Children's data
Could anyone under 18 use your product? Then India's strictest consent rules likely apply to you. Here's what handling children's data actually requires — and what's still being decided.
Who counts as a child
Under the DPDP Act, a child is anyone under 18. That is a single, bright line, with no graduated age bands. A 17-year-old on social media, a 15-year-old shopping online, and a 10-year-old gaming are all treated the same. That's broader than most global regimes. GDPR allows as low as 13–16, and the US COPPA uses under-13. This makes India's rule one of the most protective. The same protections extend to persons with disabilities, through their lawful guardian.
The three core duties
Section 9 adds three obligations on top of the normal consent rules:
- Verifiable parental consent — before you use any of a child's personal data, get consent from a parent or guardian. Then verify it.
- No tracking — you must not track or monitor a child's behaviour.
- No targeted advertising — you must not target ads at children.
Above all, Section 9 bars any processing likely to harm a child's well-being.
What "verifiable" actually means
A tick-box saying "I'm over 18" does not count. Nor does a child typing a parent's email. Rule 10 requires real technical and organisational measures. You must check that the person giving consent is really an identifiable adult. One way to do this is to verify identity against a reliable, government-backed digital identity, such as a DigiLocker-issued token. You, the Data Fiduciary, carry the burden of getting this right.
When does this apply?
These duties become enforceable during the phased rollout, and by full enforcement on 13 May 2027 at the latest. But verifiable-consent systems and age-gating take time to build. So treat this as a 2026 planning item if it affects you.
What the exemptions actually cover
NotifiedThe Fourth Schedule is part of the DPDP Rules, 2025. Rule 12 starts on 13 May 2027. Rule 12 disapplies two duties in two situations. The duties are verifiable parental consent (Section 9(1)) and no tracking (Section 9(3)). The situations are the classes of Data Fiduciary listed in Part A, and the purposes listed in Part B. Both are subject to the conditions written into the relevant Part.
Part A covers these classes (Fourth Schedule, Part A):
- clinical establishments, mental health establishments and healthcare professionals, for health services
- allied healthcare professionals, for a treatment or referral plan
- educational institutions, for tracking and monitoring for their educational activities or children's safety
- people who look after children in a crèche or day-care centre, for safety
- transport providers hired by a school, crèche or centre, for location tracking during the journey
Part B covers these purposes (Fourth Schedule, Part B):
- a power or duty under law, in the child's interests
- a subsidy, benefit, service, certificate, licence or permit for the child under Section 7(b)
- creating an email-only user account
- finding a child's real-time location for safety
- keeping harmful information, services or ads away from the child
- confirming that a user is not a child, as part of Rule 10 checks
Official text — DPDP Rules, 2025, Fourth Schedule
These exemptions are narrow, class-bound, purpose-bound, and conditional. They are not a general carve-out. If you run an EdTech, gaming, social, streaming or e-commerce product, assume they do not help you. Being adjacent to education or child safety is not the same as falling inside Part A or Part B. Read the conditions in the Schedule itself before relying on either.
What has NOT been notified is anything under Section 9(5). That is the power to let a specific Data Fiduciary process a child's data below age 18, where its processing is verifiably safe. We have not found any Section 9(5) notification. So 18 remains the line.
Official text — DPDP Act, 2023, Section 9(5)
Track this in what's still pending →
Does this apply to me?
Do you run a consumer-facing product where under-18s could plausibly sign up? Think social, gaming, e-commerce, EdTech, or streaming. Then plan for it: the realistic answer is yes. Are you strictly B2B with adult professional users? It's less likely to bite day-to-day. But even then, you still can't knowingly process a child's data without verifiable parental consent. This is general information, not legal advice.
Breaches of children's-data obligations sit in one of the Act's highest penalty tiers — up to ₹200 crore.
Sources
DPDP Act, 2023 — Sections 2(f) & 9
Notified — checked 2026-10-06. Opened the DPDP Act, 2023 (Gazette PDF). Partly in force: most duties start 13 May 2027 (G.S.R. 843(E)).
DPDP Rules, 2025 — Rule 10 (verifiable consent), Rule 12 & Fourth Schedule (exemptions)
Notified — checked 2026-10-06. Opened the DPDP Rules, 2025 (Gazette PDF).
PIB — DPDP Rules notification (background)
Status unverified — no status check recorded
The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.
Last updated: 17 August 2026 · Reviewed by Sandesh Kokate, Editor
Educational only. Re-verify against the Gazette of India before relying on anything here.
How does this apply to you?
Take the 2-minute self-check to find out whether you're a Data Fiduciary, Data Processor, or both — with your personalised action checklist.
Take the DPDP Applicability CheckYour answers stay in your browser. If you choose "Email me this report", we send your email address and result type to our report service.