DPDP Rules status: compliance window active. Read the update

Skip to content
Data Privacy · Section 9

Children's data

Could anyone under 18 use your product? Then India's strictest consent rules likely apply to you. Here's what handling children's data actually requires — and what's still being decided.

Educational only · not legal adviceLast updated: 17 August 2026Reviewed by Sandesh Kokate, Editor

Who counts as a child

Under the DPDP Act, a child is anyone under 18. That is a single, bright line, with no graduated age bands. A 17-year-old on social media, a 15-year-old shopping online, and a 10-year-old gaming are all treated the same. That's broader than most global regimes. GDPR allows as low as 13–16, and the US COPPA uses under-13. This makes India's rule one of the most protective. The same protections extend to persons with disabilities, through their lawful guardian.

The three core duties

Section 9 adds three obligations on top of the normal consent rules:

  • Verifiable parental consent — before you use any of a child's personal data, get consent from a parent or guardian. Then verify it.
  • No tracking — you must not track or monitor a child's behaviour.
  • No targeted advertising — you must not target ads at children.

Above all, Section 9 bars any processing likely to harm a child's well-being.

What "verifiable" actually means

A tick-box saying "I'm over 18" does not count. Nor does a child typing a parent's email. Rule 10 requires real technical and organisational measures. You must check that the person giving consent is really an identifiable adult. One way to do this is to verify identity against a reliable, government-backed digital identity, such as a DigiLocker-issued token. You, the Data Fiduciary, carry the burden of getting this right.

When does this apply?

These duties become enforceable during the phased rollout, and by full enforcement on 13 May 2027 at the latest. But verifiable-consent systems and age-gating take time to build. So treat this as a 2026 planning item if it affects you.

What the exemptions actually cover

Notified

The Fourth Schedule is part of the DPDP Rules, 2025. Rule 12 starts on 13 May 2027. Rule 12 disapplies two duties in two situations. The duties are verifiable parental consent (Section 9(1)) and no tracking (Section 9(3)). The situations are the classes of Data Fiduciary listed in Part A, and the purposes listed in Part B. Both are subject to the conditions written into the relevant Part.

Part A covers these classes (Fourth Schedule, Part A):

  • clinical establishments, mental health establishments and healthcare professionals, for health services
  • allied healthcare professionals, for a treatment or referral plan
  • educational institutions, for tracking and monitoring for their educational activities or children's safety
  • people who look after children in a crèche or day-care centre, for safety
  • transport providers hired by a school, crèche or centre, for location tracking during the journey

Part B covers these purposes (Fourth Schedule, Part B):

  • a power or duty under law, in the child's interests
  • a subsidy, benefit, service, certificate, licence or permit for the child under Section 7(b)
  • creating an email-only user account
  • finding a child's real-time location for safety
  • keeping harmful information, services or ads away from the child
  • confirming that a user is not a child, as part of Rule 10 checks
Official text — DPDP Rules, 2025, Fourth Schedule
PART A Classes of Data Fiduciaries in respect of whom provisions of sub-sections (1) and (3) of section 9 shall not apply 1. A Data Fiduciary who is a clinical establishment, mental health establishment or healthcare professional. Conditions: Processing is restricted to provision of health services to the child by such establishment or professional, to the extent necessary for the protection of her health. 2. A Data Fiduciary who is an allied healthcare professional. Conditions: Processing is restricted to supporting implementation of any healthcare treatment and referral plan recommended by such professional for the child, to the extent necessary for the protection of her health. 3. A Data Fiduciary who is an educational institution. Conditions: Processing is restricted to tracking and behavioural monitoring— (a) for the educational activities of such institution; or (b) in the interests of safety of children enrolled with such institution. 4. A Data Fiduciary who is an individual in whose care infants and children in a crèche or child day care centre are entrusted. Conditions: Processing is restricted to tracking and behavioural monitoring in the interests of safety of children entrusted in the care of such institution, crèche or centre. 5. A Data Fiduciary who is engaged by an educational institution, crèche or child care centre for transport of children enrolled with such institution, crèche or centre. Conditions: Processing is restricted to tracking the location of such children, in the interests of their safety, during the course of their travel to and from such institution, crèche or centre. PART B Purposes for which provisions of sub-sections (1) and (3) of section 9 shall not apply 1. For the exercise of any power, performance of any function or discharge of any duties in the interests of a child, under any law for the time being in force in India. Conditions: Processing is restricted to the extent necessary for such exercise, performance or discharge. 2. For providing or issuing of any subsidy, benefit, service, certificate, licence or permit, by whatever name called, under law or policy or using public funds, in the interests of a child, under clause (b) of section 7 of the Act. Conditions: Processing is restricted to the extent necessary for such provision or issuance. 3. For the creation of a user account for communicating by email. Conditions: Processing is restricted to the extent necessary for creating such user account, the use of which is limited to communication by email. 4. For the determination of real-time location of a child. Conditions: Processing is restricted to the tracking of real-time location of such child, in the interest of her safety and protection or security. 5. For ensuring that any information, service or advertisement likely to cause any detrimental effect on the well-being of a child is not accessible to her. Conditions: Processing is restricted to the extent necessary to ensure that such information, service or advertisement is not accessible to the child. 6. For confirmation by the Data Fiduciary that the Data Principal is not a child and observance of due diligence under rule 10. Conditions: Processing is restricted to the extent necessary for such confirmation or observance.

