CELEBRATING MORE THAN YEARS
AWARDS & RECOGNITION
UPDATES
PRACTICE AREAS
PEOPLE
News and Articles
Children's Data Consent,
Legal Risks for Businesses Processing Children's Data Without Proper Consent
Businesses increasingly collect information from children through educational platforms, gaming applications, social networks, healthcare services, e commerce platforms and other digital products. As this activity grows, Children's Data Consent has become a significant legal and compliance issue in India. Under the Digital Personal Data Protection Act, 2023, businesses processing a child's personal data must obtain verifiable consent from a parent or lawful guardian before processing, subject to prescribed exemptions. The law also imposes separate restrictions on tracking, behavioural monitoring and targeted advertising directed at children.For businesses, the issue is not simply whether a consent box exists. The real question is whether consent was obtained from the right person, in a verifiable manner, before processing began, and whether the organisation's subsequent activities remain within the permitted legal framework. Top Four Search Results for “Children's Data Consent” Search results for this emerging legal topic vary considerably because the Indian DPDP framework is still being implemented. The most relevant results identified during the research include specialist explanations of Section 9 and the parental consent mechanism, alongside academic and professional commentary. DPDP Act India: Section 9, Processing of Children's Data DPDP Reference Hub: Children's Data and Verifiable Consent NMIMS Law Review: Parental Consent and the DPDP Rules CheckDPDP: Verifiable Parental Consent under the DPDP Act The stronger content opportunity lies in moving beyond a simple explanation of parental consent. Businesses also need to understand the consequences of invalid consent, the distinction between consent and permission for specific processing activities, vendor exposure, security obligations, retention issues and the interaction between the Act and the notified Rules. What the DPDP Act Requires When Businesses Process Children's Data? Section 9 of the DPDP Act creates a special framework for processing personal data belonging to children. The Act defines a child as an individual who has not completed eighteen years of age. This threshold is important for Indian businesses because it is broader than the age threshold used in some other major privacy regimes. Before processing a child's personal data, the Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian. The requirement is not limited to particularly sensitive information. It applies to personal data of a child, subject to the exemptions created under the statutory framework. Section 9 also contains two important restrictions beyond consent. A Data Fiduciary must not process children's personal data in a manner likely to cause a detrimental effect on the child's well being. It must also not undertake tracking or behavioural monitoring of children or targeted advertising directed at children, subject to prescribed exemptions. This means parental consent should never be treated as a universal permission slip. A parent providing consent does not automatically authorise every form of data use. Why Invalid Children's Data Consent Creates Legal Exposure? The first risk arises when a business processes children's personal data without obtaining the required parental consent. Consider a learning application which allows a child to create an account independently. If the application begins collecting identifiable information before the required consent process is completed, the business may have difficulty demonstrating compliance with Section 9. The problem can become more serious where the business has no reliable record of how consent was obtained. A database entry stating "parent consent received" may not be sufficient if the organisation cannot demonstrate the verification process, date, relevant account and scope of the consent. A defensible consent system therefore requires more than an affirmative action by a user. It requires an auditable process. Verifiable Parental Consent Is Different from Ordinary Consent The DPDP Rules, 2025 provide the mechanism for verifiable parental consent. Rule 10 requires a Data Fiduciary to adopt appropriate technical and organisational measures to obtain verifiable consent from the parent before processing a child's personal data. The business must also exercise due diligence to establish whether the person identifying themselves as the parent is an identifiable adult. Rule 10 permits verification by reference to reliable identity and age information already available with the Data Fiduciary, or information voluntarily provided by the individual, including information made available through a virtual token issued by an authorised entity. This approach creates an important compliance distinction. A business cannot simply assume a person is a parent because the person has clicked "I am the parent". The organisation needs a reasonable and documented method for satisfying the statutory verification requirement. At the same time, the Rules do not require businesses to collect every conceivable identity document. A proportionate system should be designed around the statutory requirements, the nature of the service and the information already available to the organisation. Consent Does Not Permit Behavioural Tracking of Children One of the most important legal risks arises when businesses assume parental consent permits behavioural monitoring. Section 9 separately restricts tracking and behavioural monitoring of children. This means a business cannot necessarily justify behavioural profiling merely because a parent has approved the child's account. For example, an application might collect information about how long a child watches particular videos, which games they play, what educational content they select and how frequently they return. If this information is used to construct behavioural profiles, the business needs to assess whether the activity falls within the statutory prohibition or an applicable exemption. This is particularly relevant for advertising technology and recommendation systems. Product teams should therefore review analytics software, cookies, software development kits, pixels and similar technologies rather than focusing only on information deliberately collected through registration forms. Targeted Advertising Creates a Separate Compliance Risk Section 9 also restricts targeted advertising directed at children. The restriction matters because many digital businesses depend upon advertising systems operated by third party platforms. A business may not directly select an advertisement for a particular child. Its application may instead send user information to an advertising network which determines the advertisements displayed. From a compliance perspective, the technical architecture still needs careful examination. Businesses should understand what information is transferred to advertising providers, whether a child can be identified, whether the system creates profiles and whether advertising technology can distinguish children from adult users. The commercial arrangement with the advertising provider should also be reviewed alongside the technical configuration. Processing Without Consent Can Create Contractual and Commercial Problems Privacy non compliance is not confined to regulatory exposure. Businesses increasingly make representations about data protection in investment documents, customer contracts, vendor agreements and enterprise procurement questionnaires. A material privacy failure may therefore create contractual concerns if the organisation has represented compliance with applicable law. Investor due diligence can also expose weaknesses in children's data practices. An investor examining an education technology company, gaming platform or children's application may ask how age verification works, whether parental consent is documented, which vendors process children's data and whether the organisation has experienced privacy incidents. Poor documentation can therefore affect the commercial value of a business even before a regulatory authority becomes involved. Third Party Vendors Can Multiply the Risk Many businesses do not process children's data entirely within their own systems. Cloud infrastructure providers, analytics companies, customer relationship management platforms, messaging providers, advertising networks and outsourced support teams may all receive personal information. A business remains responsible for understanding these data flows.Suppose an application has a compliant parental consent mechanism but an analytics tool begins collecting information before consent is recorded. The organisation may still face a compliance problem. This is why vendor due diligence should form part of children's privacy governance. Contracts should address permitted processing, security safeguards, confidentiality, incident reporting, assistance with regulatory obligations and deletion or return of information where appropriate. Businesses reviewing their broader privacy and data protection laws framework should also map every third party receiving children's personal data. Excessive Data Collection Can Create an Additional Risk Consent does not make unnecessary collection appropriate. Businesses sometimes collect extensive information because it may become useful later. For children's services, this approach creates unnecessary privacy exposure. A business should consider whether each data field is genuinely required for the stated service.An educational platform may need a student's age group to provide appropriate learning material. It may not need precise location information. A gaming application may require an account identifier but have no genuine need for access to a child's contact list. Data minimisation reduces the consequences of a security incident and makes the organisation's compliance position easier to demonstrate. Security Failures Can Compound Consent Problems A business can obtain valid parental consent and still face legal exposure if children's personal data is inadequately protected. The DPDP Act imposes obligations on Data Fiduciaries concerning reasonable security safeguards. The Act also provides significant financial penalties for specified contraventions. A consent process therefore needs to sit alongside appropriate access controls, authentication, monitoring, secure storage and incident response procedures. Internal access should also be limited. Employees should receive access based on their actual responsibilities rather than unrestricted access to children's information. Security testing should cover both the application and the systems supporting the consent process. Poor Consent Records Can Become a Serious Evidentiary Problem One of the most overlooked risks is the inability to prove compliance. A business should be able to establish when consent was obtained, who provided it, how the person was verified and what processing was covered. The organisation should also understand how consent withdrawal is handled. If a parent withdraws consent, the business needs a process for responding appropriately and updating relevant systems. Simply changing a status field in one database may not be sufficient if children's information remains accessible through other systems or third party platforms. Good record keeping therefore has both legal and operational value. Businesses Need to Consider the DPDP Implementation Timeline The DPDP Act and Rules are being brought into force in stages. The Central Government notified the DPDP Rules, 2025 on 13 November 2025. The Rules provide different commencement periods for different provisions. Rules 3, 5 to 16, 22 and 23 are scheduled to commence eighteen months after publication. The corresponding commencement notification under the Act similarly places Sections 3 to 5, Sections 6 to 17 and several related provisions eighteen months after 13 November 2025. Section 9 therefore falls within the later commencement group. Businesses should not interpret the phased timeline as a reason to delay preparation. Rebuilding account registration, age assurance, parental verification, analytics and advertising architecture can take considerable time. Early preparation is particularly important for platforms with a large existing child user base. What Businesses Should Do Before Processing Children's Data? The starting point should be a detailed data mapping exercise. The business should identify where children's personal data enters the organisation, where it is stored, who can access it, which vendors receive it and how long it is retained. The next step should be an assessment of the registration and consent