What is verifiable consent under DPDP?
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
Verifiable consent is the consent required before processing personal data of a child or of a person with disability who has a lawful guardian: it must come from the parent or guardian. For parents, Rule 10 requires due diligence that the individual identifying as the parent is an adult who is identifiable, through two verification paths: reliable identity and age details already held, or details voluntarily provided directly or through a virtual token issued by an authorised entity, including via Digital Locker. For guardians, Rule 11 requires verifying court or authority appointment under guardianship law.
Ordinary consent is a design problem. Verifiable consent is a verification problem, and the Rules are unusually concrete about how to solve it.
Where the duty comes from
"The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed."
The manner prescribed is Rule 10 for parents and Rule 11 for lawful guardians.
The two parent verification paths
Rule 10 requires technical and organisational measures ensuring parental consent is obtained before processing a child's data, with due diligence that the individual identifying as the parent is an identifiable adult. Verification runs by reference to either reliable identity and age details already available to you, or details voluntarily provided, directly or through a virtual token mapped to them, issued by an authorised entity; a Digital Locker service provider is one route the rule names.
The rule then does something rare: it walks four illustrated cases, combining a child initiated and a parent initiated account with a parent who is or is not already your registered user. Product teams can map their onboarding directly onto those cases.
Guardians are verified differently
For a person with disability who has a lawful guardian, the due diligence is legal rather than biometric: verify that the guardian is appointed by a court, a designated authority or a local level committee under the applicable guardianship law. Rule 11 names the statutes that define those terms.
What to do
Run the children's data checker to see the full duty set with sources, and read Rule 10's official text with your onboarding flow open beside it.
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 9, (1), p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 10, p. 27. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026Rule 10 begins on Gazette page 27 and concludes on page 28.
- [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 11, p. 28. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026