THE RULES

Rule 12 - Exemptions from certain obligations applicable to processing of personal data of a child

Official text

(1)The provisions of sub-sections (1) and (3) of section 9 of the Act shall not be applicable to processing of personal data of a child by such class of Data Fiduciaries as are specified in Part A of Fourth Schedule, subject to such conditions as are specified in the said Part.

(2)The provisions of sub-sections (1) and (3) of section 9 of the Act shall not be applicable to processing of personal data of a child for such purposes as are specified in Part B of Fourth Schedule, subject to such conditions as are specified in the said Part.

Cross-references

Rule 12

Commentary

Rule 12 creates narrowly framed exceptions to two of the additional obligations that ordinarily apply when a Data Fiduciary processes a child’s personal data. It must be read with Section 9, Rules 10 and 11, and Parts A and B of the Fourth Schedule.

The Rule recognises that applying verifiable parental consent and the absolute restriction on tracking or behavioural monitoring in every situation could obstruct healthcare, education, child safety, statutory child-protection work, public benefits, age assurance and other legitimate child-centred activities. It therefore creates carefully limited exemptions. These exemptions are not blanket permissions to process children’s data and do not remove the general protections of the DPDPA.

Rule 12 is scheduled to come into force on 13 May 2027.

Section 9 imposes three distinct obligations concerning children’s personal data:

  1. Section 9(1): verifiable consent of the parent must ordinarily be obtained before processing the child’s personal data.

  2. Section 9(2): the Data Fiduciary must not undertake processing likely to cause a detrimental effect on the child’s well-being.

  3. Section 9(3): the Data Fiduciary must not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

Rule 12 exempts specified processing only from Section 9(1) and Section 9(3). It does not exempt any processing from Section 9(2).

This is the most important limitation in the Rule.

Even where a Data Fiduciary is permitted to process a child’s personal data without verifiable parental consent, or is permitted to undertake limited tracking or behavioural monitoring, it must still ensure that the processing is not likely to have a detrimental effect on the child’s well-being.

The exemption also does not remove the Data Fiduciary’s other obligations concerning:

  • lawful processing;

  • notice, where applicable;

  • purpose limitation;

  • processing only necessary personal data;

  • data accuracy;

  • security safeguards;

  • breach notification;

  • retention and erasure;

  • Data Principal rights;

  • grievance redressal;

  • and responsibility for Data Processors.

Rule 12 should therefore be understood as a targeted relaxation of two particular child-data obligations, not as an exclusion from the DPDPA.

2. Why the exemptions are necessary

An unconditional requirement for advance parental consent could sometimes operate against a child’s interests.

Consider the following situations:

  • an unconscious child needs emergency treatment;

  • a child-protection authority must investigate whether a parent is harming the child;

  • a school must track whether a young child has safely entered or left the campus;

  • a school-bus operator must locate a bus during an emergency;

  • a government authority must process data to provide a child scholarship;

  • an online service must process limited age information to determine whether the user is a child;

  • or a platform must restrict access to information likely to harm children.

In these situations, making processing dependent on an ordinary parental-consent process may be impractical, circular or contrary to the child’s interests. In some cases, the parent may be unavailable. In other cases, the parent may be the person under investigation or may have interests conflicting with those of the child.

Rule 12 addresses these situations through two routes.

3. Part A: Exemption based on the class of Data Fiduciary

Part A identifies particular categories of Data Fiduciaries, such as healthcare providers, educational institutions, childcare centres and school-transport providers. The exemption applies only where the processing satisfies the accompanying condition.

4. Part B: Exemption based on the purpose of processing

Part B focuses on why the processing is undertaken. It covers purposes such as performing legal duties in a child’s interests, providing child-centred public benefits, creating a basic email account, protecting a child from harmful information and conducting age assurance.

The two routes can overlap, but they should be analysed separately. A Data Fiduciary may belong to a Part A class, undertake a Part B purpose, or do both. In each case, the processing must remain within the precise condition stated in the Schedule.

5. Exemption does not attach to the organisation as a whole

Part A does not give permanent exempt status to a hospital, school, childcare centre or transport provider.

