Children's data under DPDP: verifiable parental consent

Updated 19 Sep 2026 · 4min read · Reviewed by ConsentLo's DPDP audit team

The DPDP Act treats everyone under 18 as a child and gives them strong protection. If your product might be used by children, these rules apply to you.

The core rules

For children's personal data you must:

  • Obtain verifiable consent from a parent or lawful guardian before processing.
  • Not process data in a way likely to harm a child's well-being.
  • Not track, behaviourally monitor or target advertising at children.

Verifying the parent

The DPDP Rules, 2025 let you verify that the consenting parent is an identifiable adult using reliable details you already hold, or a virtual token from an authorised entity such as DigiLocker. Keep a record of how each verification was done.

Exemptions

Some classes, such as healthcare providers, educational institutions and child-care centres, have limited exemptions for specific purposes like safety and education. They are narrow, so check the Rules for your use case.

Handling it in practice

ConsentLo flags child accounts from age signals, routes consent to a verified guardian, blocks tracking and advertising purposes for those accounts automatically, and records every verification as evidence.

Frequently asked questions

What age is a child under the DPDP Act?

Anyone under 18 years of age.

Can I show targeted ads to teenagers under DPDP?

No. Targeted advertising directed at children, meaning anyone under 18, is not permitted, and neither is tracking or behavioural monitoring.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.