Verifiable parental consent is what section 9(1) of the Digital Personal Data Protection Act, 2023 requires before a data fiduciary processes any personal data of a child — and in India a child is anyone under 18, with no lower tier for teenagers.
Rule 10 of the DPDP Rules 2025 sets the mechanics: the fiduciary must adopt technical and organisational measures to obtain the parent’s consent, and must check with due diligence that the person claiming to be the parent is an adult who is identifiable if the law requires — by reference to reliable identity and age details it already holds, or details the parent volunteers directly or through a virtual token issued by an authorised entity such as a Digital Locker service provider.
Section 9(3) then bans tracking, behavioural monitoring and targeted advertising directed at children, and Rule 12 with the Fourth Schedule carves out the classes and purposes exempt from both. Breach sits in the Schedule’s ₹200 crore band. This guide sets out the statutory rule, Rule 10’s four illustration cases, the exemptions, how the standard compares with COPPA and GDPR Article 8, and how to design an age-assurance and consent flow that satisfies it by 13 May 2027.

What section 9 requires
| Provision | Requirement | Note |
|---|---|---|
| Section 2(f) | A child is an individual who has not completed the age of eighteen years | No 13–16 teen tier as in COPPA or GDPR |
| Section 9(1) | Verifiable consent of the parent (or lawful guardian) before processing any personal data of a child | Rule 10 prescribes the manner; Rule 11 covers lawful guardians of persons with disability |
| Section 9(2) | No processing likely to cause any detrimental effect on the well-being of a child | Applies regardless of consent |
| Section 9(3) | No tracking or behavioural monitoring of children, and no targeted advertising directed at children | Consent cannot lift this; only a Rule 12 exemption can |
| Section 9(4) | Sub-sections (1) and (3) do not apply to prescribed classes, purposes and conditions | Rule 12 and the Fourth Schedule |
| Section 9(5) | The government may notify a lower age for a fiduciary whose children’s processing is verifiably safe | No notifications yet |
| Schedule item 3 | Penalty up to ₹200 crore for breach of section 9 | Third-highest band in the Act |
Our guide to the DPDP Act covers where section 9 sits among the fiduciary duties; DPDP penalties covers the band.
Rule 10: how verifiable parental consent is obtained
Rule 10(1) has two limbs. The fiduciary must adopt appropriate technical and organisational measures to ensure the parent’s verifiable consent is obtained before processing; and it must observe due diligence in checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any Indian law. The check is made by reference to one of three sources.
| Source (Rule 10(1)) | What it means | When it works |
|---|---|---|
| (a) Reliable details of identity and age already available with the fiduciary | The parent is an existing user whose identity and age the fiduciary has already verified | Platforms with verified adult accounts |
| (b)(i) Details of identity and age voluntarily provided by the individual | The parent supplies identity and age details issued by an entity entrusted by law or government with maintaining them | Any fiduciary; requires handling identity documents |
| (b)(ii) A virtual token mapped to such details, issued by an authorised entity | A token from a statutory or government-entrusted issuer, or from a Digital Locker service provider, confirming identity and age without the document itself | The privacy-preserving route the Rules point to |
Two definitions in Rule 10(2) anchor the standard: an adult is a person who has completed the age of eighteen; an authorised entity is one entrusted by law or by the Central or a State Government with issuing identity and age details or tokens, or a person appointed or permitted by it, and includes details or tokens made available and verified by a Digital Locker service provider notified under the Information Technology Act. Rule 10 does not ask the fiduciary to verify the child’s age — it asks it to verify that the consenting parent is an identifiable adult.
The four illustration cases
| Case | Who initiates | Parent’s status | What the fiduciary must do |
|---|---|---|---|
| 1 | The child declares she is a child and names the parent | Registered user who has previously given identity and age details | Enable the parent to identify herself; confirm it holds reliable identity and age details showing an identifiable adult |
| 2 | The child declares she is a child and names the parent | Not a registered user | Check identity and age against details issued by a law- or government-entrusted entity, or a virtual token; the parent may use a Digital Locker |
| 3 | The parent opens the account for the child | Registered user with verified details | Confirm it holds reliable identity and age details showing an identifiable adult |
| 4 | The parent opens the account for the child | Not a registered user | As Case 2: entrusted-entity details or a virtual token |
Our guide to the DPDP Rules 2025 covers Rules 10–12 alongside the rest, and consent managers the registered intermediaries that can carry the consent record.
Rule 12 and the Fourth Schedule: the exemptions
| Part | Exempt class or purpose | Condition |
|---|---|---|
| A.1 | Clinical establishments, mental health establishments, healthcare professionals | Processing restricted to providing health services to the child, to the extent necessary for her health |
| A.2 | Allied healthcare professionals | Restricted to supporting a treatment and referral plan recommended for the child |
| A.3 | Educational institutions | Tracking and behavioural monitoring restricted to educational activities or the safety of enrolled children |
| A.4 | Individuals caring for infants and children in a crèche or day-care centre | Tracking and monitoring restricted to the safety of children in their care |
| A.5 | Transport providers engaged by a school, crèche or child-care centre | Restricted to real-time location tracking during travel to and from the institution, for safety |
| B.1 | Exercise of any power, function or duty in the interests of a child under Indian law | To the extent necessary |
| B.2 | Providing a subsidy, benefit, service, certificate, licence or permit in a child’s interest under section 7(b) | To the extent necessary |
| B.3 | Creating a user account for communicating by email | Limited to an account whose use is limited to email |
| B.4 | Determining a child’s real-time location | In the interest of her safety, protection or security |
| B.5 | Ensuring information, services or advertisements likely to be detrimental to a child’s well-being are not accessible to her | To the extent necessary |
| B.6 | Confirming that a data principal is not a child, and due diligence under Rule 10 | To the extent necessary for that confirmation |
Part B item 6 is the one every fiduciary uses: the age check itself, and the parent’s identity check, are processing the fiduciary may do without prior parental consent. Everything else about the child’s account waits for it.
