THE RULES

Rule 10 - Verifiable consent for processing of personal data of a child

Official text

(1)A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to—

(a)reliable details of identity and age of the individual available with the Data Fiduciary; or

(b)details of identity and age, voluntarily provided —

(i)by the individual; or

(ii)through a virtual token mapped to such details, which is issued by an authorised entity.

(2)In this rule, the expression—

(a)“adult” shall mean an individual who has completed the age of eighteen years;

(b)“authorised entity" shall mean —

(i)an entity entrusted by law or by the Central Government or by the State Government with the issuance of details of the identity and age or a virtual token mapped to such details; or

(ii)a person appointed or permitted by the entity specified under clause (i), for such issuance, and also includes details of identity and age or token made available and verified by a Digital Locker service provider;

(c)“Digital Locker service provider” shall mean such intermediary, including a body corporate or an agency of the appropriate Government, as may be notified by the Central Government, in accordance with the rules made in this regard under the Information Technology Act, 2000 (21 of 2000);

Illustration.C is a child, P is a parent, and DF is a Data Fiduciary. A user account of C is sought to be created on the online platform of DF, by processing the personal data of C.

Case 1: C informs DF that she is a child and declares P as her parent. DF shall enable P to identify herself through its website, app or other appropriate means. P identifies herself as the parent and informs DF that she is a registered user on DF’s platform and has previously made available her identity and age details to DF. Before processing C’s personal data for the creation of her user account, DF shall check to confirm that it holds reliable identity and age details of P and that P is an identifiable adult.

Case 2: C informs DF that she is a child and declares P as her parent. DF shall enable P to identify herself through its website, app or other appropriate means. P identifies herself as the parent and informs DF that she herself is not a registered user on DF’s platform. Before processing C’s personal data for the creation of her user account, DF shall, by reference to identity and age details issued by an entity entrusted by law or the Government with maintenance of the said details or to a virtual token mapped to the identity and age, check that P is an identifiable adult. P may voluntarily make such details available using the services of a Digital Locker service provider.

Case 3: P is opening an account for C and identifies herself as C’s parent and informs DF that she is a registered user on DF’s platform and has previously made available her identity and age details to DF. Before processing C’s personal data for the creation of her user account, DF shall check to confirm that it holds reliable identity and age details of P and that P is an identifiable adult.

Case 4: P is opening an account for C and identifies herself as C’s parent and informs DF that she herself is not a registered user on DF’s platform. Before processing C’s personal data for the creation of her user account, DF shall, by reference to identity and age details issued by an entity entrusted by law or the Government with maintenance of the said details or to a virtual token mapped to the identity and age, check that P is an identifiable adult. P may voluntarily make such details available using the services of a Digital Locker service provider.

Cross-references

Rule 10

Commentary

Rule 10 establishes the process by which a Data Fiduciary must obtain and verify parental consent before processing a child’s personal data. It is not a general age-verification rule requiring every person on the internet to submit an identity document. Nor is it satisfied merely because someone claiming to be a parent clicks an approval button.

The Rule requires the Data Fiduciary to design a process that gives reasonable assurance that the person consenting is an identifiable adult acting as the child’s parent or lawful guardian. This obligation must be read together with Section 9, which establishes the substantive protections for children, and Rule 11 read with the Fourth Schedule, which creates carefully limited exemptions for specified Data Fiduciaries and purposes.

The correct legal position is therefore not that parental verification applies identically to every processing operation involving a child. The first question is whether Rule 11 and the Fourth Schedule exempt the particular processing from Section 9(1), Section 9(3), or both. If no exemption applies, Rule 10 governs the process for obtaining verifiable parental consent. If an exemption applies, it operates only within its stated class, purpose and necessity condition. Processing outside those boundaries remains subject to the ordinary requirements.

The final Rules were notified on 13 November 2025. Rules 10 and 11 are scheduled to commence eighteen months after publication, on 13 May 2027.

Section 9 creates three principal protections for children’s personal data.

First, under Section 9(1), a Data Fiduciary must obtain verifiable consent of the parent before processing a child’s personal data.

Second, under Section 9(2), the Data Fiduciary must not undertake processing likely to cause a detrimental effect on the child’s well-being.

Third, under Section 9(3), the Data Fiduciary must not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

Rule 10 operationalises Section 9(1). It explains how the Data Fiduciary must verify the adult giving parental consent.

Rule 11 and the Fourth Schedule operate differently. They identify limited circumstances in which specified Data Fiduciaries or specified purposes are exempt from Section 9(1), Section 9(3), or both.

A crucial distinction follows:

The Fourth Schedule refers only to exemptions from Section 9(1) and Section 9(3). It does not provide an exemption from Section 9(2).

Accordingly, even where parental consent is not required for a Schedule-covered processing operation, or where particular tracking or behavioural monitoring is permitted, the Data Fiduciary must still ensure that the processing is not likely to cause a detrimental effect on the child’s well-being.

Example

For example, an educational institution may conduct tracking or behavioural monitoring for educational activities or child safety within the conditions of Part A. That does not permit harmful, humiliating, coercive, discriminatory or otherwise detrimental monitoring.

