Skip to content
Higher bar than COPPA

DPDP Children's Data Protection — Section 9 Verifiable Parental Consent

DPDP Section 9 covers children under 18 — five years older than COPPA's under-13 threshold — and bans tracking, behavioural monitoring, and targeted advertising for all of them.

If your platform reaches Indian users and any of them could be under 18, Section 9 compliance is mandatory before you process a single data point.

Under 18age scope
Verifiableconsent required
No trackingor targeted ads
FreeSection 9 review
Section 9 verifiable consent reviewAge-gating UX assessmentAd-tech stack audit for minors

Section 9 hard rules — what is absolutely prohibited

Section 9 imposes categorical prohibitions that apply regardless of consent. Even with verifiable parental consent in place, certain processing activities are banned for data subjects under 18. These are not default-off features that can be toggled — they must be structurally absent from your product for identified minors.

  • Behavioural monitoring: any tracking of a child's online behaviour over time — browsing patterns, content preferences, engagement sequences — is prohibited
  • Tracking: real-time location tracking, device fingerprinting, cross-site tracking, and conversion tracking on minors are all prohibited
  • Targeted advertising: interest-based, retargeted, and profiled advertising directed at users the platform knows or ought to know are under 18 is banned
  • Profiling: creating profiles of minors — for any purpose, not just advertising — based on inferred characteristics is prohibited
  • These prohibitions apply even when a parent has consented to the child using the platform — consent does not unlock banned activities

Verifiable parental consent — mechanisms that work

The Act requires parental or guardian consent to be 'verifiable' — meaning the method must reliably establish that the consenting adult is who they claim to be and that they are actually the child's parent or guardian. The rules are expected to enumerate accepted methods; the following are the widely anticipated mechanisms based on the draft Rules framework.

  • Aadhaar-based OTP: parent's Aadhaar number is submitted; OTP is sent to the Aadhaar-linked mobile — confirms the parent's identity via the UIDAI ecosystem
  • DigiLocker verification: parent signs in with their DigiLocker credentials to access and share a government identity document confirming their identity
  • OAuth via a verified parent account: if your platform has a parent account verified through one of the above methods, the parent's sign-in to the child's account creation flow serves as verification
  • Government digital identity (future): as India expands its digital public infrastructure, additional government-backed identity verification mechanisms may be approved
  • ID document upload with liveness: parent uploads a government ID and completes a liveness check — less preferred due to manual review requirements but may be acceptable for offline-onboarding scenarios

Age-gating UX patterns that satisfy Section 9

Age determination must happen before any personal data is collected — not at account creation after the platform already knows the user's details. The age gate must be designed so that a child cannot trivially bypass it by entering a false birthdate. While no single technical standard is mandated, the design should be 'reasonably reliable' given the platform's risk profile.

  • Date-of-birth gate at the first screen: prompt for birthdate before any email or account data is entered; if under 18, route to parent verification flow rather than block entirely
  • Session continuity: if a user closes the app mid-parent-verification, resume from the verification step on return — do not collect data in the interim
  • Bypass friction: random birthdate entry should be detectable through interaction signals (e.g., birthday-wheel spin to 18 in under a second); flag suspicious patterns for additional verification
  • Re-verification on material changes: if a user previously entered a birthdate indicating adult status but later signals suggest they may be a minor, re-verify
  • Parent dashboard: after verifiable consent, provide the parent with a dashboard showing what data is being processed and controls to withdraw consent, request deletion, or restrict processing

Sector-specific considerations — edtech, gaming, social platforms

Different platform types face different implementation challenges under Section 9. The underlying legal obligation is the same, but the product and operational implications vary significantly.

  • Edtech: school-mediated consent is common internationally (FERPA in the US) but DPDP does not formally recognise a school-as-guardian model — individual parental consent is still required for personal data processing outside of what the school has contracted for
  • Gaming: in-game purchase data, gameplay behaviour, and communication logs are all personal data; loot-box algorithms that adapt to player behaviour constitute behavioural monitoring prohibited for minors
  • Social platforms: UGC posting, direct messaging, follower graphs, and recommendation feeds all involve prohibited behavioural monitoring if the user is under 18 — default-off or unavailable for verified minors
  • Kid-influencer platforms: platforms facilitating child content creators process performance data (views, engagement rates, brand-deal metrics) — all subject to Section 9; commercial arrangements involving a minor's data require parental consent for each data-processing purpose
  • Live streaming and video: watch-time tracking, comment analysis, and moderation queues that use personal data from minors require compliance; automated content moderation based on behavioural signals is impacted

Records to keep and the persons with disabilities parallel

Section 9 also includes protections for persons with disabilities: the same 'verifiable consent' requirement applies when processing is carried out on behalf of a person with a disability where the data principal cannot consent directly. A lawful guardian must provide verifiable consent in these cases. Maintain records demonstrating compliance across both minor and disability sub-populations.

  • Consent records: date, time, identity of consenting parent/guardian, verification method used, scope of consent — retained for the duration of processing and for a reasonable period after
  • Age-determination logs: evidence that age-gating was applied before data collection commenced — important in the event of a Board inquiry about a specific data principal
  • Ad-tech configuration snapshots: periodic exports of your ad-tech audience exclusion settings showing minors are excluded from targeting — document dates of configuration reviews
  • Parental withdrawal records: when a parent withdraws consent, record the withdrawal, the erasure action taken, and the date — Section 6's withdrawal-equals-pre-collection-state principle applies
  • Persons with disabilities: records of guardian identity verification, relationship to the data principal, and scope of consent granted — same retention standard as minor consent records

Cross-links — related DPDP compliance areas

Section 9 interacts with several other DPDP provisions that affect platform design. Understanding these connections prevents compliance gaps from appearing at the seams between sections.

  • Consent management (Section 6): parental consent is a form of consent governed by Section 6 — withdrawal mechanics, purpose-specific granularity, and the linkage of service provision to consent all apply. See /dpdp-consent-manager-integration.
  • Data principal rights (Section 12-14): parents exercising rights on behalf of minors must be able to nominate, access, correct, and erase the child's personal data. See /dpdp-data-principal-rights-workflow.
  • Breach notification (Section 8/Board): breaches affecting children's data attract heightened significance under the penalty framework — notify earlier, document more thoroughly. See /dpdp-breach-notification-checklist.
  • Technical safeguards (Schedule I): appropriate security measures for children's data should be calibrated to the sensitivity and vulnerability of the data principal population. See /dpdp-schedule-i-technical-safeguards.

Audit your children's data processing under Section 9

Review your age-gating, parental consent mechanisms, and ad-tech configuration against DPDP Section 9 — free first engagement, actionable gap report delivered.

Find your vulnerabilitiesStart free scan →