journey. The organisation should determine whether it can identify child users appropriately, whether parental verification works reliably and whether processing begins only after the required consent has been obtained.Technology should then be reviewed. Analytics, advertising, recommendation engines, cookies and software development kits should all be assessed. The objective is to ensure the actual technology reflects the organisation's legal position. Businesses should also review contracts with processors and vendors. Finally, the organisation should establish internal responsibility. Legal, product, engineering, marketing, security and compliance teams should understand their respective responsibilities. For organisations dealing with complex privacy questions, obtaining advice from a best corporate lawyer can help integrate data protection requirements with commercial contracts, technology arrangements and broader corporate governance. Exemptions Need Careful Legal Assessment The DPDP framework does provide exemptions for specified classes of Data Fiduciaries and purposes. The final Rules contain a Fourth Schedule setting out certain classes and purposes for which specified child related obligations do not apply, subject to conditions. Examples include certain healthcare activities, educational activities and child safety functions. Businesses should not assume an exemption applies simply because their service falls within a broad industry category. The conditions attached to an exemption matter. An educational institution, for example, may have a prescribed basis for tracking or behavioural monitoring when the activity is restricted to educational activities or the safety of enrolled children. The same principle cannot automatically be extended to commercial profiling for unrelated purposes. The safest approach is to document the precise statutory basis for any exemption relied upon. Common Mistakes Businesses Should Avoid A business may believe it is compliant because its privacy policy refers to children. This is insufficient if the underlying consent mechanism does not meet the statutory requirements. Another common mistake is relying entirely on self declared age information. Businesses also overlook third party analytics and advertising tools. A platform may appear compliant at the user interface level while collecting information through embedded technologies in the background. Another problem is treating parental consent as permission for all subsequent processing. Section 9 contains separate restrictions, including restrictions on tracking, behavioural monitoring and targeted advertising. Finally, businesses sometimes wait until enforcement becomes imminent before reviewing their systems. Privacy compliance is considerably easier when considered during product development rather than retrofitted into an established platform. Conclusion Processing children's personal data without proper consent is not simply a privacy policy issue. It can create regulatory, contractual, operational, security and commercial risks for businesses operating in India.The DPDP framework places children in a specially protected category. Businesses need verifiable parental consent before processing children's personal data where Section 9 applies. They must also consider separate restrictions concerning detrimental effects on well being, tracking, behavioural monitoring and targeted advertising. The strongest compliance approach begins with understanding the data flow. Businesses should know what they collect, why they collect it, how parental consent is verified, where the information goes, who can access it and when it should be deleted. Most importantly, legal compliance should match the technology in use. A carefully drafted policy cannot protect a business if its application behaves differently from the policy. The official Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 should remain the primary references when assessing current obligations and commencement dates. Frequently Asked Questions (FAQs) Q1. What is Children's Data Consent under Indian law? It refers to the verifiable consent of a parent or lawful guardian required before a Data Fiduciary processes personal data belonging to a child, subject to applicable exemptions under the DPDP framework. Q2. Who is considered a child under the DPDP Act? The DPDP Act defines a child as an individual who has not completed eighteen years of age. The Central Government may notify a lower age for specified circumstances where the statutory conditions are satisfied. Q3. Is a child's own consent sufficient? No. Where Section 9 applies, the Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing the child's personal data. Q4. What does verifiable parental consent mean? Rule 10 requires appropriate technical and organisational measures and due diligence to establish whether the individual identifying themselves as the parent is an identifiable adult. Verification may rely on reliable information already held by the Data Fiduciary or information voluntarily provided through specified mechanisms. Q5. Does parental consent allow targeted advertising to children? No. Section 9 separately prohibits targeted advertising directed at children, subject to prescribed exemptions. Parental consent should not be treated as permission to disregard this restriction. Q6. Can businesses track children if parents have given consent? Businesses must separately examine the prohibition on tracking and behavioural monitoring under Section 9. Consent does not automatically override this statutory restriction. Prescribed exemptions may apply in limited circumstances. Q7. What happens if a business processes children's data without proper consent? The business may face regulatory consequences under the DPDP framework, alongside contractual, commercial, reputational and investor due diligence risks. The applicable consequences depend on the nature and circumstances of the contravention. Q8. Can schools and healthcare providers rely on exemptions? Certain exemptions exist under the Fourth Schedule, but they are limited and conditional. A business or institution should establish the exact statutory basis and conditions before relying upon an exemption. Q9. When should businesses begin preparing for children's data compliance? Businesses should begin preparation before the relevant provisions become operational. Consent architecture, age assurance, vendor arrangements and technology controls can require substantial redesign, particularly for platforms with a large existing user base.  
Data Privacy Compliance,
Data Privacy Compliance for Apps and Websites Used by Children in India
Children increasingly use mobile applications and websites for education, gaming, entertainment, healthcare, shopping and communication. For businesses operating these platforms, Data Privacy Compliance is becoming a product design issue as much as a legal requirement. India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 introduce specific safeguards for children's personal data, including verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising. For an app or website used by children, privacy compliance cannot be reduced to a privacy policy or consent button. Businesses need to understand what data they collect, how they identify child users, how parental consent is verified, which vendors receive the information and how the data is eventually deleted. What Data Privacy Compliance Means for Children's Apps and Websites? Data privacy compliance refers to the legal, organisational and technical measures used by a business to collect, use, store, disclose and delete personal data in accordance with applicable law. For children's platforms, the compliance burden becomes more specific because Indian law gives children enhanced protection.The DPDP Act defines a child as an individual who has not completed eighteen years of age. This is significant for businesses accustomed to international privacy frameworks, where the age threshold for children's consent may be lower. A platform serving teenagers in India therefore needs to consider the Indian threshold when designing its privacy controls. The legal framework is built around the concept of a Data Fiduciary. Broadly, this is the organisation deciding why and how personal data is processed. An app operator, website owner or education platform may fall within this role even when technical processing is performed by third party service providers. The organisation remains responsible for understanding its data processing activities and implementing appropriate safeguards. Why Children's Data Requires a Different Compliance Approach? Children may have a different understanding of privacy risks and may be less capable of assessing the long term consequences of sharing personal information. An application may collect a child's name, age, photograph, location, device information, educational records, voice recordings or behavioural information.Some of these details may appear harmless when considered individually. Their combination can create a much more detailed picture of a child. For example, an educational application may know a student's name, school, learning performance, location and usage patterns. A gaming platform may collect information about play behaviour and interaction patterns. A children's social platform may receive photographs, messages and information about social relationships. Businesses should therefore examine the complete data environment rather than reviewing individual data fields in isolation. What Does the DPDP Act Say About Children's Personal Data? Section 9 of the DPDP Act contains specific provisions concerning processing of personal data belonging to children. Before processing such data, the Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian in the prescribed manner. The provision also prevents processing likely to cause a detrimental effect on a child's well being. The Act further prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This distinction is important. Parental consent is not a blanket permission for every form of processing. Suppose a parent approves an account for an educational application. The business cannot automatically assume the approval permits behavioural profiling or targeted advertising. Each processing activity still needs to be assessed against the statutory restrictions and applicable exemptions. Businesses should therefore design their privacy architecture around the complete lifecycle of children's data. Understanding Verifiable Parental Consent A major compliance issue is the difference between ordinary consent and verifiable parental consent. A child clicking an acceptance button does not satisfy the statutory requirement where parental consent is required. The business needs a mechanism capable of establishing the identity and adult status of the person providing consent as the parent or lawful guardian. Rule 10 of the DPDP Rules, 2025 sets out requirements concerning verifiable consent. It requires Data Fiduciaries to adopt appropriate technical and organisational measures and exercise due diligence to establish whether the individual identifying themselves as a parent is an identifiable adult. The Rules contemplate reliance on reliable identity and age information already available with the Data Fiduciary, as well as information voluntarily provided by the parent or qualifying virtual tokens. This gives businesses some flexibility in designing their consent systems. It does not, however, mean every verification method will automatically be sufficient. The business needs to assess whether its process genuinely supports the statutory requirement and whether the information collected for verification is itself handled responsibly. How Apps Should Approach Age Assurance Age assurance is one of the practical challenges for child focused platforms. An application may ask a user to enter their date of birth. Yet a simple self declaration may not establish whether the information is accurate. Businesses therefore need to assess the nature of their service, the risks associated with the data being collected and the appropriate method for identifying child users. The objective should not be indiscriminate collection of identity documents. Collecting excessive information merely to prove age can create another privacy risk. A well designed approach should consider proportionality, data minimisation and security alongside the need for reliable age assurance. For some platforms, age information may already be available through a verified parent account. For others, a separate parental verification process may be necessary. The correct approach will depend on the service, user journey and applicable legal requirements. Privacy Notices Need to Be Designed for Real Users A privacy