Back to DPDP Rules
Children's Data Processing (R.9-12)
Rules 9-12 on children's data - verifiable parental consent, age verification, persons with disabilities, and five categories of exempt entities.
7 min read
Age Verification (Rule 9)
Rule 9 requires Data Fiduciaries to make reasonable efforts to verify that consent for processing a child's data is given by a parent or lawful guardian. The standard is 'reasonable efforts' - not absolute certainty - recognising practical limitations in age verification.
Organisations must implement mechanisms to identify users who may be children and trigger the parental consent workflow. This could include age gates, self-declaration, or technical verification methods.
Verifiable Parental Consent (Rule 10)
Rule 10 prescribes mechanisms for verifiable parental consent:
• Verification through a virtual token issued to the parent
• Verification through an identity document of the parent
• Other prescribed means that provide reasonable assurance of parental identity
The consent must be specific to the processing purposes and can be withdrawn by the parent at any time. The Data Fiduciary must maintain records of parental consent obtained.
Persons with Disabilities (Rule 11)
Rule 11 addresses data processing for persons with disabilities, recognising that guardians or lawful representatives may need to exercise data protection rights on behalf of persons with disabilities who may not be able to do so independently.
The provision ensures that the DPDPA's protections extend effectively to persons with disabilities while respecting their dignity and autonomy to the extent possible.
Five Exempt Categories (Rule 12)
Rule 12 exempts five categories of entities from the verifiable parental consent requirement:
1. Clinical establishments or mental health establishments - recognising the need for children's healthcare to operate efficiently
2. Allied healthcare professionals - enabling healthcare professionals to process children's data for treatment purposes
3. Educational institutions - allowing schools and colleges to process student data without requiring verifiable parental consent for educational purposes
4. Creches or child day care centres - enabling childcare providers to process children's data for care purposes
5. Transport entities providing services for children - allowing school transport and similar services to process children's data for safety and logistics
Importantly, these exemptions only remove the verifiable parental consent requirement. The prohibition on tracking, behavioural monitoring, and targeted advertising directed at children under Section 9 still applies to all entities.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