The statutory protection of the child’s well-being remains a continuing outer boundary.

Where no exemption applies, a Data Fiduciary must obtain verifiable parental consent before processing any personal data of a child.

This means the compliance sequence must ordinarily be:

  1. determine that the proposed user is, or may be, a child;

  2. restrict pre-consent processing to what is reasonably necessary to conduct the parental-consent process;

  3. provide the parent with the required notice;

  4. explain the child’s personal data, purposes and services or uses enabled;

  5. obtain a clear affirmative consent decision;

  6. verify that the person giving consent is an adult;

  7. ensure that the adult is identifiable if required for legal compliance;

  8. exercise appropriate due diligence concerning the person’s claimed parental or guardian status;

  9. record the verification and consent evidence; and

  10. only then begin the consent-based processing of the child’s data.

The verification process and the consent process perform different functions.

Verification answers:

Is the person giving consent an identifiable adult?

Consent answers:

Has that adult been properly informed and voluntarily agreed to the specified processing of the child’s personal data?

An adult may be successfully verified but the consent may still be invalid because the notice was unclear, the purposes were bundled or no affirmative choice was obtained. Likewise, the consent interface may be clear, but Rule 10 may still be violated if the Data Fiduciary did nothing meaningful to establish that the person clicking “I agree” was an adult.

3. What Rule 10 is designed to prevent

A child-consent process is ineffective if it can be bypassed through obvious and foreseeable methods.

Rule 10 is intended to prevent situations such as:

  • a child entering a false date of birth;

  • a child creating a second email address and describing it as a parent’s address;

  • another child clicking the parental-consent link;

  • an unrelated adult approving the account without meaningful checking;

  • use of a screenshot or copied token belonging to another person;

  • reliance on an unverified assertion that the user is over eighteen;

  • or processing beginning while parental verification is still pending.

The obligation to adopt appropriate technical and organisational measures means the Data Fiduciary must consider how its actual users interact with the service. A system should not be judged only by what its policy says. It should be judged by whether the verification flow provides reasonable assurance in practice.

3.1 Illustration: Self-declaration on a child-oriented platform

A gaming platform is marketed to teenagers. During registration, it asks users to enter a date of birth. If the user selects an age below eighteen, a parental-consent screen appears. If the user selects nineteen, the account opens immediately.

Most teenage users learn that selecting nineteen bypasses the parental path. The platform conducts no further age assurance.

In this context, the Data Fiduciary may have difficulty showing that it adopted appropriate measures. The service is likely to be used by children, and the verification mechanism is easily and predictably avoided.

This does not mean every platform must demand government identity documents from every user. It means the strength and design of age assurance must correspond to the service, audience and consequences of treating a child as an adult.

4. Verification using information already held by the Data Fiduciary

Rule 10 permits a Data Fiduciary to rely on reliable identity and age details already available to it.

This route avoids repeated collection of identity documents from an adult whose identity and age have already been verified through a reliable process.

4.1 Illustration: Existing verified customer

A bank has previously verified an adult customer’s identity and age under applicable customer-identification requirements. The customer later seeks to open an eligible service or account for her child.

The bank may use the verified details already associated with the adult’s authenticated account to confirm that she is over eighteen and identifiable. It does not necessarily need to collect the same identity document again.

The bank must still:

  • securely authenticate the adult;

  • provide the child-data notice;

  • explain the purposes of processing;

  • obtain an affirmative parental-consent decision;

  • and retain evidence connecting that decision with the verified adult account.

Existing verification of adulthood does not amount to automatic consent for the child’s processing.

4.2 Reliability is more than database availability

The fact that information exists in the Data Fiduciary’s database does not make it reliable.

An unverified date of birth entered several years earlier for a newsletter subscription may be insufficient. A verified identity record obtained through a legally recognised process may provide considerably stronger assurance.

The Data Fiduciary should consider:

  • how the details were obtained;

  • whether the issuing or verifying source was reliable;

  • whether the details were actually verified;

  • whether conflicting information exists;

  • whether the account is securely authenticated;

  • and whether the information remains connected to the adult now giving consent.

4.3 Illustration: Shared family account

A streaming service holds verified age information for the account owner, but the account password is shared among family members. A person using the account approves creation of a child profile.

The platform should not assume that the approving person is necessarily the verified adult merely because the session is connected to that account. Re-authentication through an adult-controlled channel may be appropriate before the consent is recorded.

5. Verification through voluntarily provided details or a virtual token

If the adult is not already a verified user, Rule 10 permits identity and age details to be provided voluntarily:

  • directly by the individual; or

  • through a virtual token mapped to those details and issued by an authorised entity.

This creates flexibility. A Data Fiduciary need not build a single document-upload system for every person. It may accept reliable identity-and-age confirmation from an authorised source.

The verification process should follow data minimisation. The Data Fiduciary needs enough information to establish adulthood and identifiability. It should not collect every available detail merely because an identity document contains it.

5.1 Illustration: Full identity document versus age token

An educational application needs to establish that the person consenting is an adult.