notice is often treated as a legal document placed at the bottom of a website. For children's services, this approach is unlikely to be sufficient from a practical compliance perspective. The DPDP framework places emphasis on clear information concerning personal data and the purpose for processing. The Rules also establish requirements concerning notices and consent. Businesses should therefore consider how the privacy information appears during registration, parental verification and subsequent use of the service. The parent should be able to understand what information is collected, why it is needed and how it will be used.The notice should also correspond with the actual technology. If an application says it collects information only to provide educational services but embedded technologies collect additional behavioural information, the organisation may create a significant compliance gap. Tracking and Behavioural Monitoring Need Particular Attention Children's applications often rely on analytics. Analytics can help businesses understand which features users prefer, where users leave an application and how the service performs. However, businesses need to distinguish between technical analytics and activities falling within the statutory restriction on tracking or behavioural monitoring of children. The same technology may have different privacy implications depending on how it operates. For example, collecting aggregated technical information for security or service reliability may differ from creating a persistent behavioural profile of an identifiable child for commercial purposes. Product and legal teams should therefore assess analytics tools individually. A privacy review should include software development kits, cookies, pixels, advertising technologies, crash reporting tools and other third party components embedded in the application. Targeted Advertising to Children Advertising is another significant area of risk. Section 9 specifically prohibits targeted advertising directed at children, subject to prescribed exemptions. Businesses should therefore examine whether advertising systems use information about child users to determine which advertisements they see. This assessment should not stop with the company's own advertising platform. Third party advertising networks may receive information through software integrated into an application or website. An organisation should know which third parties receive information, why they receive it and whether their processing is compatible with the business's obligations. Advertising contracts and technical configurations should therefore be reviewed together. Third Party Vendors Can Create Hidden Privacy Risks Children's apps rarely operate entirely on their own infrastructure. Cloud providers may host databases. Analytics providers may process usage information. Customer support platforms may receive account information. Payment service providers may process transaction details. Communication tools may handle emails, messages or notifications. Each relationship creates a potential data flow. Businesses should maintain a record of relevant vendors and understand the role each vendor plays. Contracts should address confidentiality, security, permitted processing, incident management, deletion and assistance with regulatory obligations where appropriate. The business should also know whether a vendor uses further service providers. This is where data protection rules should be considered alongside the actual technical architecture. Legal documentation should not exist separately from the way the application operates. Data Minimisation Should Start at Product Design One of the most effective ways to reduce privacy risk is to avoid collecting unnecessary information. Before introducing a new feature, the product team should ask a simple question: does this feature genuinely require the proposed personal data? A children's learning platform may not need a precise location to deliver a mathematics lesson. A gaming application may not need access to a contact list to provide gameplay. A website may not need a child's photograph simply because an optional profile feature is available. Reducing unnecessary collection limits exposure in the event of unauthorised access and makes compliance easier to manage. Privacy should therefore be considered during product development rather than added after the application has been launched. Security Safeguards Are Part of Privacy Compliance Privacy and security are related but distinct. Privacy determines whether personal data is collected and used appropriately. Security focuses on protecting the information from unauthorised access, alteration, disclosure or loss. For children's platforms, both areas require careful attention. The DPDP Act places obligations on Data Fiduciaries concerning reasonable security safeguards. The Act also provides significant financial penalties for specified contraventions. The Schedule includes a penalty of up to ₹200 crore for breach of obligations relating to children. Businesses should therefore consider access controls, secure authentication, encryption where appropriate, vulnerability management, monitoring, secure software development and incident response procedures. Internal access should also be restricted according to business need. A developer does not necessarily need access to a complete database containing children's personal information. Data Retention and Deletion Should Be Planned Early A common privacy weakness is indefinite retention. Businesses sometimes retain information because deleting it appears inconvenient or because the organisation may need it in the future. This approach can increase privacy and security exposure. For children's applications, retention should have a clear business and legal rationale. The organisation should understand what information is retained, where it is stored, who can access it and when it should be deleted or anonymised. Deletion should also extend to relevant systems where appropriate. Removing information from the primary database while retaining copies in other systems, backups or third party platforms may leave the business with an incomplete deletion process. A documented retention framework can help avoid this problem. The DPDP Rules Are Being Implemented in Phases Businesses should pay close attention to commencement dates. The DPDP Rules, 2025 were notified in November 2025. They establish a phased implementation structure rather than making every provision operational on the same date. MeitY's official materials identify later commencement dates for several substantive requirements. The child specific provisions under Section 9 and Rule 10 are scheduled to commence eighteen months after publication of the Rules. On the notified timeline, this places commencement in May 2027. Businesses should not interpret the future commencement date as a reason to postpone preparation. Changing an application's registration process, consent architecture, databases and third party integrations can take considerable time. Organisations serving children should use the transition period to identify gaps and test their systems. Building a Practical Compliance Framework for Children's Apps A strong compliance programme begins with a data inventory. The organisation should identify every category of children's personal data collected through its application or website. It should then map where the information travels, which systems store it and which vendors process it. The next stage is to assess age assurance and parental verification.The business should then review its privacy notice, consent mechanism, analytics systems, advertising technology, vendor contracts, retention practices and security controls. Testing is equally important. A business should test what happens when a child attempts to register, when a parent provides consent, when consent is withdrawn and when a user moves from a child status to adulthood. It should also test unsuccessful verification attempts and incomplete registration journeys. Privacy compliance should be treated as an operational process rather than a one time legal exercise. How Businesses Can Strengthen Governance Responsibility should be allocated internally.Product teams need to understand privacy requirements before introducing new features. Developers need clear rules concerning personal data access. Marketing teams should know the restrictions applying to children's advertising. Procurement teams should review third party data processing arrangements. Senior management should also receive visibility into significant privacy risks. A business may have an excellent privacy policy yet remain exposed because its application behaves differently from the policy. Regular reviews can identify such gaps before they become regulatory or commercial problems. For businesses with complex data flows, engaging a best corporate law firm can also help integrate privacy obligations with contracts, technology arrangements, corporate governance and broader regulatory requirements. Common Mistakes Businesses Should Avoid One common mistake is treating a date of birth field as complete age verification. Another is assuming parental consent permits every type of data processing. Businesses also sometimes overlook third party software embedded within their websites and applications. Advertising tools, analytics services and software development kits can create additional data flows. Another recurring issue is collecting more information than necessary for age verification. Some businesses also rely heavily on written policies without testing whether their technology actually follows those policies. The strongest approach is to connect legal requirements with product design, technical controls and operational procedures. Conclusion Children's data protection requires more than a well drafted privacy policy. For apps and websites used by children in India, businesses need to connect legal requirements with product design, age assurance, parental verification, data minimisation, security, advertising controls, vendor management and retention practices.   Frequently Asked Questions (FAQs) Q1. What is Data Privacy Compliance for children's apps in India? It is the process of ensuring an application or website collects, uses, stores, shares and deletes children's personal data in accordance with applicable Indian privacy requirements, including the DPDP Act and DPDP Rules. Q21. What age is considered a child under India's DPDP framework? The DPDP Act defines a child as an individual who has not completed eighteen years of age. Q3. Is parental consent required for children's apps in India? Section 9 requires verifiable parental or lawful guardian consent before processing a child's personal data, subject to prescribed exemptions. Q4. Can an app simply ask the child to confirm their age? A child's own declaration does not replace the statutory requirement for verifiable parental consent where Section 9 applies. Businesses need an appropriate mechanism for identifying and verifying the parent or lawful guardian. Q5. Can children's apps use behavioural analytics? Businesses need to carefully assess whether their analytics activities amount to tracking or behavioural monitoring covered by Section 9. The DPDP Act prohibits tracking and behavioural monitoring of children, subject to prescribed exemptions. Q6. Can businesses show targeted advertisements to children? Section 9 prohibits targeted advertising directed at children, subject to prescribed exemptions. A business should therefore assess its advertising architecture rather than relying solely on parental consent. Q7. Do children's websites need a privacy policy? A privacy notice is an important part of a compliant privacy framework, but a policy alone does not establish compliance. Businesses also need appropriate consent, governance, security, data handling and operational controls. Q8. When will the child specific DPDP requirements take effect? The child specific requirements under Section 9 and Rule 10 are scheduled for commencement eighteen months after notification of the Rules in November 2025, placing their scheduled commencement in May 2027. Businesses should verify the latest government notifications before relying on any commencement date. Q9. What is the penalty for violating children's data obligations? The DPDP Act provides for significant financial penalties. The Schedule specifies a penalty of up to ₹200 crore for breach of obligations relating to children. Q10. Should businesses conduct a children's data audit? Yes. An audit can identify what children's information is collected, how it moves through the organisation, which third parties receive it and whether the existing product architecture supports applicable privacy requirements.
