A child's data is not a cookie.Stop treating it like one.

Under DPDPA a child is anyone under eighteen. Most EdTech platforms were built for an internet that assumed thirteen.

In one line: Under Section 2(f) a child is an individual who has not completed eighteen years of age.

The estate · EdTech & children's dataHover to inspect

Engagement metrics on children are now evidence.

The scene

The platform's best feature was adaptive learning: it watched how each student hesitated, guessed and gave up, and adjusted. The investors called it personalisation. Section 9 has another word for watching children's behaviour.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
Our users are over 13. DPDPA defines a child as under 18. Assume most of your users are children, and design for it.
The school gave consent. The Act requires verifiable consent of the parent or lawful guardian. Build parental consent into onboarding, verified.
Personalisation isn't tracking. Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions. Know exactly which exemption you rely on, or stop.

Exemptions are narrow

The Rules exempt certain classes, such as educational institutions for specified educational activities, from some Section 9 requirements. The exemption follows the purpose, not the product.

The full EdTech & children's data briefing

3 deep dives
Deep dive 01→

A tick from a twelve-year-old is not a parent's consent.

If a child can click it, it is not parental consent.

Deep dive 02→

Personalisation is monitoring with a better name.

The product watches the child. The law watches the product.

Deep dive 03→

The exemption follows the purpose, not the product.

The school's exemption does not travel with the vendor's pitch deck.

Monday morning

  1. 01Count how many users are under 18. Guess high.
  2. 02List every signal your product collects about learning behaviour.
  3. 03Map each to an exemption, or plan its removal.

Questions, answered plainly

Who is a child under DPDPA?

Under Section 2(f) a child is an individual who has not completed eighteen years of age.

What does DPDPA require for processing children's data?

Section 9 requires verifiable consent of the parent or lawful guardian, prohibits processing likely to cause detrimental effect on a child's well-being, and bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions in the Rules. Breach can attract a penalty of up to ₹200 crore.

Sector · E-commerce & D2CYour funnel runs on consent. The Act just redefined consent.Read → Sector · SaaS & IT servicesYou think you're the processor. Your contract may disagree.Read → Sector · TelecomA billion subscribers. A billion Data Principals.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner