Children’s data protection under the Digital Personal Data Protection Act 2023

Guarding the Digital Playground: Children’s Data Protection Under India’s DPDP Act

The modern playground has shifted from concrete parks to digital screens. Children browse educational videos, engage in interactive gaming platforms, and chat via social networks. However, every click, scroll, and download leaves a digital footprint. For years, the lack of a structured, comprehensive privacy framework left children’s personal data vulnerable to commercial exploitation, profiling, and targeted advertising.

The legislative response arrived with the Digital Personal Data Protection Act, 2023 (DPDP Act),^1 which, alongside the subsequent Digital Personal Data Protection Rules, 2025 (DPDP Rules), radically overhauled India’s digital ecosystem. While the DPDP Act sets out broad rights for all citizens, its provisions concerning minors are uniquely stringent. By establishing a blanket threshold for childhood at 18 years and imposing a strict prohibition on behavioural monitoring, the statutory framework changes how businesses interact with young internet users. This article evaluates the mechanisms of children’s data protection under the DPDP Act, analyses the operational realities introduced by the DPDP Rules, and contrasts India’s approach with global standards.

1. Defining the ‘Child’ Under the DPDP Act

One of the most defining and debated choices in the DPDP Act is its definition of a minor. Section 2(f) explicitly states that a ‘child’ means an individual who has not completed eighteen years of age.^2

┌─────────────────────────────────────────────────────────┐

│              DPDPA 2023: THE THREE PILLARS             │

│                 OF MINOR DATA PROTECTION                │

├─────────────────────────────────────────────────────────┤

│                                                         │

│   1. VERIFIABLE CONSENT                                 │

│      Mandatory parent/guardian approval before any     │

│      data processing takes place.                       │

│                                                         │

│   2. ABSOLUTE HARM PROHIBITION                          │

│      Ban on any processing likely to cause             │

│      detrimental effects to child well-being.           │

│                                                         │

│   3. ANTI-EXPLOITATION SHIELD                           │

│      Strict prohibition on tracking, profiling,         │

│      and targeted advertising.                          │

└─────────────────────────────────────────────────────────┘

By maintaining a uniform threshold of 18, the Indian legislature rejected the flexible age gates seen globally. For instance, the European Union’s General Data Protection Regulation (GDPR) sets the age of digital consent at 16, allowing member states to lower it to 13.^3 Similarly, the United States’ Children’s Online Privacy Protection Act (COPPA) applies exclusively to children under 13.^4

India’s decision to mandate parental oversight up to age 18 treats a tech-savvy 17-year-old high school student similarly to a 7-year-old. While this structural blanket approach protects older teenagers from aggressive profiling, it creates significant operational friction for platforms whose user base consists largely of adolescents.

2. The Mechanics of Verifiable Parental Consent

The first statutory line of defence for children is the mandate for verifiable consent. Section 9(1) of the Act stipulates:

The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian, obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed.^5

Under the Act, online businesses and platforms act as ‘Data Fiduciaries’ because they determine the purpose and means of processing personal information.^6 Conversely, individuals are termed ‘Data Principals’.^7 For minors, parents or legal guardians act as the lawful representatives.

Rule 10 of the DPDP Rules clarified the term ‘verifiable consent’.^8 A simple tick-box stating “I am over 18” or “I have my parent’s permission” is legally insufficient. Instead, Data Fiduciaries must implement multi-party authentication architectures. These practical mechanisms include:

  • Sending an OTP to a parent’s verified mobile number or email address.

  • Utilizing government-issued identity systems like Aadhaar to establish the adult’s age and identity.

  • Integrating advanced digital signatures or independent third-party verification services.

Crucially, the law imposes a strict timeline; consent must precede any data collection. A platform cannot collect a child’s name or email address during onboarding with the promise of seeking parental approval later.

3. The Prohibitions: Anti-Profiling and Targeted Advertising

While parental consent grants access to a service, it does not give platforms free rein over the data collected. Section 9 contains clear, non-negotiable prohibitions that parental consent cannot override.

A. The General Well-Being Test

Section 9(2) mandates that a Data Fiduciary shall not undertake any processing of personal data that is likely to cause any detrimental effect on the well-being of a child.^9 This is a precautionary standard. A regulator does not need to prove that actual harm has materialised; the mere likelihood or foreseeable risk of harm to a child’s psychological, emotional, or physical development makes the processing illegal.

B. Tracking, Monitoring, and Behavioural Profiling

Section 9(3) blocks the commercial monetization of children’s online activity:

A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.^10

This provision disrupts standard internet business models. Practices such as cross-site tracking (following a user across different websites to map their habits), cross-app profiling, and search history accumulation are completely illegal when applied to minors.

