On this page
The DPDP Act sets extra duties for any business that handles the personal data of a child, and the Act defines a child as anyone under eighteen. There are three: get a parent’s verifiable consent first, do not process data in a way likely to harm the child, and do not track, behaviourally monitor or target advertising at children. The Rules then list classes of business and purposes that are exempt from the first and the third, on stated conditions. All of this applies from 13 May 2027.
Who counts as a child
A child is an individual who has not completed the age of eighteen years. For a child, the Data Principal includes the parents or lawful guardian. The same duty to obtain a lawful guardian’s verifiable consent covers a person with a disability who has a lawful guardian.
The three duties in the Act
- Verifiable consent first. Before processing any personal data of a child, the Data Fiduciary must obtain the verifiable consent of her parent or lawful guardian, in the manner the Rules prescribe.
- No harm to well-being. A Data Fiduciary must not process personal data in a way that is likely to cause any detrimental effect on the well-being of a child.
- No tracking or targeted ads. A Data Fiduciary must not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
The tracking ban has no consent exception. It lifts only through the exemptions below, the Act’s general exemptions (for example legal claims and courts), or through an age that the Central Government may notify for a Data Fiduciary whose processing of children’s data it is satisfied is verifiably safe. Check the Gazette before relying on a notification.
What the Rules say about verifiable consent
The Rules give the test in one sentence:

A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to— (a) reliable details of identity and age of the individual available with the Data Fiduciary; or (b) details of identity and age, voluntarily provided— (i) by the individual; or (ii) through a virtual token mapped to such details, which is issued by an authorised entity.
An adult is an individual who has completed eighteen years. An authorised entity is a body that law or the Central or a State Government entrusts with issuing identity and age details or a token mapped to them, or a person it appoints or permits to issue them.
The Rules work through four cases for creating a child’s user account. Either way, the parent identifies herself. If she is a registered user whose identity and age details you hold, you check that you hold reliable details and that she is an identifiable adult. If she is not, you check that she is an identifiable adult by reference to details issued by a body that law or the Government entrusts with them, or to a virtual token mapped to them, which she may supply through a Digital Locker service provider.
For a person with a disability who has a lawful guardian, the business must verify that the guardian was appointed by a court, a designated authority or a local level committee under the law that applies to guardianship.
The exemptions in the Rules
The Rules lift the first and third duties, and only those, for the classes below and, for any business, for the six purposes after them. Each is restricted by its condition. The duty not to harm a child’s well-being stays in force.
| Class of business | Condition |
|---|---|
| Clinical establishment, mental health establishment or healthcare professional | Processing is restricted to providing health services to the child, to the extent necessary for the protection of her health. |
| Allied healthcare professional | Processing is restricted to supporting implementation of a healthcare treatment and referral plan recommended by such a professional for the child, to the extent necessary for the protection of her health. |
| Educational institution | Processing is restricted to tracking and behavioural monitoring for the institution’s educational activities or in the interests of the safety of enrolled children. |
| An individual in whose care infants and children are entrusted in a crèche or child day care centre | Processing is restricted to tracking and behavioural monitoring in the interests of the safety of children entrusted to the care of that institution, crèche or centre. |
| A business engaged by an educational institution, crèche or child care centre to transport children | Processing is restricted to tracking the location of those children, in the interests of their safety, during their travel to and from the institution, crèche or centre. |
| Purpose | Condition |
|---|---|
| Exercising a power, performing a function or discharging a duty in the interests of a child, under a law in India | Only to the extent necessary for that exercise, performance or discharge. |
| The State or its bodies providing a subsidy, benefit, service, certificate, licence or permit to a child, under law or policy or using public funds, in the interests of a child | Only to the extent necessary for that provision or issuance. |
| Creating a user account for communicating by email | Only to the extent necessary, and the account may be used only for email. |
| Determining a child’s real-time location | Only tracking of real-time location, in the interest of her safety, protection or security. |
| Making sure information, a service or an advertisement likely to harm a child’s well-being is not accessible to her | Only to the extent necessary for that purpose. |
| Confirming that a person is not a child and observing the due diligence on a parent that the Rules require | Only to the extent necessary for that confirmation or observance. |
The Rules define an educational institution as an institution of learning that imparts education, including vocational education. Whether a coaching centre, tuition class or app fits that wording is a question for counsel. Clinical establishment and mental health establishment take their meaning from the Clinical Establishments (Registration and Regulation) Act, 2010 and the Mental Healthcare Act, 2017. See also clinics and hospitals.
