CHILDREN'S DATA PROTECTION UNDER THE DPDP FRAMEWORK
Vaidehi Sharma
INTRODUCTION
A year ago, if you asked a parent if they knew what information an educational app or a gaming platform was collecting from their ten-year-old child most parents would have said they did not know. There was no law that required people to ask about this information. Things have changed with the Digital Personal Data Protection Act, 2023 and the rules that were announced in November 2025. The Digital Personal Data Protection Act, 2023 and the rules announced in November 2025 give India its real laws about how the personal data of children can be collected, used and stored. This article will look at what these laws say. It will also look at where the laser similar to laws, in other countries. It will look at where the laws are not clear which means parents, schools and platforms will have to figure some things out on their own. The Digital Personal Data Protection Act, 2023 is a law that affects how the personal data of children is handled.
WHO COUNTS AS A CHILD, AND WHY THAT LINE MATTERS
The DPDP Act is very straightforward about this issue. According to Section 2(f) a child is anyone who's not yet eighteen years old. There are no exceptions, no rules for older teenagers and no way for a platform to say that a sixteen-year-old is different from a six-year-old. This is a strict rule compared to other big data protection laws.
The GDPR in the European Union says that a child can give their consent at sixteen but countries can make it lower and some have made it as low as thirteen. The law in America the Children’s Online Privacy Protection Act only protects children under thirteen. India has decided to set the age at eighteen which means a lot of users who would be treated as adults in Europe or the US are protected by the DPDP Act. This is something that people can disagree on. It has been a point of argument since the Act was passed. Some companies that represent education technology, gaming and social media have said that eighteen is too old and does not make sense because a six-year-old and a seventeen-year-old use the internet, in different ways. On the hand people who fight for children’s rights think the higher age is a good idea because teenagers are just as easily tricked and hurt by bad people on the internet as younger children even if they know more about digital things.
THE CORE OBLIGATION: VERIFIABLE PARENTAL CONSENT
The main part of the rules that're just for kids is in Section 9 of the Act. Before anyone can use a kid’s information the person in charge of the information, which is called the data fiduciary, has to get permission from the kids’ parent or guardian. This permission has to be real it is not enough to have a box that says "I am a parent click here to say it is okay".
The people who make the rules want to make sure that the person who is giving permission is really the parent or guardian of the kid. They do not want the kid to pretend to be a grown up and give permission for themselves. This is a problem that happens a lot like when a kid lies about how old they're so they can join a social media site. The data fiduciary has to make an effort to check that the person who is giving permission is really the kids parent or guardian. The rules for kids are very important. The data fiduciary has to follow them which is why the kid’s personal information is safe with the data fiduciary. The data fiduciary and the rules for kids are connected the data fiduciary has to know the rules, for kids and follow them when using a kid’s information.
Section 9 does not just stop at getting consent from people. It also has two rules for the people who handle our data. First these people cannot use a child’s data in a way that could hurt the child. This rule is not very clear so it will depend on how the Data Protection Board of India understands it. The idea is to protect children even if their parents have said it is okay.
Second the law says that companies cannot track what children do online or show them ads based on what they like. This is a good rule. Many companies on the internet make money by watching what people do online and showing them ads that're more likely to interest them. The DPDP Act says that children should not be a part of this. At least that is what the law says. The digital advertising industry will have to change how it works because of this rule. The DPDP Act is trying to keep children from ads that might not be good, for them. This is a deal because many companies make a lot of money from ads. The law is trying to protect children from being targeted by these ads. Section 9 and the DPDP Act are important because they are trying to keep children online. The Data Protection Board of India will have to make sure that companies follow these rules.
HOW THE RULES OPERATIONALISE VERIFIABLE CONSENT
The Act did not say how to get consent that can be verified. This was supposed to be figured out through other laws. The Ministry of Electronics and Information Technology finally came up with the Digital Personal Data Protection Rules in 2025 on November 13 2025.
The Digital Personal Data Protection Rules have a rule, Rule 10 that talks about how to make sure a parent or guardian is really giving consent for a child and not the child itself. This rule thinks about using things, like Digi Locker, which's a government system to verify someone’s identity and age. The goal of the Digital Personal Data Protection Rules is to stop relying on people being honest. Now most platforms just ask for a date of birth to make sure someone is old enough. The Digital Personal Data Protection Rules want to move from this approach and use better ways to verify someone’s age and identity so that the Digital Personal Data Protection Rules can really protect children.
The Rules have some exemptions from the obligations they set. These exemptions are explained in Rule 12 and the Fourth Schedule to the Rules. Some groups are exempt from following all the rules in Section 9. This includes hospitals, mental health places and doctors. Only when they use the data to give health services to children. Schools, day-care centres and people who drive kids around are also exempt. Only when they track the kids to keep them safe.
The Rules also say it is okay to use a child's data in certain situations. For example, it is okay to use the data to keep the child safe or to give them subsidies or benefits. These exemptions are very specific. Do not mean that hospitals or schools can do whatever they want with a child’s data. They only apply when the data is being used for a specific reason. If a hospital starts using a child's health data for something, like making a marketing profile they will not be exempt anymore. They will have to follow all the rules in Section 9. The Rules are written in a way that makes sure hospitals and schools do not take advantage of these exemptions. The exemptions are conditional and only apply to certain situations.
WHAT HAPPENS IF A COMPANY GETS THIS WRONG
The DPDP Act supports all of this with penalties that're compared to Indian regulatory standards, very strict. According to the Schedule to the Act not following the rules about children’s data can result in a fine of up to two hundred crore rupees. The biggest fine allowed under the Act up to two hundred and fifty crore rupees is, for a data fiduciary not keeping
proper security measures in place. This applies to children's data as much as it does for any other data. These amounts are serious. Show that the government views children’s data as one of the most important areas where it does not want a relaxed approach. It is not clear yet if the Data Protection Board of India whose members were still being chosen when the Rules came into effect will actually use these powers strongly in practice. The highest possible fine is there.
