DPDP Wiki Talk to us

/The Rules · 2025

Rule 12: Exemptions from certain obligations applicable to processing of personal data of child

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 12 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 9 Processing of personal data of children
Schedules referenced
Fourth Schedule
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 12. Exemptions from certain obligations applicable to processing of personal data of child

Verbatim from the Gazette of India
(1)

The provisions of sub-sections (1) and (3) of section 9 of the Act shall not be applicable to processing of personal data of a child by such class of Data Fiduciaries as are specified in Part A of Fourth Schedule, subject to such conditions as are specified in the said Part.

(2)

The provisions of sub-sections (1) and (3) of section 9 of the Act shall not be applicable to processing of personal data of a child for such purposes as are specified in Part B of Fourth Schedule, subject to such conditions as are specified in the said Part.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryChildren and parents

Rule 12 sets out exemptions from certain rules about processing the personal data of a child. Specifically, it waives the requirements found in sub-sections (1) and (3) of section 9 of the Digital Personal Data Protection Act. The first exemption applies to specific types of Data Fiduciaries, which are entities determining the purpose and means of processing data. If a Data Fiduciary belongs to a class listed in Part A of the Fourth Schedule of the Rules, it does not have to follow those specific section 9 requirements, as long as it meets any conditions listed in that Part. The second exemption is based on the reason for processing the data. If a child's personal data is processed for a purpose listed in Part B of the Fourth Schedule, the requirements of section 9(1) and 9(3) do not apply. This is also subject to any conditions specified in Part B.

Key points

  • Certain classes of Data Fiduciaries are exempt from sub-sections (1) and (3) of section 9 of the Act when processing a child's personal data. [(1)]
  • These exempt classes of Data Fiduciaries, along with any conditions they must follow, are specified in Part A of the Fourth Schedule. [(1)]
  • Processing a child's personal data for specific purposes is also exempt from sub-sections (1) and (3) of section 9 of the Act. [(2)]
  • These exempt purposes and their conditions are listed in Part B of the Fourth Schedule. [(2)]

Common misreadings

  • Assuming that all rules regarding children's data are waived; the exemption only applies to sub-sections (1) and (3) of section 9.
  • Believing any Data Fiduciary can claim the exemption; it only applies to the specific classes or purposes listed in Part A or Part B of the Fourth Schedule.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.