Understanding Section 9 of the DPDP Act is the easy part. With the DPDP Rules’ substantive obligations due to apply from 13 May 2027, the harder question is whether your systems can recognise a child, and act on it, without anyone having to remember.
A 17-year-old signs up for your app.
In your CRM, your analytics dashboard and your marketing tools, she looks exactly like every other customer. Under India’s Digital Personal Data Protection Act, 2023, she is not. She is a child, and processing her personal data comes with obligations that most systems were never designed to enforce.
India did not adopt the under-13 thresholds used in many other jurisdictions. Under the DPDP Act, anyone who has not completed 18 years of age is a child. For EdTech, gaming, social, fintech, health and e-commerce platforms, that brings a significant share of users into scope.
So the question for leadership is not whether you have a children’s-data policy. It is whether your privacy infrastructure can turn that policy into controls that work consistently, across every system the data touches.
What the DPDP framework actually requires
Section 9 of the Act and Rule 10 of the DPDP Rules, 2025 set out the core obligations for children’s personal data:
• Verifiable parental consent. A Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing any personal data of a child (Section 9(1)). The same principle applies to a person with a disability who has a lawful guardian.
• No detrimental processing. Processing that is likely to cause any detrimental effect on the well-being of a child is not permitted (Section 9(2)).
• No tracking, behavioural monitoring or targeted advertising. A Data Fiduciary must not undertake tracking or behavioural monitoring of children, or advertising targeted at them (Section 9(3)).
• Due diligence on the parent. Rule 10 requires appropriate technical and organisational measures, and due diligence to check that the person identifying as the parent is an identifiable adult. This can be done by reference to reliable identity and age details already held by the Data Fiduciary, details provided voluntarily, or a virtual token mapped to such details and issued by an authorised entity, such as a DigiLocker-based service.
• Narrow exemptions. The Rules exempt certain classes of Data Fiduciaries (such as clinical establishments, educational institutions and child-care providers) and certain purposes from some of these obligations, but only to the extent and under the conditions specified. They are not a blanket carve-out.
• Significant penalties. Breach of the additional obligations relating to children can attract a penalty of up to ₹200 crore under the Schedule to the Act.
The timeline: The DPDP Rules were notified on 13 November 2025 and the Data Protection Board is already constituted. Most substantive obligations, including Rule 10 on children’s data, apply 18 months after notification, from 13 May 2027. A proposal to shorten this window has been discussed but, at the time of writing, has not been notified. Either way, age assurance, parent-linking and consent-record infrastructure take time to build properly.
Why this is an operational problem, not a policy problem
Children’s data rarely stays in one system. It moves from the app into the CRM, from the CRM into analytics, and on through APIs, cloud environments, SDKs and third-party processors.
Section 9(3) makes this especially sharp. An analytics SDK or advertising pixel that runs for every user may be doing exactly the kind of tracking or behavioural monitoring the Act prohibits for children. A control applied at sign-up means very little if the systems downstream never learn that the user is a child.
The Data Fiduciary also remains responsible for processing carried out on its behalf by Data Processors (Section 8). That means the “child” status has to travel with the data, including to vendors.
Five questions every organisation should be able to answer
1. Can we tell? Do we have a proportionate way to identify that a user may be under 18 at onboarding, without collecting more data than we need?
2. Can we verify the parent? Can we complete Rule 10 due diligence on the parent or guardian, and record which method was used?
3. Can we propagate? Does the child flag flow to the CRM, analytics, marketing and every processor, so that tracking and targeted advertising are switched off automatically?
4. Can we honour withdrawal? Withdrawing consent must be as easy as giving it (Section 6(4)). When a parent withdraws, does processing stop, and do our processors stop too?
5. Can we prove it? Can we show the Data Protection Board who consented, how they were verified, which notice they saw, what purpose the consent covered and when it was captured?
If any of these answers depends on spreadsheets, disconnected tools or someone remembering what to do, there is a gap between policy and capability.
Consent is a process, not a checkbox
For children’s data, a standard consent banner is not enough. Organisations need to know who gave consent, whether the parent or guardian was verified, what purpose the consent covers, which version of the notice was shown, when it was captured and what happens when it is withdrawn.
This is where DataRakshaq’s Consent Management module is built to help. It includes a dedicated workflow for minors that supports parental and guardian consent, verification, processing controls, withdrawal and a complete audit trail. Consent stops being a checkbox and becomes a traceable compliance process that can be governed and evidenced.
Visibility comes first
You cannot protect children’s data if you do not know where it lives.
DataRakshaq’s data discovery capabilities identify personal data across connected environments and can flag children’s data for appropriate governance. That visibility then connects to the rest of the DPDP programme: Records of Processing Activities, consent management, Data Protection Impact Assessments, Data Principal rights requests, breach management and audit evidence.
The objective is not another privacy dashboard. It is to connect the controls that decide how personal data is discovered, processed, governed and demonstrated as compliant.
Why this belongs on the leadership agenda
Children’s data governance cannot sit with the privacy or legal team alone.
• Product teams decide how users are identified and what age signals are collected.
• Technology teams decide how data is stored, tagged and moved.
• Marketing and growth teams run the tracking and targeting tools that Section 9(3) restricts.
• Procurement and vendor-management teams oversee the processors who receive the data.
• Compliance teams must show that all of this works as intended.
That makes children’s data protection an enterprise governance issue, and one where accountability sits with the Data Fiduciary, not its vendors.
The implementation gap is real
A March 2026 assessment of 14 AI platforms used by minors evaluated 196 criterion-level checks and reported 71% of them as non-compliant, with gaps including verifiable parental consent and safeguards for children’s data. [The statement is sourced from a March 2026 policy research report by the Advanced Study Institute of Asia (ASIA) titled “DPDP Compliance in Respect to Children’s Data – A Comprehensive Assessment of AI Tools Extensively Used by Minors in India.”]
That does not mean 71% of businesses are non-compliant. The study covered a specific set of platforms and criteria. But it illustrates the broader point: understanding a regulatory requirement is very different from having the technology and processes to enforce it.
A connected approach to children’s data
At DataRakshaq, we treat children’s data as part of the full DPDP compliance lifecycle rather than a standalone feature:
• Discover: identify and classify personal data, including children’s data, across systems.
• Consent: run guardian-linked consent workflows with verification and withdrawal built in.
• Record: connect processing activities to the Records of Processing Activities.
• Assess: use DPIA workflows to evaluate higher-risk processing involving children.
• Evidence: build a continuous, audit-ready trail for the Board, auditors and leadership.
Compliance does not happen at a single point in the data lifecycle. A control applied at collection has to remain meaningful as the data moves through internal systems, applications and third parties.
The executive question
The most useful question is not “Do we process children’s data?” For most consumer-facing businesses in India, the answer is almost certainly yes.
The better question is: “If a child uses our product tomorrow, can our systems recognise it and apply the right controls, from consent to tracking to vendors, without manual intervention?”
With May 2027 approaching, that question deserves an answer well before the deadline.
Conclusion
Children’s data protection is not another line item on a DPDP checklist. It needs visibility, verified consent, governance, risk assessment and evidence working together.
Because when the user is a child, your privacy infrastructure needs to know the difference.
If you would like to see how DataRakshaq’s minors’ consent workflow operates end to end, comment below or send us a message.
This article is for general information and does not constitute legal advice. Organisations should seek advice specific to their circumstances.

