DPDPA for Online Gaming
Every other sector can comply with Section 9 by adding a gate. Gaming cannot. A large part of the user base is under eighteen, and the prohibition on tracking and targeted advertising reaches the revenue model itself.
A date of birth field is not age assurance. It is a record of what the user typed. Section 9 uses the word verifiable, and that word is doing all of the work.
How DPDPA applies to online gaming in India
DPDPA applies to every online gaming intermediary, esports platform, fantasy sport operator and casual gaming publisher processing digital personal data in India, and to foreign operators offering services to Data Principals in India under Section 3.
Three obligations reshape the sector. Section 9 requires verifiable parental consent before processing a child's data and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 8 read with the Third Schedule imposes a three year erasure cap on intermediaries with not less than fifty lakh registered users. Rule 8 also requires a forty eight hour intimation before erasure.
The Schedule to Section 33 sets a ceiling extending to two hundred crore rupees for breach of the children obligations, determined by the Board on the Section 33(2) factors.
Substantive obligations commence on 13 May 2027. Age assurance and a retention engine are engineering programmes, not policy documents.
Eight Obligations That Bind a Gaming Platform
Verifiable Parental Consent
Section 9 requires verifiable consent of the parent or lawful guardian before any processing of a child's personal data. A tick box declaring that the user is above eighteen is a declaration, not verification.
Section 9(1), Rule 10The Advertising Prohibition
Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children. For a platform monetised by in game advertising and engagement loops, this is not a compliance item. It is a product question.
Section 9(3)Detrimental Effect
Section 9(2) prohibits processing likely to cause any detrimental effect on the wellbeing of a child. Retention mechanics, streaks, loss chasing prompts and personalised difficulty all sit inside that language.
Section 9(2)Three Year Erasure at Scale
An online gaming intermediary with not less than fifty lakh registered users in India must erase personal data three years after the Data Principal last approached it, unless retention is required by law.
Rule 8, Third ScheduleForty Eight Hour Re Engagement Notice
Before the erasure period completes, the platform must tell the Data Principal that the data will be erased unless they log in or approach it. This is a statutory notification workflow at population scale.
Rule 8Log Retention Floor
Rule 6 requires retention of logs, personal data and traffic data pertaining to the platform for a minimum period, which sets a floor beneath the erasure obligation and must be reconciled with it.
Rule 6Rights Inside Ninety Days
A Data Principal may seek a summary of processing and the identities of other fiduciaries with whom data was shared. Rule 14 sets the outer limit for a response.
Section 11, Rule 14Breach Intimation
On becoming aware of a breach, intimate affected Data Principals and the Board without delay, and file the detailed report with the Board inside 72 hours. Gaming platforms sit alongside a CERT-In obligation on the same incident.
Section 8(6), Rule 7Six Assumptions That Will Not Survive
What Platforms Currently Believe
Self Declared Age Is Not Age Assurance
The overwhelming majority of Indian gaming platforms rely on a date of birth field. That establishes nothing. It is a record of what the user typed.
The Under Eighteen Population Is Already Inside
Every platform with a large casual base already holds children's data. The obligation is not to prevent future entry. It is to deal with the account base already registered.
Engagement Analytics Is Behavioural Monitoring
Session length, churn prediction, personalised offers and difficulty tuning are behavioural monitoring by any ordinary reading. Where they touch a child's account, Section 9(3) engages.
Software Development Kits Leak
Advertising, attribution and analytics kits embedded in the client transmit device and behavioural signals to third parties. Each recipient needs a lawful position and a processor contract.
Retention Is Built for Growth, Not Erasure
Data warehouses in gaming are designed to accumulate. The Third Schedule requires the opposite capability, executed automatically, at crore scale, with prior notice.
Parental Consent Has No Withdrawal Path
Section 6(6) requires withdrawal to be as easy as giving. Almost no platform has designed a route for a parent to withdraw consent given for a child's account.
How Many of Your Users Are Children
Nobody in Indian gaming can answer that question with evidence. Not because the data is hard to obtain, but because no platform has wanted the answer.