Parental Consent,
Parental Consent Requirements for Businesses Collecting Data from Minors
Businesses increasingly interact with minors through education platforms, gaming applications, social networks, healthcare services, retail platforms and digital entertainment. In India, Parental Consent has become a central compliance consideration for organisations processing children's personal data under the Digital Personal Data Protection Act, 2023. The law treats an individual below eighteen years as a child and requires verifiable consent from a parent or lawful guardian before processing the child's personal data, subject to specified exemptions. The requirement is more substantial than adding a consent checkbox to an application. Businesses need a reliable process for identifying child users, verifying the adult providing consent, recording the consent, controlling subsequent processing and demonstrating compliance when required. What Does Parental Consent Mean Under Indian Data Protection Law? The DPDP Act places specific obligations on a Data Fiduciary when processing personal data belonging to a child. Section 9 requires verifiable consent from the child's parent or, where applicable, lawful guardian before processing begins. The statutory explanation expressly recognises consent from a lawful guardian within the meaning of parental consent. The requirement reflects an important legal distinction. A child's affirmative action on a website or application is not automatically sufficient. The business must establish the authority of an adult who is providing consent on the child's behalf. This makes parental verification a separate compliance exercise from ordinary user consent. The distinction is particularly relevant for platforms where children can create accounts independently. A company may know the age of the user but still need a process to establish who is giving consent and whether the person is an adult parent or lawful guardian. Who Is Considered a Child Under the DPDP Act? The DPDP Act adopts a clear age threshold. A child means an individual who has not completed eighteen years of age. This is important for businesses serving teenagers because the Indian framework does not generally stop enhanced child protection at thirteen, sixteen or another lower age used in some international privacy regimes. Businesses should therefore examine their user base carefully. A service may be designed for adults but still attract users below eighteen. In such cases, the organisation needs to consider how its systems identify or otherwise deal with child users. Age assessment is consequently an important part of privacy governance. It should be considered during product design rather than treated solely as a legal policy issue. Why a Simple Consent Checkbox May Not Be Enough? A conventional consent mechanism usually records an affirmative action from the user. For ordinary data processing, the organisation may rely on the Data Principal's consent in accordance with the statutory framework. Children's data introduces another layer. Rule 10 of the Digital Personal Data Protection Rules, 2025 requires a Data Fiduciary to adopt appropriate technical and organisational measures to ensure verifiable consent from the parent before processing a child's personal data. The organisation must also exercise due diligence to check whether the person claiming to be the parent is an adult and is identifiable where required for compliance with Indian law. Consequently, a declaration such as “I am the parent” may not provide sufficient evidence by itself. An organisation needs a process capable of establishing the adult's identity and age through an appropriate verification method. How Must Businesses Verify the Parent? The final Rules provide two principal routes for verification. First, the Data Fiduciary may rely on reliable identity and age details already available with it. This could be relevant where the parent is an existing verified user of the service. Second, the parent may voluntarily provide identity and age information, or provide a virtual token mapped to such information. The Rules recognise tokens issued by an authorised entity and also refer to information or tokens made available and verified through a Digital Locker service provider. The framework therefore does not prescribe a single universal technology for every business. Instead, it establishes an outcome. The organisation needs appropriate technical and organisational measures and must exercise due diligence concerning the adult claiming parental status. This gives businesses some flexibility in designing their consent architecture while placing responsibility on them to make the mechanism reliable. What Does Verifiable Consent Look Like in Practice? Consider a child attempting to create an account on an educational application. The platform may first identify the user as a child. The system can then direct the parent to a separate verification process. If the parent is already a verified user, the business may use reliable identity and age information already held by it. If the parent is not an existing user, the Rules contemplate voluntary submission of identity and age details or an appropriate virtual token. The business should then retain appropriate records showing the consent process. The important point is sequencing. Where Section 9 applies, the consent requirement arises before processing of the child's personal data. A business should therefore avoid designing a process where extensive child data is collected first and parental verification occurs later. The architecture should minimise the information collected before verification. What About Lawful Guardians? The DPDP Act expressly extends the concept of parental consent to a lawful guardian where applicable. The Rules separately address verification concerning persons with disabilities who have a lawful guardian. Rule 11 requires due diligence to establish the guardian's appointment by a court, designated authority or local level committee under the applicable guardianship law. Businesses should therefore avoid treating every adult who claims responsibility for a child as automatically authorised to provide consent. The nature of the relationship can matter. Where a service is likely to receive consent from guardians rather than biological parents, the organisation should ensure its verification process reflects the applicable legal position. Parental Consent Does Not Permit Every Form of Processing Obtaining consent does not give a business unrestricted permission to process children's data. Section 9 contains additional safeguards. A Data Fiduciary must not undertake processing likely to cause a detrimental effect on the well being of a child. The Act also prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This is an important distinction for businesses. A company cannot assume its compliance obligations end once a parent approves the account. The organisation must examine what happens to the child's information after consent. For example, analytics, recommendation engines, behavioural profiling and advertising technologies should be assessed separately. A valid consent mechanism cannot automatically authorise processing prohibited by Section 9. Are There Exemptions From Parental Consent? Yes. The DPDP Rules, 2025 establish limited and conditional exemptions under Rule 12 and the Fourth Schedule. The exemptions apply to specified classes of Data Fiduciaries or specified purposes, subject to conditions. Part A of the Fourth Schedule includes certain healthcare establishments and professionals, educational institutions and specified childcare and transport arrangements. The exemption depends on the purpose and conditions attached to the relevant category. The Rules also recognise specified purposes in Part B. Businesses should be careful when relying on these exemptions. Being an educational institution or healthcare provider does not create a blanket exemption from children's data requirements. The processing must fall within the relevant category and satisfy the applicable conditions. An exemption analysis should therefore be documented rather than assumed. What Businesses Should Consider Before Collecting a Minor's Data? The first step should be data mapping. A business should identify where children's information enters its systems, what categories are collected, why each category is required and which employees, vendors or technology providers can access it. The next consideration is age assurance. The organisation needs to understand how it identifies users who may be children and how the parental verification process will operate. The consent journey should then be mapped from beginning to end. This includes the notice presented to the parent, verification method, consent record, withdrawal mechanism and subsequent handling of the child's information. Businesses should also review their technology stack. Third party analytics tools, advertising software, customer relationship platforms and software development kits may collect or infer information independently of the main application. A privacy review limited to the company's own database may therefore miss important processing activities. Privacy Notices Must Match the Actual Consent Process A privacy notice should not promise one form of processing while the technology performs another. The DPDP Rules require notices to provide clear information about personal data being collected and the purpose for processing. The Government's explanatory note emphasises standalone, understandable notices and transparent information necessary for informed consent. For services used by minors, businesses should ensure the notice, parental consent interface and actual data practices remain consistent. If the application uses information for personalisation, analytics or another purpose, the business should assess whether the purpose is adequately described and legally permitted. This alignment is also important from an evidentiary perspective. A company should be able to demonstrate how its stated privacy practices correspond with its technical operations. Consent Records Should Be Auditable A business should be able to answer a basic question: how can you demonstrate which parent provided consent, for which child, for what processing and when? Consent records can help answer this question. The organisation should consider recording relevant information about the consent event without unnecessarily retaining additional identity information. Excessive retention creates its own privacy and security concerns. The consent architecture should also accommodate withdrawal where applicable. A parent should not face an unnecessarily complicated process simply because consent was initially provided electronically. Record keeping, access controls and retention periods should therefore form part of the overall privacy governance framework. Businesses Should Review Third Party Contracts Children's data frequently moves beyond the primary platform. A gaming company may use cloud hosting. An EdTech business may use analytics software. A healthcare application may rely on external infrastructure or communication providers. Each relationship can create a separate risk. Businesses should examine whether vendors process children's data, what information they receive, where it is stored, whether they can appoint sub processors and how they respond to security incidents. Contracts should reflect the actual processing relationship and allocate appropriate responsibilities. This is an area where data privacy lawyers can assist businesses in reviewing consent architecture, privacy notices, vendor arrangements and regulatory exposure. The objective should be to ensure legal documents reflect real technical practices rather than operating as standalone paperwork. Security Is Part of Children's Data Governance Parental consent does not remove cybersecurity obligations. The DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The statutory penalty framework also provides significant financial exposure for specified contraventions, including a penalty of up to ₹200 crore for breach of obligations relating to children. Security controls should therefore be proportionate to the data being processed. Businesses should consider access restrictions, authentication, encryption where appropriate, secure development practices, vulnerability management, monitoring and incident response. The organisation should also limit internal access. Not every employee involved with a children's service needs access to the underlying personal data. When Will the Parental Consent Rules Apply? This is an important current legal point. The final Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4 is scheduled to commence one year later, while Rules 3 and 5 to 16, along with Rules 22 and 23, are scheduled to commence eighteen months after publication. Rule 10 therefore has a scheduled commencement date of 13 May 2027. The Data Security Council of India also identifies 13 May 2027 as the commencement date for Rule 10 and the corresponding Section 9 obligations. This does not mean businesses should wait until 2027 to start preparing. Consent architecture can require changes to databases, onboarding flows, identity verification, contracts and advertising systems. Organisations with significant child user bases may need substantial lead time. How Businesses Can Prepare Now? A sensible preparation programme