Processing children's personal data
India drew its line at 18. Every user under 18 needs verifiable parental consent before you can process their personal data. Behavioural monitoring and targeted advertising to children are banned, regardless of consent.
01India draws the child line at 18, not 13
Under Section 2(f), a child is anyone under 18. That is stricter than GDPR (13 to 16 depending on the member state) and much stricter than COPPA (13).
The definition sits in Section 2(f) of the Act. Every Data Fiduciary that could plausibly process personal data of a person under 18 must have a verifiable-parental-consent path. That includes edtech platforms, gaming apps, social media, music streaming, video streaming, banking apps offering junior accounts, health apps, and school administration systems.
02What Section 9 requires
Section 9 imposes three obligations on any Data Fiduciary processing children's data.
- Sec. 9(1) — Verifiable parental consent. Before processing any personal data of a child, obtain verifiable consent from the parent or lawful guardian.
- Sec. 9(2) — Same for persons with disabilities. Where a lawful guardian has been appointed for a person with disability, verifiable guardian consent is required.
- Sec. 9(3) — Behavioural monitoring and targeted advertising ban. No tracking, no behavioural monitoring of children, no targeted advertising directed at children.
Section 9(3) applies regardless of consent. Even with verifiable parental consent, you cannot behaviourally track a child or serve them targeted advertising. This is a hard prohibition.
03Rule 10: verification methods
Rule 10 sets out approved methods to verify that consent for a child's personal data was given by the parent, and that the parent is who they say they are.
Rule 10 permits two verification paths. First, verification against reliable identity and age details already held about the parent, if the parent is themselves a Data Principal on your platform. Second, verification against a virtual token backed by a Digital Locker service provider (DigiLocker) or an equivalent identity service under the Central Government's designation.
The parent-child relationship must also be verifiable. Common approaches: Aadhaar-based Know Your Parent, DigiLocker parental-attestation flow, or a school-issued digital certificate linked to the child. Rule 10 takes effect on 14 May 2027.
04Even with parental consent, three things are still off-limits
No tracking
No cookies, SDK identifiers, or other trackers on children's sessions. Analytics that identify a child individually fall inside this ban.
No behavioural monitoring
No building of behavioural profiles, no interest-based clustering, no engagement scoring that is used to shape what the child sees.
No targeted advertising
Contextual ads (based on the page or the app screen) are fine. Behavioural targeting, retargeting, and lookalike audiences are not.
Penalty cap
Breach of Section 9 attracts the Rs. 200 crore cap, one of the two highest under the Schedule.
05Where the Government may exempt
Section 9(5) reserves a limited exemption power for the Central Government.
The Government may, by notification, exempt specific classes of Data Fiduciary or specific purposes from the age-of-consent requirement. In practice, this exemption is expected to apply to educational institutions, healthcare providers, and any Data Fiduciary whose processing is demonstrably in the child's interest and is limited to purposes the Government notifies as safe.
As of September 2026, no exemption class has been notified. Assume every child under 18 needs verifiable parental consent until the Government publishes a class-based carve-out.
06Practical playbook
-
Age-gate at signup
Ask date of birth on signup. Do not just tick "I confirm I am over 18." Store the DOB for future re-consent flows.
-
Route under-18s through a parental-consent flow
Verify the parent via DigiLocker or equivalent. Establish the parent-child link. Store the verification token, not the underlying documents.
-
Strip trackers and behavioural signals from child accounts
Do not attach analytics identifiers, ad-tech pixels, or behavioural monitoring on any session marked as under-18.
-
Switch off targeted advertising for child accounts
Serve only contextual ads. Exclude child user IDs from your ad-tech pipelines.
-
Handle transition at 18
Re-consent flow on the 18th birthday. Cannot silently move a user from child-restricted to full-adult processing without a fresh consent.