The exemption applies only to the specific processing operation that satisfies the relevant condition.

Example

For example, a hospital may process a child’s medical information without verifiable parental consent where this is necessary to protect the child’s health. The same hospital cannot rely on its status as a clinical establishment to use the child’s medical history for:

  • targeted advertising;

  • unrelated commercial profiling;

  • public fundraising material;

  • promotional testimonials;

  • sale to wellness businesses;

  • or commercial AI training unrelated to the child’s healthcare.

Similarly, a school may undertake limited behavioural monitoring for educational activities or child safety. Its status as an educational institution does not exempt unrelated:

  • commercial advertising;

  • profiling for third-party products;

  • disclosure to coaching businesses;

  • sale of behavioural information;

  • or unrestricted monitoring outside the educational context.

The relevant question is always:

Does this particular processing remain within the class, purpose and condition stated in the Fourth Schedule?

If the answer is no, the ordinary Section 9 requirements apply.

6. Part A: Exemptions for Specified Classes of Data Fiduciaries

7. Clinical establishments, mental health establishments and healthcare professionals

A clinical establishment, mental health establishment or healthcare professional may rely on the exemption where the processing is:

  • restricted to providing health services to the child; and

  • necessary to protect the child’s health.

This exemption recognises that healthcare frequently requires timely processing. A child may be unconscious, separated from a parent, in psychiatric distress or in need of immediate diagnosis and treatment.

7.1 Emergency treatment

A child is brought to a hospital after a serious accident. The hospital processes:

  • available identity information;

  • medical history;

  • allergy information;

  • diagnostic images;

  • laboratory results;

  • injuries;

  • medication;

  • and emergency contact information.

The processing is undertaken to provide health services and protect the child’s health. The hospital should not be required to postpone clinically necessary processing until an ordinary digital parental-consent workflow is completed.

The exemption can cover the processing genuinely necessary for:

  • assessment;

  • diagnosis;

  • treatment;

  • medication;

  • clinical monitoring;

  • referral;

  • discharge planning;

  • and continuity of care.

It does not authorise every use of the resulting health information.

7.2 Mental health services

A child approaches a mental health establishment in circumstances involving an immediate risk of self-harm or another serious health concern. Processing information necessary for assessment, intervention and protection may fall within the exemption.

The establishment must still confine processing to the health-service purpose. It cannot use the child’s counselling records for:

  • advertising;

  • public case studies;

  • unrelated institutional research;

  • staff entertainment;

  • or commercial profiling.

7.3 Routine healthcare

The exemption is not limited to emergencies. The language covers provision of health services necessary for protecting the child’s health. It may therefore apply to ordinary diagnosis, treatment, vaccination, rehabilitation and follow-up care.

However, necessity remains the controlling boundary. A healthcare provider should not collect broad family, behavioural or social information merely because such information might be useful at some future point. Each category should have a credible connection to the child’s health service.

7.4 Parent unavailable

A child requires urgent treatment while the parent cannot be contacted. The provider may process the information necessary to protect the child’s health.

Once the immediate circumstances permit, the provider should continue observing applicable transparency, communication and rights obligations. The exemption from Section 9(1) does not mean that the parent or lawful representative must never be informed where another provision requires communication.

7.5 Parent refuses processing necessary to protect the child

Suppose a parent refuses to permit processing necessary for a legally and clinically justified child-protection intervention. Rule 12 may prevent the parental-consent requirement from obstructing processing that satisfies the healthcare condition.

However, Rule 12 does not itself settle every dispute concerning medical treatment or consent to treatment. It addresses consent for processing personal data under the DPDPA. Separate healthcare, guardianship, child-protection and medical-consent laws may continue to govern the treatment decision.

This distinction is essential:

  • consent to medical treatment is one legal issue;

  • consent to processing personal data is another;

  • Rule 12 principally addresses the latter.

8. Allied healthcare professionals

An allied healthcare professional may rely on the exemption where processing is:

  • restricted to supporting the implementation of a healthcare treatment and referral plan recommended for the child; and

  • necessary for protecting the child’s health.

This may cover professionals supporting treatment through rehabilitation, therapy, diagnostics or another recognised allied-health function.