One design requires the parent to upload a complete identity document. The platform stores the parent’s image, full address, complete identification number, date of birth and other details.

Another design uses a token from an authorised entity that confirms that the person has completed eighteen years and is linked to a verified identity. The application stores the verification reference, date, outcome and consent record.

If the token provides sufficient assurance, the second design may satisfy the Rule while creating less privacy and security risk. Rule 10 should not be used to justify unnecessary creation of large repositories of parental identity documents.

6. Function of the virtual token

A virtual token allows the underlying identity and age details to be verified without necessarily disclosing all of those details to the Data Fiduciary.

The token should allow the Data Fiduciary to establish that:

  • the issuer is an authorised entity;

  • the identity information has been verified;

  • the person is an adult;

  • the token is valid and authentic;

  • the token relates to the adult participating in the consent process;

  • and the verification can be evidenced later if legally required.

The token should not be treated as a transferable parental-consent coupon. It verifies the adult’s identity and age. The adult must still receive the notice and make the consent decision for the specific child and processing purpose.

6.1 Illustration: Token reuse by a child

A child obtains a screenshot of an adult’s age-verification token from an earlier transaction and uploads it during registration.

A screenshot does not establish that:

  • the token is genuine;

  • it remains valid;

  • it belongs to the person now consenting;

  • or the adult approved this child’s processing.

The Data Fiduciary should validate the token through the authorised verification mechanism and bind the verification to the present consent session.

7. Authorised entities and Digital Locker verification

An authorised entity is an entity entrusted by law, the Central Government or a State Government with issuing identity and age details or a token mapped to those details. It also includes a person appointed or permitted by such an entity for that issuance.

Rule 10 also recognises identity and age information or tokens made available and verified through a Digital Locker service provider.

The Digital Locker framework permits authenticated electronic documents and document references to be made available digitally under the Information Technology Act framework. Its use under Rule 10 is a recognised method of providing verified information, not an unrestricted gateway into the adult’s account or documents.

Where a parent uses Digital Locker, the Data Fiduciary should request access only to:

  • the relevant identity-and-age confirmation;

  • a suitable document selected by the parent; or

  • the required verification token.

Approval to verify adulthood does not authorise access to unrelated:

  • educational records;

  • financial documents;

  • health records;

  • tax records;

  • certificates;

  • or other materials held in the locker.

Nor does Rule 10 make Digital Locker the exclusive route. Another method may be used if it falls within the Rule and provides appropriate assurance.

8. Due diligence concerning parental status

Rule 10 expressly requires the Data Fiduciary to check that the individual identifying herself as the parent is an identifiable adult. That is not the same as conclusively proving the complete legal parent-child relationship in every situation.

Nevertheless, Section 9 requires consent of the parent, not consent of any adult. Age verification cannot therefore be treated as the only relevant question.

The Data Fiduciary should apply due diligence proportionate to the processing risk.

For ordinary, low-risk services, a verified adult declaration linked to the child account may provide reasonable assurance. For higher-risk services, stronger evidence or additional checking may be appropriate.

Higher-risk circumstances may include services that:

  • publish a child’s profile or images;

  • enable communication with strangers;

  • process health information;

  • collect precise location;

  • use biometric identifiers;

  • permit significant spending;

  • make consequential educational decisions;

  • or expose the child to potentially harmful content.

8.1 Illustration: Low-risk educational resource

A parent seeks to create a limited account allowing a child to receive lesson materials by email. The account has no public profile, social communication, behavioural advertising, location tracking or payment function.

A proportionate process may rely on verified adulthood, an authenticated declaration of parental status and specific consent.

8.2 Illustration: Social communication platform

A platform permits children to publish photographs, communicate with unknown users and share live location.

A bare adult declaration may provide insufficient assurance considering the consequences of false approval. The Data Fiduciary may need stronger authentication and relationship-checking controls.

The Rule does not prescribe one universal evidentiary standard. It requires a defensible relationship between the risk and the verification method.

9. Rule 10 does not permit excessive collection of parental data

The parental-verification exercise creates a separate processing operation involving the adult’s personal data.

The Data Fiduciary should identify:

  • what parental information is necessary;

  • why it is necessary;

  • how it will be used;

  • how long it will be retained;

  • who can access it;

  • whether an identity token can replace a full document;

  • and when the information will be erased.

Information supplied to verify the adult must not automatically be used for:

  • marketing;

  • household profiling;

  • advertising;

  • account enrichment;

  • unrelated identity services;

  • or commercial data matching.

9.1 Illustration: Marketing to the parent

A parent provides identity and contact information solely to approve a child’s educational account. The platform adds the parent to a database for offers from education-loan providers and coaching businesses.

Parental verification does not by itself provide a lawful basis for this separate commercial use.

The Data Fiduciary should also avoid retaining complete identity documents where a limited verification record would provide sufficient evidence. A compliant system should not solve the child-consent problem by creating an unnecessary repository of high-risk adult identity data.

Rule 10 does not establish a weaker form of consent for children’s processing.