Verifiable parental consent: DPDP vs COPPA vs GDPR
| DPDP Act / Rule 10 | US COPPA | GDPR Article 8 | |
|---|---|---|---|
| Age of a child | Under 18 | Under 13 | Under 16, Member States may lower to 13 |
| Scope | Any processing of a child’s personal data | Online services directed to children or with actual knowledge | Information society services offered directly to a child, on the consent basis only |
| Verification standard | Due diligence that the parent is an identifiable adult: held details, volunteered details, or a virtual token from an authorised entity | Method reasonably calculated in light of available technology (FTC-listed methods) | Reasonable efforts, taking into consideration available technology |
| Behavioural advertising | Banned for children outright (s.9(3)) | Permitted with verifiable parental consent | Not banned by Art 8; DSA Art 28 bans profiling-based ads to minors on platforms |
| Exemptions | Rule 12 / Fourth Schedule classes and purposes | Limited (e.g. one-time contact, support for internal operations) | None in Art 8; preventive or counselling services in recital 38 |
| Penalty | Up to ₹200 crore | Civil penalties per violation (inflation-adjusted, over US$50,000) | Up to €20m or 4% turnover |
The 18 threshold plus the outright ban on tracking and targeted advertising is what makes the Indian standard the strictest of the three for consumer platforms: a service that can be used by 16- and 17-year-olds needs a verifiable parental consent flow that neither COPPA nor GDPR would require. Our guide to DPDP Act vs GDPR covers the broader comparison.
Designing the flow
- Decide how you learn a user is a child. Self-declaration at sign-up, age inference, or a declared date of birth. Part B item 6 permits the processing needed to confirm a user is not a child; design it as a minimal check rather than a document upload for everyone.
- Route each of the four cases. Child-initiated with a registered parent (Case 1), child-initiated with an unregistered parent (Case 2), parent-initiated registered (Case 3), parent-initiated unregistered (Case 4). Cases 1 and 3 rely on details you already hold; Cases 2 and 4 need a volunteered-details or token path.
- Prefer the token path for unregistered parents. A DigiLocker-style virtual token confirms identity and age without your storing an identity document — which limits what you hold, and what a breach exposes.
- Record the consent as a Rule 3-compliant notice and a section 6 consent. The parent receives the notice; the consent is free, specific, informed, unconditional and unambiguous, recorded with the diligence evidence, and withdrawable.
- Disable tracking, behavioural monitoring and targeted advertising for the child’s account. Consent does not lift section 9(3); the account must be technically incapable of them unless a Fourth Schedule exemption applies to you.
- Apply section 9(2). A documented assessment that the processing is not likely to cause any detrimental effect on the child’s well-being — content, contact, conduct and commercial risks.
- Handle guardians of persons with disability under Rule 11. Verify a court, designated-authority or local-level-committee appointment under the applicable guardianship law.
- Keep the evidence. Which source under Rule 10(1) was used, when, and the consent record — the Board’s inquiry will ask for it, and section 33(2) rewards demonstrable diligence.
Frequently asked questions
What is verifiable parental consent under the DPDP Act?
The consent of a parent or lawful guardian that a data fiduciary must obtain before processing any personal data of a child (under 18), obtained under Rule 10 with due diligence that the consenting person is an identifiable adult — by reference to reliable details already held, details the parent volunteers, or a virtual token from an authorised entity such as a Digital Locker service provider.
Does the fiduciary have to verify the child’s age?
Rule 10 requires verification that the parent is an identifiable adult, not age verification of the child. Confirming a user is not a child is itself exempt processing under Fourth Schedule Part B item 6, so a proportionate age check is expected in practice.
Can a child consent for themselves at 16 or 17?
No. A child is anyone under 18 and section 9(1) requires the parent’s consent, unless the government notifies a lower age for a specific fiduciary under section 9(5) — which has not happened.
Can we show ads to children with parental consent?
Not targeted ads. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children regardless of consent; only a Rule 12 exemption changes that, and none covers advertising.
When does the rule apply from?
Section 9 and Rules 10–12 come into force on 13 May 2027 under Rule 1(4) of the DPDP Rules 2025.
Where this leaves you
Build verifiable parental consent as a four-case flow with the token path for parents you do not already know, record the notice, the consent and the diligence source, and lock tracking and targeted advertising out of every child account rather than behind a toggle — because in India the child is anyone under 18, the ban in section 9(3) survives any consent, and the band for getting it wrong is ₹200 crore.
References
- The Digital Personal Data Protection Act, 2023 — Gazette text (MeitY) — Sections 2(f), 9 and the Schedule.
- The Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E) (MeitY) — Rules 10, 11, 12 and the Fourth Schedule.
- Regulation (EU) 2016/679 (GDPR), Article 8 — EUR-Lex — Comparison.
- FTC — Children’s Online Privacy Protection Rule (COPPA), 16 CFR Part 312 — COPPA comparison.
More on the DPDP Act
- Verifiable parental consent — you are here
- The DPDP Act: the complete guide
- The DPDP Rules 2025
- Consent managers under the DPDP Rules
- DPDP penalties: the Schedule
- DPDP Act vs GDPR
The Children’s Data and Parental Consent Procedure, the Rule 10 diligence record, the four-case consent flow specification, the section 9(2) well-being assessment and the Fourth Schedule exemption register are in the DPDP Act Toolkit, or start with the free templates.