What a breach of the child duties can cost
The Act’s Schedule sets a ceiling of up to ₹200 crore for breach of the extra obligations in relation to children. The Board can impose a penalty only after an inquiry finds the breach significant and has given the person an opportunity of being heard. See penalties explained.
Questions to answer before 13 May 2027
- Do you hold personal data of anyone under eighteen, in any record, app or form?
- Do you know each user’s age, and how would you identify a parent as an adult?
- Does anything you run track, monitor or profile children, or show them ads based on their behaviour?
The consent notice article covers the notice that goes with every request for consent, and the roles article explains who counts as a Data Principal.
Common questions
Who is a child under the DPDP Act?
An individual who has not completed eighteen years. For a child, the Data Principal includes the parents or lawful guardian.
What does verifiable parental consent require?
You must adopt appropriate technical and organisational measures to make sure a parent’s verifiable consent is obtained before processing any personal data of a child. You must also check that the person identifying herself as the parent is an adult who is identifiable if a law in force in India requires it, by reference to reliable details of identity and age you already hold, or details she volunteers or provides through a virtual token issued by an authorised entity.
Can a business track children or show them targeted ads?
No. The Act bars tracking or behavioural monitoring of children and targeted advertising directed at children. It lifts only for the classes and purposes the Rules list, on the conditions stated there, where a general exemption in the Act applies, or for an age the Central Government notifies for a Data Fiduciary whose processing is verifiably safe.
Which businesses are exempt from parental consent?
Clinical establishments, mental health establishments, healthcare professionals, allied healthcare professionals, educational institutions, individuals in whose care children in a crèche or child day care centre are entrusted, and businesses engaged to transport children for those institutions. Separately, any business is exempt for six listed purposes, such as an email-only account or confirming a user is not a child, each limited to what the purpose needs. Each exemption applies only to the processing the Rules describe. The duty not to harm a child’s well-being stays in force.
What is the penalty for breaching the child duties?
Up to ₹200 crore. That is a ceiling set by the Act’s Schedule. A penalty needs an inquiry that finds the breach significant, and an opportunity for the person to be heard.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 03: Know your data, in the toolkit
- How-to 05: Ask properly, in the toolkit
- The free duties list, every duty in plain words
In the news
- Parental Consent Necessary For Online Platforms To Use Child’s Data As Centre Notifies DPDP Rules 2025
Report from the day the Rules were notified, on the children’s data rule; our article sets out what it requires from 13 May 2027.
- Processing children’s personal data under the DPDPA
A practising lawyer’s view of the same children’s data duties we cover.
Sources
Every section, rule and date above was checked against the official text on 6 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 2(f)Child: an individual who has not completed eighteen years
- Section 2(j)Data Principal includes the parents or lawful guardian of a child
- Section 9Verifiable consent of a parent or lawful guardian; no detrimental processing; no tracking, behavioural monitoring or targeted advertising; prescribed exemptions; notified age
- Section 17(1)General exemptions, including legal claims, courts and offences: the Chapter II duties, other than sections 8(1) and 8(5), do not apply
- Section 33(1)Penalty only after an inquiry finds a significant breach and the person is given an opportunity of being heard
- The Schedule, item 3Up to ₹200 crore for breach of the additional obligations in relation to children
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 3, 5 to 16 in force eighteen months from publication
- Rule 10Verifiable consent of a parent: due diligence that she is an identifiable adult; adult and authorised entity defined; four illustrations
- Rule 11Verifiable consent of a lawful guardian of a person with disability
- Rule 12Exemptions from the first and third child duties for the Fourth Schedule classes and purposes
- Fourth Schedule, Parts A and BFive classes of Data Fiduciary and six purposes, each with a condition; definitions in the Note
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


