Children's data under DPDP
The DPDP Act treats children's data with stricter rules. Before processing the personal data of a child, you must obtain verifiable consent from a parent or lawful guardian. Tracking, behavioural monitoring, and targeted advertising directed at children are restricted. Breaches involving children's data can draw penalties of up to INR 200 crore.
Why children's consent is harder
If any part of your user base is under the age set by the Act, these rules apply to you, and they are harder to satisfy than adult consent. You have to establish that the person consenting is genuinely the child's parent or guardian, which is a verification problem, not a checkbox.
Two systems required
- 01Age assurance: a way to identify which users are children so the stricter path applies to them.
- 02Verifiable parental consent: a flow that confirms an adult with authority has agreed, and records that confirmation in a way you can prove later.
Restrictions beyond consent
The Act limits tracking and behavioural monitoring of children and restricts advertising targeted at them. For products that rely on engagement features or ad-based models, that changes what you are allowed to build for younger users, not just how you ask permission.
"The honest first step is to find out whether children are in your data at all, because you cannot apply rules you have not realised apply."
Next step
Ready to scope the work?
Book a free 30-minute call. We will map your gaps and tell you exactly what needs building.
Written by Smoketrees Digital LLP, a product engineering studio based in Bengaluru. We implement DPDP compliance directly into codebases for Indian product companies.