Engagement is the product. For children, it is the risk.
The scene
The age gate asked players to type a year of birth. Twelve-year-olds learned to type 2001 in their first week. The platform's retention team built its best campaigns on their play patterns.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
An age gate solves it.
A self-declared year is not verification.
Design age assurance that a regulator would call reasonable.
Behavioural data is anonymous.
Data linked to an account or device identifier is personal data.
Treat player telemetry as personal data by default.
Dormant players are future revenue.
The Rules set a three-year erasure window for large gaming intermediaries.
Plan erasure into the lifecycle, with notice.
Advertising in games
In-game ads that target on behaviour are targeted advertising. Directed at children, Section 9(3) restricts it.
The full Gaming briefing 3 deep dives
Deep dive 01 →
Twelve-year-olds learn to type 2001 in a week.
If the gate is easy to lie to, it is not a gate.
Deep dive 02 →
Engagement is the product. For children, it is the risk.
Every event you log is a sentence in a file about a person.
Deep dive 03 →
Dormant players are not future revenue.
The player logged off. The clock started.
Monday morning
01 Estimate the share of players under 18. Assume it is higher.
02 List every behavioural event you log.
03 Review which campaigns use them for players who may be children.
Questions, answered plainly
How does DPDPA affect online gaming companies? +
Gaming platforms must obtain verifiable parental consent for users under 18, avoid tracking, behavioural monitoring and targeted advertising directed at children, and, for large gaming intermediaries, erase data of users inactive for three years under the Rules.
Is a self-declared age gate enough under DPDPA? +
The Rules require Data Fiduciaries to adopt appropriate measures to ensure verifiable parental consent. A self-declared birth year alone is unlikely to be seen as sufficient where children are likely users.
Sector · Government vendors The State's exemption is not your exemption. Read →
Sector · Banking & BFSI Banks keep everything. The law now asks why. Read →
Sector · Fintech & NBFC Your onboarding takes ninety seconds. Your liability lasts years. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).