Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

DPDP Rules 2025 · Fourth Schedule

Fourth Schedule: exemptions for processing of children's personal data

Status
Not yet in force
Commencement
13 May 2027 · computed date, presented as interpretation until officially confirmed (how it is computed)
Source
Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) · G.S.R. 846(E) · Gazette page 36
Last verified
17 August 2026

What the Fourth Schedule says, in plain English

Plain English

Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. The summary below is what the provision says, not what is in force today. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. Status last checked 28 September 2026 against the MeitY library and India Code.

Exemptions from section 9(1) and 9(3) of the Act for processing children's data come in two parts: Part A names classes of Data Fiduciaries, including healthcare providers, schools, crèches and child transport services, and Part B names purposes, including legal duties, benefits, email account creation, safety tracking, shielding children from harmful content and age confirmation, each under set conditions.

How 13 May 2027 is computed, and why it could be 1 day later

Publication date 13 November 2025 printed on Gazette issue No. 760, plus eighteen months. The eGazette portal lists this document with a code embedding 14112025 and the Government's own PIB release states 14 November 2025, which would move the computed date by 1 day; the printed masthead date is used, and the interpretation label carries that uncertainty. The corrigendum wording change does not affect this computation.

Official text of the Fourth Schedule, as corrected by G.S.R. 892(E)

Corrected by corrigenda G.S.R. 892(E)

  • For “.” read “;” (page 38, line 2)
  • For “(a) to (f)” read “(a) to (g)” (page 38, lines 1 to 15)

The text below shows the corrected wording.

Official requirement · as corrected by G.S.R. 892(E)

Fourth Schedule.FOURTH SCHEDULE [See rule 12] PART A Classes of Data Fiduciaries in respect of whom provisions of sub-sections (1) and (3) of section 9 shall not apply S. No. Class of Data Fiduciaries Conditions (1) (2) (3) 1. A Data Fiduciary who is a clinical establishment, mental health establishment or healthcare professional. Processing is restricted to provision of health services to the child by such establishment or professional, to the extent necessary for the protection of her health. 2. A Data Fiduciary who is an allied healthcare professional. Processing is restricted to supporting implementation of any healthcare treatment and referral plan recommended by such professional for the child, to the extent necessary for the protection of her health. 3. A Data Fiduciary who is an educational institution. Processing is restricted to tracking and behavioural monitoring — (a) for the educational activities of such institution; or (b) in the interests of safety of children enrolled with such institution. 4. A Data Fiduciary who is an individual in whose care infants and children in a crèche or child day care centre are entrusted. Processing is restricted to tracking and behavioural monitoring in the interests of safety of children entrusted in the care of such institution, crèche or centre. 5. A Data Fiduciary who is engaged by an educational institution, crèche or child care centre for transport of children enrolled with such institution, crèche or centre. Processing is restricted to tracking the location of such children, in the interests of their safety, during the course of their travel to and from such institution, crèche or centre. PART B Purposes for which provisions of sub-sections (1) and (3) of section 9 shall not apply S. No. Purposes Conditions (1) (2) (3) 1. For the exercise of any power, performance of any function or discharge of any duties in the interests of a child, under any law for the time being in force in India. Processing is restricted to the extent necessary for such exercise, performance or discharge. 2. For providing or issuing of any subsidy, benefit, service, certificate, licence or permit, by whatever name called, under law or policy or using public funds, in the interests of a child, under clause (b) of section 7 of the Act. Processing is restricted to the extent necessary for such provision or issuance. 3. For the creation of a user account for communicating by email. Processing is restricted to the extent necessary for creating such user account, the use of which is limited to communication by email. 4. For the determination of real-time location of a child. Processing is restricted to the tracking of real-time location of such child, in the interest of her safety and protection or security. 5. For ensuring that any information, service or advertisement likely to cause any detrimental effect on the well-being of a child is not accessible to her. Processing is restricted to the extent necessary to ensure that such information, service or advertisement is not accessible to the child. 6. For confirmation by the Data Fiduciary that the Data Principal is not a child and observance of due diligence under rule 10. Processing is restricted to the extent necessary for such confirmation or observance. Note: In this Schedule, — (a) “advertisement” shall have the same meaning as is assigned to it in the Consumer Protection Act, 2019 (35 of 2019); (b) “allied healthcare professional” shall have the same meaning as is assigned to it in the clause (d) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021); (c) “clinical establishment” shall have the same meaning as assigned to it in the clause (c) of section 2 of the Clinical Establishments (Registration and Regulation) Act, 2010 (23 of 2010); (d) “educational institution” shall mean and include an institution of learning that imparts education, including vocational education; (e) “healthcare professional” shall have the same meaning as is assigned to it in clause (j) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021); (f) “health services” shall mean the services required to be provided by a healthcare professional as referred to in clause (j) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021); and (g) “mental health establishment” shall have the same meaning as is assigned to it in clause (p) of sub-section (1) of section 2 of the Mental Healthcare Act, 2017 (10 of 2017).

