AMLEGALS — Strategic Lawyering

DPDPA for EdTech: Children's Data and Verifiable Parental Consent

DPDPA for EdTech: Children's Data and Verifiable Parental Consent

Engagement metrics on children are now evidence.

The scene

The platform's best feature was adaptive learning: it watched how each student hesitated, guessed and gave up, and adjusted. The investors called it personalisation. Section 9 has another word for watching children's behaviour.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Our users are over 13.

DPDPA defines a child as under 18.

Assume most of your users are children, and design for it.

The school gave consent.

The Act requires verifiable consent of the parent or lawful guardian.

Build parental consent into onboarding, verified.

Personalisation isn't tracking.

Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions.

Know exactly which exemption you rely on, or stop.

Exemptions are narrow

The Rules exempt certain classes, such as educational institutions for specified educational activities, from some Section 9 requirements. The exemption follows the purpose, not the product.

The full EdTech & children's data briefing 3 deep dives

Deep dive 01 →

A tick from a twelve-year-old is not a parent's consent.

If a child can click it, it is not parental consent.

Deep dive 02 →

Personalisation is monitoring with a better name.

The product watches the child. The law watches the product.

Deep dive 03 →

The exemption follows the purpose, not the product.

The school's exemption does not travel with the vendor's pitch deck.

Monday morning

01 Count how many users are under 18. Guess high.

02 List every signal your product collects about learning behaviour.

03 Map each to an exemption, or plan its removal.

Questions, answered plainly

Who is a child under DPDPA? +

Under Section 2(f) a child is an individual who has not completed eighteen years of age.

What does DPDPA require for processing children's data? +

Section 9 requires verifiable consent of the parent or lawful guardian, prohibits processing likely to cause detrimental effect on a child's well-being, and bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions in the Rules. Breach can attract a penalty of up to ₹200 crore.

Sector · E-commerce & D2C Your funnel runs on consent. The Act just redefined consent. Read →

Sector · SaaS & IT services You think you're the processor. Your contract may disagree. Read →

Sector · Telecom A billion subscribers. A billion Data Principals. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).