📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.

Differences

This shows you the differences between two versions of the page.


dpdp-children-data-parental-consent-rules-2025 [2026/07/10 21:25] (current) – created - external edit 127.0.0.1
Line 1: Line 1:
 +{{htmlmetatags>metatag-description=(Under the DPDP Rules 2025, apps will need verifiable parental consent before handling a child's data from 13 May 2027. What Indian parents should know now.)&metatag-keywords=(children data protection India parental consent, DPDP Rules 2025, verifiable parental consent, DigiLocker Age Token)&metatag-robots=(index,follow)&metatag-og:title=(Children's Data Online: Parental Consent Under DPDP Rules 2025)&metatag-og:description=(Under the DPDP Rules 2025, apps will need verifiable parental consent before handling a child's data from 13 May 2027. What Indian parents should know now.)&metatag-og:type=(article)}}
 +===== Children's Data Online: Parental Consent Under DPDP Rules 2025 =====
  
 +Imagine Dr. Shrawan Kumar Pathak opening his daughter Kashvi's tablet and finding she has signed up to a new game that asks for her name, photo and location. He wonders what the law actually says about a child sharing data online in India. This guide answers that question in plain terms for parents.
 +
 +The short version: a new rule will soon require apps to get a parent's verified permission before they collect or use a child's data. That rule is already notified, but the duty on apps becomes enforceable from **13 May 2027**. Until then, parents rely on existing app controls and grievance channels.
 +
 +==== What Rule 10 will require of apps ====
 +
 +Here is the core of the new protection, in plain bullets. These obligations on platforms become enforceable from 13 May 2027.
 +
 +  * Before handling the personal data of a child (anyone under 18), an app must obtain **verifiable parental consent** from the parent or lawful guardian.
 +  * The app must use appropriate technical measures to confirm that the person giving consent is an identifiable adult.
 +  * The app must not track or monitor a child's behaviour.
 +  * The app must not run targeted or behavioural advertising directed at children.
 +  * The same heightened protection applies to a person with a disability who has a lawful guardian.
 +
 +This comes from Section 9 of the Digital Personal Data Protection Act 2023, read with Rule 10 of the DPDP Rules 2025, notified on 13 November 2025 by the Ministry of Electronics and Information Technology (Gazette G.S.R. 846(E)).
 +
 +==== Does my child need my consent to use an app? ====
 +
 +Under the new framework, yes. Section 9 of the DPDP Act 2023 treats anyone below 18 years as a child. An app that acts as a Data Fiduciary, meaning it decides why and how personal data is processed, will have to obtain verifiable parental consent before it processes a child's personal data.
 +
 +This is a higher bar than a simple tick-box. The app cannot just ask the child to confirm "I am over 18" or "my parent agrees". It will have to actually verify that a real, identifiable adult is giving the consent on the child's behalf.
 +
 +Remember the timing. Rule 10 is notified, so the text of the law is fixed, but the duty on apps to follow it starts on 13 May 2027. Before that date, apps are not legally bound by Rule 10, though many already offer parental controls you can use today.
 +
 +==== How will an app verify that I am the parent? ====
 +
 +The DPDP Rules 2025 expect the app to use appropriate technical measures to check that the person giving consent is an identifiable adult. There are two main routes the rules contemplate.
 +
 +**Route one: identity already verified on the platform.** If the parent's identity and age are already reliably known to the app, for example because the parent holds a verified adult account, the app can rely on that existing verification when the parent consents for the child.
 +
 +**Route two: independent verification using a DigiLocker Age Token.** Where the parent's identity is not already known, the app can rely on an independent check. This can use an Aadhaar-linked DigiLocker "Age Token", a virtual token that confirms the adult's identity and age without handing the app a full copy of the parent's Aadhaar.
 +
 +In simple terms, the Age Token is a digital slip from DigiLocker that says "this person is a verified adult" without revealing every detail on the document. It lets the app trust that a genuine parent or guardian is giving consent, while sharing as little personal information as possible.
 +
 +==== Can apps show my child targeted ads? ====
 +
 +No, not once Rule 10 is in force. The DPDP Act 2023 prohibits tracking, behavioural monitoring and targeted advertising directed at children. So an app will not be allowed to build a profile of your child's activity to push tailored ads at them.
 +
 +This is one of the clearest protections in the new law. It is aimed at the common pattern where a child's clicks, watch time and in-app behaviour are quietly used to serve advertising. From 13 May 2027, that practice directed at children will not be permitted.
 +
 +The same protection extends to a person with a disability who has a lawful guardian. The guardian steps into the role the parent plays for a child, and the app must seek verifiable consent from that guardian in the same way.
 +
 +==== What can I do right now, before 13 May 2027? ====
 +
 +You do not have to wait until 2027 to protect your child. Practical steps you can take today:
 +
 +  * Use the age-rating and parental-control tools that apps, app stores and devices already provide. Most platforms let you set age limits, screen time and content filters.
 +  * Review what data a child's app actually collects. Check the app's permissions and privacy settings, and turn off location, microphone or contacts access where it is not needed.
 +  * Read the privacy policy for what the app says it does with a child's data, and remove apps that ask for far more than they need.
 +  * If something looks wrong, complain to the platform's grievance officer. Most apps must name a grievance contact, and a written complaint creates a record you can escalate.
 +
 +The older information technology law framework from the year 2000 still applies to sensitive personal data in the meantime, so platforms are not operating in a vacuum before the DPDP duties begin.
