The Act treats anyone under 18 as a child, and sets a noticeably higher bar for processing their data than it does for adults.
WHAT'S DIFFERENT FOR CHILDREN'S DATA
CONSENT
Verifiable parental consent
Not just a checkbox saying “I am a parent” — the consent-giver’s identity has to be verifiable.
NO TRACKING
No behavioural monitoring or targeted ads
Prohibited outright for children, regardless of what an adult might separately consent to.
PENALTY
Up to ₹200 crore
Among the highest penalty tiers in the Act — children’s data is treated as a red line, not a routine category.
“Verifiable” is the operative word that trips organisations up: a form that simply asks “Are you the parent?” with no way to check the answer doesn’t meet the bar. The Rules expect an actual verification mechanism, which is a meaningfully bigger build than a standard consent flow.
Common misconception — That verifiable parental consent is just ordinary consent with a parent’s name on it. It specifically requires verifying that the person consenting really is the parent or guardian — an added step, not a relabelled one.
Children’s data isn’t a stricter version of ordinary consent. It’s a genuinely different, higher standard.
SOURCES DPDP Rules and the Future of Child Data Safety — Observer Research Foundation — https://www.orfonline.org/expert-speak/dpdp-rules-and-the-future-of-child-data-safety · The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf