Verifiable parental consent under DPDP Rules 2025
If your platform can be used by anyone under 18, you must verify a parent's consent before processing their data — and prove you did. Here is what that takes.
Who this applies to
Under the DPDP Act, a "child" is any person under the age of 18 — a notably high bar compared with some other jurisdictions. The moment your service processes the personal data of someone in that age band, the children's-data rules apply. That sweeps in obvious cases like edtech platforms, kids' games, and youth-focused apps, but also any general-audience service that does not screen for age and therefore foreseeably has under-18 users. If you cannot confidently say your user base excludes minors, you should design for the children's-data regime.
What "verifiable" actually demands
Ordinary consent is not enough for children. The Rules require verifiable parental consent, which shifts the responsibility onto the Data Fiduciary to confirm that the person granting consent is in fact the child's parent or lawful guardian — and that the adult is genuinely an adult. Acceptable approaches generally involve verifying a parent's identity and relationship to the child, for instance by sending a one-time password to a parent's registered mobile number, accepting an identity document that establishes the parental relationship, or using a digital signature or government-backed identity check where legally feasible. The method must be reliable enough to stand up to scrutiny, not a token checkbox.
The record you have to keep
Verification is only half the obligation; proving it is the other half. You need a parent-linked consent record that captures which adult consented, when, for which purposes, and how they were verified. This is your audit trail if the Data Protection Board or a parent ever questions whether consent was properly obtained. Build it as structured data from the start — retrofitting a consent ledger after the fact is painful and unreliable.
The hard limits on processing children's data
Beyond consent, the Act places specific guardrails on what you can do with a child's data. You must not undertake processing likely to cause a detrimental effect on a child's wellbeing, and you must not engage in tracking, behavioural monitoring, or targeted advertising directed at children. In practice this means stripping children's accounts out of your behavioural ad and profiling pipelines, and collecting only the data genuinely needed to deliver the service. The Rules do contemplate limited, carefully bounded exemptions for certain situations — for example where delay would harm a child's interests in a clinical context — but these are narrow and not a general escape hatch for commercial platforms.
Withdrawal must be symmetric
A parent who can grant consent in two taps must be able to revoke it just as easily. Asymmetric flows — easy to opt in, buried or manual to opt out — are exactly the pattern the Act is designed to prevent. Plan a withdrawal path that is as visible and frictionless as the consent path, and that propagates: when a parent withdraws, downstream processing and any shared data must stop and be cleaned up.
What to do before May 2027
Start by determining whether your service foreseeably has under-18 users and how you will establish age. Then design a verifiable parental-consent flow, a parent-linked consent ledger, a children's-data processing policy that excludes tracking and behavioural ads, and a symmetric withdrawal mechanism. Because these touch onboarding, identity, data architecture, and advertising at once, they take real engineering time — which is why the platforms most exposed are starting now rather than waiting for the 2027 deadline.
Frequently asked questions
What age counts as a "child" under the DPDP Act?
Anyone under 18. The DPDP Act sets the threshold at 18, so the children's-data rules — including verifiable parental consent and the ban on tracking and targeted advertising — apply to all users below that age, which is a higher bar than in several other data-protection regimes.
How do I verify parental consent in practice?
You must reliably confirm the consenting adult is the child's parent or lawful guardian. Common methods include sending a one-time password to a parent's registered mobile number, accepting an identity document that establishes the relationship, or using a digital signature or government-backed identity verification where legally available. Whatever method you choose, keep a record of who consented, when, for what purposes, and how they were verified.
Can I show targeted ads to under-18 users if I have parental consent?
No. The Act prohibits tracking, behavioural monitoring, and advertising directed at children, and parental consent does not unlock those activities. You must exclude children's accounts from behavioural advertising and profiling, and limit processing to what is needed to deliver the service. Failure to comply with children's-data duties can attract penalties of up to ₹200 crore.
Get your children's-data compliance in shape
Niti Bharat's Children's Data Compliance tool helps edtech, gaming, and app teams assess their verifiable-consent flows, records, and processing limits against the DPDP Rules 2025.
Assess Children's Data Compliance