In short: Under India’s DPDP Act and the DPDP Rules 2025, DPDP children’s data parental consent India requirements mean every startup or app that processes data of anyone under 18 must obtain verifiable consent from a parent or guardian — before any processing begins — and is absolutely prohibited from tracking or targeting children with behavioural ads.
Key points
- The DPDP Act defines a “child” as anyone under 18 years of age — a broader threshold than many global regimes, including the US COPPA framework which covers only under-13s.
- Section 9(1) of the DPDP Act requires a Data Fiduciary to obtain verifiable parental or guardian consent before processing any child’s personal data, with no exception for implied or passive consent.
- The DPDP Rules 2025, notified on 13 November 2025, operationalise this through Rules 10, 11, and 12, which set out precise verification systems, permitted exemptions, and special safeguards.
- Platforms must verify that the consenting person is genuinely a parent or guardian — self-declaration by a child pretending to be an adult is not sufficient compliance.
- Behavioural tracking and targeted advertising directed at children are absolutely prohibited under the Act, regardless of whether parental consent has been obtained.
- Violations of children’s data obligations can attract penalties of up to ₹200 crore per violation under the Act’s penalty schedule.
What is the legal framework for children’s data under the DPDP Act?
India’s Digital Personal Data Protection Act, 2023 was published on 11 August 2023. The DPDP Rules 2025 were then notified on 13 November 2025 via Gazette Notification G.S.R. 846(E), issued by the Ministry of Electronics and Information Technology (MeitY).
Together, the Act and the Rules create a layered compliance structure. The Act sets out the core obligations and prohibitions. The Rules fill in the operational detail — particularly around how verification must actually work in practice.
For startups and app developers, the most immediately relevant provisions are Section 9 of the Act (the primary obligation) and Rules 10, 11, and 12 of the 2025 Rules (the implementation mechanics).
Who counts as a “child” under the DPDP Act?
Under Section 2(f) of the Act, a child is any individual who has not completed the age of eighteen years. This aligns with India’s general age of majority under civil law.
This is a notably broad definition compared to some international frameworks. Consider the comparison below:
| Jurisdiction / Law | Definition of “Child” for Data Protection |
|---|---|
| India — DPDP Act, 2023 | Under 18 years of age |
| USA — COPPA | Under 13 years of age |
| India — General age of majority | 18 years (aligns with Act) |
The practical consequence for Indian startups is significant: a platform that assumed it only needed to worry about very young children is almost certainly wrong. If your app is used by teenagers — students, gamers, social users — they are all “children” under the Act until they turn 18.
What does Section 9 of the DPDP Act actually require?
Section 9(1) of the Act states that a Data Fiduciary must, before processing any personal data of a child (or a person with a disability who has a lawful guardian), obtain the verifiable consent of the parent or lawful guardian.
The word “before” is critical. You cannot process first and seek consent afterwards. Consent must precede any data processing activity involving a child.
Section 9(3) goes further by imposing two absolute prohibitions, which apply regardless of whether parental consent has been obtained:
- No behavioural tracking: Platforms cannot track or monitor a child’s activity across an app or website to build a profile of that child.
- No targeted advertising: Advertisements directed at children based on user profiles or behavioural data are banned outright. Purely contextual ads — those that do not involve any tracking or profiling — may be permissible, but this distinction requires careful legal assessment for each use case.
These prohibitions are structural, not just procedural. You cannot “consent your way out” of them. Even if a parent provides full consent, a platform still cannot engage in behavioural tracking or targeted advertising directed at that child.
How must verifiable parental consent actually be obtained? Rules 10, 11, and 12 explained
The core requirement under Rule 10
Rule 10 of the DPDP Rules 2025 sets out that no child’s personal data may be processed without verifiable parental consent. A fiduciary must adopt both technical and organisational measures to ensure the person giving consent is genuinely a parent or guardian — not the child themselves using a workaround.
The parent’s identity and age details must be verified from reliable records. The Rules specifically identify government-backed tools such as Aadhaar or DigiLocker as examples of acceptable verification mechanisms.
Two permitted verification methods
The Rules provide for two routes to verify a parent’s identity and age:
- Existing platform records: If the parent is already a registered user of your platform and their age and identity details are already on file, those details may be used to verify them as a consenting adult. This is described in the Rules as verification by reference to “reliable details” already held by the Data Fiduciary.
