Who is a child, and what Section 9 requires
Under the Act a child is an individual who has not completed eighteen years of age. This is higher than the age used in several overseas regimes, and it means many mainstream services will process some children’s data.
Section 9(1) requires a Data Fiduciary, before processing any personal data of a child, to obtain verifiable consent of the parent or lawful guardian, in the manner prescribed. The same approach applies to a person with disability who has a lawful guardian.
What is prohibited for children
Section 9(3) sets out firm prohibitions. A Data Fiduciary must not:
- Undertake processing that is likely to cause any detrimental effect on the well-being of a child.
- Undertake tracking or behavioural monitoring of children.
- Undertake targeted advertising directed at children.
These are not balanced against a business interest. They are prohibitions that apply once the Data Principal is a child, which is why reliable age assurance matters at the design stage.
Verifiable parental consent and age verification
Rule 10 of the DPDP Rules, 2025 sets out how verifiable consent is to be obtained. In practice this means the Data Fiduciary must take reasonable steps to confirm that the person giving consent is the parent or lawful guardian and is an adult, which can draw on reliable identity and age details already available or on a voluntary verification.
The design question for any service is how to tell whether a user is a child before processing begins, without collecting more data than necessary. Age assurance should itself be proportionate and should not become an excuse for excessive data collection.
Exemptions and a possible lower age
Section 9(4) allows the Central Government to notify, for certain classes of Data Fiduciary or for certain purposes, that the obligations in Section 9(1) and Section 9(3) apply in a modified form, or that a lower age than eighteen applies, subject to conditions. This provides room for services such as education or health to be treated appropriately, but only to the extent notified.
Until such a notification applies to an organisation, the full Section 9 regime governs any processing of children’s data.
How AMLEGALS advises on children’s data
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team assesses whether a service processes children’s data, designs the verifiable consent flow under Rule 10, and reviews advertising and analytics so they do not breach the Section 9(3) prohibitions.

