Businesses increasingly interact with minors through education platforms, gaming applications, social networks, healthcare services, retail platforms and digital entertainment. In India, Parental Consent has become a central compliance consideration for organisations processing children's personal data under the Digital Personal Data Protection Act, 2023. The law treats an individual below eighteen years as a child and requires verifiable consent from a parent or lawful guardian before processing the child's personal data, subject to specified exemptions. The requirement is more substantial than adding a consent checkbox to an application. Businesses need a reliable process for identifying child users, verifying the adult providing consent, recording the consent, controlling subsequent processing and demonstrating compliance when required.
What Does Parental Consent Mean Under Indian Data Protection Law?
The DPDP Act places specific obligations on a Data Fiduciary when processing personal data belonging to a child. Section 9 requires verifiable consent from the child's parent or, where applicable, lawful guardian before processing begins. The statutory explanation expressly recognises consent from a lawful guardian within the meaning of parental consent. The requirement reflects an important legal distinction. A child's affirmative action on a website or application is not automatically sufficient. The business must establish the authority of an adult who is providing consent on the child's behalf. This makes parental verification a separate compliance exercise from ordinary user consent. The distinction is particularly relevant for platforms where children can create accounts independently. A company may know the age of the user but still need a process to establish who is giving consent and whether the person is an adult parent or lawful guardian.
Who Is Considered a Child Under the DPDP Act?
The DPDP Act adopts a clear age threshold. A child means an individual who has not completed eighteen years of age. This is important for businesses serving teenagers because the Indian framework does not generally stop enhanced child protection at thirteen, sixteen or another lower age used in some international privacy regimes. Businesses should therefore examine their user base carefully. A service may be designed for adults but still attract users below eighteen. In such cases, the organisation needs to consider how its systems identify or otherwise deal with child users. Age assessment is consequently an important part of privacy governance. It should be considered during product design rather than treated solely as a legal policy issue.
Why a Simple Consent Checkbox May Not Be Enough?
A conventional consent mechanism usually records an affirmative action from the user. For ordinary data processing, the organisation may rely on the Data Principal's consent in accordance with the statutory framework. Children's data introduces another layer. Rule 10 of the Digital Personal Data Protection Rules, 2025 requires a Data Fiduciary to adopt appropriate technical and organisational measures to ensure verifiable consent from the parent before processing a child's personal data. The organisation must also exercise due diligence to check whether the person claiming to be the parent is an adult and is identifiable where required for compliance with Indian law. Consequently, a declaration such as “I am the parent” may not provide sufficient evidence by itself. An organisation needs a process capable of establishing the adult's identity and age through an appropriate verification method.
How Must Businesses Verify the Parent?
The final Rules provide two principal routes for verification. First, the Data Fiduciary may rely on reliable identity and age details already available with it. This could be relevant where the parent is an existing verified user of the service. Second, the parent may voluntarily provide identity and age information, or provide a virtual token mapped to such information. The Rules recognise tokens issued by an authorised entity and also refer to information or tokens made available and verified through a Digital Locker service provider. The framework therefore does not prescribe a single universal technology for every business. Instead, it establishes an outcome. The organisation needs appropriate technical and organisational measures and must exercise due diligence concerning the adult claiming parental status. This gives businesses some flexibility in designing their consent architecture while placing responsibility on them to make the mechanism reliable.
What Does Verifiable Consent Look Like in Practice?
Consider a child attempting to create an account on an educational application. The platform may first identify the user as a child. The system can then direct the parent to a separate verification process. If the parent is already a verified user, the business may use reliable identity and age information already held by it. If the parent is not an existing user, the Rules contemplate voluntary submission of identity and age details or an appropriate virtual token. The business should then retain appropriate records showing the consent process. The important point is sequencing. Where Section 9 applies, the consent requirement arises before processing of the child's personal data. A business should therefore avoid designing a process where extensive child data is collected first and parental verification occurs later. The architecture should minimise the information collected before verification.
What About Lawful Guardians?
The DPDP Act expressly extends the concept of parental consent to a lawful guardian where applicable. The Rules separately address verification concerning persons with disabilities who have a lawful guardian. Rule 11 requires due diligence to establish the guardian's appointment by a court, designated authority or local level committee under the applicable guardianship law. Businesses should therefore avoid treating every adult who claims responsibility for a child as automatically authorised to provide consent. The nature of the relationship can matter. Where a service is likely to receive consent from guardians rather than biological parents, the organisation should ensure its verification process reflects the applicable legal position.
