DPDP Child Data Consent: Age Verification, Parent Consent and Product-Design Controls
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
The final child-data framework requires verifiable parent/lawful-guardian consent and restricts tracking/behavioural monitoring and targeted advertising, but these core obligations are on the May 2027 commencement track as of 4 October 2026.
Finin2min 2-Minute Summary
- Section 9 requires verifiable parental/lawful-guardian consent before processing a child's personal data, subject to notified exemptions.
- The Act restricts processing likely to cause detrimental effect and prohibits tracking/behavioural monitoring and targeted advertising directed at children, subject to statutory exemptions.
- Final Rules 10-12 specify verification mechanics and exemption classes/purposes.
- These provisions are notified but not yet operative on 4 October 2026 under the phased commencement.
- Products should minimise age-verification data and avoid turning the verification process into a new profiling system.
Current status: readiness, not present-tense enforcement
Design age assurance proportionately
The objective is to know whether the user is a child and, where necessary, verify the adult providing consent. Collect only the information needed for that decision and keep stronger verification for higher-risk processing rather than defaulting to intrusive identity collection for every visitor.
Document how false age declarations, shared devices and guardian disputes are handled.
Parental consent needs an auditable relationship
Future compliance should show which parent/lawful guardian consented, what child processing was described, how the adult was verified and how withdrawal affects the child's account/data.
Do not assume a card payment or generic family-account login proves lawful guardianship.
October 2026 status: child-data product controls can be built before commencement
Section 9 and Rules 10-12 are part of the future-dated core framework scheduled for May 2027, not current October 2026 enforcement. Product teams should use the implementation window to test how child accounts are detected, how an adult's parent/guardian status is verified, and how existing child users will be transitioned once the provisions commence.
Legacy accounts are the difficult population. A service may know only a self-declared birth year, while older profiles have no age field at all. Create a migration decision tree that minimises new identity collection but identifies cases requiring stronger verification.
Advertising and analytics teams should separately inventory trackers, recommendation systems and behavioural profiles that can touch child accounts. Turning off one advertising SDK while internal profiling continues may not satisfy the future restriction.
- Build a legacy-account age-assurance migration plan.
- Inventory SDKs/trackers that touch child accounts.
- Separate guardian verification from ordinary user KYC.
- Test consent withdrawal when the child account remains active.
Product-design guardrails
- Age/child determination logic.
- Verifiable parent/guardian process.
- Child-purpose data minimisation.
- No prohibited tracking/targeted-ad pathway.
- Exemption mapping where relied upon.
- Consent withdrawal and account transition.
- Evidence log without unnecessary identity retention.
Questions readers commonly ask
Are the child-data rules already in force in October 2026?
No. The relevant core Act/rules are on the 18-month commencement track for May 2027.
Is every age-verification method prescribed?
No single universal method is mandated for every product; the final rules describe verifiable-consent requirements and checks.
Can child users be behaviourally tracked for ads?
The Act prohibits tracking/behavioural monitoring and targeted advertising directed at children, subject to prescribed exemptions.
Should age verification collect full KYC by default?
Use a proportionate method and minimise data unless stronger verification is genuinely needed.
Official / primary sources
- DPDP Act, 2023 - Section 9 child-data obligations
- DPDP Rules, 2025 - Rules 10-12 and child-related schedules
- DPDP enforcement timeline - Core obligations scheduled after 18 months
Disclaimer
Important: General educational and professional-reference material. Apply the current Code, Rules, insurance contract/regulatory instrument or DPDP commencement status to the exact facts before acting. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.