Children's data under DPDP: verifiable parental consent
Updated 19 Sep 2026 · 4min read · Reviewed by ConsentLo's DPDP audit team
The DPDP Act treats everyone under 18 as a child and gives them strong protection. If your product might be used by children, these rules apply to you.
The core rules
For children's personal data you must:
- Obtain verifiable consent from a parent or lawful guardian before processing.
- Not process data in a way likely to harm a child's well-being.
- Not track, behaviourally monitor or target advertising at children.
Verifying the parent
The DPDP Rules, 2025 let you verify that the consenting parent is an identifiable adult using reliable details you already hold, or a virtual token from an authorised entity such as DigiLocker. Keep a record of how each verification was done.
Exemptions
Some classes, such as healthcare providers, educational institutions and child-care centres, have limited exemptions for specific purposes like safety and education. They are narrow, so check the Rules for your use case.
Handling it in practice
ConsentLo flags child accounts from age signals, routes consent to a verified guardian, blocks tracking and advertising purposes for those accounts automatically, and records every verification as evidence.
Frequently asked questions
What age is a child under the DPDP Act?
Anyone under 18 years of age.
Can I show targeted ads to teenagers under DPDP?
No. Targeted advertising directed at children, meaning anyone under 18, is not permitted, and neither is tracking or behavioural monitoring.