---
title: "Children's data and persons with disability under the DPDP Act"
url: https://dpdp.myndsolution.com/wiki/guides/children-and-persons-with-disability/
description: "Verifiable parental consent, the ban on tracking and targeted advertising at children, guardian verification, and the exemptions in the Fourth Schedule."
kind: guide
updated: 2026-09-09
text_type: analysis
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/guides/children-and-persons-with-disability/
---
# Children's data and persons with disability under the DPDP Act

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.


The Act treats children and persons with disability who have a lawful guardian as one protected group and puts three duties on anyone processing their personal data. The Rules set out how consent is verified in each case, and list the situations where two of the three duties fall away.

## Who counts as a child

A "child" is an individual who has not completed the age of eighteen years ([section 2(f)](/wiki/act/section-2/)). Where the individual is a child, the [Data Principal](/wiki/glossary/data-principal/) includes her parents or lawful guardian; where she is a person with disability, it includes her lawful guardian acting on her behalf ([section 2(j)](/wiki/act/section-2/)).

## Three duties

Before processing the personal data of a child, or of a person with disability who has a lawful guardian, a [Data Fiduciary](/wiki/glossary/data-fiduciary/) must obtain the "verifiable consent" of the parent or lawful guardian, in the prescribed manner. "Consent of the parent" includes the consent of a lawful guardian wherever applicable ([section 9(1)](/wiki/act/section-9/)).

Second, it must not undertake processing that is likely to cause any detrimental effect on the well-being of a child ([section 9(2)](/wiki/act/section-9/)). Third, it must not track or behaviourally monitor children, or direct targeted advertising at them ([section 9(3)](/wiki/act/section-9/)). The second duty stands on its own: the exemptions below reach only the first and third.

## Verifying a parent

[Rule 10](/wiki/rules/rule-10/) turns "verifiable consent" into a concrete test. Appropriate technical and organisational measures must ensure the parent's verifiable consent is obtained before any of the child's personal data is processed, and due diligence must check that the individual identifying herself as the parent is an adult who is identifiable if that is needed for compliance with a law in force in India. An "adult" is an individual who has completed the age of eighteen years.

The check may run against either of two things:

- reliable details of identity and age of that individual already held by the Data Fiduciary; or
- details of identity and age voluntarily provided, either by the individual herself or through a virtual token mapped to those details and issued by an authorised entity.

An "authorised entity" is one entrusted by law or by the Central or a State Government with issuing identity and age details or a token mapped to them, or a person it appoints or permits, and the expression also covers details or a token made available and verified by a Digital Locker service provider ([rule 10(2)](/wiki/rules/rule-10/)).

The Rules' four illustrations turn on one distinction. If the parent is already a registered user who previously gave the platform her identity and age details, the platform checks its own records to confirm she is an identifiable adult. If she is not a registered user, it must check against details issued by an entity entrusted by law or by the Government, or a token mapped to them, which she may supply through a Digital Locker service provider. Whether the child declares the parent or the parent opens the account herself makes no difference ([rule 10](/wiki/rules/rule-10/)).

## Verifying a lawful guardian

Where an individual identifies herself as the lawful guardian of a person with disability, the Data Fiduciary must observe due diligence to verify that the guardian was appointed by a court of law, by a designated authority, or by a local level committee, under the law applicable to guardianship ([rule 11(1)](/wiki/rules/rule-11/)).

Each of those terms is defined ([rule 11(2)](/wiki/rules/rule-11/)):

| Term | Meaning |
| --- | --- |
| Designated authority | An authority designated under section 15 of the Rights of Persons with Disabilities Act, 2016 to support persons with disabilities in exercising their legal capacity |
| Local level committee | A committee constituted under section 13 of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999 |
| Law applicable to guardianship | The Rights of Persons with Disabilities Act, 2016 and its rules, for a person with long term physical, mental, intellectual or sensory impairment who cannot take legally binding decisions despite adequate support; the National Trust Act, 1999 and its rules, for a person with autism, cerebral palsy, mental retardation, a combination of those, or severe multiple disability |
| Person with disability | Both groups above, in each case where the individual cannot take legally binding decisions despite adequate and appropriate support |

Note the limit built in. Rule 11 reaches only individuals who cannot take legally binding decisions and who have a guardian appointed under one of those two laws. It is not a rule about disability generally.