Section 9 removes the option of not knowing. It requires verifiable parental consent before processing, which means the platform must first establish who is a child.
Once that number exists, three consequences follow. Behavioural targeting must switch off for that cohort. Parental consent must be obtained or the accounts must be closed. And a withdrawal path must exist for every parent who changes their mind.
The platform that runs this analysis in 2026 has a product problem. The one that runs it in 2027 has an enforcement problem.
Related DPDPA Resources
Children's Data
Section 9 and Rule 10
Child Data Deep Dive
Processing standards
How To: Children's Data
Operational steps
Retention and Erasure
Rule 8 mechanics
Dark Patterns
Consent design boundaries
DPDPA for E-Commerce
Two crore user threshold
DPDP Rules, 2025
23 Rules and 7 Schedules
Penalty Exposure
Schedule to Section 33
Gaming Sector DPDPA Advisory
AMLEGALS advises gaming intermediaries on age assurance design, parental consent and withdrawal flows, the profiling boundary under Section 9(3), and the retention engine required by Rule 8 and the Third Schedule.
Our data privacy counsel will reach out within one working day.
What gaming operators and boards are asking
What does DPDPA require from an online gaming platform regarding children?
Section 9 requires verifiable consent of the parent or lawful guardian before processing the personal data of any individual below eighteen years of age. It prohibits processing likely to cause a detrimental effect on the wellbeing of a child, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 prescribes the manner of obtaining and verifying parental consent. The Fourth Schedule sets out exempted classes of fiduciary and exempted purposes.
Which gaming platforms fall under the Third Schedule retention cap?
The Third Schedule applies to an online gaming intermediary having not less than fifty lakh registered users in India. For that class, personal data must be erased three years after the Data Principal last approached the platform for performance of the specified purpose or the exercise of rights, unless retention is required for compliance with any law. E-commerce entities and social media intermediaries are covered at a two crore registered user threshold.
What is the 48 hour pre erasure notice under Rule 8?
Rule 8 requires the Data Fiduciary to inform the Data Principal at least forty eight hours before the erasure period completes that the personal data will be erased, unless the Data Principal logs in or otherwise approaches the platform. It is a statutory re engagement window. It must be engineered into the retention system and evidenced, because the notice is the compliance artefact.
What is the penalty for mishandling children's data under DPDPA?
The Schedule to Section 33 prescribes a penalty extending up to two hundred crore rupees for breach of the additional obligations in relation to children under Section 9. The amount is determined by the Data Protection Board on the factors in Section 33(2), including the nature, gravity and duration of the breach and the type of personal data affected. It is a Board determined ceiling, not a per instance multiplier.
Is a declared date of birth sufficient age gating under DPDPA?
Section 9 uses the word verifiable. A self declared date of birth is a statement by the user and verifies nothing. Rule 10 contemplates that the Data Fiduciary adopt appropriate technical and organisational measures to ensure that the person identifying as the parent is an adult identifiable if required in connection with compliance under any law, including through reliable identity details or a virtual token mapped to them.
Does the advertising prohibition apply to all users or only to identified children?
It applies to advertising directed at children. Where a platform knows or ought to know that a substantial part of its base is under eighteen and its targeting cannot distinguish, the prohibition cannot be answered by saying the platform did not know. Age assurance is the mechanism by which a platform earns the right to advertise to the rest of its base.
How do real money gaming operators sit within DPDPA?
DPDPA governs personal data. It sits alongside, and does not displace, the separate legal framework applicable to real money gaming, intermediary obligations and any state law. For DPDPA purposes the pressure points are the same, namely age assurance, retention at scale, profiling, breach intimation and the processor chain around payments, verification and marketing partners.
What should a gaming platform build before 13 May 2027?
Four capabilities. Age assurance that produces evidence rather than a declaration. A parental consent and withdrawal flow. A retention engine that executes the three year erasure with the forty eight hour prior intimation. A profiling boundary that switches behavioural targeting off for accounts assured as children.
