Section 9(4) is the statutory power behind Rule 12: it lets the Central Government notify that sections 9(1) and 9(3) do not apply, or apply with modifications, to processing of a child's personal data by specified Data Fiduciaries or classes of Data Fiduciaries, for specified purposes and subject to prescribed conditions.
Section 9(5) is a separate power: where the Central Government is satisfied that a Data Fiduciary has ensured its processing of children's personal data is done in a verifiably safe manner, it may notify the age above which that Data Fiduciary is exempt from all or any of the section 9(1) and 9(3) obligations, as specified in the notification. Unlike Rule 12, which exempts whole categories of entity, section 9(5) allows an individual Data Fiduciary with verifiably safe processing to be exempted for children above a notified age.
Separately, the Fourth Schedule to the Rules, Part B, made under section 9(4), sets out six purposes for which sections 9(1) and 9(3) do not apply:
1. Exercising a power, performing a function or discharging a duty in the interests of a child under any law in force, restricted to what is necessary
2. Providing or issuing a subsidy, benefit, service, certificate, licence or permit in the interests of a child under section 7(b), restricted to what is necessary
3. Creating a user account for communication by email, limited to that use
4. Determining the real-time location of a child in the interest of her safety, protection or security, restricted to that tracking
5. Ensuring information, a service or an advertisement likely to cause a detrimental effect on a child's well-being is not accessible to her, restricted to that purpose
6. Confirming that the Data Principal is not a child and observing due diligence under Rule 10, restricted to what is necessary
See
Section 9 for the full framework.