These exemptions are narrow, class-bound, purpose-bound, and conditional. They are not a general carve-out. If you run an EdTech, gaming, social, streaming or e-commerce product, assume they do not help you. Being adjacent to education or child safety is not the same as falling inside Part A or Part B. Read the conditions in the Schedule itself before relying on either.

What has NOT been notified is anything under Section 9(5). That is the power to let a specific Data Fiduciary process a child's data below age 18, where its processing is verifiably safe. We have not found any Section 9(5) notification. So 18 remains the line.

Official text — DPDP Act, 2023, Section 9(5)
(5) The Central Government may, if satisfied that a Data Fiduciary has ensured that its processing of personal data of children is done in a manner that is verifiably safe, notify for such processing by such Data Fiduciary the age above which that Data Fiduciary shall be exempt from the applicability of all or any of the obligations under sub-sections (1) and (3) in respect of processing by that Data Fiduciary as the notification may specify.

Track this in what's still pending →

Does this apply to me?

Do you run a consumer-facing product where under-18s could plausibly sign up? Think social, gaming, e-commerce, EdTech, or streaming. Then plan for it: the realistic answer is yes. Are you strictly B2B with adult professional users? It's less likely to bite day-to-day. But even then, you still can't knowingly process a child's data without verifiable parental consent. This is general information, not legal advice.

Breaches of children's-data obligations sit in one of the Act's highest penalty tiers — up to ₹200 crore.

Sources

Source
MeitY — DPDP Act (Gazette PDF)

DPDP Act, 2023 — Sections 2(f) & 9

Notified — checked 2026-10-06. Opened the DPDP Act, 2023 (Gazette PDF). Partly in force: most duties start 13 May 2027 (G.S.R. 843(E)).

Source
MeitY — DPDP Rules, 2025 (Gazette PDF)

DPDP Rules, 2025 — Rule 10 (verifiable consent), Rule 12 & Fourth Schedule (exemptions)

Notified — checked 2026-10-06. Opened the DPDP Rules, 2025 (Gazette PDF).

Source
PIB — DPDP Rules notification (background)

PIB — DPDP Rules notification (background)

Status unverified — no status check recorded

The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.

Last updated: 17 August 2026 · Reviewed by Sandesh Kokate, Editor

Educational only. Re-verify against the Gazette of India before relying on anything here.

How does this apply to you?

Take the 2-minute self-check to find out whether you're a Data Fiduciary, Data Processor, or both — with your personalised action checklist.

Take the DPDP Applicability Check

Your answers stay in your browser. If you choose "Email me this report", we send your email address and result type to our report service.