/The Rules · 2025
Rule 10: Verifiable consent for processing of personal data of child
DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.
- Provision
- Rule 10 of The Digital Personal Data Protection Rules, 2025
- Status
- Comes into force on 13 May 2027 (phase 3)
- Made under
- s. 9 Processing of personal data of children
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to—
In this rule, the expression—
“Digital Locker service provider” shall mean such intermediary, including a body corporate or an agency of the appropriate Government, as may be notified by the Central Government, in accordance with the rules made in this regard under the Information Technology Act, 2000 (21 of 2000);
A Data Fiduciary (any person who determines the purpose and means of processing personal data) must obtain verifiable consent from a parent before processing any personal data of a child. To do this, the Data Fiduciary must put in place appropriate technical and organizational measures. The Data Fiduciary must also use due diligence to confirm that the person claiming to be the parent is actually an adult, meaning someone who has completed eighteen years of age. This person must be identifiable if required for compliance with any Indian law. To verify the parent's age and identity, the Data Fiduciary can rely on reliable details it already has on file. If the Data Fiduciary does not already have these details, the parent can voluntarily provide them. The parent can provide these details directly or through a virtual token issued by an authorized entity, such as a government-entrusted issuer or a Digital Locker service provider.
Key points
- A Data Fiduciary must use technical and organizational measures to get verifiable consent from a parent before processing a child's personal data. (1)
- The Data Fiduciary must check that the person identifying as the parent is an adult who is at least eighteen years old. (1, 2(a))
- Verification can be done using reliable identity and age details already held by the Data Fiduciary. (1(a))
- Verification can also be done using details voluntarily provided by the individual, including through a virtual token from an authorized entity like a Digital Locker service provider. (1(b), 2(b))
Common misreadings
- Parents are not forced to use a government ID or Digital Locker if the Data Fiduciary already has reliable identity and age details on file.
- The rule requires verifying that the parent is an adult, not just obtaining a simple declaration without any checks.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.