The parent must receive a notice meeting Section 5 and Rule 3. The consent must satisfy Section 6 by being:

  • free;

  • specific;

  • informed;

  • unconditional;

  • unambiguous;

  • expressed through clear affirmative action;

  • and limited to personal data necessary for the specified purpose.

The parent should be told, in understandable language:

  • what personal data of the child will be processed;

  • why it is required;

  • what service or use it enables;

  • whether a purpose is optional;

  • whether information will be shared;

  • how consent may be withdrawn;

  • and how rights and grievances may be pursued.

Verification proves that the decision came from an adult. It does not prove that the decision was informed.

10.1 Illustration: Bundled consent

A learning platform presents one acceptance covering:

  • account creation;

  • classes;

  • continuous session recording;

  • behavioural profiling;

  • targeted commercial offers;

  • location tracking;

  • and use of assignments to train a commercial AI product.

The parent’s identity and age are verified, and the parent clicks “Accept.”

The adult verification may comply with part of Rule 10, but the consent architecture remains legally defective if distinct purposes are bundled, unnecessary personal data is requested or prohibited child-related processing is included.

A verified adult cannot consent around the substantive restrictions of Section 9.

Rule 10 requires consent before processing the child’s personal data. Yet some limited processing may be unavoidable to determine that the user is a child and to begin the parental flow.

The correct approach is to restrict pre-consent processing to what is reasonably necessary for:

  • age-status determination;

  • initiating parental verification;

  • securing the verification process;

  • preventing fraud or circumvention;

  • and abandoning incomplete registrations.

The Data Fiduciary should not treat a “pending parental approval” account as permission to begin full processing.

11.1 Illustration: Pending gaming account

A child supplies age information and the parent’s contact route. The account remains pending.

Before parental approval, the platform should not:

  • publish the child’s profile;

  • activate social messaging;

  • collect a contact list;

  • track precise location;

  • build behavioural profiles;

  • serve targeted advertising;

  • or send the child’s activity into an AI-training system.

Only the minimum information needed to complete or terminate the verification process should be processed, subject to an appropriately short retention period.

12. The four Rule 10 illustrations

The four illustrations describe two practical questions:

  1. Did the child or the parent initiate the account creation?

  2. Does the Data Fiduciary already hold reliable information about the parent?

They are not four materially different legal standards.

12.1 Where the child initiates registration

The child identifies the parent. The Data Fiduciary must move the consent process to the parent through its website, app or another appropriate method.

If the parent is already a verified user, the Data Fiduciary may check its reliable existing details.

If the parent is not an existing user, the Data Fiduciary may verify identity and age through voluntarily supplied details or an authorised token, including through Digital Locker where used.

12.2 Where the parent initiates registration

The parent directly creates the account for the child.

The same verification obligation applies. The Data Fiduciary cannot assume adulthood or identity simply because the user selected “I am the parent.”

Existing reliable details may be used for a registered parent. A new parent may use an authorised verification route.

In every case, the Data Fiduciary must complete the relevant verification and obtain specific informed consent before commencing the child’s consent-based processing.

13. Rule 11 and the Fourth Schedule

Rule 11 qualifies the application of Section 9(1) and Section 9(3). The Fourth Schedule contains two kinds of exemptions:

  • Part A identifies particular classes of Data Fiduciaries and permits limited processing by them subject to stated conditions.

  • Part B identifies particular purposes for which limited processing may occur subject to stated conditions.

These are conditional exemptions. They are not status-based immunity from the DPDPA.

A Data Fiduciary relying on the Fourth Schedule should be able to show:

  1. the processing falls within a listed class or purpose;

  2. the stated condition is satisfied;

  3. the data processed is necessary for that limited activity;

  4. the exemption is invoked only for the relevant processing operation;

  5. Section 9(2) remains satisfied;

  6. all other applicable DPDPA duties continue; and

  7. processing outside the exemption is separately assessed.

The Schedule should be applied operation by operation. A hospital, school or childcare centre is not exempt for everything it does merely because it belongs to a listed class.

Part A covers clinical establishments, mental health establishments, healthcare professionals and allied healthcare professionals, subject to narrow conditions.

A clinical establishment, mental health establishment or healthcare professional receives the relevant exemption only where processing is restricted to providing health services to the child and is necessary for protecting her health.

An allied healthcare professional is covered only where the processing supports implementation of a healthcare treatment and referral plan recommended for the child and is necessary for protecting her health.

The exemptions recognise that requiring a complete parental-verification process before every urgent or clinically necessary operation could obstruct healthcare. A healthcare provider may need to process information immediately for diagnosis, treatment, safety or continuity of care.

The exemption, however, follows the healthcare purpose and necessity condition. It does not attach to every activity conducted by the healthcare organisation.

14.1 Illustration: Emergency treatment

An unconscious child is brought to a hospital after an accident. The hospital processes:

  • identity information where available;

  • injuries;

  • medical history;

  • diagnostic results;

  • allergy information;

  • and treatment records.

The processing is necessary to protect the child’s health. Insisting that the hospital complete an ordinary online parental-verification workflow before taking clinical action would undermine the purpose of the exemption.

