Children’s Data and the DPDP Act: What Parents Should Know
TL;DR: India's DPDP Act sets an unusually high bar for children's data — anyone under 18 requires verifiable parental consent before a platform can process their data at all. Here's what that means in practice, and where the real gaps still are.
👉 See if your data's already leaked — free 30-second check →
India's threshold is stricter than most global laws
Under the DPDP Act, anyone under 18 is classified as a child, requiring verifiable parental or guardian consent before their personal data can be processed. This is notably stricter than comparable laws elsewhere — the US's COPPA sets the bar at 13, and GDPR generally allows 13-16 depending on the EU member state. In practice, this means Indian teenagers who might independently manage their own accounts elsewhere are, under Indian law, meant to have parental consent involved.
What platforms are required to do
Data Fiduciaries must verify whether a user is a child, validate the parent or guardian's identity and that they're not themselves a minor, confirm the legitimacy of the parent-child relationship, and obtain verifiable consent — not just a checkbox, but consent that can genuinely be authenticated. Acceptable verification methods under the rules include government-backed systems like DigiLocker and OTP-based confirmation tied to the parent's registered mobile number.
What's explicitly prohibited
The DPDP Rules specifically prohibit processing children's data in ways that could cause detrimental effects to their wellbeing — including tracking, behavioral monitoring, and targeted advertising directed at minors. This is a meaningful protection on paper, addressing exactly the kind of profiling-for-advertising model that's common on platforms popular with teenagers.
The real-time location tracking exception
One notable carve-out in the finalized rules: platforms are exempt from the standard parental-consent requirement specifically for real-time location tracking done for a child's safety and protection — recognizing that family-safety and location-sharing apps serve a genuinely different purpose than behavioral advertising, and shouldn't be blocked by the same consent friction.
A known gap: verification is harder than it sounds
The requirement for "verifiable" consent sounds solid on paper, but in practice, confirming that a specific adult truly is a specific child's parent, at scale, across millions of users, remains genuinely difficult for platforms to implement reliably. Researchers and privacy advocates have pointed out that parents themselves sometimes help children misrepresent their age to access platforms nominally restricted to adults — meaning the legal framework doesn't fully solve the underlying behavioral pattern it's designed around.
What this means for parents practically
- Be aware that age limits on platforms exist for a real regulatory reason, not just a company preference — bypassing them (even to make a child's experience "easier") sidesteps protections specifically designed for their wellbeing.
- Review privacy settings on any platform your child does legitimately use, since default settings aren't always the most protective option even on platforms that comply with the consent requirements.
- Be thoughtful about "sharenting" — posting photos, school details, or location information about your child on your own accounts creates a digital footprint for them that they had no say in, well before they're old enough to manage their own privacy choices.
- Understand that location-sharing safety apps are a legitimate, separately-regulated category — distinct from general tracking or advertising-driven data collection.
Connecting this to your own exposure as a parent
Much of a child's early digital footprint is actually created by parents — sign-ups, forms, and posts made on their behalf, often using a parent's own phone number or email as the account contact. Checking what's tied to your own phone number and email is a reasonable starting point before extending the same thinking to accounts you manage for a child. Scan My Shadow checks your phone number and email across 1,500+ sources.
FAQs
Is it illegal for my teenager to have a social media account without my consent?
Under the DPDP Act, platforms are meant to require verifiable parental consent before processing a minor's data — in practice, enforcement of this at the individual account level is still developing, and many teens do use accounts platforms are technically required to gate.
Can I request a platform delete data collected about my child without proper consent?
Yes — as a parent or guardian, you can generally exercise correction and erasure rights on your child's behalf, and a lack of proper verifiable consent in the first place strengthens the basis for such a request.
Are educational and gaming apps held to the same standard as social media?
Yes, in principle — the DPDP Act's child-data provisions apply broadly to any Data Fiduciary processing a minor's data, with some additional obligations specifically for higher-risk categories like social media intermediaries.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated
