Section 9 Mandate · High-Stakes Compliance

Children's Data Protection — Section 9 Is Among the Strictest Children's Privacy Laws Globally

Section 9 of the DPDP Act defines a “child” as any individual under 18 years of age — one of the most conservative thresholds globally. GDPR allows Member States to lower consent age to 13. US COPPA applies only to children under 13. India's uniform 18-year threshold means your obligation covers a much larger portion of your user base than most global frameworks.

If your product, platform, or service can be accessed by anyone under 18 — and for most digital services, it can — Section 9 applies to you. The penalty for violations involving children's data reaches ₹200 crore.

PrivacyOS provides the tools to comply: age verification, verifiable parental consent workflows, guardian consent for persons with disabilities, behavioural tracking restrictions, and ad targeting controls — all integrated with your consent management and compliance programme.

· DPDPA Compliance · Trust Assured
FAST TRACK APPLICATION

Apply for DPDPA Assessment

Fill the details to get started with our corporate panel.

Representative PortraitRepresentative PortraitRepresentative PortraitRepresentative Portrait
4.9/5

Trusted by 1,000+ compliance teams

Trusted by leading enterprise and mid-market brands

Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Section 9 Mandates

What Section 9 Requires

Verifiable Parental Consent (Section 9(1))

Before processing any personal data of a child, you must obtain verifiable consent from the child's parent or lawful guardian. The key word is “verifiable” — a child clicking “I am over 18” does not count. A child typing their parent's email address does not count. You must independently confirm that the person giving consent is actually the parent or guardian and that they are identifiable as an adult.

Rule 10 of the DPDP Rules 2025 specifies two verification pathways:

  • Existing verified parent account: If the parent already uses your platform and their identity has been verified, they can authorise the child's account from their own verified account.
  • Independent DigiLocker verification: If the parent is not on your platform, their identity and age must be independently verified via Aadhaar-linked DigiLocker tokens.

Consent must be obtained before any processing begins. A “trust first, verify later” approach — letting children sign up and verifying retroactively — is not compliant under Section 9(1).

Absolute Prohibitions (Section 9(3))

Even with valid parental consent, certain processing activities are categorically prohibited for children's data:

  • Behavioural tracking and monitoring — no tracking children's online behaviour for engagement optimisation
  • Targeted advertising — no ads directed at children based on their personal data or behaviour
  • Profiling — no building profiles of children for any purpose

These prohibitions apply regardless of parental consent. You cannot consent your way out of them.

Guardian Consent for Persons with Disabilities (Rule 11)

Section 9 also covers persons with disability who have a lawful guardian. The consent and verification requirements mirror those for children, with additional verification of the guardianship relationship.

Age Verification Obligation

Before you can apply Section 9 protections, you must first determine whether a user is a child. This requires age-gating mechanisms — not just a date-of-birth field (which children can easily falsify), but reasonable technical measures to identify when a data subject is under 18.

Platform Features

What PrivacyOS Provides

Age Verification Gates

Configurable age verification mechanisms that determine whether a user is a child before any personal data is collected. Multiple verification levels based on your risk tolerance and user experience requirements.

Verifiable Parental Consent Workflows

End-to-end parental consent flows that satisfy Section 9(1) and Rule 10:

  • • Parent identification and age verification (DigiLocker or existing account)
  • • Consent request delivery to the verified parent
  • • Parent review of what data will be collected and for what purposes
  • • Affirmative consent capture with timestamp and verification log
  • • Child account activation only after verified consent is completed

The entire flow is logged for audit evidence.

Tracking and Profiling Restrictions

Automated enforcement of Section 9(3) prohibitions:

  • • Disable behavioural tracking scripts for identified child accounts
  • • Block ad targeting algorithms from using children's data
  • • Prevent profiling engines from processing child records
  • • Flag any processing activity that attempts to use children's data for prohibited purposes

Integration with Consent Management

Children's consent is managed within the same consent management platform as adult consent — but with additional controls, verification steps, and restrictions applied automatically based on age classification.

Industry Scope

Who Must Comply

Any organisation whose digital products or services may be accessed by individuals under 18 in India. This includes:

EdTech platforms

Learning apps, online tutoring, student information systems

Social media

Any platform allowing user-generated content or social interaction

Gaming companies

Mobile games, online gaming platforms, game streaming

E-commerce

Platforms where minors may place orders or create accounts

Content platforms

Video streaming, music apps, content aggregators

Health apps

Fitness trackers, mental health apps used by adolescents

DPDPA SECTION 9 GUARDIAN CONSENT

Avoid ₹200 Cr Penalties on Children's Data Processing

Integrate verifiable parental consent, DigiLocker age token verification, and automated behavioural ad-blocking in minutes.

Frequently Asked Questions

Protect Children's Data Under DPDPA

Safeguard minor data subjects with certified parental verification mechanisms and automated ad-tracking killswitches.