Parental Consent Does Not Permit Every Form of Processing
Obtaining consent does not give a business unrestricted permission to process children's data. Section 9 contains additional safeguards. A Data Fiduciary must not undertake processing likely to cause a detrimental effect on the well being of a child. The Act also prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This is an important distinction for businesses. A company cannot assume its compliance obligations end once a parent approves the account. The organisation must examine what happens to the child's information after consent. For example, analytics, recommendation engines, behavioural profiling and advertising technologies should be assessed separately. A valid consent mechanism cannot automatically authorise processing prohibited by Section 9.
Are There Exemptions From Parental Consent?
Yes. The DPDP Rules, 2025 establish limited and conditional exemptions under Rule 12 and the Fourth Schedule. The exemptions apply to specified classes of Data Fiduciaries or specified purposes, subject to conditions. Part A of the Fourth Schedule includes certain healthcare establishments and professionals, educational institutions and specified childcare and transport arrangements. The exemption depends on the purpose and conditions attached to the relevant category. The Rules also recognise specified purposes in Part B. Businesses should be careful when relying on these exemptions. Being an educational institution or healthcare provider does not create a blanket exemption from children's data requirements. The processing must fall within the relevant category and satisfy the applicable conditions. An exemption analysis should therefore be documented rather than assumed.
What Businesses Should Consider Before Collecting a Minor's Data?
The first step should be data mapping. A business should identify where children's information enters its systems, what categories are collected, why each category is required and which employees, vendors or technology providers can access it. The next consideration is age assurance. The organisation needs to understand how it identifies users who may be children and how the parental verification process will operate. The consent journey should then be mapped from beginning to end. This includes the notice presented to the parent, verification method, consent record, withdrawal mechanism and subsequent handling of the child's information. Businesses should also review their technology stack. Third party analytics tools, advertising software, customer relationship platforms and software development kits may collect or infer information independently of the main application. A privacy review limited to the company's own database may therefore miss important processing activities.
Privacy Notices Must Match the Actual Consent Process
A privacy notice should not promise one form of processing while the technology performs another. The DPDP Rules require notices to provide clear information about personal data being collected and the purpose for processing. The Government's explanatory note emphasises standalone, understandable notices and transparent information necessary for informed consent. For services used by minors, businesses should ensure the notice, parental consent interface and actual data practices remain consistent. If the application uses information for personalisation, analytics or another purpose, the business should assess whether the purpose is adequately described and legally permitted. This alignment is also important from an evidentiary perspective. A company should be able to demonstrate how its stated privacy practices correspond with its technical operations.
Consent Records Should Be Auditable
A business should be able to answer a basic question: how can you demonstrate which parent provided consent, for which child, for what processing and when?
Consent records can help answer this question.
The organisation should consider recording relevant information about the consent event without unnecessarily retaining additional identity information. Excessive retention creates its own privacy and security concerns. The consent architecture should also accommodate withdrawal where applicable. A parent should not face an unnecessarily complicated process simply because consent was initially provided electronically. Record keeping, access controls and retention periods should therefore form part of the overall privacy governance framework.
Businesses Should Review Third Party Contracts
Children's data frequently moves beyond the primary platform. A gaming company may use cloud hosting. An EdTech business may use analytics software. A healthcare application may rely on external infrastructure or communication providers. Each relationship can create a separate risk. Businesses should examine whether vendors process children's data, what information they receive, where it is stored, whether they can appoint sub processors and how they respond to security incidents. Contracts should reflect the actual processing relationship and allocate appropriate responsibilities. This is an area where data privacy lawyers can assist businesses in reviewing consent architecture, privacy notices, vendor arrangements and regulatory exposure. The objective should be to ensure legal documents reflect real technical practices rather than operating as standalone paperwork.
Security Is Part of Children's Data Governance
Parental consent does not remove cybersecurity obligations. The DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The statutory penalty framework also provides significant financial exposure for specified contraventions, including a penalty of up to ₹200 crore for breach of obligations relating to children. Security controls should therefore be proportionate to the data being processed. Businesses should consider access restrictions, authentication, encryption where appropriate, secure development practices, vulnerability management, monitoring and incident response. The organisation should also limit internal access. Not every employee involved with a children's service needs access to the underlying personal data.
When Will the Parental Consent Rules Apply?
