Children’s data Applies from 13 May 2027

Children’s data, DPDP Act: who is a child and who must consent?

A woman at an office reception desk on a phone call.

Under the DPDP Act a child is anyone under 18. Before processing a child’s personal data you need the verifiable consent of a parent or lawful guardian, and you may not track, behaviourally monitor or target advertising at children. The Rules exempt listed classes and purposes, on conditions. These duties start on 13 May 2027.

Last checked against the official text: Updated 6 min read

On this page
  1. Who counts as a child
  2. The three duties in the Act
  3. What the Rules say about verifiable consent
  4. The exemptions in the Rules
  5. What a breach of the child duties can cost
  6. Questions to answer before 13 May 2027
  7. Common questions
  8. In the news
  9. Sources

The DPDP Act sets extra duties for any business that handles the personal data of a child, and the Act defines a child as anyone under eighteen. There are three: get a parent’s verifiable consent first, do not process data in a way likely to harm the child, and do not track, behaviourally monitor or target advertising at children. The Rules then list classes of business and purposes that are exempt from the first and the third, on stated conditions. All of this applies from 13 May 2027.

Who counts as a child

A child is an individual who has not completed the age of eighteen years. For a child, the Data Principal includes the parents or lawful guardian. The same duty to obtain a lawful guardian’s verifiable consent covers a person with a disability who has a lawful guardian.

The three duties in the Act

  • Verifiable consent first. Before processing any personal data of a child, the Data Fiduciary must obtain the verifiable consent of her parent or lawful guardian, in the manner the Rules prescribe.
  • No harm to well-being. A Data Fiduciary must not process personal data in a way that is likely to cause any detrimental effect on the well-being of a child.
  • No tracking or targeted ads. A Data Fiduciary must not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

The tracking ban has no consent exception. It lifts only through the exemptions below, the Act’s general exemptions (for example legal claims and courts), or through an age that the Central Government may notify for a Data Fiduciary whose processing of children’s data it is satisfied is verifiably safe. Check the Gazette before relying on a notification.

The Rules give the test in one sentence:

A woman working on a laptop beside a stack of papers.

A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to— (a) reliable details of identity and age of the individual available with the Data Fiduciary; or (b) details of identity and age, voluntarily provided— (i) by the individual; or (ii) through a virtual token mapped to such details, which is issued by an authorised entity.

An adult is an individual who has completed eighteen years. An authorised entity is a body that law or the Central or a State Government entrusts with issuing identity and age details or a token mapped to them, or a person it appoints or permits to issue them.

The Rules work through four cases for creating a child’s user account. Either way, the parent identifies herself. If she is a registered user whose identity and age details you hold, you check that you hold reliable details and that she is an identifiable adult. If she is not, you check that she is an identifiable adult by reference to details issued by a body that law or the Government entrusts with them, or to a virtual token mapped to them, which she may supply through a Digital Locker service provider.

For a person with a disability who has a lawful guardian, the business must verify that the guardian was appointed by a court, a designated authority or a local level committee under the law that applies to guardianship.

The exemptions in the Rules

The Rules lift the first and third duties, and only those, for the classes below and, for any business, for the six purposes after them. Each is restricted by its condition. The duty not to harm a child’s well-being stays in force.

Class of businessCondition
Clinical establishment, mental health establishment or healthcare professionalProcessing is restricted to providing health services to the child, to the extent necessary for the protection of her health.
Allied healthcare professionalProcessing is restricted to supporting implementation of a healthcare treatment and referral plan recommended by such a professional for the child, to the extent necessary for the protection of her health.
Educational institutionProcessing is restricted to tracking and behavioural monitoring for the institution’s educational activities or in the interests of the safety of enrolled children.
An individual in whose care infants and children are entrusted in a crèche or child day care centreProcessing is restricted to tracking and behavioural monitoring in the interests of the safety of children entrusted to the care of that institution, crèche or centre.
A business engaged by an educational institution, crèche or child care centre to transport childrenProcessing is restricted to tracking the location of those children, in the interests of their safety, during their travel to and from the institution, crèche or centre.
PurposeCondition
Exercising a power, performing a function or discharging a duty in the interests of a child, under a law in IndiaOnly to the extent necessary for that exercise, performance or discharge.
The State or its bodies providing a subsidy, benefit, service, certificate, licence or permit to a child, under law or policy or using public funds, in the interests of a childOnly to the extent necessary for that provision or issuance.
Creating a user account for communicating by emailOnly to the extent necessary, and the account may be used only for email.
Determining a child’s real-time locationOnly tracking of real-time location, in the interest of her safety, protection or security.
Making sure information, a service or an advertisement likely to harm a child’s well-being is not accessible to herOnly to the extent necessary for that purpose.
Confirming that a person is not a child and observing the due diligence on a parent that the Rules requireOnly to the extent necessary for that confirmation or observance.

