Rule 10 · Section 9
DPDP Rule 10: Verifiable Consent for Children
Rule 10 sets the operational due-diligence standard for obtaining verifiable consent of a parent before processing a child’s personal data under Section 9.
What Rule 10 says
Rule 10 applies where a Data Fiduciary processes personal data of a child under Section 9. It requires appropriate technical and organizational measures to ensure verifiable consent of the parent is obtained before such processing.
The Rule also requires due diligence that the person identifying as the parent is an adult and is identifiable, if required. The text provides multiple pathways for that diligence, including using reliable identity and age details already available, details voluntarily provided by the individual, or a virtual token mapped to such details issued by an authorized entity.
Rule 10 should be read together with Section 9 and related Rules 11 and 12. It does not create a single mandatory vendor method; it sets an outcome and due-diligence expectation that must be defensible for the facts.
What it means in practice
Treat Rule 10 as an onboarding control, not a legal footnote. First identify where child personal data may be processed: youth-facing products, family accounts, education services, or mixed-age flows where children may enter by design or by behavior.
Then design a clear parent-consent sequence: age signal, parent/guardian declaration, adult due diligence, notice and purpose context, consent capture, and evidence retention. The same rigor should apply to withdrawal and updates so the consent lifecycle remains enforceable in systems, not just in policy documents.
Keep Rule 10 distinct from Rule 11. Rule 10 concerns parental consent for children’s data. Rule 11 concerns lawful guardianship for certain persons with disability and has separate diligence logic.
For the broader framework and exemptions context, see DPDP Section 9: Children’s Personal Data.
Common mistakes
- Assuming a child’s own click can substitute for Rule 10 parental verifiable consent.
- Treating Rule 10 as a checkbox exercise without documenting how age/adulthood diligence was actually performed.
- Claiming one commercial identity tool is legally mandatory when the Rule permits different diligence pathways.
- Mixing Rule 10 and Rule 11 into one generic “guardian consent” flow with no distinction.
Official source
ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.
Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.