The Digital Personal Data Protection Act and Rules are being implemented step by step. The main parts, like the Data Protection Board started from the day the Rules were announced. Other parts, like getting consent from people are being introduced over about eighteen months. The Digital Personal Data Protection Act and Rules are expected to be enforced by mid-2027. For a company that is making or running a platform that children might use this slow introduction of the Digital Personal Data Protection Act and Rules is not a reason to wait. It is very expensive and disruptive to add consent checks, age checks and data tracking systems, to a product after it has already been launched. It is better to include these things from the beginning. The direction of the Digital Personal Data Protection Act and Rules is clear so companies should get ready now.
HOW INDIA'S APPROACH COMPARES
When you look at the approach next to the GDPR and COPPA some things really stand out. The GDPR has a rule that says kids have to be sixteen to give consent. Each country can make this age lower if they want as long as it is not below thirteen. This has made a mess in Europe because everything is different from one place to another. COPPA is different it only protects kids under thirteen. People have been saying for years that this is not good enough because it leaves a lot of teenagers without any special protection. This means that the people in charge have to use rules to protect these teenagers, which is not ideal.
India has decided that eighteen is the age for consent and this is the same with no exceptions. This makes Indias rules the strongest of the three at least on paper. When it comes to actually putting these rules into practice India is not as far along as the others. The GDPR has been around for a time so there are a lot of examples of how it works in real life. The DPDP framework in India is just starting out so a lot of things still need to be figured out like what verifiable" parental consent means. This will take some time. Will probably involve a lot of discussions, lawsuits and decisions from the people in charge over the next few years. The Indian approach, to the DPDP framework is still. The DPDP framework will be shaped by these
discussions and decisions. The DPDP framework and the GDPR are both important. The DPDP framework has a lot to learn from the GDPR.
WHERE THE GAPS STILL ARE
The framework is not complete. It still has problems. One big issue is verifying someone’s age. This is a tough problem to solve with technology. Now there is no good way to stop a kid from using their parent’s device or account to get around the rules.
For example, the government ID-based approaches that are being considered do not work perfectly. A kid can still use their parents’ device or credentials to get past the gate. There is also a question about what happens when a kid grows up. The rules do not say what should happen when a kid turns eighteen and can make their decisions. The Act does not say how the consent that a parent gave when their child was little should be handled when the child becomes an adult. Companies will have to figure out a way to handle this transition on their own. The Age Verification issue is still a problem. The "detrimental effect, on being" standard is also very broad. This means that it will be hard to understand what it really means until the Data Protection Board starts making decisions and courts start interpreting it. The framework and the Age Verification issue will take time to be fully understood.
CONCLUSION
For all its edges the child-specific rules under the DPDP Act and the 2025 Rules shows a real change in how Indian law deals with children online. It takes the country from a place where children’s data was handled at best indirectly through privacy rules or companies making their own rules to a place with a clear legal duty, a clear group that enforces it and serious fines for breaking the rules. The eighteen-year age limit, the need for permission and the complete ban on tracking kids and showing them, ads are all much stronger than what other countries have, at least on paper. The real challenge, like with data protection laws will be, about making sure the rules are followed: whether the Data Protection Board actually checks that these rules are met with the same seriousness that the fines suggest and whether websites see the time to follow the rules as a real deadline instead of something to think about later.
REFERENCES
1. The Digital Personal Data Protection Act, 2023, s 2(f).
2. Regulation (EU) 2016/679 (General Data Protection Regulation), art 8.
3. Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 (1998). 4. Drishti IAS, "DPDP Act 2023 and the Issue of Parental Consent" (2025). 5. The Digital Personal Data Protection Act, 2023, s 9(1).
6. The Digital Personal Data Protection Act, 2023, s 9(2).
7. The Digital Personal Data Protection Act, 2023, s 9(3).
8. Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), notified 13 November 2025.
9. Digital Personal Data Protection Rules, 2025, r 10.
10. Digital Personal Data Protection Rules, 2025, r 12 read with the Fourth Schedule. 11. Digital Personal Data Protection Rules, 2025, Fourth Schedule, Part A. 12. The Digital Personal Data Protection Act, 2023, Schedule (Section 33), entry relating to breach of Section 9 obligations.
13. The Digital Personal Data Protection Act, 2023, Schedule (Section 33), entry relating to failure to maintain reasonable security safeguards.
14. Ministry of Electronics and Information Technology, Enforcement Notification under the Digital Personal Data Protection Act, 2023, dated 13 November 2025.
15. Regulation (EU) 2016/679, art 8(1).
16. Federal Trade Commission, Children's Online Privacy Protection Rule, 16 C.F.R. Part 312.
AUTHOR(s): Isha Kumari, BBA.LL.B graduate from ITM University, intern at The Legal Lock
More to Read
REGULATION OF AI-GENERATED DEEPFAKES UNDER INDIAN LAW
blogs
DATA FIDUCIARY LIABILITY UNDER THE DPDP FRAMEWORK
blogs
High-Performance Hub: Streamlining Law Firm Intake
blogs
The Corporate Secrets That Leave Thousands Broken: Inside the Mass Tort Battles You Never Hear About
blogs
The Difference Between Simple and Aggravated Assault Under New Jersey Law
blogs
DOES INDIA NEED A COMPREHENSIVE AI REGULATION ACT?
blogs