Post

Navigating Children's Data: The Verifiable Consent Conundrum Under DPDPA Section 9

Navigating Children's Data: The Verifiable Consent Conundrum Under DPDPA Section 9

The Digital Personal Data Protection Act, 2023 (DPDPA), now firmly in force, has ushered in a new era for data privacy in India. Among its most impactful provisions is Section 9, which specifically addresses the processing of children’s personal data. This section represents a significant shift, placing stringent obligations on Data Fiduciaries (DFs) and fundamentally reshaping how online services and platforms interact with India’s vast youth demographic. The core challenge for businesses, particularly in August 2026, lies in practically implementing the mandate of “verifiable parental consent” within the diverse Indian digital landscape.

The Mandate of Section 9: A Shield for Minors

Section 9 of the DPDPA defines a “child” as any individual under the age of eighteen. For any processing of a child’s personal data, a Data Fiduciary must obtain verifiable consent from the child’s parent or lawful guardian. This is a non-negotiable prerequisite, moving beyond mere declarations to require a demonstrable verification process. Furthermore, Section 9(3) imposes outright prohibitions on DFs: they cannot undertake tracking or behavioural monitoring of children, engage in targeted advertising directed at children, or process data that is likely to cause harm to a child. These prohibitions are broad and aim to create a safer digital environment, reflecting a more protective stance than many global counterparts. The DPDP Rules, subsequently notified, provide the much-anticipated operational details for these requirements.

The phrase “verifiable parental consent” is where the rubber meets the road for Indian businesses. Unlike the GDPR’s “reasonable efforts to verify,” DPDPA Section 9(1) demands a more robust, verifiable mechanism. The DPDP Rules have outlined various acceptable methods, acknowledging India’s unique digital infrastructure. These methods typically include leveraging existing digital identity frameworks like Aadhaar (with appropriate safeguards and consent from the parent), integrating with DigiLocker for identity verification, or using multi-factor authentication linked to a parent’s KYC-verified mobile number or email address. For higher-risk data processing activities, the Rules may also permit a combination of digital declarations followed by an offline or video-based verification step. The onus is entirely on the Data Fiduciary to demonstrate that consent was indeed obtained from a legitimate parent or guardian. This requires careful age-gating mechanisms at the point of data collection and robust backend verification systems, which many DFs are still working to fully integrate into their existing platforms.

Sectoral Nuances: Financial Services and Beyond

The implications of Section 9 extend significantly to regulated sectors. Financial institutions (FIs) under RBI, investment platforms regulated by SEBI, and insurance providers overseen by IRDAI frequently deal with minors’ data, whether for opening child savings accounts, managing mutual fund investments for minors, or processing child insurance policies. While these sectors already have stringent KYC norms, the DPDPA adds another layer. Under existing RBI guidelines, for instance, a minor’s account is typically operated by a guardian. Now, the FI must not only verify the guardian’s identity but also obtain verifiable consent for the processing of the minor’s data, aligning with DPDPA Section 9(1). This often means adapting existing digital onboarding flows to incorporate specific DPDPA-compliant parental consent mechanisms. Similarly, educational technology (EdTech) platforms, which inherently cater to children, face immense pressure to overhaul their data practices, ensuring all data processing, including analytics, adheres strictly to Section 9’s prohibitions on tracking and targeted advertising.

The Broader Prohibitions and Their Impact

Beyond consent, the DPDPA’s explicit bans on tracking, behavioural monitoring, and targeted advertising directed at children (Section 9(3)) are game-changers. This means that services popular with children, such as gaming apps, social media platforms, and streaming services, cannot use algorithms to profile children for advertising purposes or to keep them engaged through manipulative design. This is a stricter stance than, for example, the US’s COPPA, which focuses more on parental notice and consent for data collection. For Indian businesses, this necessitates a fundamental re-evaluation of their business models that rely on ad revenue from child users. Any processing “likely to cause harm to a child” (Section 9(4)) is also prohibited, a broad clause that requires DFs to conduct thorough Data Protection Impact Assessments (DPIAs) to identify and mitigate potential risks.

Practical Takeaway

Indian businesses, particularly those operating in the digital space or catering to younger audiences, must treat DPDPA Section 9 as a critical compliance pillar. General Counsels and Data Protection Officers should prioritize a comprehensive audit of all data processing activities involving individuals under 18. This includes implementing robust age-gating mechanisms, integrating verifiable parental consent flows (leveraging the mechanisms specified in the DPDP Rules), and rigorously enforcing the prohibitions on tracking, behavioural monitoring, and targeted advertising. Investing in privacy-by-design principles from the outset, coupled with regular training for staff on child data protection, is no longer optional but a legal imperative. The goal is not just compliance, but fostering a safer, more privacy-respecting digital environment for India’s future generations.

This post is licensed under CC BY 4.0 by the author.