Before processing the personal data of a child, a Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian. The Act also prohibits processing that is likely to cause any detrimental effect on a child's wellbeing, and restricts tracking, behavioural monitoring and targeted advertising directed at children.
"Verifiable" is the operative word: you must be able to show that the consent came from an adult with authority, not merely that a box was ticked on a form a child could complete.
The first practical step is identifying children's data in your inventory at all. Sectors that hold it without thinking of themselves as child-facing — paediatrics, education, family retail, gaming — are the ones most often caught out.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →