AMLEGALS — Strategic Lawyering
Online Gaming — Where the Statute Meets the Business Model

DPDPA for Online Gaming

Every other sector can comply with Section 9 by adding a gate. Gaming cannot. A large part of the user base is under eighteen, and the prohibition on tracking and targeted advertising reaches the revenue model itself.

Section 9Rule 10Third Schedule50 Lakh Users₹200 Crore Ceiling

A date of birth field is not age assurance. It is a record of what the user typed. Section 9 uses the word verifiable, and that word is doing all of the work.

The Position in One Paragraph

How DPDPA applies to online gaming in India

DPDPA applies to every online gaming intermediary, esports platform, fantasy sport operator and casual gaming publisher processing digital personal data in India, and to foreign operators offering services to Data Principals in India under Section 3.

Three obligations reshape the sector. Section 9 requires verifiable parental consent before processing a child's data and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 8 read with the Third Schedule imposes a three year erasure cap on intermediaries with not less than fifty lakh registered users. Rule 8 also requires a forty eight hour intimation before erasure.

The Schedule to Section 33 sets a ceiling extending to two hundred crore rupees for breach of the children obligations, determined by the Board on the Section 33(2) factors.

Substantive obligations commence on 13 May 2027. Age assurance and a retention engine are engineering programmes, not policy documents.

Obligation Map

Eight Obligations That Bind a Gaming Platform

Verifiable Parental Consent

Section 9 requires verifiable consent of the parent or lawful guardian before any processing of a child's personal data. A tick box declaring that the user is above eighteen is a declaration, not verification.

Section 9(1), Rule 10

The Advertising Prohibition

Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children. For a platform monetised by in game advertising and engagement loops, this is not a compliance item. It is a product question.

Section 9(3)

Detrimental Effect

Section 9(2) prohibits processing likely to cause any detrimental effect on the wellbeing of a child. Retention mechanics, streaks, loss chasing prompts and personalised difficulty all sit inside that language.

Section 9(2)

Three Year Erasure at Scale

An online gaming intermediary with not less than fifty lakh registered users in India must erase personal data three years after the Data Principal last approached it, unless retention is required by law.

Rule 8, Third Schedule

Forty Eight Hour Re Engagement Notice

Before the erasure period completes, the platform must tell the Data Principal that the data will be erased unless they log in or approach it. This is a statutory notification workflow at population scale.

Rule 8

Log Retention Floor

Rule 6 requires retention of logs, personal data and traffic data pertaining to the platform for a minimum period, which sets a floor beneath the erasure obligation and must be reconciled with it.

Rule 6

Rights Inside Ninety Days

A Data Principal may seek a summary of processing and the identities of other fiduciaries with whom data was shared. Rule 14 sets the outer limit for a response.

Section 11, Rule 14

Breach Intimation

On becoming aware of a breach, intimate affected Data Principals and the Board without delay, and file the detailed report with the Board inside 72 hours. Gaming platforms sit alongside a CERT-In obligation on the same incident.

Section 8(6), Rule 7
Failure Modes

Six Assumptions That Will Not Survive

What Platforms Currently Believe

Self Declared Age Is Not Age Assurance

The overwhelming majority of Indian gaming platforms rely on a date of birth field. That establishes nothing. It is a record of what the user typed.

The Under Eighteen Population Is Already Inside

Every platform with a large casual base already holds children's data. The obligation is not to prevent future entry. It is to deal with the account base already registered.

Engagement Analytics Is Behavioural Monitoring

Session length, churn prediction, personalised offers and difficulty tuning are behavioural monitoring by any ordinary reading. Where they touch a child's account, Section 9(3) engages.

Software Development Kits Leak

Advertising, attribution and analytics kits embedded in the client transmit device and behavioural signals to third parties. Each recipient needs a lawful position and a processor contract.

Retention Is Built for Growth, Not Erasure

Data warehouses in gaming are designed to accumulate. The Third Schedule requires the opposite capability, executed automatically, at crore scale, with prior notice.

