Processing Children’s Data: Consent and Safeguards

The Act treats anyone under 18 as a child, and sets a noticeably higher bar for processing their data than it does for adults.

WHAT'S DIFFERENT FOR CHILDREN'S DATA

CONSENT

Verifiable parental consent

Not just a checkbox saying “I am a parent” — the consent-giver’s identity has to be verifiable.

NO TRACKING

No behavioural monitoring or targeted ads

Prohibited outright for children, regardless of what an adult might separately consent to.

PENALTY

Up to ₹200 crore

Among the highest penalty tiers in the Act — children’s data is treated as a red line, not a routine category.

“Verifiable” is the operative word that trips organisations up: a form that simply asks “Are you the parent?” with no way to check the answer doesn’t meet the bar. The Rules expect an actual verification mechanism, which is a meaningfully bigger build than a standard consent flow.

Common misconception — That verifiable parental consent is just ordinary consent with a parent’s name on it. It specifically requires verifying that the person consenting really is the parent or guardian — an added step, not a relabelled one.

Children’s data isn’t a stricter version of ordinary consent. It’s a genuinely different, higher standard.

SOURCES  DPDP Rules and the Future of Child Data Safety — Observer Research Foundation — https://www.orfonline.org/expert-speak/dpdp-rules-and-the-future-of-child-data-safety   ·   The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.