Post

Verifiable Consent: Navigating Children's Data Protection Under DPDPA Section 9

Verifiable Consent: Navigating Children's Data Protection Under DPDPA Section 9

As of July 2026, India’s digital landscape is firmly governed by the Digital Personal Data Protection Act, 2023 (DPDPA), with its accompanying Rules now fully operational. A critical area of compliance, and one that presents unique challenges in the Indian context, is the protection of children’s data. Section 9 of the DPDPA establishes a robust framework, placing significant obligations on Data Fiduciaries to safeguard the privacy of minors. Central to this framework is the requirement for verifiable parental consent, a concept that demands careful interpretation and practical implementation across diverse Indian demographics.

The DPDPA’s Framework for Children’s Data

The DPDPA defines a ‘child’ as an individual who has not completed eighteen years of age, as per Section 2(c). Section 9(1) unequivocally mandates that a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing any personal data of a child. This foundational requirement underscores the Act’s commitment to protecting vulnerable populations. Beyond consent, the DPDPA imposes further restrictions: Section 9(2) prohibits Data Fiduciaries from undertaking tracking or behavioural monitoring of children, or targeted advertising directed at them. Furthermore, Section 9(3) prohibits any processing of children’s data that is likely to cause detriment to their well-being. These provisions collectively aim to create a safer digital environment for India’s youth, moving beyond mere consent to proactive protection. The DPDP Rules, notified earlier this year, have been instrumental in detailing the specific mechanisms and standards for achieving this verifiable consent.

The term “verifiable” is where the rubber meets the road for Indian businesses. Unlike jurisdictions with more uniform digital identification systems, India presents a complex tapestry of digital literacy, internet access, and socio-economic backgrounds. The DPDP Rules acknowledge this diversity, outlining a risk-based approach to verification methods. For low-risk data processing activities (e.g., educational apps not collecting sensitive personal data), simpler methods like a declaration from the parent followed by an email confirmation might suffice. However, for higher-risk activities, particularly those involving sensitive personal data or significant commercial implications, more robust verification is expected.

Methods likely encouraged by the DPDP Rules, based on global best practices adapted for India, could include: using official government identification linked to parents (e.g., through Aadhaar-enabled authentication, albeit with strict privacy safeguards to prevent misuse), digital signatures, or even knowledge-based authentication where parents answer questions only they would know. Direct credit card verification, common in some Western jurisdictions like under COPPA in the US, might have limited applicability in India due to lower credit card penetration. The emphasis is on “reasonable efforts” by the Data Fiduciary to ensure the person providing consent is indeed the child’s parent or guardian, rather than an absolute guarantee, which would be impractical. This contrasts with GDPR’s Article 8, which also requires “reasonable efforts” to verify parental consent but operates within a different digital identity ecosystem.

Sectoral Nuances and Regulatory Overlaps

The DPDPA does not operate in a vacuum. Its provisions on children’s data intersect with existing sectoral regulations, necessitating a harmonised approach. For financial services, the Reserve Bank of India (RBI) already has stringent Know Your Customer (KYC) norms for minors’ bank accounts or digital wallets, typically requiring guardian consent and documentation. Similarly, SEBI for investment accounts and IRDAI for insurance policies involving minors have established protocols. The DPDP Rules likely build upon these existing frameworks, requiring Data Fiduciaries in these sectors to integrate DPDPA’s verifiable consent requirements into their existing compliance processes.

Furthermore, the IT Rules, 2021 (as amended), particularly those pertaining to due diligence by intermediaries, continue to inform the broader online safety landscape. While the DPDPA is the primary legislation for personal data protection, the spirit of protecting children online, including through age-appropriate design and content moderation, remains a shared regulatory objective. The newly constituted Data Protection Board of India (DPBI) will play a crucial role in issuing specific guidelines and adjudicating on compliance, particularly in cases where sectoral rules might seem to diverge or require clarification vis-à-vis the DPDPA.

Balancing Protection with Practicality

The DPDPA’s stance on children’s data is unequivocally protective. However, implementing verifiable parental consent mechanisms in a country with over 1.4 billion people, a significant portion of whom are minors, presents substantial practical challenges for businesses. The “reasonable efforts” standard is key here. It implies that Data Fiduciaries must implement measures proportionate to the risks involved in their data processing activities concerning children. This necessitates a careful assessment of the type of data collected, the purpose of processing, and the potential impact on the child. Simplicity, clarity, and accessibility in consent requests, potentially in multiple Indian languages, will be crucial. Businesses are encouraged to adopt privacy-by-design principles, ensuring that their products and services are inherently designed to protect children’s data by default, rather than as an afterthought.

Practical takeaway:

Indian businesses, particularly those offering services or products likely to be accessed by children, must urgently review and fortify their age-gating and parental consent mechanisms. Understand the specific verifiable consent methods permitted or recommended by the DPDP Rules for your sector and the risk level of your data processing. Integrate these requirements into your existing KYC/AML or onboarding processes, especially if regulated by RBI, SEBI, or IRDAI. Prioritise clear, transparent communication with parents, ensuring consent requests are easily understandable and accessible. Invest in robust technical solutions for age verification and parental authentication, and conduct regular internal audits to ensure ongoing compliance. The Data Protection Board of India is active, and proactive adherence to Section 9 is not just a legal mandate but a business imperative for trust and reputation.

This post is licensed under CC BY 4.0 by the author.