should begin with a children's data inventory. The organisation should identify whether it actually needs to collect personal data from minors. If the service can operate without collecting such information, redesigning the user journey may be simpler than implementing a complex verification system. Where collection is necessary, businesses should develop an age assurance and parental verification framework. The next step should be testing. A consent system should be tested against different user journeys, including an existing parent user, a new parent, a child attempting to register independently and situations where consent is withdrawn. Technology teams should also examine third party tools. A platform may have a compliant registration page while an embedded analytics tool continues behavioural tracking. Finally, the business should establish governance. Responsibility for children's data should be clearly assigned. Internal policies should address consent records, access, retention, security incidents and vendor management. Businesses with broader corporate structuring, technology contracts or regulatory questions may also wish to involve a corporate law firm when integrating privacy obligations with their wider legal framework. Common Mistakes Businesses Should Avoid One common mistake is treating an age declaration as equivalent to parental verification. Another is collecting a child's information before completing the required verification process. Businesses also risk assuming consent permits behavioural monitoring or targeted advertising. Section 9 imposes separate restrictions on these activities, subject to prescribed exemptions. Another problem arises when businesses rely on an exemption without checking its conditions. Finally, some organisations focus heavily on the privacy policy but overlook their software, vendors and internal data flows. A defensible privacy programme must cover the complete lifecycle of the information. Conclusion Parental consent under India's DPDP framework is not merely a procedural checkbox. It requires businesses to think carefully about age assurance, adult verification, consent records, data minimisation, security and the purposes for which children's information is processed. The most important compliance distinction is between recording consent and proving verifiable parental consent. Businesses need systems capable of demonstrating who provided consent and ensuring the processing permitted by the consent remains within the boundaries of Indian data protection law. The final Rules provide businesses with a defined framework for verification, including reliance on reliable identity and age information and qualifying virtual tokens. They also introduce limited exemptions for specified organisations and purposes. With the principal child data provisions scheduled for commencement in May 2027, businesses have an opportunity to address these issues before they become urgent operational requirements.   Frequently Asked Questions (FAQs) Q1. Is parental consent mandatory for collecting children's data in India? Under Section 9 of the DPDP Act, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. Q2.What age is considered a minor under the DPDP Act? For the purposes of the DPDP Act, a child is an individual who has not completed eighteen years of age. Q3.What is verifiable parental consent? Verifiable parental consent requires a Data Fiduciary to use appropriate technical and organisational measures and exercise due diligence to establish that the person providing consent as a parent is an identifiable adult. Rule 10 permits reliance on reliable identity and age details or voluntarily provided information or qualifying virtual tokens. Q4.Is an OTP sufficient for parental consent? An OTP may be part of a broader verification process, but businesses should not assume an OTP alone automatically satisfies the statutory concept of verifiable consent. The organisation must consider whether its complete process establishes the adult's identity and age as contemplated by Rule 10. Q5.Can a child provide consent for their own data? Where Section 9 applies, the statutory framework requires verifiable consent from the parent or lawful guardian before processing the child's personal data. Q6.Can businesses track children's online behaviour after obtaining parental consent? Section 9 prohibits tracking or behavioural monitoring of children, subject to prescribed exemptions. Parental consent should not be treated as a general authorisation to undertake prohibited processing. Q7.Can companies use targeted advertising for children? Section 9 prohibits targeted advertising directed at children, subject to prescribed exemptions. Q8.Are schools exempt from obtaining parental consent? The Rules provide limited exemptions for specified educational processing. The exemption is conditional and should be assessed against the relevant provisions of the Fourth Schedule. Q9.When will Rule 10 of the DPDP Rules apply? Rule 10 is scheduled to commence eighteen months after publication of the Rules on 13 November 2025. The scheduled date is 13 May 2027. Q10.What is the penalty for violating children's data obligations? The DPDP Act's Schedule provides for a penalty of up to ₹200 crore for breach of the obligations relating to children. The actual penalty depends on the nature and circumstances of the contravention.
Children’s Data Protection,
Children’s Data Protection Under India’s DPDP Act: What Businesses Need to Know
The rapid growth of digital services for children has made Children's Data Protection an important legal issue for businesses operating in India. Educational platforms, gaming companies, healthcare providers, social platforms, e commerce businesses and family focused applications may collect information from users below eighteen years of age. India’s Digital Personal Data Protection Act, 2023 introduces specific safeguards for such processing, including verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising. The Digital Personal Data Protection Rules, 2025 now provide greater operational clarity, although the substantive children’s data provisions are subject to the Act’s phased commencement framework. For businesses, the issue extends well beyond publishing a privacy policy. Organisations need to examine their products, consent mechanisms, technology infrastructure, advertising practices, contracts and internal governance before the relevant provisions become operational. What Does Children’s Data Protection Mean Under the DPDP Act? The DPDP Act takes a broad approach to the protection of children’s personal data. Section 2(g) defines a child as an individual who has not completed eighteen years of age. This age threshold is important because businesses cannot simply adopt the age threshold used under another country's privacy regime and assume it will satisfy Indian requirements. Section 9 of the Act specifically deals with processing personal data of children. Before processing such data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian in the prescribed manner. The provision also requires businesses to ensure their processing does not cause a detrimental effect on the well being of a child. Further, subject to prescribed exemptions, the Act prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. This creates a higher compliance threshold than ordinary personal data processing. A business must therefore understand not only what information it collects, but also how its product uses information after collection. A child’s name, age, photograph, account details, location, educational information or online activity may all form part of a wider data processing ecosystem. Why the DPDP Act Matters to Businesses? The DPDP Act establishes a framework for digital personal data processing in India. It places obligations on Data Fiduciaries, meaning organisations which determine the purpose and means of processing personal data. The distinction is commercially significant. A company does not avoid responsibility simply because another company provides the technical infrastructure used for processing. Cloud providers, analytics vendors, software providers and other processors may support the service, but the business still needs to understand its own statutory responsibilities. The Act also creates rights for Data Principals and establishes an enforcement structure through the Data Protection Board of India. The statutory framework therefore moves privacy away from being purely an internal policy issue and towards formal organisational accountability. For businesses dealing with children, this accountability becomes particularly important because the law treats children's data as requiring additional safeguards. The Current Legal Position and Commencement Timeline One of the most important points for businesses is the phased implementation of the DPDP framework. The Central Government notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. The Rules provide for different commencement dates. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4 is scheduled to commence one year after publication, while Rules 3 and 5 to 16, along with Rules 22 and 23, are scheduled to commence eighteen months after publication. The Act follows a similar phased approach. India Code records Sections 2, 18 to 26, 35 to 43 and specified provisions of Section 44 as commencing on 13 November 2025. Substantive provisions including Sections 3 to 5, Sections 7 to 17 and other specified provisions are scheduled to commence eighteen months from that date. Section 9 falls within this later group. Accordingly, as of August 2026, businesses should distinguish between provisions already operational and provisions scheduled to commence later. This distinction is important for legal accuracy. Businesses should not describe every DPDP obligation as fully enforceable today. At the same time, waiting until the final commencement date would be commercially unwise. Product changes, vendor negotiations, consent architecture and internal governance can take months to implement. Verifiable Parental Consent Is Central to Compliance The most visible obligation concerning children's data is parental consent. Section 9 requires verifiable consent from the parent or lawful guardian before processing a child's personal data. The final Rules provide greater detail on how verification is expected to work. Rule 10 requires a Data Fiduciary to adopt appropriate technical and organisational measures and conduct due diligence to establish whether the person presenting themselves as a parent is an identifiable adult. Verification may rely on reliable identity and age information already available to the Data Fiduciary or information voluntarily provided by the individual or through a virtual token issued by an authorised entity. This creates an important design challenge. A business must verify parental authority without creating an unnecessarily intrusive identity collection process. Collecting excessive information from parents can create additional privacy and security risks. The consent mechanism should therefore be designed around necessity, proportionality and security. A simple declaration such as “I am the parent” may not be sufficient where the law requires verifiable consent. Businesses should document the verification methodology and retain appropriate evidence of consent. The Restrictions on Tracking and Behavioural Monitoring The DPDP Act takes a particularly cautious approach to children's behavioural data. Section 9 restricts tracking and behavioural monitoring of children, along with targeted advertising directed at children, subject to prescribed exemptions. This can affect technologies businesses commonly use for analytics and personalisation. For example, a platform may use cookies, device identifiers, engagement data, location information or interaction histories to understand user behaviour. For an adult audience, these practices may form part of ordinary analytics. A child focused service requires a much more careful assessment. Businesses should therefore review software development kits, analytics tools, advertising pixels, recommendation systems and third party tracking technologies before deployment. The question should not simply be whether the technology collects personal data. The business should ask whether it tracks or monitors the behaviour of children and whether the proposed activity falls within a permitted exemption. Targeted Advertising to Children Requires Particular Caution Advertising models based on user profiling can create significant legal concerns. A business may collect information about content preferences, browsing behaviour, purchasing patterns or engagement levels and use it to deliver personalised advertisements. Section 9 places a specific restriction on targeted advertising directed at children, subject to prescribed exemptions. This means marketing teams should not treat children's advertising as merely another segmentation exercise. Businesses need to understand how their advertising systems identify audiences and whether child users can enter those audiences. This becomes more complicated for platforms serving both adults and children. Age assurance, account design and advertising controls may therefore need to work together. A company should also examine whether external advertising partners receive information about child users and what contractual restrictions apply to such