The digital economy has fundamentally transformed how we interact with services, but it has also created unprecedented vulnerabilities, particularly for those least equipped to navigate its complexities. Children scrolling through apps and persons with disabilities accessing essential services, leave behind trails of personal data, often without meaningful understanding or control. India's Digital Personal Data Protection Act, 2023, and the accompanying Rules notified in November 2025, attempt to address this asymmetry by imposing heightened obligations on entities processing such sensitive information.
What emerges from these provisions is not merely a compliance checklist, but a philosophical statement: vulnerability demands structural protection, not just procedural formality.
Beyond Tick-Box Consent: The Architecture of Verifiable Parental Authorization
The distinction between consent and verifiable consent represents the conceptual backbone of child data protection under Section 9(1) of the Act. While ordinary consent might suffice for adult data principals, the legislation recognizes that children lack the legal capacity and cognitive maturity to meaningfully authorize data processing. The responsibility therefore shifts to parents, but with a critical safeguard: Data Fiduciaries cannot simply accept someone's claim to be a parent at face value.
This is where Rule 10 transforms policy into practice. The verification mechanism it establishes operates on two tracks. First, where Data Fiduciaries already possess reliable identity and age details of the parent, perhaps from prior interactions, they may rely on that existing information to confirm adult status. Second, where no such relationship exists, verification must occur through voluntarily provided identity and age details, either submitted directly or transmitted via virtual tokens issued by authorized entities.
The shift from "maintenance" in the draft rules to "issuance" in the final definition of authorized entities is subtle but consequential. It narrows the scope to entities specifically empowered to generate foundational identity credentials - government registrars, authentication authorities, and similar bodies with legal mandates. This tightening reflects a concern with source authenticity: verification is only as reliable as the issuing authority.
What makes this framework operationally feasible is the Digital Locker service provider mechanism. These government-notified intermediaries serve as secure conduits, allowing parents to share verified credentials without repeatedly exposing sensitive documents across multiple platforms. The parent maintains control, the platform receives verification, and document proliferation—with its attendant security risks—is minimized. This triangulated trust model may well become a template for identity verification in other regulatory contexts.
Yet implementation challenges loom. How many platforms have the technical sophistication to integrate with authorized entities and Digital Locker providers? What happens to smaller Data Fiduciaries lacking such infrastructure? The eighteen-month implementation timeline for these provisions (bringing them into force in May 2027) suggests the government recognizes that building this ecosystem requires time. It remains to be seen whether the provided timeline will be adequate.
Disability and Capacity: The Delicate Balance of Autonomy and Protection
Rule 11's treatment of persons with disabilities navigates difficult terrain. Disabilities vary enormously in nature and impact, and the law must protect while respecting autonomy. The key addition in the final rules that guardian consent is required only for individuals who, "despite being provided adequate and appropriate support, [are] unable to take legally binding decisions," acknowledges this complexity.
This formulation respects the principle of supported decision-making enshrined in the Rights of Persons with Disabilities Act, 2016. Not every person with a disability requires a guardian. Indeed, many live independent lives. The requirement triggers only when decision-making capacity is genuinely absent, even with appropriate accommodation. This approach respects the agency and decision-making capacity of people with disabilities.
However, the verification burden on Data Fiduciaries is substantial. Confirming that a guardian has been appointed by a court, designated authority, or local level committee under applicable guardianship law demands access to formal legal documentation and institutional records. Unlike parental relationships, which are easier to establish, legal guardianship requires navigating multiple statutory frameworks - the 2016 Act for certain disabilities, the National Trust Act of 1999 for others. Data Fiduciaries will need clear processes for document verification and record-keeping to demonstrate compliance.
What Cannot Be Done: The Absolute Prohibitions
Section 9 does more than mandate consent; it prohibits entire categories of processing. Tracking and behavioural monitoring of children, barring specific purposes, is forbidden. Targeted advertising directed at minors is impermissible. Any processing likely to cause detrimental effects on child well-being is off-limits. These are not qualified restrictions subject to balancing tests; they are categorical bars.
The implications are far-reaching. Social media platforms that build engagement through algorithmic recommendation based on behavioural tracking must redesign their systems for users under eighteen. Ed-tech companies cannot deploy adaptive learning systems that would otherwise constitute behavioural monitoring. Gaming platforms must forego targeted in-app purchases directed at minor users. The potential penalties, up to two hundred crore rupees under the Schedule, underscore the gravity with which these prohibitions are treated.