Show the text as originally printed, before corrigendum

FOURTH SCHEDULE [See rule 12] PART A Classes of Data Fiduciaries in respect of whom provisions of sub-sections (1) and (3) of section 9 shall not apply S. No. Class of Data Fiduciaries Conditions (1) (2) (3) 1. A Data Fiduciary who is a clinical establishment, mental health establishment or healthcare professional. Processing is restricted to provision of health services to the child by such establishment or professional, to the extent necessary for the protection of her health. 2. A Data Fiduciary who is an allied healthcare professional. Processing is restricted to supporting implementation of any healthcare treatment and referral plan recommended by such professional for the child, to the extent necessary for the protection of her health. 3. A Data Fiduciary who is an educational institution. Processing is restricted to tracking and behavioural monitoring — (a) for the educational activities of such institution; or (b) in the interests of safety of children enrolled with such institution. 4. A Data Fiduciary who is an individual in whose care infants and children in a crèche or child day care centre are entrusted. Processing is restricted to tracking and behavioural monitoring in the interests of safety of children entrusted in the care of such institution, crèche or centre. 5. A Data Fiduciary who is engaged by an educational institution, crèche or child care centre for transport of children enrolled with such institution, crèche or centre. Processing is restricted to tracking the location of such children, in the interests of their safety, during the course of their travel to and from such institution, crèche or centre. PART B Purposes for which provisions of sub-sections (1) and (3) of section 9 shall not apply S. No. Purposes Conditions (1) (2) (3) 1. For the exercise of any power, performance of any function or discharge of any duties in the interests of a child, under any law for the time being in force in India. Processing is restricted to the extent necessary for such exercise, performance or discharge. 2. For providing or issuing of any subsidy, benefit, service, certificate, licence or permit, by whatever name called, under law or policy or using public funds, in the interests of a child, under clause (b) of section 7 of the Act. Processing is restricted to the extent necessary for such provision or issuance. 3. For the creation of a user account for communicating by email. Processing is restricted to the extent necessary for creating such user account, the use of which is limited to communication by email. 4. For the determination of real-time location of a child. Processing is restricted to the tracking of real-time location of such child, in the interest of her safety and protection or security. 5. For ensuring that any information, service or advertisement likely to cause any detrimental effect on the well-being of a child is not accessible to her. Processing is restricted to the extent necessary to ensure that such information, service or advertisement is not accessible to the child. 6. For confirmation by the Data Fiduciary that the Data Principal is not a child and observance of due diligence under rule 10. Processing is restricted to the extent necessary for such confirmation or observance. Note: In this Schedule, — (a) “advertisement” shall have the same meaning as is assigned to it in the Consumer Protection Act, 2019 (35 of 2019). (a) “allied healthcare professional” shall have the same meaning as is assigned to it in the clause (d) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021); (b) “clinical establishment” shall have the same meaning as assigned to it in the clause (c) of section 2 of the Clinical Establishments (Registration and Regulation) Act, 2010 (23 of 2010); (c) “educational institution” shall mean and include an institution of learning that imparts education, including vocational education; (d) “healthcare professional” shall have the same meaning as is assigned to it in clause (j) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021); (e) “health services” shall mean the services required to be provided by a healthcare professional as referred to in clause (j) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021); and (f) “mental health establishment” shall have the same meaning as is assigned to it in clause (p) of sub-section (1) of section 2 of the Mental Healthcare Act, 2017 (10 of 2017).

Commencement basis · Rules 3, 5 to 16, 22 and 23

“Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication in the Official Gazette.”

Wording as corrected by corrigenda G.S.R. 892(E).

Sources cited on this page

  1. [1]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), Fourth Schedule, p. 36. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmedThe Fourth Schedule begins on Gazette page 36 and concludes on page 38. As printed, the Note lists two items lettered (a). Corrigenda G.S.R. 892(E) item (v)(a) corrects the full stop after "(35 of 2019)" to a semicolon, and item (v)(b) relabels the Note items (a) to (g) across lines 1 to 15 of page 38; the corrected text applies both.
  2. [2]
    Corrigenda to the Digital Personal Data Protection Rules, 2025 (G.S.R. 892(E)), (v), p. 1. Published 11 December 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Pointer to the official correction, not a requirement · Verified 17 August 2026Document status: published; in effectItems (v)(a) and (v)(b) of corrigenda G.S.R. 892(E) state the corrections applied in the corrected text.
  3. [3]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Interpretation, requires judgment · Verified 17 August 2026In force since 13 November 2025Rule 1(4) names Rule 12, which this Schedule serves, in the group due eighteen months after publication and does not name the Schedules. The Fourth Schedule is presented as commencing with Rule 12 (computed 13 May 2027, interpretation until confirmed).
  4. [4]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Printed text, since corrected by G.S.R. 892(E); quoted as published · Verified 16 August 2026In force since 13 November 2025
    Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.
    As printed. Corrigenda G.S.R. 892(E) item (i)(b) corrects the closing words to read in the Official Gazette; the computation is unaffected.
  5. [5]
    Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Interpretation, requires judgment · Verified 16 August 2026Document status: published; text subject to corrigendum G.S.R. 892(E)The calendar date 13 May 2027 is computed from the printed publication date and is presented as interpretation until officially confirmed.
  6. [6]
    Corrigenda to the Digital Personal Data Protection Rules, 2025 (G.S.R. 892(E)), (v)(a), p. 1. Published 11 December 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official correction to the printed text, quoted · Verified 16 August 2026Document status: published; in effect
    in page 38, – (a) line 2, for “.”, read “;”
  7. [7]
    Corrigenda to the Digital Personal Data Protection Rules, 2025 (G.S.R. 892(E)), (v)(b), p. 1. Published 11 December 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official correction to the printed text, quoted · Verified 16 August 2026Document status: published; in effect
    (b) lines 1 to 15, for “(a) to (f)”, read “(a) to (g)”
    The corrigendum names a RANGE, lines 1 to 15 of page 38, and not a clause by clause instruction. That the range begins at line 1 is what shows the relettering reaches the first definition, the one ending “(35 of 2019)”, so that item becomes (a) and the 6 that follow move to (b) to (g). Recorded in the locator as line 1 to line_end 15 since 2026-08-28; before that the record held only the page and this note carried the range.