AMLEGALS — Strategic Lawyering
Back to Documents
Framework

Children Data Consent Framework

Verifiable parental consent mechanisms for processing data of individuals under 18

Section 9Rule 10Rule 12

Children deserve heightened protection. DPDPA recognizes this by requiring verifiable parental consent before processing any personal data of individuals below 18 years. Rule 12 of the DPDP Rules, 2025 provides specific exemptions from certain obligations for prescribed categories of Data Fiduciaries.

The Age Threshold

Under DPDPA, a child is anyone below 18 years of age. This is higher than GDPR which typically uses 13-16 depending on member state. For any service that might be used by individuals under 18, you must have mechanisms to identify minors and obtain parental consent.

Verifiable Consent Requirement

Parental consent must be verifiable. A checkbox claiming parental approval is insufficient. You must implement mechanisms that provide reasonable assurance that the person consenting is actually the parent or legal guardian. The level of verification should be proportionate to the risks of the processing.

Key Points
  • Age verification before data collection
  • Parent or guardian identification
  • Consent verification mechanism
  • Record of consent with verification method

Prohibited Activities

Section 9 and Rule 10 restrict certain activities regarding children data. Tracking, behavioral monitoring, and targeted advertising directed at children are restricted. Processing that could cause significant harm to a child is prohibited. Rule 12 provides specific exemptions from certain of these obligations for prescribed categories of Data Fiduciaries.

EdTech and Educational Services

Rule 12 provides specific provisions for educational institutions and their data processors. Schools can process student data for educational purposes. EdTech providers processing on behalf of schools must adhere to educational purpose limitations. But commercial use of student data requires the full parental consent framework.

Essential Clauses

Age Verification Method

Section 9

How you determine if a user is under 18

Parent Identification Process

Rule 10

How you verify the consenting adult is a parent or guardian

Consent Verification Mechanism

Rule 10

Technical or procedural verification of parental consent

Prohibited Processing Declaration

Section 9(2)

Explicit statement of processing activities not conducted for children

Purpose Limitation for Children Data

Section 9

Restricted purposes for which children data may be processed

Consent Withdrawal by Parent

Section 6(4)

How parents can revoke consent

Child Attaining Majority

Section 9

How consent transitions when child turns 18

Implementation Steps

1

Assess whether your services may be used by individuals under 18

2

Implement age verification at account creation or data collection

3

Design parental consent flow triggered for identified minors

4

Select appropriate consent verification method based on processing risk

5

Build consent records including verification method used

6

Implement processing restrictions for children data

7

Disable prohibited features like behavioral tracking for child accounts

8

Create process for consent refresh when child turns 18

Frequently Asked Questions

Need This Document Drafted?

Understanding the requirement is the first step. Having it implemented correctly is what protects your organization. Our team drafts DPDPA-compliant documents tailored to your specific operations.

Get in Touch

DPDPA Children Data Consent: questions and answers

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

What makes consent valid under DPDPA?

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent.

Is a Data Fiduciary responsible for its vendors under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. Section 8(2) requires a Data Fiduciary to engage a Data Processor under a valid contract. Detailed contractual clause architecture is an implementation best practice guided by Section 8(2).

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Children Data Consent?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Children Data Consent under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Children Data Consent under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Children Data Consent?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Children Data Consent rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Children Data Consent?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Children Data Consent · DPDPA Exposure Assessment