Section 9(2) still applies. The hospital must not process the information in a way likely to harm the child’s well-being, and the other applicable obligations concerning security, accuracy, retention and lawful processing remain.

14.2 Illustration: Hospital marketing

The same hospital later uses the child’s treatment history to send targeted advertisements for commercial wellness packages or shares the information with an advertising platform.

That activity is not protected merely because the hospital is a clinical establishment. It is not processing restricted to health services necessary for protecting the child’s health.

The processing must be assessed under the ordinary DPDPA framework, including the child protections in Section 9.

14.3 Illustration: Allied professional

A physiotherapist implements a rehabilitation plan recommended for a child after surgery. The physiotherapist processes mobility assessments and treatment progress necessary to implement that plan.

The allied-health exemption may apply within that treatment-support purpose.

If the physiotherapist then uses videos of the child’s therapy sessions for public promotion or commercial AI training, that separate use falls outside the limited condition.

15. Educational institutions

The educational-institution exemption is specifically directed at tracking and behavioural monitoring undertaken:

  • for the educational activities of the institution; or

  • in the interests of the safety of children enrolled with it.

It does not provide a general exemption from parental consent for every category of processing undertaken by a school, college, vocational institution or other institution of learning.

Its principal effect is to qualify the Section 9(3) prohibition where monitoring is genuinely connected with education or safety and remains within the stated condition.

15.1 Illustration: Academic progress monitoring

A school’s digital learning system records:

  • assignment completion;

  • attendance in online classes;

  • test progress;

  • and participation in learning modules.

The information is used by teachers to support educational activities and identify students who need academic assistance.

Such monitoring may fall within the educational-activity limb, provided it is restricted to that purpose and implemented proportionately.

The school should not infer from the exemption that it may use the same behavioural information for:

  • commercial advertising;

  • sale to coaching businesses;

  • unrelated personality profiling;

  • prediction of family income;

  • or public ranking and humiliation.

15.2 Illustration: Safety monitoring

A school uses access cards to record when children enter and leave the campus. It uses CCTV in appropriate areas to protect children and investigate safety incidents.

The processing may fall within the safety condition where it is genuinely directed at the safety of enrolled children.

This does not automatically justify:

  • cameras in highly private locations;

  • indefinite retention;

  • public facial-recognition databases;

  • continuous monitoring outside the educational setting;

  • or use of footage for promotional materials.

15.3 Illustration: Commercial edtech provider

A private edtech company supplies an analytics platform to a school.

The company does not automatically become an “educational institution” simply because its customer is a school. Its legal role depends on the actual arrangement.

If it processes information only on the school’s instructions as a Data Processor, the school remains responsible for the processing. If the provider independently uses student data to train its commercial models, advertise products or build cross-school profiles, it may be determining its own purpose and cannot rely casually on the school’s educational exemption.

15.4 Educational activity must remain genuine

The expression “educational activities” should not be interpreted as covering everything a school finds administratively or commercially useful.

A direct and credible connection should exist between the monitoring and:

  • teaching;

  • learning;

  • academic participation;

  • course delivery;

  • educational assessment;

  • student support;

  • or another genuine educational function.

Even then, necessity and proportionality remain relevant. Continuous surveillance should not be used where a less intrusive method can adequately support the educational objective.

16. Crèches and child day-care centres

The Fourth Schedule permits limited tracking and behavioural monitoring where infants and children are entrusted to the care of an individual, crèche or child day-care centre, and the processing is undertaken in the interests of their safety.

The exemption reflects the responsibility of caregivers to supervise children who may not be able to report danger, leave the premises safely or communicate their needs.

16.1 Illustration: Attendance and authorised pickup

A day-care centre records:

  • arrival;

  • departure;

  • authorised pickup person;

  • movement between supervised areas;

  • and safety incidents.

This processing may be justified as safety-related monitoring.

The exemption does not automatically permit the centre to:

  • sell behavioural observations to advertisers;

  • build long-term commercial profiles;

  • share live video publicly;

  • retain footage indefinitely;

  • or use children’s images in promotional material.

16.2 Illustration: Live parent-feed cameras

A crèche offers parents live access to classroom cameras.

The safety exemption does not automatically settle whether unrestricted or continuously accessible live feeds are appropriate. The system could expose other children and caregivers, permit unauthorised viewing and create substantial security risk.

The crèche would need to assess:

  • whether the feed is necessary for safety;

  • who can access it;

  • whether less intrusive alternatives exist;

  • whether other children are visible;

  • what security measures apply;

  • and how recordings, if any, are retained.

Being safety-related in a general sense is not enough. The particular processing must remain restricted to what is necessary for child safety.

17. Transport providers engaged by educational and childcare institutions

A transport provider engaged by an educational institution, crèche or child-care centre may track the location of enrolled children during travel to and from that institution, where the tracking is in the interests of their safety.

This exemption is tightly bounded by:

  • the identity of the engaging institution;

  • the transport function;

  • the safety purpose;

  • the child’s journey to or from the institution;

  • and location tracking necessary during that travel.

