A tick from a twelve-year-oldis not a parent's consent.
Under the Rules, the platform must be able to show that the adult is an adult, and is the parent.
In one line: It is consent from a child's parent or lawful guardian that the Data Fiduciary has taken reasonable steps to verify, as prescribed by the DPDP Rules, including checking that the person is an identifiable adult.
If a child can click it, it is not parental consent.
The scene
The sign-up flow had a checkbox: ‘I am a parent or guardian.’ Analytics showed it was ticked in under a second, on phones logged into a student's school email, at ten in the morning on weekdays.
Where the thinking breaks
What the Rules point to
The DPDP Rules describe verification using reliable details of identity and age already available to the fiduciary, or voluntarily provided, including through tokens from authorised entities. The method must be proportionate and auditable.
Monday morning
- 01Walk through sign-up as a child would.
- 02Time how long it takes to become a ‘parent’.
- 03Choose a verification method you could defend to the Board.
Questions, answered plainly
What is verifiable parental consent under DPDPA?
It is consent from a child's parent or lawful guardian that the Data Fiduciary has taken reasonable steps to verify, as prescribed by the DPDP Rules, including checking that the person is an identifiable adult.
What is the penalty for breaching children's data obligations?
Breach of the additional obligations for children under Section 9 can attract a penalty of up to ₹200 crore.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner