Children's Data Protection — Section 9 Is Among the Strictest Children's Privacy Laws Globally
Section 9 of the DPDP Act defines a “child” as any individual under 18 years of age — one of the most conservative thresholds globally. GDPR allows Member States to lower consent age to 13. US COPPA applies only to children under 13. India's uniform 18-year threshold means your obligation covers a much larger portion of your user base than most global frameworks.
If your product, platform, or service can be accessed by anyone under 18 — and for most digital services, it can — Section 9 applies to you. The penalty for violations involving children's data reaches ₹200 crore.
PrivacyOS provides the tools to comply: age verification, verifiable parental consent workflows, guardian consent for persons with disabilities, behavioural tracking restrictions, and ad targeting controls — all integrated with your consent management and compliance programme.
Apply for DPDPA Assessment
Fill the details to get started with our corporate panel.
Trusted by 1,000+ compliance teams
Trusted by leading enterprise and mid-market brands
















What Section 9 Requires
Verifiable Parental Consent (Section 9(1))
Before processing any personal data of a child, you must obtain verifiable consent from the child's parent or lawful guardian. The key word is “verifiable” — a child clicking “I am over 18” does not count. A child typing their parent's email address does not count. You must independently confirm that the person giving consent is actually the parent or guardian and that they are identifiable as an adult.
Rule 10 of the DPDP Rules 2025 specifies two verification pathways:
- • Existing verified parent account: If the parent already uses your platform and their identity has been verified, they can authorise the child's account from their own verified account.
- • Independent DigiLocker verification: If the parent is not on your platform, their identity and age must be independently verified via Aadhaar-linked DigiLocker tokens.
Consent must be obtained before any processing begins. A “trust first, verify later” approach — letting children sign up and verifying retroactively — is not compliant under Section 9(1).
Absolute Prohibitions (Section 9(3))
Even with valid parental consent, certain processing activities are categorically prohibited for children's data:
- • Behavioural tracking and monitoring — no tracking children's online behaviour for engagement optimisation
- • Targeted advertising — no ads directed at children based on their personal data or behaviour
- • Profiling — no building profiles of children for any purpose
These prohibitions apply regardless of parental consent. You cannot consent your way out of them.
Guardian Consent for Persons with Disabilities (Rule 11)
Section 9 also covers persons with disability who have a lawful guardian. The consent and verification requirements mirror those for children, with additional verification of the guardianship relationship.
Age Verification Obligation
Before you can apply Section 9 protections, you must first determine whether a user is a child. This requires age-gating mechanisms — not just a date-of-birth field (which children can easily falsify), but reasonable technical measures to identify when a data subject is under 18.
What PrivacyOS Provides
Age Verification Gates
Configurable age verification mechanisms that determine whether a user is a child before any personal data is collected. Multiple verification levels based on your risk tolerance and user experience requirements.
Verifiable Parental Consent Workflows
End-to-end parental consent flows that satisfy Section 9(1) and Rule 10:
- • Parent identification and age verification (DigiLocker or existing account)
- • Consent request delivery to the verified parent
- • Parent review of what data will be collected and for what purposes
- • Affirmative consent capture with timestamp and verification log
- • Child account activation only after verified consent is completed
The entire flow is logged for audit evidence.
Tracking and Profiling Restrictions
Automated enforcement of Section 9(3) prohibitions:
- • Disable behavioural tracking scripts for identified child accounts
- • Block ad targeting algorithms from using children's data
- • Prevent profiling engines from processing child records
- • Flag any processing activity that attempts to use children's data for prohibited purposes
Integration with Consent Management
Children's consent is managed within the same consent management platform as adult consent — but with additional controls, verification steps, and restrictions applied automatically based on age classification.
Who Must Comply
Any organisation whose digital products or services may be accessed by individuals under 18 in India. This includes:
EdTech platforms
Learning apps, online tutoring, student information systems
Social media
Any platform allowing user-generated content or social interaction
Gaming companies
Mobile games, online gaming platforms, game streaming
E-commerce
Platforms where minors may place orders or create accounts
Content platforms
Video streaming, music apps, content aggregators
Health apps
Fitness trackers, mental health apps used by adolescents
Avoid ₹200 Cr Penalties on Children's Data Processing
Integrate verifiable parental consent, DigiLocker age token verification, and automated behavioural ad-blocking in minutes.
Frequently Asked Questions
Protect Children's Data Under DPDPA
Safeguard minor data subjects with certified parental verification mechanisms and automated ad-tracking killswitches.