17.1 Illustration: School-bus tracking

A school engages a bus operator. GPS is used to:

  • show the bus route;

  • alert the school and parent to delays;

  • confirm pickup and drop-off;

  • locate the bus during an emergency;

  • and ensure children reach the correct destination.

This may fall within the exemption.

The operator should not use the location information to:

  • build movement profiles outside the journey;

  • track the child on weekends;

  • advertise nearby businesses;

  • monitor the family’s general location;

  • or retain route-level personal information indefinitely.

17.2 Illustration: Personal device location

A transport provider installs an application that continuously tracks the child’s personal phone, including after the child leaves the bus.

That processing exceeds the natural boundaries of location tracking during travel to and from the institution. The exemption is not a general authority to monitor the child’s location throughout the day.

18. Exercise of powers and duties under law

Part B exempts processing undertaken for the exercise of a power, performance of a function or discharge of a duty in the interests of a child under Indian law, provided the processing is restricted to what is necessary.

This provision may apply where public authorities, courts, statutory bodies or persons exercising legally assigned functions must process a child’s personal data to protect the child or fulfil a child-centred legal responsibility.

18.1 Illustration: Child-protection authority

A legally authorised child-protection authority processes:

  • identity information;

  • care history;

  • family information;

  • school information;

  • and safety reports to investigate and protect a child believed to be at risk.

The processing may proceed without the ordinary parental-consent requirement where it is necessary for the statutory function.

This is particularly important where the parent may be:

  • unavailable;

  • the subject of the investigation;

  • acting against the child’s interests;

  • or unable lawfully to provide the relevant decision.

The exemption cannot be used for processing unrelated to the legally assigned function. Nor does it remove the continuing prohibition against processing likely to cause a detrimental effect on the child’s well-being.

19. Subsidies, benefits, services, certificates, licences and permits

Part B also covers processing necessary to provide or issue a subsidy, benefit, service, certificate, licence or permit under law, policy or public funding in the interests of a child under Section 7(b).

This must be read with Rule 5 and the Second Schedule.

19.1 Illustration: Child scholarship

A State authority processes a child’s:

  • identity;

  • age;

  • educational enrolment;

  • academic record;

  • household eligibility information;

  • and bank-related disbursement data to assess and provide a scholarship.

Where the processing falls within Section 7(b) and is necessary for providing the benefit, the parental-consent requirement may not apply within the scope of the exemption.

The authority must still comply with the applicable standards concerning:

  • lawfulness;

  • necessity;

  • accuracy;

  • retention;

  • security;

  • intimation;

  • rights access;

  • and accountability.

The exemption is not authority to repurpose scholarship data for commercial advertising or unrelated profiling.

19.2 Parent acting against the child’s interest

The exemption may be especially important where a child-centred public benefit should not depend entirely on a parent’s willingness or ability to complete a commercial-style consent flow.

Example

For example, a parent’s refusal to participate should not necessarily prevent a legally entitled child from receiving a protective service where the State has independent statutory authority to process the necessary data in the child’s interests.

20. Creation of an email account

Part B creates an exemption for processing necessary to create a user account used only for communication by email.

This is a narrow functional exemption. It is not a general exemption for every application that happens to require an email address.

The processing must be restricted to what is necessary to:

  • create the email account;

  • operate the account;

  • secure it;

  • and enable email communication.

20.1 Illustration: Basic child email account

A service creates a limited email account for a child. It processes:

  • account identifier;

  • credentials;

  • address-book information entered by the user;

  • message-routing data;

  • and security information necessary for email operation.

The exemption may apply to the account-creation purpose and email communication.

It does not automatically permit:

  • behavioural advertising;

  • cross-service tracking;

  • analysis of message content for unrelated commercial profiling;

  • social-media features;

  • gaming;

  • location tracking;

  • or building targeted advertising profiles.

If the account expands into a broader social, entertainment or advertising service, the additional processing must be assessed separately.

21. Protecting children from harmful information

Part B permits processing necessary to ensure that information likely to cause a detrimental effect on a child’s well-being is not accessible to the child.

This allows measures such as age assurance, content classification, safety filtering and access restriction where the purpose is to protect the child from harmful information.

21.1 Illustration: Age-gated content

A platform hosts general content and a restricted area containing material unsuitable for children. It carries out a proportionate age check to prevent child access to the restricted area.

The processing may fall within the exemption where it is limited to the protective purpose.

The platform should not use the age-check data to:

  • create advertising profiles;

  • infer unrelated personal characteristics;

  • disclose identity information to content partners;

  • or track the individual across unrelated services.

21.2 Avoiding the verification paradox

Without this exemption, a Data Fiduciary could face a circular problem:

  • it needs to process age-related information to determine whether the user is a child;

  • but it cannot know whether parental consent is required until it performs that processing.

Part B resolves this problem by allowing the limited processing necessary to confirm age or prevent harmful content access.

22. Processing to confirm that a person is not a child

Part B expressly exempts processing carried out to confirm that the Data Principal is not a child and to perform due diligence under Rule 10.

This provision supports the basic functioning of age assurance.

