---
title: "Rule 10: Verifiable consent for processing of personal data of child"
url: https://dpdp.myndsolution.com/wiki/rules/rule-10-verifiable-consent-for-processing-of-personal-data-of-child/
description: "Rule 10 of the Digital Personal Data Protection Rules, 2025 (Verifiable consent for processing of personal data of child). Official text verbatim, comes…"
kind: rule
updated: 2026-09-09
official_source: https://egazette.gov.in/WriteReadData/2025/267650.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/rules/rule-10-verifiable-consent-for-processing-of-personal-data-of-child/
---
# Rule 10: Verifiable consent for processing of personal data of child

*The Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.*

## Official text

- **(1)** A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to—
  - **(a)** reliable details of identity and age of the individual available with the Data Fiduciary; or
  - **(b)** details of identity and age, voluntarily provided —
    - **(i)** by the individual; or
    - **(ii)** through a virtual token mapped to such details, which is issued by an authorised entity.

- **(2)** In this rule, the expression—
  - **(a)** “adult” shall mean an individual who has completed the age of eighteen years;
  - **(b)** “authorised entity" shall mean —
    - **(i)** an entity entrusted by law or by the Central Government or by the State Government with the issuance of details of the identity and age or a virtual token mapped to such details; or
    - **(ii)** a person appointed or permitted by the entity specified under clause (i), for such issuance, and also includes details of identity and age or token made available and verified by a Digital Locker Service Provider;
  - **(c)** “Digital Locker service provider” shall mean such intermediary, including a body corporate or an agency of the appropriate Government, as may be notified by the Central Government, in accordance with the rules made in this regard under the Information Technology Act, 2000 (21 of 2000);
      > **Illustration.** C is a child, P is a parent, and DF is a Data Fiduciary. A user account of C is sought to be created on the online platform of DF, by processing the personal data of C.
      Case 1: C informs DF that she is a child and declares P as her parent. DF shall enable P to identify herself through its website, app or other appropriate means. P identifies herself as the parent and informs DF that she is a registered user on DF’s platform and has previously made available her identity and age details to DF. Before processing C’s personal data for the creation of her user account, DF shall check to confirm that it holds reliable identity and age details of P and that P is an identifiable adult.
      Case 2: C informs DF that she is a child and declares P as her parent. DF shall enable P to identify herself through its website, app or other appropriate means. P identifies herself as the parent and informs DF that she herself is not a registered user on DF’s platform. Before processing C’s personal data for the creation of her user account, DF shall, by reference to identity and age details issued by an entity entrusted by law or the Government with maintenance of the said details or to a virtual token mapped to the identity and age, check that P is an identifiable adult. P may voluntarily make such details available using the services of a Digital Locker service provider.
      Case 3: P is opening an account for C and identifies herself as C’s parent and informs DF that she is a registered user on DF’s platform and has previously made available her identity and age details to DF. Before processing C’s personal data for the creation of her user account, DF shall check to confirm that it holds reliable identity and age details of P and that P is an identifiable adult.
      Case 4: P is opening an account for C and identifies herself as C’s parent and informs DF that she herself is not a registered user on DF’s platform. Before processing C’s personal data for the creation of her user account, DF shall, by reference to identity and age details issued by an entity entrusted by law or the Government with maintenance of the said details or to a virtual token mapped to the identity and age, check that P is an identifiable adult. P may voluntarily make such details available using the services of a Digital Locker service provider.


## Made under

- [s. 9 Processing of personal data of children](https://dpdp.myndsolution.com/wiki/act/section-9-processing-of-personal-data-of-children/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

A Data Fiduciary (any person who determines the purpose and means of processing personal data) must obtain verifiable consent from a parent before processing any personal data of a child. To do this, the Data Fiduciary must put in place appropriate technical and organizational measures. The Data Fiduciary must also use due diligence to confirm that the person claiming to be the parent is actually an adult, meaning someone who has completed eighteen years of age. This person must be identifiable if required for compliance with any Indian law. To verify the parent's age and identity, the Data Fiduciary can rely on reliable details it already has on file. If the Data Fiduciary does not already have these details, the parent can voluntarily provide them. The parent can provide these details directly or through a virtual token issued by an authorized entity, such as a government-entrusted issuer or a Digital Locker service provider.

### Key points

- A Data Fiduciary must use technical and organizational measures to get verifiable consent from a parent before processing a child's personal data. (1)
- The Data Fiduciary must check that the person identifying as the parent is an adult who is at least eighteen years old. (1, 2(a))
- Verification can be done using reliable identity and age details already held by the Data Fiduciary. (1(a))
- Verification can also be done using details voluntarily provided by the individual, including through a virtual token from an authorized entity like a Digital Locker service provider. (1(b), 2(b))

### Common misreadings

- Parents are not forced to use a government ID or Digital Locker if the Data Fiduciary already has reliable identity and age details on file.
- The rule requires verifying that the parent is an adult, not just obtaining a simple declaration without any checks.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: DPDP Rules, 2025, r. 10. Official source: https://egazette.gov.in/WriteReadData/2025/267650.pdf
