Section 9 · Rules 10–12

DPDP Section 9: Children's Personal Data

Section 9 sets additional obligations when a Data Fiduciary processes personal data of a child — including verifiable consent of a parent or lawful guardian and limits on certain tracking and advertising practices, subject to Rules and exemptions.

What Section 9 says

Under Section 2(f), a child is an individual who has not completed eighteen years of age. Where the Act refers to a Data Principal who is a child, the parent or lawful guardian may act in the relevant consent context as provided.

Section 9 requires a Data Fiduciary, before processing personal data of a child, to obtain verifiable consent of the parent or lawful guardian. The Act also restricts processing that involves tracking or behavioural monitoring of children, or targeted advertising directed at children, except as otherwise provided. The Central Government may prescribe exemptions and classes of Data Fiduciaries or purposes for which certain Section 9 obligations do not apply.

The Digital Personal Data Protection Rules, 2025 elaborate the operational picture. Rule 10 specifically addresses verifiable consent for processing personal data of a child. Rule 11 addresses verifiable consent where a person with disability has a lawful guardian (see Lawful Guardian under DPDP). Rule 12 and the Fourth Schedule set out exemptions for specified classes of Data Fiduciaries and purposes, subject to stated conditions.

Rule 10 requires appropriate technical and organisational measures so that verifiable consent of the parent is obtained before processing a child’s personal data, and due diligence that the individual identifying as the parent is an adult who is identifiable if required — including by reference to reliable identity and age details already held, details voluntarily provided, or a virtual token mapped to such details issued by an authorised entity (which may include Digital Locker service provider pathways as described in the Rule). The Rules describe due-diligence approaches; they do not mandate a single commercial verification product.

What it means in practice

Organisations should first determine whether they process personal data of individuals under eighteen — including accounts that may be used by children, family products, education or youth-facing services, and marketing directed at children. If children’s data is in scope, map which processing is based on parental or guardian consent versus any Rule 12 / Fourth Schedule exemption that may apply on the facts.

Operational design typically includes age-gating or self-declaration flows, a clear parent or guardian identification step, retention of evidence that consent was obtained in a verifiable manner, and product controls that avoid prohibited tracking, behavioural monitoring or targeted advertising directed at children unless an applicable exemption covers that processing. Notice language should match the purposes for which guardian consent is sought.

Treat Rules 10–12 as implementation detail for Section 9, not as optional extras. Confirm commencement dates for the relevant Rules before treating them as enforceable for your planning timeline. Where lawful guardianship (rather than parenthood) is involved — including for certain persons with disability — follow Rule 11 due diligence rather than informal assumptions about who may consent.

Common mistakes

  • Using informal labels such as “minor consent” instead of the Act’s child / parent or lawful guardian framing.
  • Treating a checkbox by the child as sufficient where Section 9 requires verifiable consent of a parent or lawful guardian.
  • Assuming one branded identity technology is legally mandated; Rule 10 sets due-diligence pathways, not a single vendor mandate.
  • Ignoring tracking, behavioural monitoring and targeted advertising restrictions that apply unless an exemption under the Act or Rule 12 applies.

Official source

ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.

Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.