8.1 Rehabilitation plan

A child recovering from surgery is referred to a physiotherapist. The physiotherapist processes:

  • clinical referral information;

  • mobility limitations;

  • treatment exercises;

  • progress measurements;

  • and follow-up observations.

The processing directly supports the recommended treatment and referral plan. It may fall within the exemption to the extent necessary to protect the child’s health.

The professional cannot rely on the exemption to use videos of therapy sessions for:

  • social-media promotion;

  • commercial demonstrations;

  • unrelated AI training;

  • or marketing to other families.

8.2 Scope fixed by the treatment and referral plan

The allied-health exemption is narrower than a general health-related purpose. The processing must support implementation of the treatment and referral plan recommended for the child.

If an allied healthcare professional begins a materially separate activity unrelated to that plan, the exemption may not apply.

Example

For example, an occupational therapist treating a child under a referral plan may process relevant therapeutic observations. If the same professional creates a separate commercial database to compare children for product development, that processing requires an independent legal assessment.

9. Educational institutions

An educational institution may rely on the exemption for tracking and behavioural monitoring where the monitoring is undertaken:

  • for the educational activities of the institution; or

  • in the interests of the safety of children enrolled with it.

This exemption principally qualifies Section 9(3). It recognises that some observation of attendance, participation, performance and safety is inherent in running an educational institution.

It is not a general permission to monitor every aspect of a child’s behaviour.

9.1 Educational activities

A school may process information concerning:

  • attendance;

  • assignment completion;

  • classroom participation;

  • examination performance;

  • learning progress;

  • use of educational resources;

  • and participation in institution-led learning activities.

Such monitoring may be directed at teaching, assessment, student support and educational planning.

Consider a school learning portal that records whether students:

  • attended an online lesson;

  • submitted assignments;

  • completed learning modules;

  • or require additional academic support.

This is linked to the educational activities of the institution. The processing may fall within the exemption if it remains restricted to that purpose.

The school must still consider whether the monitoring is proportionate. A legitimate educational objective does not justify collecting every available behavioural signal.

Example

For example, monitoring assignment completion does not necessarily justify:

  • continuous webcam observation at home;

  • emotion recognition;

  • monitoring unrelated browsing;

  • scanning private messages;

  • recording family conversations;

  • or collecting precise location outside school activities.

9.2 Child safety

A school may use limited tracking or monitoring to protect children, such as:

  • campus entry and departure records;

  • visitor-management records;

  • attendance checks;

  • appropriate CCTV in common or safety-relevant areas;

  • emergency location information during excursions;

  • or systems used to identify whether a child has safely boarded transport.

The safety connection must be genuine. The word “safety” should not become a broad label for unlimited surveillance.

9.3 CCTV example

A school operates CCTV at entrances, corridors and common areas to prevent unauthorised entry and investigate safety incidents.

Such processing may fall within the safety condition.

The exemption would not automatically justify:

  • CCTV in toilets or changing areas;

  • audio recording throughout classrooms;

  • indefinite footage retention;

  • facial-recognition analysis of every child;

  • use of footage for marketing;

  • public sharing of recordings;

  • or monitoring children after they leave school.

9.4 Behavioural scoring

A school adopts software that continuously analyses facial expressions, voice, movement and online activity to assign each student an “attention score” and “obedience score.”

The school argues that the system supports educational activities.

The exemption should not be treated as conclusive merely because the software has an educational label. The school must still consider:

  • whether the processing is genuinely necessary;

  • whether less intrusive methods are available;

  • whether the system is accurate;

  • whether the scores unfairly label children;

  • whether the results affect opportunities;

  • whether the monitoring is likely to harm well-being;

  • and whether the system processes data beyond the educational purpose.

Because Section 9(2) remains applicable, a monitoring system that causes humiliation, anxiety, exclusion or unjustified adverse treatment may remain prohibited even if it is nominally connected to educational activities.

9.5 Educational technology vendors

A technology provider supplying a learning platform to a school does not automatically become an educational institution.

If the provider acts only on the school’s instructions, it may be a Data Processor. The school, as Data Fiduciary, remains responsible for the processing.

