Skip to main content
Finin2minAction Guide · source-controlled
DPDP, Privacy & DataUpdated 5 October 2026

DPDP Child Data Consent: Age Verification, Parent Consent and Product-Design Controls

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

The final child-data framework requires verifiable parent/lawful-guardian consent and restricts tracking/behavioural monitoring and targeted advertising, but these core obligations are on the May 2027 commencement track as of 4 October 2026.

Finin2min 2-Minute Summary

Current status: readiness, not present-tense enforcement

Design age assurance proportionately

The objective is to know whether the user is a child and, where necessary, verify the adult providing consent. Collect only the information needed for that decision and keep stronger verification for higher-risk processing rather than defaulting to intrusive identity collection for every visitor.

Document how false age declarations, shared devices and guardian disputes are handled.

Parental consent needs an auditable relationship

Future compliance should show which parent/lawful guardian consented, what child processing was described, how the adult was verified and how withdrawal affects the child's account/data.

Do not assume a card payment or generic family-account login proves lawful guardianship.

October 2026 status: child-data product controls can be built before commencement

Section 9 and Rules 10-12 are part of the future-dated core framework scheduled for May 2027, not current October 2026 enforcement. Product teams should use the implementation window to test how child accounts are detected, how an adult's parent/guardian status is verified, and how existing child users will be transitioned once the provisions commence.

Legacy accounts are the difficult population. A service may know only a self-declared birth year, while older profiles have no age field at all. Create a migration decision tree that minimises new identity collection but identifies cases requiring stronger verification.

Advertising and analytics teams should separately inventory trackers, recommendation systems and behavioural profiles that can touch child accounts. Turning off one advertising SDK while internal profiling continues may not satisfy the future restriction.

Product-design guardrails

Questions readers commonly ask

Are the child-data rules already in force in October 2026?

No. The relevant core Act/rules are on the 18-month commencement track for May 2027.

Is every age-verification method prescribed?

No single universal method is mandated for every product; the final rules describe verifiable-consent requirements and checks.

Can child users be behaviourally tracked for ads?

The Act prohibits tracking/behavioural monitoring and targeted advertising directed at children, subject to prescribed exemptions.

Should age verification collect full KYC by default?

Use a proportionate method and minimise data unless stronger verification is genuinely needed.

Official / primary sources

Disclaimer

Important: General educational and professional-reference material. Apply the current Code, Rules, insurance contract/regulatory instrument or DPDP commencement status to the exact facts before acting. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.