Parental Consent Has No Withdrawal Path

Section 6(6) requires withdrawal to be as easy as giving. Almost no platform has designed a route for a parent to withdraw consent given for a child's account.

The Uncomfortable Question

How Many of Your Users Are Children

Nobody in Indian gaming can answer that question with evidence. Not because the data is hard to obtain, but because no platform has wanted the answer.

Section 9 removes the option of not knowing. It requires verifiable parental consent before processing, which means the platform must first establish who is a child.

Once that number exists, three consequences follow. Behavioural targeting must switch off for that cohort. Parental consent must be obtained or the accounts must be closed. And a withdrawal path must exist for every parent who changes their mind.

The platform that runs this analysis in 2026 has a product problem. The one that runs it in 2027 has an enforcement problem.

Gaming Sector DPDPA Advisory

AMLEGALS advises gaming intermediaries on age assurance design, parental consent and withdrawal flows, the profiling boundary under Section 9(3), and the retention engine required by Rule 8 and the Third Schedule.

Request a Confidential Briefing

Our data privacy counsel will reach out within one working day.

Insights & Answers

What gaming operators and boards are asking

What does DPDPA require from an online gaming platform regarding children?

Section 9 requires verifiable consent of the parent or lawful guardian before processing the personal data of any individual below eighteen years of age. It prohibits processing likely to cause a detrimental effect on the wellbeing of a child, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 prescribes the manner of obtaining and verifying parental consent. The Fourth Schedule sets out exempted classes of fiduciary and exempted purposes.

Which gaming platforms fall under the Third Schedule retention cap?

The Third Schedule applies to an online gaming intermediary having not less than fifty lakh registered users in India. For that class, personal data must be erased three years after the Data Principal last approached the platform for performance of the specified purpose or the exercise of rights, unless retention is required for compliance with any law. E-commerce entities and social media intermediaries are covered at a two crore registered user threshold.

What is the 48 hour pre erasure notice under Rule 8?

Rule 8 requires the Data Fiduciary to inform the Data Principal at least forty eight hours before the erasure period completes that the personal data will be erased, unless the Data Principal logs in or otherwise approaches the platform. It is a statutory re engagement window. It must be engineered into the retention system and evidenced, because the notice is the compliance artefact.

What is the penalty for mishandling children's data under DPDPA?

The Schedule to Section 33 prescribes a penalty extending up to two hundred crore rupees for breach of the additional obligations in relation to children under Section 9. The amount is determined by the Data Protection Board on the factors in Section 33(2), including the nature, gravity and duration of the breach and the type of personal data affected. It is a Board determined ceiling, not a per instance multiplier.

Is a declared date of birth sufficient age gating under DPDPA?

Section 9 uses the word verifiable. A self declared date of birth is a statement by the user and verifies nothing. Rule 10 contemplates that the Data Fiduciary adopt appropriate technical and organisational measures to ensure that the person identifying as the parent is an adult identifiable if required in connection with compliance under any law, including through reliable identity details or a virtual token mapped to them.

Does the advertising prohibition apply to all users or only to identified children?

It applies to advertising directed at children. Where a platform knows or ought to know that a substantial part of its base is under eighteen and its targeting cannot distinguish, the prohibition cannot be answered by saying the platform did not know. Age assurance is the mechanism by which a platform earns the right to advertise to the rest of its base.

How do real money gaming operators sit within DPDPA?

DPDPA governs personal data. It sits alongside, and does not displace, the separate legal framework applicable to real money gaming, intermediary obligations and any state law. For DPDPA purposes the pressure points are the same, namely age assurance, retention at scale, profiling, breach intimation and the processor chain around payments, verification and marketing partners.

What should a gaming platform build before 13 May 2027?

Four capabilities. Age assurance that produces evidence rather than a declaration. A parental consent and withdrawal flow. A retention engine that executes the three year erasure with the forty eight hour prior intimation. A profiling boundary that switches behavioural targeting off for accounts assured as children.