Asia-Pacific India

DPDPA Children's Data Rules: Parental Consent to Age 18

India's DPDP Act sets the world's highest age for data consent: verifiable parental consent under 18, bans on tracking and targeted ads, and INR 200 crore penalties.

Regulation

Digital Personal Data Protection Act, 2023, section 9 (processing of children's data)

Max Penalty

Up to INR 200 crore for violating children's data obligations

Enforcing Authority

Data Protection Board of India

Official Source

www.meity.gov.in

Executive Summary

  • The DPDPA defines a child as anyone under 18, the highest age threshold among major privacy laws (COPPA: 13; GDPR: 13-16).
  • Processing a child's data requires verifiable parental (or lawful guardian) consent, with the draft 2025 rules specifying verification through existing account data, identity/age tokens, or Digital Locker credentials.
  • Three activities are banned outright for children: tracking, behavioral monitoring, and targeted advertising, regardless of consent.
  • Processing 'likely to cause detrimental effect on the well-being of a child' is prohibited as a general standard on top of the specific bans.
  • Violations carry penalties up to INR 200 crore; the government can exempt classes of fiduciaries (like health and education providers) or lower age gates for those processing data in ways verified as safe.

India wrote the strictest children’s privacy rules in any major market, and set the bar at an age no other regime touches: 18. Under DPDPA section 9, every user below the age of majority needs a verified parent behind them, and the three technologies that fund most consumer internet products, tracking, behavioral monitoring, targeted advertising, are banned for that entire cohort. For platforms whose Indian user base skews young, section 9 is not a compliance detail; it is a product-architecture decision.

RuleDPDPA s. 9 + draft DPDP Rules (2025)
ChildUnder 18
RequirementsVerifiable parental consent; no tracking, behavioral monitoring, or targeted ads
PenaltyUp to INR 200 crore
FrameworkMeitY

Engineering the requirement

Age assurance without over-collection. You cannot apply children’s rules without knowing who is a child, and you cannot demand government ID from everyone without violating data minimization. The draft rules’ three verification routes (existing verified account data, identity tokens, Digital Locker) all target the parent’s adulthood and identity, so the emerging pattern is: self-declared age at signup, risk-based escalation to verification, and parental flows triggered below 18.

Consent plumbing. Parental consent must satisfy the act’s general consent standard, free, specific, informed, affirmative, so the parent needs their own notice, their own withdrawal path, and linkage to the child’s account. Fiduciaries also inherit erasure and grievance duties running to both parent and child.

The ad-stack question. Because the tracking and targeted-advertising bans are consent-proof, the only compliant configurations are: no under-18 users (with credible age assurance), or under-18 modes with profiling, SDK-level tracking, and personalized ads disabled. Half-measures, personalization flags that still feed measurement pipelines, are exactly what audits of Significant Data Fiduciaries will probe.

Placement in the global stack

Operators already running COPPA gates and UK Children’s Code age-appropriate design have the machinery but the wrong thresholds and the wrong defaults; the India profile raises the age to 18 and converts “high privacy by default” into “prohibited outright”. Build the strictest profile once and parameterize by jurisdiction. The wider Indian regime is covered in the DPDPA guide and the GDPR comparison; test your public surfaces for trackers with a free scan.

Frequently Asked Questions

Why 18, and what does it mean in practice?

The act ties the threshold to India's age of majority rather than a policy-chosen digital age. Practically it means services popular with 13-17-year-olds, gaming, social, edtech, need parental-consent flows India has never operated at scale, and the age-assurance market becomes compliance infrastructure. The government can notify lower effective ages for fiduciaries that demonstrate verifiably safe processing.

What counts as verifiable parental consent?

The draft DPDP Rules offer three routes: matching against identity and age data the fiduciary already holds on the consenting parent; a virtual identity token issued against government ID; or Digital Locker-based verification. The design goal is confirming the consenting adult is an identifiable adult, not merely a checkbox claim of parenthood.

Is contextual advertising to children allowed?

The section 9 ban covers targeted advertising 'directed at children' plus tracking and behavioral monitoring. Contextual ads that do not rely on profiling the child are the generally understood safe harbor, but ad-tech supply chains rarely run clean contextual-only for logged-in minors, so most operators disable personalized ad stacks for under-18 accounts in India entirely.

How does this compare to COPPA and GDPR?

COPPA: under-13, parental consent, but behavioral advertising is possible with consent. GDPR Article 8: 13-16 for information-society services on consent basis only, no categorical ad ban. The DPDPA is strictest on all three axes: highest age, consent always required (no alternative basis), and advertising/tracking prohibited outright. The UK Children's Code approaches it in spirit but is a design code, not statute.

Are there exemptions?

Yes: the government can exempt classes of fiduciaries or purposes by notification, and the draft rules contemplate carve-outs for healthcare providers, educational institutions, and child-safety purposes, exempting them from specified consent and tracking restrictions where processing is necessary for those functions. Exemptions are function-scoped, not blanket.

Regulatory Crosswalk

COPPAGDPR Art. 8UK Children's Code

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.