A founder I spoke with recently runs a coding platform for teenagers. Good product, genuinely useful, thousands of students signed up. However, when I mentioned verifiable parental consent under the DPDP Act, he looked a little blank. “Wait,” he said, “most of my users are 15, 16, 17. Are they even considered children under this law?”
Yes. And that one word — “children” — carries a lot more weight in this law than most businesses realize.
Under DPDP, “Child” Means Anyone Under 18 — Not Under 13
This trips people up constantly, especially if they’ve worked with GDPR before. GDPR sets the digital age of consent as low as 13, depending on the country. In contrast, India’s DPDP Act draws the line differently. It defines a “child” as anyone who hasn’t turned 18 yet.
Think about what that actually covers. A 17-year-old signs up for an online coding course. Similarly, a 16-year-old plays a multiplayer game, and a 15-year-old joins a social app. Indian law treats every one of them as a child. Therefore, you cannot process their personal data without verifiable consent from a parent or lawful guardian first.
Does your platform have users under 18? Most consumer apps in India do, whether they realize it or not. As a result, you can’t quietly skip this requirement.
What “Verifiable” Actually Means Here
This goes further than a simple checkbox. Section 9 of the Act and Rule 10 of the DPDP Rules 2025 set the standard. You can’t just ask “are you over 18?” and trust the answer. Instead, you need to genuinely verify who the parent is, confirm they’re an adult, and establish that they’re actually the parent or lawful guardian of that specific child.
The rules point toward DigiLocker — India’s government-backed digital document wallet — as the go-to verification method. Specifically, DigiLocker verifies the parent’s identity and confirms their relationship to the child through that same trusted channel. Additionally, there’s another route: if a parent already uses the platform themselves, you can rely on their existing verified details when their child signs up separately.
The point is simple. You need a real, traceable record that an actual adult gave consent, not a checkbox someone tapped through in three seconds.
What You’re Not Allowed to Do With Children’s Data
Beyond just collecting consent, the law draws a hard line around certain practices entirely. Platforms cannot:
- Track or behaviourally monitor children
- Profile children based on their activity
- Serve targeted advertising to users under 18
This catches a lot of platforms off guard, especially ad-supported apps and games that have historically relied on behavioural data to drive engagement and revenue. Does your business model depend on tracking what teenage users click, watch, or scroll past? If so, you’ll need to rethink that model under this law.
Are There Any Exceptions?
Yes, a few, and they matter if your business falls into one of these categories. Rule 10 carves out specific exemptions where the strict verifiable-consent requirement doesn’t apply. For instance, healthcare providers don’t need this consent when processing a child’s data purely for medical treatment. Additionally, certain other platform categories, listed under the Act’s schedules, may also qualify for narrower exemptions tied to specific, defined purposes.
That said, lawmakers kept these exemptions deliberately narrow. Most consumer platforms — EdTech, gaming, social apps, e-commerce sites with teenage users — won’t qualify. So don’t assume you do without a proper legal review.
The Deadline You Actually Need to Watch
Here’s the timeline in plain terms. The government notified the DPDP Rules 2025 on 13 November 2025. Meanwhile, full compliance — including the verifiable parental consent framework — needs to be in place by roughly May 2027. That sounds far off. However, it isn’t, once you factor in what actually needs building.
For example, you need a working consent-verification flow, integration with a system like DigiLocker, updated privacy notices, internal processes for parent-linked consent records, and a plan for handling consent withdrawal. None of that gets built in a weekend, and definitely not in the panic of a looming deadline.
What to Actually Do Right Now
If you run a platform with users under 18, here’s where I’d start:
Figure out how many of your users are actually minors. You might be surprised. A lot of platforms assume their user base skews adult and never actually check.
Map out your current age-verification process, honestly. A single checkbox during sign-up won’t hold up anymore. Be honest with yourself about the gap between where you stand and where the law expects you to be.
Start building the consent-verification flow now, not in 2027. DigiLocker integration, consent records, parent-linked accounts — this takes real engineering and legal work together, not a quick patch.
Review your ad and analytics setup. Are you tracking, profiling, or targeting users who might be under 18? If so, stop that practice or restructure it, regardless of the consent question entirely.
Why This Genuinely Matters
Penalties under the DPDP Act can reach up to ₹250 crore for serious violations. Moreover, regulators are expected to scrutinize mishandled children’s data especially closely. But beyond the fine, there’s a trust dimension too. Indeed, parents, investors, and app stores are all paying closer attention to how platforms handle young users’ data. Consequently, getting caught flat-footed on this doesn’t look good for anyone.
Does your platform have users under 18? If you’re not sure where you currently stand, find out now rather than later. I help businesses across Delhi NCR build compliant consent frameworks and review their DPDP Act readiness through my DPDP Act Compliance Consulting services. Need someone handling this on an ongoing basis? Take a look at DPO services as well. Book a free consultation — Advocate Nitin Kumar Vashista, DPDP Act & GDPR Compliance Consultant, Gurgaon.