It means the Data Fiduciary may process the limited identity, age or token information necessary to determine whether:

  • the user is an adult; or

  • the person claiming to be the parent is an identifiable adult.

The exemption is restricted to confirmation and due diligence. It does not become a general legal basis for storing complete identity documents or using them for unrelated commercial purposes.

22.1 Illustration: Adult user confirmed

A user supplies a verified token confirming that she has completed eighteen years. The Data Fiduciary records the outcome and a verification reference.

Once the user is confirmed as an adult, the Data Fiduciary should not retain or use additional age-verification information beyond what is justified by:

  • proof of compliance;

  • fraud prevention;

  • security;

  • or another applicable law.

The exemption should not become a mechanism for identity enrichment.

23. What the Fourth Schedule does not exempt

The Fourth Schedule does not exempt the listed Data Fiduciaries or purposes from the entire DPDPA.

Unless another provision applies, they remain subject to obligations concerning:

  • lawful processing;

  • purpose limitation;

  • valid consent where consent remains required;

  • notice where applicable;

  • data accuracy;

  • reasonable security safeguards;

  • breach intimation;

  • erasure and retention;

  • Data Principal rights;

  • grievance redressal;

  • Processor responsibility;

  • and accountability.

Most importantly, the Schedule does not remove Section 9(2). Harmful processing remains prohibited.

23.1 Illustration: Technically exempt but harmful monitoring

A school uses behavioural monitoring software during educational activities. The software continuously assigns students “obedience scores,” publicly ranks them and automatically labels children as disruptive based on facial movements.

Even if the processing is connected with educational activity, the school must separately consider whether the system is likely to cause a detrimental effect on the child’s well-being.

The educational exemption does not shield harmful implementation.

24. Processing must remain within the exemption

A single system may conduct both exempt and non-exempt processing.

Example

For example, a school application may:

  • track class attendance for education;

  • monitor bus location for safety;

  • create advertising profiles;

  • analyse social interactions for commercial product development;

  • and share student data with third-party advertisers.

The first two functions may potentially fall within the Fourth Schedule if their conditions are met. The remaining functions do not become exempt merely because they operate through the same application.

The Data Fiduciary must separate:

  • purposes;

  • data fields;

  • access permissions;

  • retention periods;

  • legal grounds;

  • and Processor instructions.

A broad label such as “student experience” cannot merge educational safety processing with unrelated commercial uses.

25. Withdrawal, transition and change of purpose

Where parental consent remains the legal basis, the parent must be able to withdraw it with ease comparable to that with which it was given.

When withdrawal occurs, the Data Fiduciary must stop the relevant consent-based processing within a reasonable time and cause its Data Processors to stop, unless another legal basis supports continued processing.

If a Fourth Schedule exemption independently applies to a limited operation, withdrawal of consent may not necessarily stop that operation. For example, a school may continue safety-related bus tracking during the child’s journey where the Schedule lawfully permits the processing.

The Data Fiduciary must explain this distinction accurately. It should not claim that parental consent is the basis while later arguing that withdrawal has no effect because the processing was actually exempt.

Illustration

A parent withdraws consent for an educational application’s commercial analytics. The school continues recording attendance required for educational activities and safety.

The organisation should separate:

  • optional commercial analytics, which should stop if consent was its basis; and

  • limited educational or safety processing covered by the applicable exemption.

The same data should not be indiscriminately retained or reused merely because part of the system performs an exempt function.

26. When the child becomes an adult

Rule 10 does not provide a complete transition mechanism when the child completes eighteen years.

Nevertheless, once the person becomes an adult, the basis for allowing the parent to act as part of the child’s Data Principal representation changes. Future consent and rights should ordinarily be controlled by the now-adult individual.

The Data Fiduciary should have a reasonable transition mechanism that:

  • identifies when the child becomes an adult;

  • informs the individual;

  • allows review of ongoing consent-based processing;

  • enables the individual to make her own choices;

  • transfers rights and account control;

  • removes unnecessary parental access;

  • and preserves historical records only where legally required.

Illustration

A parent gave consent for an educational account when the student was sixteen. At eighteen, the student should be able to take direct control of:

  • consent settings;

  • access rights;

  • correction requests;

  • erasure requests;

  • and account communications.

The parent should not retain permanent access to the adult student’s personal data merely because the original account was parent-approved.

27. Evidence and accountability

The Data Fiduciary should be able to demonstrate:

  • why it treated the user as a child or adult;

  • what parental-verification method was used;

  • what information was checked;

  • why that information was considered reliable;

  • which authorised entity or token was used;

  • what notice was shown;

  • what consent was given;

  • when verification and consent occurred;

  • whether processing started only afterward;

  • whether an exemption was relied upon;

  • the precise Fourth Schedule class or purpose;

  • how the necessity condition was applied;

  • and how the continuing prohibition against detrimental processing was addressed.

Where an exemption is used, the record should not merely state “Fourth Schedule applies.” It should explain why the exact processing fits the condition.

