Skip to main content

Sources last verified on 17 August 2026. Methodology

DPDP rules for children's personal data

Children

By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed

The short answer

A child is anyone under eighteen. Before processing a child's personal data, verifiable consent of the parent or lawful guardian is required, with due diligence that the person consenting is an identifiable adult. The Act separately prohibits processing likely to cause detrimental effect on a child's wellbeing, and tracking, behavioural monitoring and targeted advertising directed at children. Exemptions exist for prescribed classes and purposes, subject to conditions, and deciding whether one fits you is legal judgment.

The child data provisions are among the most operationally demanding in the framework, because they require verification machinery, not just policy text.

Eighteen is the line

The Act defines a child as an individual who has not completed the age of eighteen years. There is no lower tier in the definition; the Act does allow the government, for a Data Fiduciary it is satisfied processes children's data in a verifiably safe manner, to notify an age above which that fiduciary is exempt from some or all of the consent and tracking obligations. The definition of child stays at eighteen.

What the Act prohibits outright

Beyond consent, section 9 prohibits processing likely to cause any detrimental effect on the wellbeing of a child, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. For consumer products this is frequently the harder constraint, because it reaches analytics and advertising architecture, not just sign up flows.

What verifiable parental consent requires

Rule 10 requires technical and organisational measures to ensure verifiable parental consent before processing a child's personal data, with due diligence that the individual identifying as the parent is an identifiable adult. The rule gives two verification paths and illustrates them with four concrete cases; the verifiable consent deep dive walks them one by one.

Rule 11 adds the parallel duty for lawful guardians of persons with disability: verify that the guardian is appointed by a court, designated authority or local level committee under the applicable guardianship law.

The exemptions are conditional

Certain classes of Data Fiduciaries and purposes are exempt from parts of section 9, subject to the conditions in the Fourth Schedule. The classes and conditions are being ingested on this site with verification; whether an educational or health context fits one is a legal judgment, not a default.

What to do

Run the children's data checker to see which duties are in play for you. The official texts live at Rule 10, Rule 11 and Rule 12.

Rule 10, official textThe education guide

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(f), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  2. [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 9, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  3. [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 10, p. 27. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026Rule 10 begins on Gazette page 27 and concludes on page 28.
  4. [4]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026Rules 10 to 12 are in the eighteen month commencement group; the computed date 13 May 2027 is interpretation until officially confirmed.

childrenparental consentrule 10