Compliance Guide

DPDP Children Data Protection Compliance

DPDP Section 9 imposes the strictest rules on processing children's data — verifiable parental conse. Get expert help today.

Discuss this page with an LLM

DPDP Action Sheet

Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.

For DPDP Children Data Protection Compliance, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.

1. Lead Forms

Check:

  • What data are you collecting?
  • Is the purpose clear at the point of collection?
  • Is marketing consent separate from service communication?
  • Can the user withdraw consent later?

Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.

2. Email and WhatsApp

Check:

  • Who is on the list?
  • Where did consent come from?
  • Is the list imported from a vendor, event, webinar, scrape or old CRM?
  • Can you prove the source of consent?

Common mistake: treating every lead as permanently marketable.

3. Ads and Retargeting

Check:

  • Are pixels or ad platforms receiving identifiable user behavior?
  • Are audiences built from customer lists?
  • Are lookalike or remarketing audiences using personal data?

Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.

4. Website Analytics

Check:

  • Which tools run on the site?
  • Are IP address, device identifiers, session IDs or form fields being captured?
  • Is analytics used only for measurement, or also for profiling and targeting?

Common mistake: installing tools first and asking privacy questions later.

5. Vendor List

Make a quick list:

  • CRM
  • Email platform
  • WhatsApp provider
  • Analytics
  • Ad pixels
  • Form tool
  • Landing page builder
  • Webinar tool

For each vendor, answer: what data goes there, why, who can access it and how deletion works.

6. This Week's Action

Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.

If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.

Book a DPDP clarity call

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

The DPDP Act defines any individual under 18 as a child. You cannot rely on a simple “I am over 18” checkbox. You must implement a mechanism to verify that the person providing consent is the actual parent or legal guardian. This involves checking government IDs or using OTP-based verification linked to the parent’s registered mobile number before any child’s data enters your database.

Prohibition on Behavioral Tracking

You are legally barred from tracking a child’s behavior or profiling them for commercial gain. This means your platform cannot use cookies to monitor learning patterns for the purpose of serving targeted advertisements. Any data collected must serve the primary purpose of the service, such as academic grading or health monitoring, rather than building a marketing persona.

WorkflowPersonal Data CollectedDPDP Compliance Risk
EdTech OnboardingGrade, school name, and student IDUnauthorized profiling of minor’s academic performance
School Transport TrackingReal-time GPS coordinates and route historySurveillance risk without specific parental override
Pediatric Health RecordsVaccination dates and growth chartsProcessing health data without a verified guardian link
Online Gaming ChatsVoice recordings and text logsCollection of unsolicited personal identifiers in open fields

Educational platforms face a conflict between “seamless access” and “verifiable consent.” While teachers often sign up entire classes, the DPDP Act requires individual parental consent for each student. Using a “blanket consent” from a school principal does not satisfy the legal requirement for a direct link between the data fiduciary and the legal guardian.

This week

Review your sign-up forms and identify every field that collects a user’s age. If the user is under 18, ensure your system immediately redirects to a parent-only verification screen instead of allowing the child to proceed.

Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?

Frequently asked questions

Is the age of consent 13 or 18 under the DPDP Act?

Unlike international laws like COPPA, the Indian DPDP Act sets the age of a minor at 18. You must obtain verifiable parental consent for any user who has not yet reached their 18th birthday.

Can we use a child's learning data to suggest new courses?

You can suggest courses based on the current curriculum, but you cannot track general browsing habits to serve behavioral ads. Any recommendation engine must be strictly limited to the educational service the parent agreed to.

Do we need to delete a child's data once they turn 18?

You do not need to delete it, but the legal basis for processing changes. Once the user reaches 18, you must seek fresh consent directly from them to continue processing their data as an adult.

Book clarity call