- Government-backed identity or age tokens: Where the parent is not already a verified user, platforms must use government-issued or government-backed mechanisms — such as Aadhaar-based verification or DigiLocker — to confirm the parent’s identity and age before processing their child’s data.
The underlying policy rationale is clear: without this verification, a child could simply claim to be their own parent through self-declaration, rendering the consent requirement meaningless.
Why this matters operationally for developers
For most startups, the first verification route will only be available in a narrow set of circumstances — where your platform already has a verified adult user who is then identified as the child’s parent. In practice, many platforms will need to build Aadhaar or DigiLocker integration into their onboarding flow for child users.
This is not a trivial technical or commercial decision. It has implications for onboarding friction, user experience, third-party API costs, and data minimisation obligations. You should factor it into your product roadmap now, not after launch.
For a broader overview of digital compliance obligations that affect founders and small businesses, see our Law for You guides on thecourtroom.in, which cover data protection, contracts, and regulatory compliance in plain language.
What are the penalties for getting this wrong?
The DPDP Act’s penalty schedule is graduated by the nature of the violation. For violations of obligations specifically relating to children, the Act provides for penalties of up to ₹200 crore per violation. The highest penalty in the Act — up to ₹250 crore — applies to failures to maintain reasonable security safeguards.
These are not nominal figures. For an early-stage startup, a penalty at this level would be existential. And because each violation is assessed separately, multiple instances of non-compliance could compound quickly.
Practical compliance checklist for founders and developers
Based solely on the verified legal requirements in the Act and the 2025 Rules, here is a practical starting-point checklist. This is not exhaustive, and you should take specific legal advice for your platform’s circumstances.
| Compliance Step | Relevant Provision | Key Action |
|---|---|---|
| Identify whether your platform processes children’s data | Section 2(f) DPDP Act | Audit your user base — anyone under 18 is a child under the Act |
| Gate access pending parental consent | Section 9(1) DPDP Act | No processing before verified parental consent is obtained |
| Implement a verifiable consent mechanism | Rule 10, DPDP Rules 2025 | Use existing verified records or integrate Aadhaar/DigiLocker |
| Remove behavioural tracking for child users | Section 9(3) DPDP Act | Disable cross-platform and in-app profiling for under-18 users |
| Remove targeted advertising for child users | Section 9(3) DPDP Act | Switch to purely contextual ads or no ads for under-18 users |
| Document your verification process | Rules 10–12, DPDP Rules 2025 | Maintain records of how parental consent was verified |
Frequently asked questions
Does the DPDP Act’s parental consent requirement apply to my app if it is not specifically designed for children?
Yes. The Act does not limit its children’s data obligations to platforms that are intentionally directed at children. If your platform processes the personal data of any user who is under 18, the parental consent and anti-tracking requirements apply, regardless of your intended audience. If your platform could foreseeably be used by teenagers, you need a compliance strategy for child users.
Can a parent simply tick a checkbox to give verifiable consent under the DPDP Rules 2025?
No. The Rules specifically require that the consenting person’s identity and age be verified — either through reliable records already held by the platform or through government-backed tools such as Aadhaar or DigiLocker. A simple self-declaration or checkbox is not sufficient, because the Rules are designed to prevent a child from impersonating a parent to bypass the consent gate.
If I obtain verifiable parental consent, can I then show targeted ads to child users on my platform?
No. The prohibition on targeted advertising directed at children under Section 9(3) of the Act is absolute — it applies regardless of whether parental consent has been obtained. Consent does not unlock the ability to engage in behavioural tracking or targeted advertising for child users. Purely contextual advertising that involves no tracking or profiling may be a different matter, but each use case should be assessed carefully with legal advice.
Primary sources
- Digital Personal Data Protection Act, 2023 — India Code (indiacode.nic.in)
- Ministry of Electronics and Information Technology (MeitY) — official DPDP Rules notifications
- Press Information Bureau (PIB) — official government releases on the DPDP Rules 2025
Written by Editorial Team, The Courtroom · Last verified 2026-07-14
This article is for general information only and is not legal advice. Laws change; verify against the primary sources cited and consult a qualified advocate for your situation.