However, one can argue that categorical prohibitions create categorical problems. What constitutes "behavioural monitoring" versus legitimate educational assessment? When does personalized content recommendation become impermissible tracking? These definitional boundaries will inevitably require clarification through board guidance and, ultimately, adjudication.
The Safety Exemptions: Pragmatism Within Protection
Recognizing that absolutism can undermine the very interests it seeks to protect, the Fourth Schedule carves out exemptions where verifiable consent requirements and processing prohibitions do not apply. These exemptions are not loopholes - they are carefully bounded authorizations tied to specific purposes and conditions.
Part A identifies five classes of exempt Data Fiduciaries. Clinical establishments, mental health facilities, and healthcare professionals may process children's data to the extent necessary for health protection. Allied healthcare professionals may do so for implementing treatment plans. Educational institutions may engage in tracking and behavioural monitoring for educational activities or student safety. Childcare providers may monitor for safety purposes. Transport service providers engaged by schools may track children's locations during transit.
The common thread is purpose limitation: exemptions are available only when processing serves the child's welfare, and only to the extent necessary for that specific purpose. An educational institution cannot claim the exemption for tracking students beyond campus boundaries or for commercial purposes. A healthcare provider cannot extend health-related data processing to marketing.
Part B's six purpose-based exemptions similarly reflect pragmatic necessities. Government entities may process children's data for statutory functions and benefit delivery. Platforms may create email-only accounts without full parental verification. Systems may block harmful content. Significantly added in the final rules, real-time location tracking is permissible when strictly limited to safety, protection, or security interests.
This location tracking exemption deserves particular attention. It responds to the ubiquity of school bus tracking systems, institutional safety protocols, and parental monitoring applications. Without this clarification, such widely accepted practices might have violated the behavioural monitoring prohibition. By formalizing the exemption while binding it tightly to safety purposes, the rules acknowledge reality without opening floodgates.
Yet scope creep remains a risk. "Safety" and "security" are elastic concepts, stretched to justify surveillance. The burden will fall on the Data Protection Board to police these boundaries and ensure exemptions remain tethered to their protective purposes.
What This Means for Data Protection's Future in India
These provisions signal India's intent to take child and disability data protection seriously, moving beyond aspirational principles to operational specifics. The framework is comprehensive, the obligations substantial, and the penalties meaningful. Whether the execution matches the ambition will depend on three factors: the Data Protection Board's enforcement capacity, the development of supporting infrastructure like Digital Locker integration, and Data Fiduciaries' willingness to invest in genuine compliance rather than cosmetic gestures.
For businesses, particularly technology platforms, the compliance burden is real. Building age verification systems, implementing verifiable consent workflows, redesigning features to eliminate child tracking, and documenting exemption compliance require significant technical and operational investment. The temptation will be to adopt minimal viable compliance or geographic blocking. However, the board’s take on whether to follow an educative or punitive approach in initial enforcement will shape how seriously these obligations are taken.
For children and persons with disabilities, the framework offers meaningful protection, if enforced. The prohibition on exploitative practices like behavioural tracking and targeted advertising addresses genuine harms. The consent requirements ensure parents have gatekeeping authority. The disability provisions respect autonomy while protecting those genuinely unable to self-advocate.
Perhaps most significantly, these rules establish that India's data protection regime will not treat all data principals as interchangeable. Vulnerability creates entitlement to enhanced protection, and the state will impose affirmative obligations to provide it. This principle, once embedded in law and practice, may extend to other vulnerable categories - elderly persons, economically disadvantaged populations, marginalized communities, creating a rights-protective framework that addresses power asymmetries rather than assuming equal bargaining positions.
The architecture is now in place. The test begins in May 2027, when these provisions take effect. Whether India's framework becomes a model or a cautionary tale will depend on implementation, enforcement, and the willingness of all stakeholders to prioritize protection over convenience.
Malcolm Hendricks is a Senior Associate - Public Policy with the Data Security Council of India. Based out of Mumbai, he focuses on the policy and regulatory developments in the domains of Data, Tech & AI ecosystem. He can be reached at : malcolm.hendricks@dsci.in or policy@dsci.in
Author: Malcolm Hendricks