
Verifiable Parental Consent Under DPDP: What Section 9 Demands
Under the DPDP Act, anyone below 18 is a child. Section 9 needs verified parental consent and bans tracking and targeted ads for children. What Rule 10 asks for, and an 8-step checklist.
If a child can sign up for your app, fill in your admission form or join your loyalty programme, the DPDP Act changes how you collect their data. From 13 May 2027, you will need verifiable parental consent before processing any personal data of a child, and under the Act a child is anyone below 18. That covers far more users than most teams assume: school students, many first-year undergraduates, teenage gamers and young shoppers.
This guide explains what Section 9 of the Digital Personal Data Protection Act, 2023 and Rule 10 of the DPDP Rules, 2025 require, what "verifiable" means in practice, the activities that are off limits for children altogether, and a checklist to start on now.
Key takeaways
- A "child" under the DPDP Act is anyone who has not completed 18 years (Section 2(f)).
- Section 9(1) requires verifiable consent of the parent or lawful guardian before processing any personal data of a child.
- Rule 10 asks you to check that the person consenting as a parent is an identifiable adult, using reliable identity and age details or a token from an authorised entity such as a DigiLocker service provider.
- Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, even with consent.
- Breach of Section 9 obligations can attract a penalty of up to Rs 200 crore. The obligations apply from 13 May 2027.
Why children's data is suddenly in the spotlight
Children's data is already a public issue in India, well before Section 9 takes effect. In July 2026 the Supreme Court directed that the model consent form for APAAR student IDs be amended nationwide to give parents an option to refuse consent, extending an earlier Odisha High Court ruling. In late September, an RTI reply reported by MediaNama showed that UIDAI has "viewing rights" on children's biometric update status in the national school database, with no written agreement in place.
Neither is a DPDP enforcement action. But both show where scrutiny is heading: parents, courts and journalists are asking who can see children's data, on what basis, and whether "consent" was ever real. Private businesses should expect the same questions.
What Section 9 of the DPDP Act requires
Section 9 of the DPDP Act sets three rules for any Data Fiduciary processing children's personal data:
- Verifiable parental consent (Section 9(1)). Before processing any personal data of a child, you must obtain the verifiable consent of the parent. "Parent" includes a lawful guardian.
- No detrimental processing (Section 9(2)). You must not process a child's data in a way likely to cause any detrimental effect on the child's well-being.
- No tracking, monitoring or targeted ads (Section 9(3)). You must not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children.
The third rule is the one product teams tend to miss. Parental consent does not unlock it. A parent cannot consent to behavioural advertising aimed at their child, because the Act prohibits the activity itself. If your analytics, recommendation engine or ad stack profiles users, you need a way to keep children out of it.
Section 9 also has a close cousin: Section 9(1) and Rule 11 apply similar verifiable consent requirements to a person with a disability who has a lawful guardian.
What makes parental consent "verifiable" under Rule 10
The Act leaves the method to the Rules. Rule 10 of the DPDP Rules, 2025 requires a Data Fiduciary to adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before processing a child's data. It also requires due diligence to check that the person identifying as the parent is an adult who is identifiable, if required for compliance with any law in India.
Rule 10 describes two broad ways to do that check:
- Details you already hold. Reliable identity and age details already available with you, for example because the parent is an existing, verified user of your service.
- Details or a token from an authorised entity. Identity and age details provided voluntarily by the parent, or a virtual token mapped to them, issued by an entity entrusted by law or by the government with maintaining such details. The Rule expressly includes details or tokens verified and made available by a Digital Locker service provider.
The Rules include illustrations covering a child who identifies as a child and a parent who may or may not already be a registered user. The common thread is that you cannot simply take a tick-box at face value when a child is involved. You need a documented, reasonable basis for believing an adult parent gave consent.
Exemptions: who gets relief, and how much
Rule 12 and the Fourth Schedule exempt certain classes of Data Fiduciaries and certain purposes from parts of Section 9. The listed classes include clinical establishments and healthcare professionals, educational institutions, and child care centres, but the relief is tied to specific purposes and limited to the extent necessary. The Fourth Schedule also lists purposes such as ensuring a child cannot access information likely to harm their well-being.
The practical lesson: an exemption is narrow, not a blanket pass. A school may be exempt for tracking attendance and safety, yet still need verifiable parental consent for a marketing newsletter or a third-party learning app. Read the Fourth Schedule line by line against your actual processing activities, and record which exemption you rely on for which purpose.
Getting verifiable parental consent right
Common mistakes to avoid
- Assuming "child" means under 13. Global products often use 13 or 16. Under DPDP it is 18.
- Relying on a date-of-birth field alone. A child can type any year. You need a sensible age gate and a verification step when the answer suggests a minor.
- Letting the child "confirm" parental consent. A checkbox saying "my parent agrees" is not verification of an adult.
- Running the same tracking for everyone. Section 9(3) needs children to be routed away from behavioural monitoring and targeted advertising, including through cookies and SDKs. See our cookie consent guide.
- No plan for the 18th birthday. Decide how you will seek fresh consent from the young adult once they turn 18.
A checklist for 2027
- Map every journey where someone under 18 could share personal data: sign-up, forms, apps, events, offline registrations.
- Add an age gate that asks for age neutrally, without nudging the user towards "over 18".
- When a user indicates they are under 18, route them to a parent consent flow before any processing starts.
- Verify the parent is an identifiable adult using details you already hold or a token from an authorised entity such as DigiLocker, as Rule 10 describes.
- Take granular consent for each purpose, with a Section 5 notice the parent can understand on its own. Our DPDPA consent guide covers notice and consent basics.
- Switch off tracking, behavioural profiling and targeted advertising for children's accounts.
- Document any Fourth Schedule exemption you rely on, purpose by purpose.
- Give parents an easy way to review and withdraw consent, and keep a verifiable record of every consent event.
How Consently helps
Consently is a DPDP-native consent management platform built by G. Giri & Partners LLP. For Section 9, it offers Aadhaar-based age verification through DigiLocker (signing in with Meri Pehchaan), alongside an over-18 self-declaration, so you can build the verification step into your consent flow. Consent is captured per purpose, can be confirmed by email or SMS OTP before it is recorded, and parents can review, update or withdraw it from a preference centre. Your legal team should still decide which verification method suits each journey.
Not sure where your organisation stands? Try our DPDP compliance calculator, or book a demo to see the parental consent flow.
FAQ
Who counts as a child under the DPDP Act?
Anyone who has not completed 18 years of age (Section 2(f)). The Act allows the government to notify a lower age for certain Data Fiduciaries whose processing is verifiably safe (Section 9(5)), but no such notification applies today.
Can a parent consent to targeted ads for their child?
No. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children. Parental consent does not make these activities lawful, subject only to exemptions notified under the Rules.
Is DigiLocker mandatory for verifiable parental consent?
No. Rule 10 lists DigiLocker-verified details or tokens as one option. You may also rely on reliable identity and age details you already hold. What matters is a reasonable, documented check that the parent is an identifiable adult.
When do the children's data obligations apply?
Section 9 and Rule 10 take effect on 13 May 2027, 18 months after the DPDP Rules were notified in November 2025. Age gates, parent flows and tracking changes take time to build, so it is worth starting now.
This article is for general information and is not legal advice. Please consult a qualified lawyer for advice on your specific situation.