Example

For example, an educational institution relying on the tracking exemption should be able to show:

  • the educational or safety purpose;

  • what behaviour or location is monitored;

  • why the monitoring is needed;

  • where and when it occurs;

  • who can access the information;

  • how long it is retained;

  • and why it is not used for unrelated purposes.

28. Integrated illustrations

28.1 Illustration A: School learning platform

A school provides an online platform for assignments, attendance and teacher feedback.

The school may rely on the educational-institution exemption for tracking and behavioural monitoring genuinely required for its educational activities. It may record assignment completion, class attendance and learning progress.

The exemption does not automatically permit the platform provider to:

  • use student work to train an independent commercial AI model;

  • create advertising profiles;

  • sell learning-behaviour insights;

  • or combine records across unrelated schools.

If the provider undertakes those activities for its own purposes, their legality must be assessed separately.

The school must also ensure that its monitoring is not likely to cause a detrimental effect on the child’s well-being.

28.2 Illustration B: Child healthcare

A child receives urgent medical treatment. The hospital processes medical information necessary to diagnose and protect the child’s health without waiting for completion of an ordinary parental-verification workflow.

The healthcare exemption may apply.

If the hospital later wishes to use the records for a commercial advertisement or unrelated product development, that additional purpose is not covered simply because the data originated in healthcare.

28.3 Illustration C: School transport

A bus operator tracks the bus and records pickup and drop-off to protect children during the school journey.

The processing may fall within the transport exemption.

The operator cannot use the route information to build family movement profiles, track the child outside the journey or target nearby commercial offers.

28.4 Illustration D: Content restriction

A platform processes a verified age token to prevent a child from entering an area containing harmful content.

The processing may fall within Part B.

The platform should retain only the information needed to demonstrate the age-control outcome and should not use the token to construct an unrelated identity or advertising profile.

28.5 Illustration E: Mixed-purpose educational application

A learning application processes student data for:

  • class attendance;

  • safety alerts;

  • personalised learning;

  • advertising;

  • and commercial AI development.

The educational exemption may potentially apply to attendance and safety monitoring. It does not automatically apply to advertising or commercial AI training.

Each purpose must be examined separately. Exempt processing cannot be used as a gateway for non-exempt processing.

29. Enforcement implications

A significant breach of the obligations concerning children under Section 9 may attract a monetary penalty of up to ₹200 crore under the DPDPA Schedule.

The maximum is not automatic. The Board must follow the statutory inquiry procedure and consider the Section 33 factors.

A failure may be especially serious where a Data Fiduciary:

  • knowingly provides a child-oriented service with an easily bypassed age gate;

  • treats any unverified adult as a parent;

  • begins processing before verification;

  • collects excessive parental identity information;

  • uses verification data for unrelated purposes;

  • relies on a Fourth Schedule exemption outside its stated condition;

  • treats institutional status as a blanket exemption;

  • undertakes tracking beyond educational, health or safety purposes;

  • continues child profiling or targeted advertising;

  • ignores likely harm to the child’s well-being;

  • or fails to stop non-exempt processing after withdrawal.

Other obligations may also be engaged. A breach exposing parent and child identity records may involve security and breach-notification failures. A misleading parental notice may affect notice and consent validity. Failure to erase unnecessary verification data may involve retention and erasure obligations.

Conclusion

Rule 10 and the Fourth Schedule create a carefully balanced framework.

The ordinary rule is that a Data Fiduciary must obtain valid parental consent and must verify, through proportionate technical and organisational measures, that the person giving that consent is an identifiable adult. Reliable information already held may be used. New identity and age details may be supplied voluntarily, directly or through a token issued by an authorised entity, including through a recognised Digital Locker route.

That process must not become an excuse for indiscriminate identity-document collection. The Data Fiduciary should obtain only what is reasonably necessary to verify adulthood, identifiability and the parental-consent transaction. The parent’s information must remain protected and purpose-limited.

Rule 11 and the Fourth Schedule then create narrow exceptions for certain health, educational, childcare, transport, governmental, child-benefit, email, content-safety and age-confirmation activities. Those exceptions are limited by purpose and necessity. They do not exempt the organisation’s entire business, they do not remove the rest of the DPDPA, and they do not permit processing likely to have a detrimental effect on a child’s well-being.

The proper legal analysis is therefore:

  1. identify whether the individual is a child;

  2. identify the precise processing operation;

  3. determine whether a Fourth Schedule exemption applies;

  4. apply the exact condition and necessity boundary;

  5. where no exemption applies, complete Rule 10 verification and valid parental consent before processing;

  6. where an exemption applies, restrict processing to its permitted scope;

  7. continue applying security, purpose limitation, retention, rights and accountability duties; and

  8. ensure no processing is likely to cause a detrimental effect on the child’s well-being.

Key point

Rule 10 does not simply require proof that an adult clicked a button. It requires a trustworthy, proportionate and auditable connection between the adult, the parental role, the consent decision and the particular processing of the child’s data. The Fourth Schedule relieves that requirement only for narrowly defined activities where health, education, safety, legal duties, child-centred public benefits, email access, content protection or age assurance justify limited processing. Outside those boundaries, the ordinary child-protection framework continues in full.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.