/The Rules · 2025
Rule 12: Exemptions from certain obligations applicable to processing of personal data of child
DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.
- Provision
- Rule 12 of The Digital Personal Data Protection Rules, 2025
- Status
- Comes into force on 13 May 2027 (phase 3)
- Made under
- s. 9 Processing of personal data of children
- Schedules referenced
- Fourth Schedule
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
The provisions of sub-sections (1) and (3) of section 9 of the Act shall not be applicable to processing of personal data of a child by such class of Data Fiduciaries as are specified in Part A of Fourth Schedule, subject to such conditions as are specified in the said Part.
The provisions of sub-sections (1) and (3) of section 9 of the Act shall not be applicable to processing of personal data of a child for such purposes as are specified in Part B of Fourth Schedule, subject to such conditions as are specified in the said Part.
Rule 12 sets out exemptions from certain rules about processing the personal data of a child. Specifically, it waives the requirements found in sub-sections (1) and (3) of section 9 of the Digital Personal Data Protection Act. The first exemption applies to specific types of Data Fiduciaries, which are entities determining the purpose and means of processing data. If a Data Fiduciary belongs to a class listed in Part A of the Fourth Schedule of the Rules, it does not have to follow those specific section 9 requirements, as long as it meets any conditions listed in that Part. The second exemption is based on the reason for processing the data. If a child's personal data is processed for a purpose listed in Part B of the Fourth Schedule, the requirements of section 9(1) and 9(3) do not apply. This is also subject to any conditions specified in Part B.
Key points
- Certain classes of Data Fiduciaries are exempt from sub-sections (1) and (3) of section 9 of the Act when processing a child's personal data. [(1)]
- These exempt classes of Data Fiduciaries, along with any conditions they must follow, are specified in Part A of the Fourth Schedule. [(1)]
- Processing a child's personal data for specific purposes is also exempt from sub-sections (1) and (3) of section 9 of the Act. [(2)]
- These exempt purposes and their conditions are listed in Part B of the Fourth Schedule. [(2)]
Common misreadings
- Assuming that all rules regarding children's data are waived; the exemption only applies to sub-sections (1) and (3) of section 9.
- Believing any Data Fiduciary can claim the exemption; it only applies to the specific classes or purposes listed in Part A or Part B of the Fourth Schedule.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.