 +
 +If a public authority, school or government portal is involved and you want to know what data it holds or what rules it follows, a formal information request can help. You can use the [[https://righttoinformation.wiki/tools/ai-rti-draft-app.html|AI RTI Drafter]] to prepare one, and the [[https://righttoinformation.wiki/act|RTI Act 2005]] explains your right to that information. For a wider view of how citizen rights and complaints work, see [[https://righttoinformation.wiki/book|The RTI Playbook]].
 +
 +==== Where do I complain if an app ignores the rules? ====
 +
 +Start with the app's own grievance officer. If that does not resolve matters, India has separate regulators for different sectors, and it helps to know which one covers your issue. The guide on [[https://righttoinformation.wiki/which-regulator-to-complain-to-india-sebi-rbi-irdai-trai-dgca-hub|which regulator to complain to]] can point you in the right direction. Once the DPDP enforcement machinery is fully active, the data protection authority created under the Act will be the body for data-related complaints.
 +
 +==== Frequently asked questions ====
 +
 +==== Who counts as a child under the DPDP Act 2023? ====
 +
 +Anyone below the age of 18 years. This is set by Section 9 of the DPDP Act 2023. Until a person turns 18, an app handling their personal data will need verifiable parental consent.
 +
 +==== Is Rule 10 in force today? ====
 +
 +No. Rule 10 of the DPDP Rules 2025 is notified, but the obligations it places on apps become enforceable from 13 May 2027, which is 18 months after the rules were notified on 13 November 2025.
 +
 +==== What is a DigiLocker Age Token in simple words? ====
 +
 +It is a virtual token from DigiLocker, linked to Aadhaar, that confirms an adult's identity and age to an app. It lets an app verify a parent without the parent handing over a full copy of their Aadhaar.
 +
 +==== Will apps be allowed to advertise to my child? ====
 +
 +Targeted and behavioural advertising directed at children is prohibited under the DPDP Act 2023. Once Rule 10 is in force, apps will not be able to profile your child to serve them tailored ads.
 +
 +==== Does this protect my child with a disability who has a guardian? ====
 +
 +Yes. The same heightened protection applies to a person with a disability who has a lawful guardian. The guardian gives the verifiable consent in place of the person, just as a parent does for a child.
 +
 +==== What should I do before 2027 if an app collects too much of my child's data? ====
 +
 +Use the app's parental controls, tighten its permissions, review its privacy policy, and complain to the platform's grievance officer if needed. The older information technology framework from 2000 still protects sensitive personal data in the meantime.
 +
 +==== Sources ====
 +
 +  * Digital Personal Data Protection Act 2023, Section 9, Ministry of Electronics and Information Technology.
 +  * DPDP Rules 2025, Rule 10, notified 13 November 2025, Gazette G.S.R. 846(E), Ministry of Electronics and Information Technology.
 +  * Ministry of Electronics and Information Technology (MeitY) notifications on commencement, with the children's data provisions enforceable from 13 May 2027.
 +===== DPDP Act: Children's data and parental consent rules under the Digital Personal Data Protection Act 2025? =====
 +
 +The Digital Personal Data Protection (DPDP) Act 2023 (notified 2025) has specific rules for children's data. Here is the complete guide:
 +
 +  - **Step 1: Who is a child?** (a) under the DPDP Act, a "child" is any person below 18 years of age, (b) the definition is stricter than GDPR (which defines a child as below 16), (c) all protections for children apply to anyone under 18.
 +  - **Step 2: Parental consent.** (a) before processing a child's personal data: verifiable parental consent is mandatory, (b) the consent must be obtained from a parent or lawful guardian, (c) the consent must be: (i) specific, (ii) informed, (iii) unambiguous, (iv) verifiable, (d) the Data Fiduciary must verify that the person giving consent is indeed the parent/guardian.
 +  - **Step 3: Prohibited processing.** (a) no processing of children's data that is likely to cause: (i) cognitive harm, (ii) physical harm, (iii) behavioral harm, (b) no targeted advertising at children, (c) no tracking of children's behavioral patterns, (d) no processing that encourages children to provide personal data unnecessarily.
 +  - **Step 4: Data Fiduciary obligations.** (a) the Data Fiduciary must: (i) obtain verifiable parental consent, (ii) ensure data minimization (collect only what is necessary), (iii) implement security safeguards, (iv) not retain data longer than necessary, (v) provide a privacy policy in simple language, (b) the Data Fiduciary must appoint a Data Protection Officer (for significant data fiduciaries).
 +  - **Step 5: Educational institutions.** (a) schools can process children's data for educational purposes with parental consent, (b) the consent must cover: (i) admission records, (ii) academic records, (iii) health records (if necessary), (c) the school must not share data with third parties (e.g., coaching centers, ed-tech companies) without additional consent.
 +  - **Step 6: Ed-tech and gaming apps.** (a) ed-tech apps (e.g., Byju's, Unacademy) must obtain parental consent before collecting children's data, (b) gaming apps cannot process children's data for targeted advertising, (c) social media platforms must restrict accounts for users below 18, (d) the Data Protection Board can impose penalties up to Rs 200 crore for violations.
 +  - **Step 7: Rights of the child/parent.** (a) the parent can: (i) access the child's data, (ii) request correction/erasure, (iii) withdraw consent, (iv) nominate someone to exercise rights in case of death/incapacity, (b) the child (upon turning 18) can: (i) access their data, (ii) request erasure of data collected during childhood, (c) file a complaint with the Data Protection Board if the Data Fiduciary violates the rules.
 +
 +See [[https://righttoinformation.wiki/dpdp-children-data-parental-consent-rules-2025|DPDP Children]] and [[https://righttoinformation.wiki/india-dpdp-compliance|DPDP Compliance]].
 +
 +{{tag>dpdp act children data parental consent 18 years verifiable data protection board 200 crore 2026}}