EdTech & Gaming9 min readAugust 2026

Section 9 of DPDPA: How EdTech & Gaming Platforms Must Handle Children's Data

Under-18 age threshold, mandatory verifiable parental consent, and absolute bans on tracking. An actionable technical guide for platforms serving minors.

Pooja Deshmukh

Pooja Deshmukh

Privacy Engineer & CIPM • PrivacyOS Global Research Desk

Section 9 of DPDPA: How EdTech & Gaming Platforms Must Handle Children's Data

Why Section 9 is the Strictest Regime in the DPDP Act

Under the DPDP Act 2023, anyone under 18 years of age is legally classified as a child. This is significantly more stringent than the EU GDPR (age 16) or the US COPPA (age 13). There is no tiered age classification: teenagers, college students under 18, and kindergarteners are subject to the same strict protections.

Violations under Section 9 carry penalties up to ₹200 crore, making child data governance a top-tier operational risk.

---

The 3 Non-Negotiable Rules of Section 9

1. Verifiable Parental Consent (VPC)

A simple self-declaration checkbox ("I am 18+") is legally invalid. Platforms must implement verifiable parental consent workflows before ingesting any personal data of a minor. Approved mechanisms include:
  • DigiLocker-based guardian verification
  • SMS/OTP-authenticated parent account linkage
  • Tokenized identity verification via government-backed IDs
  • 2. Absolute Prohibition on Behavioural Tracking & Targeted Ads

    Section 9(3) imposes a complete ban on tracking student/child user behaviour, creating engagement heatmaps, or serving targeted advertisements based on user data. This ban applies even if the parent gives consent.

    3. Ban on Processing Likely to Cause Detrimental Effect

    Platforms cannot process children's data in any manner that could cause physical or psychological harm, algorithmic addiction, or discriminatory outcome.

    ---

    Architectural Checklist for Tech Teams

  • Strip tracking pixels (Meta Pixel, Google Tag Manager) from all pages accessed by minors.
  • Implement purpose-isolated databases for children's learning records.
  • Provide parent-facing self-service DSR portals for instant access and erasure.
  • Tags:#Section 9#EdTech#Parental Consent#Children Privacy
    STAY AHEAD OF DPDPA RULES

    Prepare Your Systems For The 2027 DPBI Enforcement

    Evaluate consent banners, DSR portals, vendor DPAs, and data discovery with an interactive PrivacyOS platform walkthrough.