Home / Act 2023 / Sec. 9
Sec. 9 · Chapter II · DPDP Act 2023

Processing children's personal data

India drew its line at 18. Every user under 18 needs verifiable parental consent before you can process their personal data. Behavioural monitoring and targeted advertising to children are banned, regardless of consent.

Verified 8 Sep 2026 DPDP Act 2023, Sec. 9 6 min read Also: Rule 10, Rule 11

01India draws the child line at 18, not 13

Under Section 2(f), a child is anyone under 18. That is stricter than GDPR (13 to 16 depending on the member state) and much stricter than COPPA (13).

The definition sits in Section 2(f) of the Act. Every Data Fiduciary that could plausibly process personal data of a person under 18 must have a verifiable-parental-consent path. That includes edtech platforms, gaming apps, social media, music streaming, video streaming, banking apps offering junior accounts, health apps, and school administration systems.

Sec. 2(f), Sec. 9 DPDP Act 2023. GDPR Art. 8. COPPA 15 USC ss.6501.

02What Section 9 requires

Section 9 imposes three obligations on any Data Fiduciary processing children's data.

  1. Sec. 9(1) — Verifiable parental consent. Before processing any personal data of a child, obtain verifiable consent from the parent or lawful guardian.
  2. Sec. 9(2) — Same for persons with disabilities. Where a lawful guardian has been appointed for a person with disability, verifiable guardian consent is required.
  3. Sec. 9(3) — Behavioural monitoring and targeted advertising ban. No tracking, no behavioural monitoring of children, no targeted advertising directed at children.

Section 9(3) applies regardless of consent. Even with verifiable parental consent, you cannot behaviourally track a child or serve them targeted advertising. This is a hard prohibition.

Sec. 9 DPDP Act 2023.

03Rule 10: verification methods

Rule 10 sets out approved methods to verify that consent for a child's personal data was given by the parent, and that the parent is who they say they are.

Rule 10 permits two verification paths. First, verification against reliable identity and age details already held about the parent, if the parent is themselves a Data Principal on your platform. Second, verification against a virtual token backed by a Digital Locker service provider (DigiLocker) or an equivalent identity service under the Central Government's designation.

The parent-child relationship must also be verifiable. Common approaches: Aadhaar-based Know Your Parent, DigiLocker parental-attestation flow, or a school-issued digital certificate linked to the child. Rule 10 takes effect on 14 May 2027.

Rule 10 DPDP Rules 2025 (effective 14 May 2027).

04Even with parental consent, three things are still off-limits

Sec. 9(3)(a)

No tracking

No cookies, SDK identifiers, or other trackers on children's sessions. Analytics that identify a child individually fall inside this ban.

Sec. 9(3)(b)

No behavioural monitoring

No building of behavioural profiles, no interest-based clustering, no engagement scoring that is used to shape what the child sees.

Sec. 9(3)(c)

No targeted advertising

Contextual ads (based on the page or the app screen) are fine. Behavioural targeting, retargeting, and lookalike audiences are not.

Rs. 200 cr

Penalty cap

Breach of Section 9 attracts the Rs. 200 crore cap, one of the two highest under the Schedule.

05Where the Government may exempt

Section 9(5) reserves a limited exemption power for the Central Government.

The Government may, by notification, exempt specific classes of Data Fiduciary or specific purposes from the age-of-consent requirement. In practice, this exemption is expected to apply to educational institutions, healthcare providers, and any Data Fiduciary whose processing is demonstrably in the child's interest and is limited to purposes the Government notifies as safe.

As of September 2026, no exemption class has been notified. Assume every child under 18 needs verifiable parental consent until the Government publishes a class-based carve-out.

Sec. 9(5) DPDP Act. No exemption notifications published as of September 2026.

06Practical playbook

  1. Age-gate at signup

    Ask date of birth on signup. Do not just tick "I confirm I am over 18." Store the DOB for future re-consent flows.

  2. Route under-18s through a parental-consent flow

    Verify the parent via DigiLocker or equivalent. Establish the parent-child link. Store the verification token, not the underlying documents.

  3. Strip trackers and behavioural signals from child accounts

    Do not attach analytics identifiers, ad-tech pixels, or behavioural monitoring on any session marked as under-18.

  4. Switch off targeted advertising for child accounts

    Serve only contextual ads. Exclude child user IDs from your ad-tech pipelines.

  5. Handle transition at 18

    Re-consent flow on the 18th birthday. Cannot silently move a user from child-restricted to full-adult processing without a fresh consent.

Ship a Rule 10 verifiable parental consent flow. dcomply ships a Children's Data Handling module with DigiLocker integration, behavioural-monitoring blockers, and 18th-birthday transition triggers. See how →