This is an important current legal point. The final Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4 is scheduled to commence one year later, while Rules 3 and 5 to 16, along with Rules 22 and 23, are scheduled to commence eighteen months after publication. Rule 10 therefore has a scheduled commencement date of 13 May 2027. The Data Security Council of India also identifies 13 May 2027 as the commencement date for Rule 10 and the corresponding Section 9 obligations. This does not mean businesses should wait until 2027 to start preparing. Consent architecture can require changes to databases, onboarding flows, identity verification, contracts and advertising systems. Organisations with significant child user bases may need substantial lead time.
How Businesses Can Prepare Now?
A sensible preparation programme should begin with a children's data inventory. The organisation should identify whether it actually needs to collect personal data from minors. If the service can operate without collecting such information, redesigning the user journey may be simpler than implementing a complex verification system. Where collection is necessary, businesses should develop an age assurance and parental verification framework. The next step should be testing. A consent system should be tested against different user journeys, including an existing parent user, a new parent, a child attempting to register independently and situations where consent is withdrawn. Technology teams should also examine third party tools. A platform may have a compliant registration page while an embedded analytics tool continues behavioural tracking. Finally, the business should establish governance. Responsibility for children's data should be clearly assigned. Internal policies should address consent records, access, retention, security incidents and vendor management. Businesses with broader corporate structuring, technology contracts or regulatory questions may also wish to involve a corporate law firm when integrating privacy obligations with their wider legal framework.
Common Mistakes Businesses Should Avoid
One common mistake is treating an age declaration as equivalent to parental verification. Another is collecting a child's information before completing the required verification process. Businesses also risk assuming consent permits behavioural monitoring or targeted advertising. Section 9 imposes separate restrictions on these activities, subject to prescribed exemptions. Another problem arises when businesses rely on an exemption without checking its conditions. Finally, some organisations focus heavily on the privacy policy but overlook their software, vendors and internal data flows. A defensible privacy programme must cover the complete lifecycle of the information.
Conclusion
Parental consent under India's DPDP framework is not merely a procedural checkbox. It requires businesses to think carefully about age assurance, adult verification, consent records, data minimisation, security and the purposes for which children's information is processed. The most important compliance distinction is between recording consent and proving verifiable parental consent. Businesses need systems capable of demonstrating who provided consent and ensuring the processing permitted by the consent remains within the boundaries of Indian data protection law. The final Rules provide businesses with a defined framework for verification, including reliance on reliable identity and age information and qualifying virtual tokens. They also introduce limited exemptions for specified organisations and purposes. With the principal child data provisions scheduled for commencement in May 2027, businesses have an opportunity to address these issues before they become urgent operational requirements.
Frequently Asked Questions (FAQs)
Q1. Is parental consent mandatory for collecting children's data in India?
Under Section 9 of the DPDP Act, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions.
Q2.What age is considered a minor under the DPDP Act?
For the purposes of the DPDP Act, a child is an individual who has not completed eighteen years of age.
Q3.What is verifiable parental consent?
Verifiable parental consent requires a Data Fiduciary to use appropriate technical and organisational measures and exercise due diligence to establish that the person providing consent as a parent is an identifiable adult. Rule 10 permits reliance on reliable identity and age details or voluntarily provided information or qualifying virtual tokens.
Q4.Is an OTP sufficient for parental consent?
An OTP may be part of a broader verification process, but businesses should not assume an OTP alone automatically satisfies the statutory concept of verifiable consent. The organisation must consider whether its complete process establishes the adult's identity and age as contemplated by Rule 10.
Q5.Can a child provide consent for their own data?
Where Section 9 applies, the statutory framework requires verifiable consent from the parent or lawful guardian before processing the child's personal data.
Q6.Can businesses track children's online behaviour after obtaining parental consent?
Section 9 prohibits tracking or behavioural monitoring of children, subject to prescribed exemptions. Parental consent should not be treated as a general authorisation to undertake prohibited processing.
Q7.Can companies use targeted advertising for children?
Section 9 prohibits targeted advertising directed at children, subject to prescribed exemptions.
Q8.Are schools exempt from obtaining parental consent?
The Rules provide limited exemptions for specified educational processing. The exemption is conditional and should be assessed against the relevant provisions of the Fourth Schedule.
Q9.When will Rule 10 of the DPDP Rules apply?
Rule 10 is scheduled to commence eighteen months after publication of the Rules on 13 November 2025. The scheduled date is 13 May 2027.
Q10.What is the penalty for violating children's data obligations?
The DPDP Act's Schedule provides for a penalty of up to ₹200 crore for breach of the obligations relating to children. The actual penalty depends on the nature and circumstances of the contravention.











