DPDPA Phase II enforcement 13 November 2026 — penalties up to ₹250 crore. Check your readiness →
Book a Demo
How-To

Children's Data Under DPDPA Section 9: Verifiable Parental Consent, Explained

Data Adhikaar Editorial Team 6 July 2026 2 min read
Children's Data Under DPDPA Section 9: Verifiable Parental Consent, Explained

India's DPDPA sets one of the world's strictest bars for children's data: a child is anyone under 18, and processing their personal data requires verifiable consent from a parent or lawful guardian (Section 9(1)).

The three Section 9 obligations

  1. Verifiable parental consent before processing a child's personal data.
  2. No processing likely to cause detrimental effect on a child's well-being (Section 9(2)).
  3. No tracking, behavioural monitoring, or targeted advertising directed at children (Section 9(3)).

Penalty ceiling for getting this wrong: ₹200 crore.

What "verifiable" means under the DPDP Rules 2025

The Rules require the Data Fiduciary to adopt appropriate technical and organisational measures to check that the person granting consent is an adult who is the child's parent or guardian — using reliable identity and age details already held, or details verified through services such as Digital Locker (DigiLocker) or other government-issued identity mechanisms. A simple "I am over 18" checkbox does not survive this test.

Who must care — beyond edtech

Any platform a minor can realistically use: edtech and gaming, social apps, e-commerce with student segments, healthcare (paediatrics), coaching institutes, even HR systems processing apprentice data. If your age-gate is decorative, your first compliance question is "do we knowingly or should-knowingly process children's data?"

Exemptions

The Rules exempt certain classes — for example healthcare professionals treating a child, or educational institutions for defined purposes — from parts of Section 9, subject to conditions. Exemptions are narrow; read them precisely before relying on one.

An implementation blueprint

  • Age assurance: a declared date of birth plus risk-based verification for restricted features.
  • Parental consent flow: verify the parent's identity/age (DigiLocker-class evidence), record the consent artefact, link it to the child's record.
  • Feature gating: disable tracking, profiling, personalised ads and dark-pattern engagement loops for child accounts.
  • Evidence: retain the verification and consent trail — you will need to prove it years later.

Sammati captures and proves parental consent in the parent's language, and Drishti flags children's data the moment it appears in a connected system unregistered. See how it fits your sector in DPDPA for EdTech.

#childrens-data#parental-consent#section-9#edtech#dpdpa

Data Adhikaar Editorial Team

DPDPA Compliance Specialists, Qodequay Technologies

Get DPDPA-ready before the enforcement window closes.

Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.

Or call +91 98226 28174