The Rules define an educational institution as an institution of learning that imparts education, including vocational education. Whether a coaching centre, tuition class or app fits that wording is a question for counsel. Clinical establishment and mental health establishment take their meaning from the Clinical Establishments (Registration and Regulation) Act, 2010 and the Mental Healthcare Act, 2017. See also clinics and hospitals.

What a breach of the child duties can cost

The Act’s Schedule sets a ceiling of up to ₹200 crore for breach of the extra obligations in relation to children. The Board can impose a penalty only after an inquiry finds the breach significant and has given the person an opportunity of being heard. See penalties explained.

Questions to answer before 13 May 2027

  • Do you hold personal data of anyone under eighteen, in any record, app or form?
  • Do you know each user’s age, and how would you identify a parent as an adult?
  • Does anything you run track, monitor or profile children, or show them ads based on their behaviour?

The consent notice article covers the notice that goes with every request for consent, and the roles article explains who counts as a Data Principal.

Common questions

Who is a child under the DPDP Act?

An individual who has not completed eighteen years. For a child, the Data Principal includes the parents or lawful guardian.

What does verifiable parental consent require?

You must adopt appropriate technical and organisational measures to make sure a parent’s verifiable consent is obtained before processing any personal data of a child. You must also check that the person identifying herself as the parent is an adult who is identifiable if a law in force in India requires it, by reference to reliable details of identity and age you already hold, or details she volunteers or provides through a virtual token issued by an authorised entity.

Can a business track children or show them targeted ads?

No. The Act bars tracking or behavioural monitoring of children and targeted advertising directed at children. It lifts only for the classes and purposes the Rules list, on the conditions stated there, where a general exemption in the Act applies, or for an age the Central Government notifies for a Data Fiduciary whose processing is verifiably safe.

Which businesses are exempt from parental consent?

Clinical establishments, mental health establishments, healthcare professionals, allied healthcare professionals, educational institutions, individuals in whose care children in a crèche or child day care centre are entrusted, and businesses engaged to transport children for those institutions. Separately, any business is exempt for six listed purposes, such as an email-only account or confirming a user is not a child, each limited to what the purpose needs. Each exemption applies only to the processing the Rules describe. The duty not to harm a child’s well-being stays in force.

What is the penalty for breaching the child duties?

Up to ₹200 crore. That is a ceiling set by the Act’s Schedule. A penalty needs an inquiry that finds the breach significant, and an opportunity for the person to be heard.

Next steps

In the news

Sources

Every section, rule and date above was checked against the official text on 6 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)

  • Section 2(f)Child: an individual who has not completed eighteen years
  • Section 2(j)Data Principal includes the parents or lawful guardian of a child
  • Section 9Verifiable consent of a parent or lawful guardian; no detrimental processing; no tracking, behavioural monitoring or targeted advertising; prescribed exemptions; notified age
  • Section 17(1)General exemptions, including legal claims, courts and offences: the Chapter II duties, other than sections 8(1) and 8(5), do not apply
  • Section 33(1)Penalty only after an inquiry finds a significant breach and the person is given an opportunity of being heard
  • The Schedule, item 3Up to ₹200 crore for breach of the additional obligations in relation to children

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4)Rules 3, 5 to 16 in force eighteen months from publication
  • Rule 10Verifiable consent of a parent: due diligence that she is an identifiable adult; adult and authorised entity defined; four illustrations
  • Rule 11Verifiable consent of a lawful guardian of a person with disability
  • Rule 12Exemptions from the first and third child duties for the Fourth Schedule classes and purposes
  • Fourth Schedule, Parts A and BFive classes of Data Fiduciary and six purposes, each with a condition; definitions in the Note

Notifications

Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)

  • G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17 in force eighteen months from 13 November 2025

A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.