DPDP Wiki Talk to us

/The Rules · 2025

Rule 10: Verifiable consent for processing of personal data of child

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 10 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 9 Processing of personal data of children
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 10. Verifiable consent for processing of personal data of child

Verbatim from the Gazette of India
(1)

A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to—

(a)

reliable details of identity and age of the individual available with the Data Fiduciary; or

(b)

details of identity and age, voluntarily provided —

(i)

by the individual; or

(ii)

through a virtual token mapped to such details, which is issued by an authorised entity.

(2)

In this rule, the expression—

(a)

“adult” shall mean an individual who has completed the age of eighteen years;

(b)

“authorised entity" shall mean —

(i)

an entity entrusted by law or by the Central Government or by the State Government with the issuance of details of the identity and age or a virtual token mapped to such details; or

(ii)

a person appointed or permitted by the entity specified under clause (i), for such issuance, and also includes details of identity and age or token made available and verified by a Digital Locker Service Provider;

(c)

“Digital Locker service provider” shall mean such intermediary, including a body corporate or an agency of the appropriate Government, as may be notified by the Central Government, in accordance with the rules made in this regard under the Information Technology Act, 2000 (21 of 2000);

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryChildren and parentsCentral GovernmentState Government

A Data Fiduciary (any person who determines the purpose and means of processing personal data) must obtain verifiable consent from a parent before processing any personal data of a child. To do this, the Data Fiduciary must put in place appropriate technical and organizational measures. The Data Fiduciary must also use due diligence to confirm that the person claiming to be the parent is actually an adult, meaning someone who has completed eighteen years of age. This person must be identifiable if required for compliance with any Indian law. To verify the parent's age and identity, the Data Fiduciary can rely on reliable details it already has on file. If the Data Fiduciary does not already have these details, the parent can voluntarily provide them. The parent can provide these details directly or through a virtual token issued by an authorized entity, such as a government-entrusted issuer or a Digital Locker service provider.

Key points

  • A Data Fiduciary must use technical and organizational measures to get verifiable consent from a parent before processing a child's personal data. (1)
  • The Data Fiduciary must check that the person identifying as the parent is an adult who is at least eighteen years old. (1, 2(a))
  • Verification can be done using reliable identity and age details already held by the Data Fiduciary. (1(a))
  • Verification can also be done using details voluntarily provided by the individual, including through a virtual token from an authorized entity like a Digital Locker service provider. (1(b), 2(b))

Common misreadings

  • Parents are not forced to use a government ID or Digital Locker if the Data Fiduciary already has reliable identity and age details on file.
  • The rule requires verifying that the parent is an adult, not just obtaining a simple declaration without any checks.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.