Consent of the parent" includes the consent of a lawful guardian wherever applicable (section 9(1)).

Second, it must not undertake processing that is likely to cause any detrimental effect on the well-being of a child (section 9(2)). Third, it must not track or behaviourally monitor children, or direct targeted advertising at them (section 9(3)). The second duty stands on its own: the exemptions below reach only the first and third.

Verifying a parent#

Rule 10 turns "verifiable consent" into a concrete test. Appropriate technical and organisational measures must ensure the parent's verifiable consent is obtained before any of the child's personal data is processed, and due diligence must check that the individual identifying herself as the parent is an adult who is identifiable if that is needed for compliance with a law in force in India. An "adult" is an individual who has completed the age of eighteen years.

The check may run against either of two things:

  • reliable details of identity and age of that individual already held by the Data Fiduciary; or
  • details of identity and age voluntarily provided, either by the individual herself or through a virtual token mapped to those details and issued by an authorised entity.

An "authorised entity" is one entrusted by law or by the Central or a State Government with issuing identity and age details or a token mapped to them, or a person it appoints or permits, and the expression also covers details or a token made available and verified by a Digital Locker service provider (rule 10(2)).

The Rules' four illustrations turn on one distinction. If the parent is already a registered user who previously gave the platform her identity and age details, the platform checks its own records to confirm she is an identifiable adult. If she is not a registered user, it must check against details issued by an entity entrusted by law or by the Government, or a token mapped to them, which she may supply through a Digital Locker service provider. Whether the child declares the parent or the parent opens the account herself makes no difference (rule 10).

Verifying a lawful guardian#

Where an individual identifies herself as the lawful guardian of a person with disability, the Data Fiduciary must observe due diligence to verify that the guardian was appointed by a court of law, by a designated authority, or by a local level committee, under the law applicable to guardianship (rule 11(1)).

Each of those terms is defined (rule 11(2)):

TermMeaning
Designated authorityAn authority designated under section 15 of the Rights of Persons with Disabilities Act, 2016 to support persons with disabilities in exercising their legal capacity
Local level committeeA committee constituted under section 13 of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999
Law applicable to guardianshipThe Rights of Persons with Disabilities Act, 2016 and its rules, for a person with long term physical, mental, intellectual or sensory impairment who cannot take legally binding decisions despite adequate support; the National Trust Act, 1999 and its rules, for a person with autism, cerebral palsy, mental retardation, a combination of those, or severe multiple disability
Person with disabilityBoth groups above, in each case where the individual cannot take legally binding decisions despite adequate and appropriate support

Note the limit built in. Rule 11 reaches only individuals who cannot take legally binding decisions and who have a guardian appointed under one of those two laws. It is not a rule about disability generally.

Where the duties fall away#

The consent requirement in section 9(1) and the tracking and advertising ban in section 9(3) do not apply to processing by certain classes of Data Fiduciary, or for certain purposes, subject to conditions (section 9(4), rule 12). They are listed in the two parts of the Fourth Schedule, and each exemption runs only as far as its stated condition.

Part A: classes of Data Fiduciary#

ClassCondition
Clinical establishment, mental health establishment or healthcare professionalRestricted to providing health services to the child, to the extent necessary to protect her health
Allied healthcare professionalRestricted to supporting a treatment and referral plan that professional recommended for the child, to the extent necessary to protect her health
Educational institutionRestricted to tracking and behavioural monitoring for the institution's educational activities, or in the interests of the safety of children enrolled with it
An individual in whose care infants and children in a crèche or child day care centre are entrustedRestricted to tracking and behavioural monitoring in the interests of the safety of children entrusted to that institution, crèche or centre
A Data Fiduciary engaged by an educational institution, crèche or child care centre to transport enrolled childrenRestricted to tracking those children's location, in the interests of their safety, during travel to and from the institution, crèche or centre

Part B: purposes#

PurposeCondition
Exercising a power, performing a function or discharging a duty in the interests of a child under a law in force in IndiaRestricted to what is necessary for that exercise, performance or discharge
Providing or issuing a subsidy, benefit, service, certificate, licence or permit in the interests of a child, under law, policy or public funds, under section 7(b)Restricted to what is necessary for that provision or issuance
Creating a user account for communicating by emailRestricted to what is necessary to create the account, whose use is limited to email
Determining a child's real-time locationRestricted to that tracking, in the interest of her safety, protection or security
Ensuring that information, a service or an advertisement likely to cause a detrimental effect on a child's well-being is not accessible to herRestricted to what is necessary to keep it inaccessible
Confirming that the Data Principal is not a child, and observing the due diligence under rule 10Restricted to what is necessary for that confirmation or observance

The last entry closes a loop: age checking would itself involve processing a child's data, so the Rules exempt it.

The age-based exemption by notification#

The Central Government may also notify, for a particular Data Fiduciary, an age above which it is exempt from all or any of the obligations in section 9(1) and 9(3), but only if satisfied that its processing of children's data "is done in a manner that is verifiably safe" (section 9(5)). No such notification appears in the sources on this site.

Penalty#

A breach in observing the additional obligations in relation to children under section 9 carries a penalty that "may extend to two hundred crore rupees" (the Schedule), the second-highest figure in the Act.

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.