Back to Key Provisions

Processing of Children's Data

Detailed analysis of the DPDPA's provisions on processing children's personal data - verifiable parental consent, tracking prohibitions, and exemptions under the Rules.

10 min read

Special Protections for Children

Section 9 of the DPDPA establishes heightened protections for the processing of children's personal data. A "child" is defined as any individual who has not completed the age of eighteen years. These provisions reflect the Act's recognition that children are a vulnerable category requiring additional safeguards. The DPDP Rules (R.10-12) operationalise these provisions with specific mechanisms for age verification and parental consent.

Prohibition on Tracking and Targeting (Section 9(3))

The Act imposes absolute prohibitions on certain activities with respect to children: • Tracking or behavioural monitoring of children (Section 9(3)) • Targeted advertising directed at children (Section 9(3)) These are categorical bans - they apply regardless of parental consent. Even if a parent consents, a Data Fiduciary cannot track a child's online behaviour or target advertisements at them. This approach is more restrictive than the GDPR, which regulates but does not categorically prohibit targeted advertising to children. The DPDPA's absolute ban reflects a strong policy position on protecting children from commercial exploitation of their data.

Age Verification (R.10)

Rule 10 requires Data Fiduciaries to make "reasonable efforts" to verify whether a Data Principal is a child. This includes: • Implementing age gates or age declaration mechanisms • Using technology-based verification where appropriate • Applying risk-based approaches proportional to the nature of the service The "reasonable efforts" standard is deliberately flexible, recognising that the appropriate verification mechanism will vary by context. A gaming platform may require different verification than a government portal.

Exemptions from Verifiable Consent (R.12)

Rule 12 exempts five categories of entities from the verifiable parental consent requirement: 1. Clinical establishments or mental health establishments 2. Allied healthcare professionals 3. Educational institutions 4. Creches or child day care centres 5. Transport entities providing services for children These exemptions are narrowly scoped to the specific purpose of each category. A healthcare provider is exempt only for healthcare processing, not for marketing to children. Section 9(4) of the Act is the enabling power that lets Rule 12 disapply sections 9(1) (verifiable parental consent) and 9(3) (the tracking and targeting prohibitions) for these exempt entities and purposes.

The Exemption Power (Section 9(4) and 9(5))

Section 9(4) empowers the Central Government to notify that sub-sections (1) and (3) of section 9 shall not apply, or shall apply with modifications, to processing of a child's personal data by a Data Fiduciary or class of Data Fiduciaries for such purposes and subject to such conditions as may be prescribed. This is the enabling power behind the Rule 12 exemptions described above. Section 9(5) is a separate, narrower power: where the Central Government is satisfied that a Data Fiduciary has ensured its processing of children's personal data is done in a verifiably safe manner, it may notify the age above which that Data Fiduciary is exempt from all or any of the section 9(1) and 9(3) obligations, as specified in the notification. This allows individual Data Fiduciaries with verifiably safe processing to be exempted for older children, distinct from the class-wide, purpose-based exemptions under section 9(4). Separately, the Fourth Schedule to the Rules, Part B, made under section 9(4), sets out six purposes for which sections 9(1) and 9(3) do not apply: 1. Exercising a power, performing a function or discharging a duty in the interests of a child under any law in force, restricted to what is necessary for that purpose 2. Providing or issuing a subsidy, benefit, service, certificate, licence or permit in the interests of a child under section 7(b), restricted to what is necessary 3. Creating a user account for communication by email, limited to that use 4. Determining the real-time location of a child in the interest of her safety, protection or security, restricted to that tracking 5. Ensuring information, a service or an advertisement likely to cause a detrimental effect on a child's well-being is not accessible to her, restricted to that purpose 6. Confirming that the Data Principal is not a child and observing due diligence under Rule 10, restricted to what is necessary

Persons with Disabilities (R.11)

Rule 11 addresses the processing of personal data of persons with disabilities who have lawful guardians. The provisions parallel the children's data framework, requiring guardian consent and providing appropriate safeguards. This inclusion reflects the Act's intent to protect individuals who may not be in a position to provide fully informed consent on their own behalf, while respecting the dignity and autonomy of persons with disabilities through the framework of lawful guardianship.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.