If the provider independently uses children’s information to:

  • improve a commercial product;

  • create cross-school profiles;

  • train its own AI model;

  • advertise services;

  • or sell educational analytics, it may be determining an independent purpose. That activity does not automatically inherit the school’s exemption.

The Fourth Schedule follows the legally qualifying processing. It does not travel automatically through every vendor relationship.

10. Crèches and child day-care centres

The Schedule permits limited tracking and behavioural monitoring in the interests of the safety of infants and children entrusted to the care of an individual, crèche or child day-care centre.

The exemption reflects the reality that young children may require close supervision and may not be able to report danger or unauthorised removal.

Permitted safety-related processing may include:

  • attendance;

  • arrival and departure;

  • authorised pickup records;

  • access to restricted areas;

  • emergency contact information;

  • incident monitoring;

  • and age-appropriate supervision.

10.1 Authorised pickup

A day-care centre records the names and contact details of persons authorised to collect each child and logs the time of departure.

This processing is directly connected with preventing a child from being released to an unauthorised person. It may fall within the safety condition.

The centre should not use the authorised pickup list for:

  • marketing;

  • commercial profiling;

  • sale to local businesses;

  • or unrelated family-network analysis.

10.2 Live camera feeds

A crèche installs cameras and gives parents continuous remote access to a live video feed showing all children.

The operator cannot assume that the safety exemption automatically validates this arrangement. The system raises additional questions:

  • Are other children visible?

  • Can access credentials be shared?

  • Is the feed recorded?

  • Can outsiders obtain access?

  • Is ongoing remote access necessary for safety?

  • Would incident alerts or controlled review achieve the purpose more safely?

  • How long is footage retained?

  • Can employees or parents download recordings?

The exemption permits necessary safety monitoring, not unrestricted digital observation of every child by every parent.

11. Child-transport providers

A Data Fiduciary engaged by an educational institution, crèche or child-care centre to transport children may track their location:

  • in the interests of the children’s safety; and

  • during travel to and from the institution, crèche or centre.

The boundaries are unusually clear. The exemption is connected to the journey and safety purpose.

11.1 School-bus tracking

A school engages a bus operator that uses GPS and boarding records to:

  • locate the bus;

  • notify the school of delays;

  • confirm pickup and drop-off;

  • identify route deviations;

  • and respond to emergencies.

The processing may fall within the exemption.

The operator cannot extend the exemption to:

  • tracking the child after leaving the bus;

  • accessing the location of the child’s personal device throughout the day;

  • analysing family movement patterns;

  • sending location-based advertisements;

  • or retaining individual journey histories indefinitely.

11.2 Route-level versus child-level tracking

A transport provider may sometimes achieve the safety purpose by tracking the vehicle rather than each child’s personal phone or wearable device.

Necessity requires considering the less intrusive option. If vehicle-level tracking and boarding confirmation adequately protect the child, continuous device-level surveillance may be excessive.

12. Part B: Exemptions Based on the Purpose of Processing

13. Exercise of statutory powers, functions or duties in the child’s interests

Part B applies where processing is necessary for the exercise of a power, performance of a function or discharge of a duty in the interests of a child under Indian law.

This provision is particularly important for:

  • courts;

  • child-welfare authorities;

  • police or specialised child-protection units;

  • statutory commissions;

  • adoption authorities;

  • welfare bodies;

  • and other persons performing legally assigned child-centred functions.

13.1 Child-protection investigation

A child-protection authority receives information suggesting that a child is being abused by a parent. It processes:

  • the child’s identity;

  • school information;

  • health records;

  • family information;

  • witness accounts;

  • and safety reports.

Requiring consent from the parent under investigation would undermine the statutory protection function. The exemption permits processing necessary to perform the legal duty in the child’s interests.

The authority cannot use this exemption for processing unrelated to the child-protection function.

13.2 Court proceeding

A court processes a child’s personal data in custody, protection, adoption or maintenance proceedings.

The processing may be necessary for the exercise of judicial power and performance of duties in the child’s interests. The parental-consent requirement cannot be allowed to prevent the court from carrying out its function.

