Back to Key Provisions

Processing of Children's Data

Detailed analysis of the DPDPA's provisions on processing children's personal data - verifiable parental consent, tracking prohibitions, and exemptions under the Rules.

10 min read

Special Protections for Children

Section 9 of the DPDPA establishes heightened protections for the processing of children's personal data. A "child" is defined as any individual who has not completed the age of eighteen years. These provisions reflect the Act's recognition that children are a vulnerable category requiring additional safeguards. The DPDP Rules (R.9-12) operationalise these provisions with specific mechanisms for age verification and parental consent.

Prohibition on Tracking and Targeting (Section 9(2)-(3))

The Act imposes absolute prohibitions on certain activities with respect to children: • Tracking or behavioural monitoring of children (Section 9(2)) • Targeted advertising directed at children (Section 9(3)) These are categorical bans - they apply regardless of parental consent. Even if a parent consents, a Data Fiduciary cannot track a child's online behaviour or target advertisements at them. This approach is more restrictive than the GDPR, which regulates but does not categorically prohibit targeted advertising to children. The DPDPA's absolute ban reflects a strong policy position on protecting children from commercial exploitation of their data.

Age Verification (R.9)

Rule 9 requires Data Fiduciaries to make "reasonable efforts" to verify whether a Data Principal is a child. This includes: • Implementing age gates or age declaration mechanisms • Using technology-based verification where appropriate • Applying risk-based approaches proportional to the nature of the service The "reasonable efforts" standard is deliberately flexible, recognising that the appropriate verification mechanism will vary by context. A gaming platform may require different verification than a government portal.

Exemptions from Verifiable Consent (R.12)

Rule 12 exempts five categories of entities from the verifiable parental consent requirement: 1. Clinical establishments or mental health establishments 2. Allied healthcare professionals 3. Educational institutions 4. Creches or child day care centres 5. Transport entities providing services for children These exemptions are narrowly scoped to the specific purpose of each category. A healthcare provider is exempt only for healthcare processing, not for marketing to children. Importantly, the tracking and targeting prohibitions (Section 9(2)-(3)) continue to apply even to exempt entities - the exemption only relates to the verifiable consent requirement.

Persons with Disabilities (R.11)

Rule 11 addresses the processing of personal data of persons with disabilities who have lawful guardians. The provisions parallel the children's data framework, requiring guardian consent and providing appropriate safeguards. This inclusion reflects the Act's intent to protect individuals who may not be in a position to provide fully informed consent on their own behalf, while respecting the dignity and autonomy of persons with disabilities through the framework of lawful guardianship.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.