Children's data and verifiable consent
In short
A child is an individual who has not completed eighteen years of age. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the parent or the lawful guardian. Section 9 also prohibits processing that is likely to cause any detrimental effect on the well being of a child, and prohibits tracking, behavioural monitoring and targeted advertising directed at children.
Rule 10 sets out how the parent is to be verified, Rule 11 covers a person with a disability who has a lawful guardian, and Rule 12 with the Fourth Schedule sets out the classes of Data Fiduciary and the purposes for which the Section 9(1) and 9(3) obligations do not apply.
01How a parent is verified under Rule 10
The Data Fiduciary must adopt appropriate technical and organisational measures to ensure verifiable parental consent is obtained, and must observe due diligence to check that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law in force in India. The check is made by reference to either:
- reliable details of identity and age already held by the Data Fiduciary; or
- details of identity and age voluntarily provided by the individual, or provided through a virtual token mapped to such details issued by an authorised entity.
An adult means an individual who has completed eighteen years of age. An authorised entity means an entity entrusted by law or by the Central or State Government with issuing identity and age details or a virtual token mapped to them, or a person appointed or permitted by such an entity, and includes details made available and verified by a Digital Locker service provider.
Rule 10 works through four illustrated cases, distinguishing a parent who is already a registered user with identity details on file from one who is not. The design consequence is that an organisation with a verified adult user base has a materially lighter path than one starting from nothing.
02Exempted classes and purposes
Rule 12 disapplies Section 9(1) and 9(3) for the classes in Part A of the Fourth Schedule and the purposes in Part B, each subject to stated conditions.
| Part A, classes | Condition, in summary |
|---|---|
| Clinical establishment, mental health establishment or healthcare professional | Processing restricted to provision of health services to the child, to the extent necessary to protect her health |
| Allied healthcare professional | Restricted to supporting a treatment and referral plan for the child |
| Educational institution | Restricted to tracking and behavioural monitoring for educational activities or for the safety of enrolled children |
| Individual in whose care children in a creche or day care centre are entrusted | Restricted to tracking and behavioural monitoring in the interests of safety |
| Entity engaged for transport of enrolled children | Restricted to tracking location during travel to and from the institution |
Part B covers purposes rather than entities, including exercise of a power or function in the interests of a child under law, issuing a subsidy, benefit, service, certificate, licence or permit in the interests of a child, creating an email account, determining a child's real time location in the interests of her safety, restricting access to content likely to be detrimental to her well being, and confirming that a Data Principal is not a child.
Each exemption is conditional and narrow. The condition column is the operative part, not the class column.
03Persons with disability, Rule 11
Where consent is obtained from an individual identifying herself as the lawful guardian of a person with disability, the Data Fiduciary must observe due diligence to verify that the guardian is appointed by a court of law, or by a designated authority under Section 15 of the Rights of Persons with Disabilities Act 2016, or by a local level committee under Section 13 of the National Trust Act 1999.
04Common questions
What age is a child under the DPDP Act?
An individual who has not completed eighteen years of age.
Is age verification of every user required?
The Act requires verifiable parental consent before processing a child's personal data. Part B of the Fourth Schedule specifically permits processing to the extent necessary to confirm that a Data Principal is not a child, and to observe due diligence under Rule 10.
Can a school track enrolled children?
Part A of the Fourth Schedule disapplies Sections 9(1) and 9(3) for an educational institution where processing is restricted to tracking and behavioural monitoring for its educational activities or in the interests of the safety of enrolled children.
Ask an AI assistant about this page
Each button opens the assistant with the prompt below already written.
Answers are generated by third party systems and are not published or verified by this site. Check anything load bearing against the gazette text.