processing. Exemptions Under the DPDP Rules The Rules recognise certain exemptions from specific children's data obligations. The explanatory note published by the Ministry of Electronics and Information Technology identifies specific classes of organisations, including certain healthcare professionals, educational institutions and childcare providers, which may benefit from exemptions for defined purposes. The exemptions are subject to conditions and are not a blanket permission to process children's personal data without safeguards. For example, processing may be permitted for activities connected with healthcare, education, child safety or transportation, depending on the applicable category and conditions. This purpose based approach matters. An educational institution should not assume its entire database is exempt merely because it is an educational institution. The organisation should identify the precise processing activity and establish whether it falls within the relevant statutory exemption. A written exemption assessment can be valuable during internal compliance reviews. Data Minimisation Should Start at Product Design Children's privacy cannot be managed effectively if a business collects excessive information from the outset. A useful question is simple: does the service genuinely need every piece of information being collected? An educational application may need a child's name, class and learning records to provide its service. It may not need precise location data, extensive behavioural profiles or unrelated demographic information. Data minimisation reduces both compliance exposure and cybersecurity risk. Product teams should therefore involve privacy considerations before new features are released. A feature which creates a new category of children's data should trigger a review before development is completed. Privacy by design is considerably easier than restructuring a mature product after launch. Privacy Notices and Consent Records Businesses should ensure their privacy notices accurately describe their processing activities. The DPDP Rules introduce specific notice requirements, including clear information about the personal data being processed and the purpose for processing. The Government's explanatory note emphasises accessible information and transparency for Data Principals. For children's services, the privacy notice should align with the parental consent process. A common compliance weakness occurs when the privacy notice describes one processing purpose while the product performs additional analytics or marketing activities. The legal document, application interface and internal data practices should therefore remain consistent. Businesses should also maintain reliable records showing how and when consent was obtained. Consent records may become important when responding to complaints, regulatory enquiries or internal audits. Children's Data and Third Party Vendors Modern businesses rarely operate entirely within their own technology environment. An application may use external cloud hosting, analytics, customer support software, communication services, payment platforms and advertising networks. Every such relationship should be examined where children's personal data is involved. The business should know what information is shared, why it is shared, where it is stored, how long it is retained and what happens when the relationship ends. Vendor contracts should contain appropriate provisions dealing with confidentiality, security, permitted processing, breach reporting, deletion, subcontracting and assistance with legal obligations. A business should also maintain an up to date inventory of relevant vendors. It is difficult to demonstrate effective privacy governance when the organisation does not know who has access to its data.  Security Obligations Cannot Be Separated From Children's Privacy Consent alone does not protect children's information. A business can have a perfectly designed consent mechanism and still face serious exposure if its databases, applications or vendor systems are insecure. The DPDP framework requires Data Fiduciaries to adopt reasonable security safeguards. The statutory penalty framework provides significant financial exposure for specified breaches, including penalties of up to ₹250 crore for failure to take reasonable security safeguards and up to ₹200 crore for breach of obligations relating to children. Security controls should therefore be proportionate to the nature and volume of data handled. Access restrictions, authentication, encryption where appropriate, secure software development, monitoring, vulnerability management and incident response should form part of the wider governance framework. Employee awareness is also important. A child’s information may be exposed through simple operational mistakes such as incorrect email distribution, insecure file sharing or excessive employee access. What Happens After a Data Breach? Businesses should have an incident response procedure before an incident occurs. The response should establish who investigates the breach, who makes legal decisions, who communicates with affected parties and who manages regulatory engagement where required. Children's information can present distinctive risks. A breach involving a child's location, photograph, school details or behavioural information may create consequences beyond ordinary commercial inconvenience. Incident response should therefore consider the nature of the affected information and the potential impact on children. The DPDP framework contains specific requirements concerning personal data breaches, while the Rules provide operational detail for breach intimation. Businesses should ensure their technical and legal teams understand the applicable requirements before an incident occurs. Artificial Intelligence Creates New Children's Data Questions AI based products create another layer of complexity. A business may use children's data to personalise educational content, generate recommendations, analyse performance or develop machine learning systems. Before using information for a new purpose, the organisation should examine whether the proposed processing is consistent with the original purpose, notice and applicable consent framework. A company should not assume data collected for one service can automatically be reused to train a commercial AI system. AI governance should therefore be integrated into children's data governance. Product teams should identify whether AI tools receive personal data, whether external providers process it and whether the proposed use is necessary for the service. What Businesses Should Do Before Section 9 Becomes Operational? Businesses handling children's data should use the transition period to conduct a detailed privacy readiness assessment. The first stage should be data mapping. Identify where children's information enters the organisation, what categories are collected, where the information is stored and which internal teams and external vendors can access it. The second stage should involve an age and consent assessment. Determine how the business will identify child users and how it will obtain and verify parental consent where required. The third stage should focus on product design. Review analytics, behavioural monitoring, recommendation engines, advertising systems and location features. The fourth stage should involve contractual review. Vendor and partner agreements should reflect the organisation's actual data processing arrangements. The final stage should involve governance. Assign responsibility for privacy compliance, consent records, data inventories, incident response and regulatory developments. Businesses can consult the official Digital Personal Data Protection Rules, 2025 published by MeitY for the notified regulatory text and commencement information. Why Businesses Should Prepare Before the Legal Deadline? The transition period should not be viewed as a reason to postpone compliance. A privacy programme may require changes to software architecture, account creation, consent flows, databases, advertising technology and contracts. These changes cannot always be completed immediately. Early preparation also gives businesses an opportunity to identify commercially unnecessary data collection. For example, a company may discover it has been collecting precise location information simply because an analytics tool automatically captures it. Removing unnecessary collection may be easier than creating a complex legal justification for retaining it. The objective should be to build a product where privacy safeguards support the business model rather than obstruct it. The Role of Legal Advisers in Children's Data Compliance Children's data compliance involves several disciplines. Technology teams understand the systems. Product teams understand the user journey. Marketing teams understand advertising practices. Security teams understand infrastructure. Legal professionals connect these activities with statutory requirements. Businesses may therefore benefit from involving data privacy law firms when reviewing complex children's data processing arrangements, particularly where the service involves large scale processing, behavioural technology, international vendors or sensitive categories of information. A legal review should examine the actual product rather than only the privacy policy.  The right questions include whether parental consent is genuinely verifiable, whether the business collects more information than necessary, whether tracking technologies operate on child accounts, whether vendors receive children's data and whether the business can demonstrate compliance through reliable records. The objective is practical risk management, not paperwork for its own sake. Where the organisation has wider corporate governance or commercial contracting concerns, a corporate lawyer can also help connect privacy requirements with shareholder arrangements, technology contracts, vendor agreements and business operations. Conclusion India's DPDP framework represents a significant shift in how businesses must approach children's personal data. Section 9 places specific emphasis on verifiable parental consent, child well being and restrictions on behavioural monitoring, tracking and targeted advertising. The DPDP Rules, 2025 provide additional operational detail and introduce specified exemptions for certain organisations and purposes. For businesses, the strongest response is early preparation. Children's privacy should be considered during product development, vendor selection, marketing planning and technology design rather than being addressed only when a regulatory deadline approaches. A defensible compliance framework should allow the organisation to answer five basic questions clearly: What children's data do we collect? Why do we need it? Who can access it? How do we obtain and record consent? When do we delete it? Businesses able to answer these questions with evidence will be better placed to manage the legal, operational and reputational risks associated with children's personal data. Frequently Asked Questions (FAQs) Q1. What is Children's Data Protection under the DPDP Act? It refers to the additional legal safeguards applicable to processing personal data belonging to individuals who have not completed eighteen years of age. Section 9 of the DPDP Act specifically addresses children's personal data. Q2. What age is considered a child under India's DPDP Act? A child is an individual who has not completed eighteen years of age. Q3. Is parental consent mandatory for children's data? Section 9 requires verifiable consent from the parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. Q4. Can businesses track children online? Section 9 restricts tracking and behavioural monitoring of children, subject to prescribed exemptions. Businesses should therefore review analytics, advertising and profiling technologies used on child facing services. Q5. Can businesses show targeted advertisements to children? Targeted advertising directed at children is restricted under Section 9, subject to prescribed exemptions. Q6. Does the DPDP Act apply only to children's apps? No. The relevant obligations can affect any Data Fiduciary processing personal data of children. This can include education, healthcare, gaming, retail, entertainment and other digital services. Q7. Are schools exempt from children's data requirements? The Rules provide specific exemptions for certain educational institutions and specified purposes. These exemptions are conditional and should not be interpreted as a general exemption from all DPDP obligations. Q8. When will Section 9 become applicable? Section 9 is scheduled to commence eighteen months after 13 November 2025, alongside other substantive provisions listed in the commencement notification. This places the scheduled commencement date at 13 May 2027, subject to any subsequent notification or amendment. Q9. What penalties can apply for children's data violations? The DPDP Act's Schedule provides for a penalty of up to ₹200 crore for breach of the additional obligations relating to children. Other contraventions carry different maximum penalties. Q10. Is a privacy policy enough for compliance? No. Businesses need a broader framework covering data mapping, consent management, security safeguards, vendor governance, retention, rights management, incident response and internal accountability.  
