Back to DPDP Rules

Children's Data Processing (R.10-12)

Rules 10-12 on children's data - verifiable parental consent, age verification, persons with disabilities, and five categories of exempt entities.

7 min read

Age Verification (Rule 10)

Rule 10 requires Data Fiduciaries to make reasonable efforts to verify that consent for processing a child's data is given by a parent or lawful guardian. The standard is 'reasonable efforts' - not absolute certainty - recognising practical limitations in age verification. Organisations must implement mechanisms to identify users who may be children and trigger the parental consent workflow. This could include age gates, self-declaration, or technical verification methods.

Persons with Disabilities (Rule 11)

Rule 11 addresses data processing for persons with disabilities, recognising that guardians or lawful representatives may need to exercise data protection rights on behalf of persons with disabilities who may not be able to do so independently. The provision ensures that the DPDPA's protections extend effectively to persons with disabilities while respecting their dignity and autonomy to the extent possible.

Five Exempt Categories (Rule 12)

Rule 12 exempts five categories of entities from the verifiable parental consent requirement: 1. Clinical establishments or mental health establishments - recognising the need for children's healthcare to operate efficiently 2. Allied healthcare professionals - enabling healthcare professionals to process children's data for treatment purposes 3. Educational institutions - allowing schools and colleges to process student data without requiring verifiable parental consent for educational purposes 4. Creches or child day care centres - enabling childcare providers to process children's data for care purposes 5. Transport entities providing services for children - allowing school transport and similar services to process children's data for safety and logistics Rule 12 is made under the power in section 9(4) of the Act, which lets the Central Government disapply sections 9(1) (verifiable parental consent) and 9(3) (tracking, behavioural monitoring, and targeted advertising) for notified purposes and classes of Data Fiduciary. For these five categories, both prohibitions are disapplied within the scope of the exemption, not only the consent requirement. See Section 9 for the full framework.

The Exemption Power (Section 9(4) and 9(5))

Section 9(4) is the statutory power behind Rule 12: it lets the Central Government notify that sections 9(1) and 9(3) do not apply, or apply with modifications, to processing of a child's personal data by specified Data Fiduciaries or classes of Data Fiduciaries, for specified purposes and subject to prescribed conditions. Section 9(5) is a separate power: where the Central Government is satisfied that a Data Fiduciary has ensured its processing of children's personal data is done in a verifiably safe manner, it may notify the age above which that Data Fiduciary is exempt from all or any of the section 9(1) and 9(3) obligations, as specified in the notification. Unlike Rule 12, which exempts whole categories of entity, section 9(5) allows an individual Data Fiduciary with verifiably safe processing to be exempted for children above a notified age. Separately, the Fourth Schedule to the Rules, Part B, made under section 9(4), sets out six purposes for which sections 9(1) and 9(3) do not apply: 1. Exercising a power, performing a function or discharging a duty in the interests of a child under any law in force, restricted to what is necessary 2. Providing or issuing a subsidy, benefit, service, certificate, licence or permit in the interests of a child under section 7(b), restricted to what is necessary 3. Creating a user account for communication by email, limited to that use 4. Determining the real-time location of a child in the interest of her safety, protection or security, restricted to that tracking 5. Ensuring information, a service or an advertisement likely to cause a detrimental effect on a child's well-being is not accessible to her, restricted to that purpose 6. Confirming that the Data Principal is not a child and observing due diligence under Rule 10, restricted to what is necessary See Section 9 for the full framework.

Frequently Asked Questions

Was this useful?

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.