Why EdTech is uniquely affected by Section 9
Most sectors process children’s data incidentally. EdTech processes it as the primary business. Students are often the majority of users, and many are under eighteen.
Section 9 does not distinguish between educational and commercial use. The prohibition on tracking and behavioural monitoring applies regardless of intent. An adaptive learning algorithm that tracks a student’s progress, engagement and learning patterns is monitoring behaviour — even if the purpose is educational.
The Central Government may exempt certain classes of Data Fiduciaries from some Section 9 duties for verifiably safe processing (Section 9(4)). Until such notification, the full Section 9 applies.
Verifiable parental consent under Rule 10
Section 9(1) requires the Data Fiduciary to obtain verifiable consent of the parent or lawful guardian before processing a child’s personal data. Rule 10 prescribes the mechanism.
The consent must be verifiable — the Data Fiduciary must be able to confirm that the person consenting is the parent or lawful guardian. A simple checkbox is unlikely to satisfy this. The verification method must be proportionate to the risk.
The tracking and behavioural monitoring prohibition
Section 9(2) prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. For EdTech, this means:
- Engagement tracking (time on page, click patterns, scroll depth) used for product optimisation: this is behavioural monitoring.
- Adaptive learning algorithms that adjust content based on a student’s performance patterns: this processes behavioural data.
- Gamification metrics (points, streaks, leaderboards) based on a student’s activity: this monitors behaviour.
- Content recommendation based on a student’s history: this is personalisation based on behavioural data.
- Advertising to children based on their activity or interests: this is targeted advertising.
Each of these must be assessed. Some may be permissible if they do not constitute "tracking or behavioural monitoring" within the meaning of Section 9(2). The assessment depends on the specific implementation, the data processed and whether the processing is limited to the educational purpose.
Age verification and gate design
The platform must determine whether a user is a child before processing their data. Rule 10 prescribes the age verification mechanism. Common approaches:
- Self-declared age at sign-up: simple but not verifiable without additional checks.
- Parental email or phone verification: the parent confirms the child’s registration.
- Government ID-linked verification: proportionate for higher-risk processing.
The choice depends on the risk and the processing. A platform that collects minimal data may use a lighter mechanism. A platform that tracks behaviour must use a more robust one.
Product changes EdTech platforms may need
Compliance is not a policy layer on top of the existing product. It may require product changes:
- A separate data pathway for children that limits behavioural data collection.
- An opt-in model for adaptive features, with verifiable parental consent.
- Removing targeted advertising from the children’s experience entirely.
- A retention schedule that erases children’s data when they leave the platform or turn eighteen.
- A DSAR process that allows parents to exercise rights on behalf of their children.
How AMLEGALS advises EdTech platforms
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The team assesses each processing activity against Section 9, advises on age verification and parental consent mechanisms, reviews the adaptive learning pipeline for tracking and monitoring risks, and designs the product-level changes needed.