MHCO Updates
Rea Estate
BOMBAY HIGH COURT ALLOWS REFUND OF STAMP DUTY PAID ON CANCELLED DEVELOPMENT AGREEMENT
The Bombay High Court, vide judgment dated 20 August 2026 in Sai Innovation v. Joint District Registrar and Collector of Stamps, Pune City & Ors. (Writ Petition No. 7566 of 2016), has held that a Development Agreement which fails to achieve its intended purpose and is subsequently cancelled can qualify for refund of stamp duty under Section 47(c)(5) of the Maharashtra Stamp Act, 1958 (“the Stamp Act”), and that such an agreement can avail the extended limitation period under the proviso to Section 48(1) where stamp duty has been calculated with reference to Article 25 of Schedule I. Background: Sai Innovation had entered into a Development Agreement (“said Agreement”) dated 15 April 2013 with the owners of land at Village Mauje Balewadi, Pune, for development of approximately 8,000 sq. metres of land and paid stamp duty under Article 25 read with Article 5 of Schedule I to the Stamp Act. The owners were unable to obtain sanction of the building plans within a reasonable time, and disputes subsequently arose between the parties. The said Agreement was therefore cancelled by a registered Deed of Cancellation (“said Deed”) dated 18 February 2014, registered on 24 February 2014, and the consideration received was returned. Sai Innovation thereafter applied on 7 April 2014 for refund of the stamp duty. The Respondent Nos 1&2 vide their orders dated 11 August 2014 and 6 December 2014 (“Impugned Orders”) respectively, rejected the refund application of the Petitioner, principally on the ground that the said Agreement was not a “conveyance” and therefore did not fall within the proviso to Section 48(1) of the Stamp Act. Issue: The Court dealt with the following issues: Whether the said Agreement had failed to achieve its intended purpose to attract Section 47(c)(5) of the Stamp Act; Whether a Development Agreement could avail the benefit of the proviso to Section 48(1), particularly where stamp duty was calculated as per Article 25 of Schedule I; Whether the reference to “actual, open possession” in Clause 13 of said Agreement be interpreted as transfer of possession to the developer, notwithstanding Clause 11 of the said Agreement which described the developer as a licensee; and Whether the Respondents could subsequently rely upon the alleged transfer of possession as a ground for rejecting the refund claim, when the refund claim had initially been rejected by the Impugned Orders on other grounds, and the issue of possession did not form part of the reasons recorded in those orders. Key Findings The Court, while differentiating between Section 47 and Section 48 of the Stamp Act, held that while Section 47 is the main provision that gives the right to a refund of stamp duty, Section 48 only deals with the time limit. In the present case, the proposed development under the said Agreement was never acted upon, and the parties later cancelled the said Agreement by the said Deed. As a result, the transaction had clearly failed to achieve its intended purpose under Section 47(c)(5) of the Stamp Act. The Court therefore said the refund claim had to be examined first under Section 47 and could not be turned down simply by pointing to the limitation period. On the question of possession, the Court held that Clause 13 of the said Agreement could not be read in isolation from Clause 11. Although Clause 13 referred to “actual, open possession”, Clause 11 expressly described the developer’s rights as those of “a licensee for development”. Reading the Agreement as a whole, the Court concluded that the developer was granted only a limited contractual licence to enter the property and undertake development activities, and that there was no transfer of legal or exclusive possession. The Court also noted that the absence of a separate possession receipt, by itself, did not establish that possession had been transferred. Held In light of the above reasoning, the Court allowed the writ petition and quashed the Impugned Orders passed by the Respondents. The Court held that the refund application was filed within the extended period prescribed under the proviso to Section 48(1) of the Stamp Act and, accordingly, rejected the Respondents’ objection that the claim was barred by the ordinary six-month limitation period. MHCO Comment Parties seeking refund of stamp duty on a cancelled Development Agreement should note that Section 47 governs the substantive entitlement to refund, while the proviso to Section 48(1) determines the applicable limitation period. Further, the legal character of a Development Agreement should be assessed by reading the same meaningfully and not in isolation from other clauses provided therein. By: Mr. Bhushan Shah, Partner Ms. Meeta Kadhi, Associate Partner Mr. Saptadip Nandi Chowdhury, Associate
SEBI Update
REGULATORY UPDATE | SEBI IMPOUNDS ₹ 3.67 CR FROM TWO ENTITIES FOR ALLEGED MANIPULATIVE TRADES DURING CLOSING AUCTION SESSION
BACKGROUND The Securities and Exchange Board of India (“SEBI”) passed an Ex-Parte Interim Order dated 19 August 2026 against Copthall Mauritius Investment Limited (“Copthall”) and Mansi Share and Stock Broking Private Limited (“Mansi”) in relation to alleged manipulative trading during the Closing Auction Session (“CAS”) on the BSE SENSEX expiry day. SEBI's CAS framework, introduced vide Circular dated 16 January 2026 and made effective from 3 August 2026, provides for determination of the closing price through a dedicated auction mechanism based on the interaction of buy and sell orders. The framework replaced the earlier methodology based on the volume-weighted average price (“VWAP”) for securities covered under the CAS framework, which determined the price of securities based on the closing price of the security or focused on the weight of trades executed in the last 30 minutes of the trading session. Now, under the CAS framework, the price of securities is determined based on buy and sell orders in a single pool, executed at a single equilibrium price in a dedicated 20-minute daily auction timeline. SEBI’S FINDING SEBI prima facie found that the trading activity of Copthall and Mansi was linked to their outstanding SENSEX option positions and was undertaken to influence the Indicative Equilibrium Price (“IEP”) and closing price of the SENSEX so as to obtain a favourable payoff from their expiry-day F&O positions. On 13 August 2026, SEBI's surveillance observed three sharp movements in the SENSEX during the CAS. Upon examination of the trade and order logs, SEBI observed that these movements coincided with large and aggressive buy orders placed by Copthall and sell orders placed by Mansi in SENSEX constituent securities, which were subsequently cancelled. SEBI accordingly examined the trading activity of the two entities and its linkage with their outstanding SENSEX option positions. SEBI noted that the material on record did not prima facie indicate that the two Noticees acted in concert. Rather, each appeared to have adopted a separate strategy to move the SENSEX in a direction favourable to its respective F&O positions. SEBI'S DIRECTIONS SEBI directed that the bank accounts of Copthall and Mansi be impounded to the extent of ₹2,96,16,000 and ₹71,64,773 respectively, aggregating a total of ₹3,67,80,773. SEBI also debarred the noticees from accessing the securities markets and prohibited them from participating in the CAS, including placing, modifying or cancelling orders. Restrictions were also imposed on their bank and demat accounts, transfer/redemption of securities and disposal of assets without SEBI's permission. They were further directed to cooperate with SEBI's ongoing examination/investigation. MHCO COMMENT The order is significant in the context of the newly introduced CAS framework and SEBI's surveillance of potential attempts to influence the closing price through order placement and cancellation. The order demonstrates that SEBI is examining the nature, timing and price of orders, their impact on the IEP, subsequent cancellation of orders and the corresponding F&O positions of the concerned entities. The directions are interim in nature and are based on prima facie findings pending further investigation. SEBI has expressly clarified that the detailed investigation is to proceed independently of the prima facie observations contained in the interim order. Notably, SEBI has not alleged that Copthall and Mansi acted in concert. The findings against the two entities are based on their respective trading patterns and F&O positions. Since the order is ex-parte and interim in nature, the findings remain subject to SEBI's further examination, as well as the Noticees' replies and opportunity of hearing. By: Mr. Bhushan Shah, Partner Ms. Sayali Kshirsagar, Associate
IBC Update
IBC UPDATE - REMOVAL OF INTERIM MORATORIUM FOR PERSONAL GUARANTORS APPLIES TO PENDING PROCEEDINGS
Recently, the Bombay High Court in the case of Tata Capital Financial Services Limited v. Neel Motors LLP & Ors., held that the amendment introducing Section 96(4) of the Insolvency and Bankruptcy Code, 2016 (“IBC”) applies to insolvency applications filed before that date which remain pending. The Court consequently held that the interim moratorium under Section 96 ceased to operate against the personal guarantors from 26 May 2026, enabling Tata Capital to pursue limited interim relief under Section 9 of the Arbitration and Conciliation Act, 1996 (“Arbitration Act”). FACTS: The Petitioner, Tata Capital Financial Services Limited (“Tata Capital”) extended financial assistance to Respondent No. 1, Neel Motors LLP, under a Channel Finance Agreement. Respondent Nos. 2 to 4 were individual guarantors and partners of Neel Motors LLP, while Respondent No. 5 was a separate LLP acting as guarantor. The Letters of Guarantee contained arbitration clauses with Mumbai as the seat. In 2021, Tata Capital filed a petition under Section 9 of the Arbitration Act seeking interim protection. Approximately one month prior to filing the Section 9 petition, Tata Capital had initiated Corporate Insolvency Resolution Process (“CIRP”) against Neel Motors under the IBC. The CIRP ultimately failed and Neel Motors was ordered to be liquidated by the NCLT, Mumbai, on 1 April 2022. Thereafter, in June 2022, Tata Capital initiated insolvency proceedings under Section 95 of the IBC against Respondent Nos. 2, 3 and 4, who were the individual guarantors (“Guarantors”). The filing of the Section 95 applications triggered the interim moratorium under Section 96, stalling the Section 9 petition. The legal position changed with the insertion of Section 96(4) into the IBC which came into force on 26 May 2026. The amendment provided that Section 96 would not apply where an application was filed for initiating an insolvency resolution process in respect of a personal guarantor to a corporate debtor. Relying upon the amendment, Tata Capital sought consideration of its pending Section 9 petition. The principal issue before the Court was whether Section 96(4) could apply to Section 95 applications which had been filed before 