## Where the duties fall away

The consent requirement in section 9(1) and the tracking and advertising ban in section 9(3) do not apply to processing by certain classes of Data Fiduciary, or for certain purposes, subject to conditions ([section 9(4)](/wiki/act/section-9/), [rule 12](/wiki/rules/rule-12/)). They are listed in the two parts of the [Fourth Schedule](/wiki/rules/schedule-4/), and each exemption runs only as far as its stated condition.

### Part A: classes of Data Fiduciary

| Class | Condition |
| --- | --- |
| Clinical establishment, mental health establishment or healthcare professional | Restricted to providing health services to the child, to the extent necessary to protect her health |
| Allied healthcare professional | Restricted to supporting a treatment and referral plan that professional recommended for the child, to the extent necessary to protect her health |
| Educational institution | Restricted to tracking and behavioural monitoring for the institution's educational activities, or in the interests of the safety of children enrolled with it |
| An individual in whose care infants and children in a crèche or child day care centre are entrusted | Restricted to tracking and behavioural monitoring in the interests of the safety of children entrusted to that institution, crèche or centre |
| A Data Fiduciary engaged by an educational institution, crèche or child care centre to transport enrolled children | Restricted to tracking those children's location, in the interests of their safety, during travel to and from the institution, crèche or centre |

### Part B: purposes

| Purpose | Condition |
| --- | --- |
| Exercising a power, performing a function or discharging a duty in the interests of a child under a law in force in India | Restricted to what is necessary for that exercise, performance or discharge |
| Providing or issuing a subsidy, benefit, service, certificate, licence or permit in the interests of a child, under law, policy or public funds, under [section 7(b)](/wiki/act/section-7/) | Restricted to what is necessary for that provision or issuance |
| Creating a user account for communicating by email | Restricted to what is necessary to create the account, whose use is limited to email |
| Determining a child's real-time location | Restricted to that tracking, in the interest of her safety, protection or security |
| Ensuring that information, a service or an advertisement likely to cause a detrimental effect on a child's well-being is not accessible to her | Restricted to what is necessary to keep it inaccessible |
| Confirming that the Data Principal is not a child, and observing the due diligence under [rule 10](/wiki/rules/rule-10/) | Restricted to what is necessary for that confirmation or observance |

The last entry closes a loop: age checking would itself involve processing a child's data, so the Rules exempt it.

## The age-based exemption by notification

The Central Government may also notify, for a particular Data Fiduciary, an age above which it is exempt from all or any of the obligations in section 9(1) and 9(3), but only if satisfied that its processing of children's data "is done in a manner that is verifiably safe" ([section 9(5)](/wiki/act/section-9/)). No such notification appears in the sources on this site.

## Penalty

A breach in observing the additional obligations in relation to children under section 9 carries a penalty that "may extend to two hundred crore rupees" ([the Schedule](/wiki/act/schedule/)), the second-highest figure in the Act.

## Key provisions

- [Section 9, processing of personal data of children](/wiki/act/section-9/)
- [Section 2, definitions](/wiki/act/section-2/)
- [Rule 10, verifiable consent for processing of personal data of child](/wiki/rules/rule-10/)
- [Rule 11, verifiable consent for persons with disability who have a lawful guardian](/wiki/rules/rule-11/)
- [Rule 12, exemptions from certain obligations](/wiki/rules/rule-12/)
- [Fourth Schedule, exempt classes and purposes](/wiki/rules/schedule-4/)
- [The Schedule to the Act, penalties](/wiki/act/schedule/)