Impacted Digital Sectors

Operational Consequences under Section 9(3)

Ed-Tech Platforms

Cannot profile students’ learning patterns to upsell unrelated commercial coaching courses.

Online Gaming

Forbidden from using behavioural data to design predatory mechanics, such as targeted loot boxes or engagement loops aimed at minors.

Social Media & E-Commerce

Prohibited from delivering personalised feeds or algorithmic advertisements based on a minor’s historical preferences.

4. Statutory Exemptions: Balancing Protection and Utility

Recognising that a total ban on processing children’s data without parental consent could disrupt essential services, the legislature built a safety valve into Section 9(4) and Section 9(5).^11 The DPDP Rules formalised these exemptions, allowing data processing for specific, verifiably safe activities that benefit minors.^12

Parental consent is not mandatory in the following circumstances:

  • Child Protection Duties: Processing data to secure a child from immediate physical or digital harm.

  • State Subsidies and Services: Issuing government benefits, education certificates, or welfare allowances directly to minors.

  • Basic Communications: Creating basic email accounts or providing access to standard communication tools, provided data usage is limited to the functionality of the service.

  • Real-Time Safety Tracking: Processing geo-location details exclusively for real-time safety and security (e.g., school bus tracking systems).

Furthermore, the Central Government retains the power to exempt certain Data Fiduciaries from the strictures of Section 9 if they prove their data processing mechanisms are verifiably safe.

5. Enforcement, Penalties, and Global Context

The enforcement of these rules falls under the Data Protection Board of India (DPBI), an independent regulatory body established to investigate data breaches and penalise non-compliance.^13

┌─────────────────────────────────────────────────────────┐

│               DPBI STATUTORY FINING POWERS              │

├─────────────────────────────────────────────────────────┤

│                                                         │

│   [!] General Security Failures: Up to ₹250 Crores      │

│                                                         │

│   [!] Violating Children’s Data Duties: Up to ₹200 Crores│

│                                                         │

│   [!] Failure to Report Data Breaches: Up to ₹200 Crores │

│                                                         │

└─────────────────────────────────────────────────────────┘

The financial stakes are deliberately high. Under the Schedule to the DPDP Act, a breach of statutory obligations regarding children can attract monetary penalties reaching up to ₹200 crore.^14

This punitive regime matches the aggressive stance taken by global regulators. For instance, the European data protection authorities fined a major video-sharing app €345 million in 2023 for systemic failures in its default privacy settings for minors.^15 By pairing high penalties with strict statutory language, the DPDP Act signals that children’s privacy is an issue of corporate liability, rather than a secondary compliance concern.

6. Conclusion

The Digital Personal Data Protection Act, 2023, represents a significant step forward for data privacy in India. By establishing robust requirements for verifiable parental consent, banning behavioural tracking, and introducing heavy financial penalties for violations, the law shifts the digital ecosystem toward systemic safety for minors.

However, operational challenges remain. The decision to define childhood up to 18 years requires businesses to completely redesign user interfaces and data architectures for teenagers, who are traditionally granted greater autonomy under western privacy regimes. As the DPBI steps up enforcement, businesses can no longer view child privacy as an afterthought. Enterprises must adopt privacy-by-design architectures, construct robust age-gating mechanisms, and clean their data systems of tracking tools. Ultimately, the DPDP Act establishes a clear standard for the digital economy: children online are to be treated as young minds to be protected, not data products to be monetised.

Bibliography

Primary Sources

Statutes (India)

  • Digital Personal Data Protection Act, 2023

Delegated Legislation (India)

  • Digital Personal Data Protection Rules, 2025

Foreign Legislation

  • European Parliament and Council Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) [2016] OJ L119/1

  • Children’s Online Privacy Protection Act of 1998, 15 U.S.C. §§ 6501–6506 (USA)

Footnotes

^1 Digital Personal Data Protection Act, 2023 (DPDP Act).

^2 ibid s 2(f).

^3 Regulation (EU) 2016/679 (General Data Protection Regulation) [2016] OJ L119/1, art 8.

^4 Children’s Online Privacy Protection Act of 1998, 15 U.S.C. § 6501(1).

^5 DPDP Act, s 9(1).

^6 ibid s 2(i).

^7 ibid s 2(j).

^8 Digital Personal Data Protection Rules, 2025 (DPDP Rules), r 10.

^9 DPDP Act, s 9(2).

^10 ibid s 9(3).

^11 ibid s 9(4)–(5).

^12 DPDP Rules, r 12.

^13 DPDP Act, ch V.

^14 ibid Schedule.

^15 Data Protection Commission (Ireland), ‘Inquiry into TikTok Technology Limited’ (September 2023).