Verifiable Parental Consent Under DPDPA: A Practical Guide for EdTech
Verifiable Parental Consent Under DPDPA: A Practical Guide for EdTech
If a child can click it, it is not parental consent.
The scene
The sign-up flow had a checkbox: ‘I am a parent or guardian.’ Analytics showed it was ticked in under a second, on phones logged into a student's school email, at ten in the morning on weekdays.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
A declaration is enough.
The Rules require due diligence to check that the person is an identifiable adult.
Verify the adult, not just the checkbox.
We can verify later.
Section 9 requires consent before processing a child's data.
Verify before the first lesson, not after the first invoice.
What the Rules point to
The DPDP Rules describe verification using reliable details of identity and age already available to the fiduciary, or voluntarily provided, including through tokens from authorised entities. The method must be proportionate and auditable.
Monday morning
01 Walk through sign-up as a child would.
02 Time how long it takes to become a ‘parent’.
03 Choose a verification method you could defend to the Board.
Questions, answered plainly
What is verifiable parental consent under DPDPA? +
It is consent from a child's parent or lawful guardian that the Data Fiduciary has taken reasonable steps to verify, as prescribed by the DPDP Rules, including checking that the person is an identifiable adult.
What is the penalty for breaching children's data obligations? +
Breach of the additional obligations for children under Section 9 can attract a penalty of up to ₹200 crore.
Sector · EdTech A child's data is not a cookie. Stop treating it like one. Read →
EdTech & children's data · Deep dive Personalisation is monitoring with a better name. Read →
EdTech & children's data · Deep dive The exemption follows the purpose, not the product. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).