top of page

How to Design a Verifiable Parental Consent Process Under the DPDP Rules 2025

Writer: Kaustav Chowdhury
Kaustav Chowdhury
1 hour ago
6 min read

A service that may be used by anyone under eighteen will have to obtain verifiable parental consent before it processes that user's personal data. The obligation sits in section 9(1) of the Digital Personal Data Protection Act, 2023 and the manner of compliance is prescribed by rule 10 of the Digital Personal Data Protection Rules, 2025. Neither is in force yet, which is the first thing to establish before designing anything.

Step 1: Fix the Commencement Position Before You Design

The commencement of the Act was notified separately from the Rules. By G.S.R. 843(E) dated November 13, 2025, issued under section 1(2), the Central Government brought section 2 and sections 18 to 26, among others, into force at once, section 6(9) and section 27(1)(d) one year after publication, and sections 3 to 5, most of section 6, and sections 7 to 17 eighteen months after publication. Section 9 is in the third group.

The Rules follow the same shape. Rules 1, 2 and 17 to 21 commenced on publication of G.S.R. 846(E) dated November 13, 2025, rule 4 one year later, and rules 3, 5 to 16, 22 and 23 eighteen months later. Rule 10 is in the last group. So what commences in November 2026 is the consent manager machinery, not the children's data obligation, which commences with the eighteen month tranche in May 2027.

That matters in practice because the design work is long and the obligation is unforgiving when it arrives. Treat the period as build time, and say so in internal papers, rather than describing the obligation as operative.

Step 2: Settle Who Counts as a Child, and How You Will Know

Section 2(f) defines a child as an individual who has not completed the age of eighteen years. There is no graduated age band, so a sixteen year old is a child for the purposes of the Act. Section 2(j) then provides that where the data principal is a child, the expression includes the parents or lawful guardian, which is why correspondence and rights requests have to be capable of coming from the parent.

The practical question is how the service determines age at all. Rule 12 read with Part B of the Fourth Schedule treats processing undertaken to confirm that a data principal is not a child, or to observe the due diligence the Rules require, as outside the obligations in section 9(1) and (3), subject to the conditions stated there. So an age assurance step can be built without the parental consent gate closing on the step itself.

Step 3: Record the Adult Check the Way Rule 10 Requires

Rule 10(1) requires the data fiduciary to adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained, and to observe due diligence for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law in force in India. An adult, for this rule, is an individual who has completed eighteen years.

The rule then gives the permitted references. The first is reliable details of identity and age of the individual already available with the data fiduciary. The second is details of identity and age voluntarily provided, either by the individual or through a virtual token mapped to such details issued by an authorised entity, an expression that takes in a Digital Locker service provider notified under the Information Technology Act, 2000. Build to those three routes and no others.

Step 4: Keep the Consent Itself to the Statutory Standard

Verifiability is about the parent. The quality of the consent is governed separately by section 6(1), which requires consent that is free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and which signifies agreement to processing limited to the personal data necessary for the specified purpose.

Section 6(4) gives the right to withdraw at any time, with the ease of doing so comparable to the ease with which consent was given, and section 6(6) requires the fiduciary on withdrawal to cease, and to cause its data processors to cease, processing. A parental consent flow that takes three screens to grant and a written request to withdraw does not meet that test.

Step 5: Deal With Lawful Guardians Under Rule 11

Rule 11 covers the parallel case of a person with disability who has a lawful guardian. Where an individual identifies herself as that guardian, the fiduciary must observe due diligence to verify that the guardian is appointed by a court of law, or by a designated authority, or by a local level committee, under the law applicable to guardianship.

The rule ties those terms to specific statutes: a designated authority under section 15 of the Rights of Persons with Disabilities Act, 2016, and a local level committee constituted under section 13 of the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999. The verification is of the appointment, not of the relationship, so the artefact to collect is the order or certificate.

Step 6: Switch Off Tracking and Targeted Advertising

Section 9(3) prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. This is a flat prohibition rather than a consent condition, so parental consent does not cure it. Section 9(2) separately prohibits processing likely to cause any detrimental effect on the well-being of a child.

For a general audience service the engineering consequence is that the advertising and analytics stack has to be capable of running in a reduced mode for an identified subset of users, which is a different problem from suppressing a single banner. Scope that work early, because it is usually the longest item on the list.

Step 7: Check for an Exemption Before You Build the Gate

Rule 12 lifts section 9(1) and (3) for the classes of data fiduciary specified in Part A of the Fourth Schedule and for the purposes specified in Part B, in each case subject to the conditions stated there. Part A covers clinical and mental health establishments and healthcare professionals, allied healthcare professionals, educational institutions, individuals caring for children in a creche or day care centre, and transport service providers, each confined to a stated purpose such as the protection of the child's health or her safety in transit.

The exemptions are purpose bound, not entity bound. A school is relieved of the bar on behavioural monitoring for educational activities and for the safety of enrolled children, and not for anything else. Map each processing activity against the stated purposes before concluding that the gate is unnecessary.

Common Pitfalls to Avoid

  • Describing the obligation as current: Section 9 and rule 10 commence with the eighteen month tranche. An internal note or client advisory that presents them as live law misstates the position.

  • Collecting more than the adult check needs: The references rule 10 permits are identity and age. A full identity document set gathered for a yes or no question is an exposure of its own.

  • Treating the Fourth Schedule as an entity level pass: Part A and Part B both operate subject to conditions tied to specific purposes. Processing outside the stated purpose is outside the exemption.

  • Forgetting that the parent is the data principal: Section 2(j) includes the parents or lawful guardian within the expression. Rights requests and notices have to work for them.

  • Assuming consent cures behavioural monitoring: Section 9(3) is a prohibition. No consent, parental or otherwise, makes tracking or targeted advertising directed at children permissible.

  • Building asymmetric withdrawal: Section 6(4) requires withdrawal to be comparably easy. A one click grant with a written withdrawal fails on the face of the provision.

  • Underweighting the penalty: The Schedule to the Act sets a penalty of up to Rs 200 crore for breach of the obligation in respect of children under section 9.

Key Statutory Provisions

  • Section 2 of the Digital Personal Data Protection Act, 2023: Clause (f) defines a child as an individual who has not completed eighteen years. Clause (j) includes the parents or lawful guardian within the expression data principal.

  • Section 6 of the Act: The standard of consent in sub-section (1), withdrawal with comparable ease in sub-section (4), and the duty in sub-section (6) to cease processing and to cause processors to cease.

  • Section 9 of the Act: Verifiable consent of the parent or lawful guardian before processing, the bar on processing likely to have a detrimental effect on a child's well being, and the bar on tracking, behavioural monitoring and targeted advertising directed at children.

  • Rule 10 of the Digital Personal Data Protection Rules, 2025: The measures and due diligence by which the parent's status as an identifiable adult is checked, and the three permitted references for identity and age.

  • Rule 11 of the Rules: Verification that a lawful guardian is appointed by a court, a designated authority or a local level committee under the applicable guardianship law.

  • Rule 12 and the Fourth Schedule: The classes and purposes for which section 9(1) and (3) do not apply, subject to the conditions specified.

Sources and References


Disclaimer: This article is for informational purposes only and does not constitute legal advice. Readers should consult a qualified legal professional for advice specific to their circumstances.

Comments


bottom of page