26 May 2026 but continued to remain pending on the date of the amendment. Tata Capital’s Case Tata Capital contended that, in view of the newly inserted Section 96(4), the moratorium under   Section 96 no longer operated against the individual guarantors and the expression “where an application is filed” was sufficiently broad to include pending applications. It further relied upon the legislative purpose behind the amendment, that it was intended to “remove any perverse incentives” associated with the initiation of individual insolvency proceedings. Considering the considerable delay since filing of the Section 9 petition, Tata Capital only sought disclosure of the guarantors’ assets and an injunction restraining them from selling, transferring, alienating, encumbering or otherwise dealing with such assets pending arbitration. Guarantor’s Case The guarantors opposed the application, contending that such an interpretation would give the amendment retrospective effect. They submitted that the expression “where an application is filed” covers only applications filed after 26 May 2026 and could not extend to applications which had already been filed. Any other interpretation, according to the guarantors, would retrospectively alter the legal consequences attached to the pending proceedings. They further argued that although insolvency proceedings are not strictly recovery proceedings, both the insolvency and arbitration proceedings were directed towards recovery of the same debt and Tata Capital should therefore not be permitted to pursue both simultaneously Court’s Finding The Hon’ble Court held that the expression “where an application is filed” in Section 96(4) encompasses applications which had already been filed and continued to remain pending before the adjudicating authority. Had the legislature intended to restrict the provision only to applications filed after 26 May 2026, it could have expressly used language to that effect. The Court distinguished between retrospective and retroactive operation, relying upon the Supreme Court’s decision in Securities and Exchange Board of India v. Rajkumar Nagpal, the Court observed that a provision is retrospective when it operates backwards and impairs vested rights, whereas a retroactive provision operates prospectively on a character or status originating in the past. The existence of antecedent facts does not, by itself, make its application retrospective. Accordingly, the moratorium under Section 96 operated against Respondent Nos. 2 to 4 until 25 May 2026 but ceased from 26 May 2026 when Section 96(4) came into force. The pending Section 9 petition was therefore no longer barred by the IBC moratorium. The Court further acknowledged the possibility of a conflict of interest where the creditor initiating insolvency proceedings may also be pursuing claims against the individual guarantor. However, it held that such considerations could not override the express statutory language, particularly when Section 96(4) was agnostic as to the identity of the person who initiated the Section 95 proceedings. MHCO Comment Pending proceedings can be affected by a new provision without the provision necessarily being retrospective. The decisive factor is whether the provision changes completed past rights or operates prospectively upon an existing/pending legal status. Section 96(4) therefore lifted the Section 96 moratorium prospectively from 26 May 2026 even in respect of Section 95 applications filed prior to the amendment coming into force. By: Mr. Bhushan Shah, Partner Ms. Neha Lakshman, Associate Partner
Litigation
SUPREME COURT CLARIFIES INHERITANCE RIGHTS WHERE PROPERTY IS JOINTLY HELD IN THE NAMES OF TWO WIDOWS UNDER THE INDIAN SUCCESSION ACT, 1925
The Supreme Court, in Shakuntala & Ors. v. Robert Anthony & Ors. (Civil Appeal arising out of SLP(C) No. 9449 of 2020, judgment dated 30 July 2026), has held that where immovable property is purchased and registered in the joint names of two wives of a common husband, the property vests in the two wives themselves, and Section 33 of the Indian Succession Act, 1925 (“the Act”) which governs succession to the estate of a male intestate survived by a widow and lineal descendants cannot be applied to the entirety of such property merely because the husband had provided the purchase consideration. The Court set aside the concurrent (and mutually inconsistent) findings of the Trial Court, First Appellate Court and the High Court of Chhattisgarh, and worked out the succession afresh by applying Sections 33, 35 and 38 of the Act separately to each wife's share. Background: One Mattus Anthony (“MA”) had two wives, Filomina and Shyam Bai. In 1959, MA purchased a parcel of land for a consideration of INR 300 in the joint names of his two wives. Filomina had three children (the plaintiffs), while Shyam Bai had one son, John Anthony, who predeceased her in 1985 leaving behind his widow and four children (defendant Nos. 1 to 5). Filomina died in 1985, MA died intestate in 1991, and Shyam Bai died in 2000. In 2002, defendant Nos. 1 to 5 (the widow and children of John Anthony) sold half of the property, i.e., their understood share, to defendant No. 6. The plaintiffs, contending that the property was joint ancestral property in which they too had a share, challenged the sale as void. Figure: Family Tree of Mattus Anthony and the parties to the litigation Family Tree: The Trial Court decreed the suit, holding the sale deed invalid for want of consent of all co-owners and granting the plaintiffs a one-fourth share. The First Appellate Court reversed this, holding that each wife independently held a half share in the property (since it was purchased in their joint names), that the defendants, as legal heirs of John Anthony, were entitled to Shyam Bai's half, and that the 2002 sale deed was accordingly valid. The High Court, in second appeal, took yet another view: applying Section 33 of the Act on the footing that MA had died intestate leaving behind two widows and lineal descendants, it held that both widows, together, were entitled to one-third of the property, while the plaintiffs – treated as MA's only “lineal descendants” because John Anthony was held not to qualify as such – were entitled to the remaining two-thirds. Issue Before the Court: The principal question before the Supreme Court was whether Section 33 of the Act, which applies to the estate of a male who dies intestate, could be applied to property that was purchased in the joint names of MA's two wives, or whether the property had to be treated as belonging to the two wives themselves, with succession to each wife's share being worked out independently. Key Findings of the Court: The Court held that Section 33 of the Act, on its plain text, applies only to the property of a deceased male intestate. Since the property in question was purchased and registered in the names of MA's two wives, it was, in law, their property and not MA's, notwithstanding that MA had provided the consideration. The High Court's application of Section 33 to the entire property was accordingly held to be misconceived, since it proceeded on the incorrect premise that the property vested in MA and passed on his death to his widows and lineal descendants. Having held that the property vested independently in the two wives, the Court worked out succession separately to each half. As Filomina predeceased MA, the Court applied Section 35 of the Act (which gives a surviving husband the same rights over his intestate wife's property as a widow would have over her intestate husband's property). Applying Section 33 through the mechanism of Section 35, MA became entitled to one-third of Filomina's half share, with the remaining two-thirds devolving directly upon her children (the plaintiffs). On MA's own death intestate in 1991, the one-third share he had inherited from Filomina devolved equally upon all four of his children through both wives the three plaintiffs and John Anthony as tenants-in-common, there being no concept of joint family property, as under Hindu law, applicable to succession under the Indian Succession Act. As regards Shyam Bai's half share (together with the portion she in turn received through MA), the Court held that since Shyam Bai's own son, John Anthony, had predeceased her, the property devolved on her surviving grandchildren (defendant Nos. 2 to 5) under Section 38 of the Act, which governs the case of an intestate survived by grandchildren but no surviving child. On this basis, the defendants' entitlement was confined to Shyam Bai's share (as enlarged by the portion received through MA), and did not extend to any part of Filomina's share, contrary to the High Court's view that the two widows' shares should be pooled together and treated as a single one-third block. Treatment of Ancillary Contentions: The Court noted two further contentions that were not seriously pressed by the parties and did not call for detailed adjudication. First, on the question of benami, reliance was placed on Valliammal v. Subramaniam (2004) 7 SCC 233, for the proposition that intention and source of funds are relevant to a benami transaction; however, since it was undisputed that MA had purchased the property in the names of his two wives out of love and affection, no case of benami arose. Second, the validity of MA's second marriage to Shyam Bai was not in dispute between the parties, who were agreed that the controversy was confined to the extent of inheritance rights and not the existence of Shyam Bai's status as MA's widow. MHCO Comment: This decision offers useful guidance on succession disputes arising out of property held in the names of multiple wives of a common husband under the Indian Succession Act, 1925. The Court's central holding that property registered in the name of a person is that person's property in the eyes of the law, irrespective of who funded the purchase (absent a proven case of benami)  reaffirms settled principles of ownership and cautions against conflating source-of-funds with title. Equally significant is the Court's demonstration of how Sections 33, 35 and 38 of the ISA interact and must be applied sequentially, and separately, wherever succession opens up more than once within the same family (here, on the deaths of Filomina, MA and Shyam Bai in turn), rather than being collapsed into a single, composite application of Section 33 to the family's property as a whole. The decision will be of particular relevance in estate planning and succession litigation involving Christian families with blended households, where property is often held jointly in the names of multiple spouses, and underscores the importance of tracing title and the chain of succession event-by-event rather than treating the ultimate distribution as a single-step exercise.   By: Ms. Purvi Asher, Partner Ms. Ananya Sakpal, Associate Disclaimer: This legal update is intended for general information purposes only and does not constitute legal advice. Readers are advised to seek specific legal advice before acting upon any information contained herein.
LIFE AT MHCO
Need Help? Chat with us