Confidentiality, security, restricted access and other applicable legal protections continue to apply.

14. Child-centred subsidies, benefits and public services

Part B covers processing necessary to provide or issue a subsidy, benefit, service, certificate, licence or permit:

  • under law or policy or through public funds;

  • under Section 7(b); and

  • in the interests of a child.

This exemption should be read with Rule 5 and the Second Schedule governing State processing.

14.1 Scholarship

A State authority processes:

  • the child’s identity and age;

  • school enrolment;

  • educational performance;

  • eligibility information;

  • household-income information;

  • and payment details to assess and disburse a scholarship.

Where Section 7(b) applies, processing necessary to provide the benefit may be undertaken without requiring the ordinary verifiable parental-consent process under Section 9(1).

The authority must still comply with the applicable standards concerning:

  • lawfulness;

  • necessity;

  • reasonable accuracy;

  • security;

  • retention;

  • intimation;

  • rights access;

  • and accountability.

The scholarship data cannot be repurposed for unrelated advertising or profiling merely because it was lawfully processed for a public benefit.

14.2 Child-health benefit

A public health programme processes the information necessary to issue treatment support or a health certificate to eligible children.

The processing may fall within Part B where it is necessary for providing the child-centred service or benefit.

The exemption should not be expanded to cover every item of family or medical information held by the State. Only data necessary for the particular programme should be processed.

15. Creation of a user account for email communication

The Fourth Schedule permits processing necessary to create a user account whose use is limited to communicating by email.

The exemption is narrow. It does not apply to every digital platform simply because the platform uses an email address for login.

The account itself must be for email communication, and the processing must be limited to what is necessary to create and operate that email account.

15.1 Basic email account

A provider creates a limited email service for a child. It processes:

  • an account identifier;

  • login credentials;

  • address-book information supplied by the user;

  • message-routing data;

  • security logs;

  • and information required to deliver email.

The processing may fall within the exemption.

The provider cannot use this provision as authority for:

  • targeted advertising;

  • analysis of message content for unrelated commercial profiling;

  • cross-platform tracking;

  • social-media recommendations;

  • location monitoring;

  • gaming;

  • or training unrelated commercial models on children’s communications.

15.2 Service using email as a login identifier

A gaming service creates an account using the child’s email address.

That is not necessarily an account “for communicating by email.” The fact that email is used as a login credential does not transform the gaming account into an exempt email-communication account.

The substance of the service, not the technical use of an email address, determines whether the exemption applies.

16. Protecting the child from harmful information

Part B permits processing necessary to ensure that information likely to cause a detrimental effect on a child’s well-being is not accessible to her.

This supports age assurance, content restriction, safety filters and access controls directed specifically at protecting children from harmful material.

16.1 Restricted-content area

A platform hosts both general content and material unsuitable for children. It performs a proportionate age check before allowing access to the restricted area.

The processing may fall within the exemption because it is undertaken to prevent harmful information from reaching a child.

The platform should not use the age-verification data for:

  • unrelated advertising;

  • identity enrichment;

  • cross-service profiling;

  • disclosure to other content businesses;

  • or indefinite tracking.

16.2 Content filtering

An app uses limited age information to activate child-appropriate content filters and disable access to unsuitable material.

That processing may fall within the exemption when it is genuinely restricted to child protection.

If the app simultaneously constructs a detailed behavioural profile for commercial recommendations, that additional processing is not automatically covered.

16.3 Detrimental information and overblocking

Protection from harmful information does not necessarily justify indiscriminate filtering of lawful and beneficial information. The Data Fiduciary should ensure that the protective measure is reasonably connected to information likely to have a detrimental effect on children.

An excessively broad filter may restrict access to:

  • educational resources;

  • healthcare information;

  • disability support;

  • child-protection services;

  • or age-appropriate information.

The exemption permits necessary protection, not arbitrary information control.

17. Age confirmation and Rule 10 due diligence

Part B permits processing necessary:

  • to confirm that a Data Principal is not a child; and

  • to observe the due-diligence requirements under Rule 10.

This exemption resolves a practical circularity. A Data Fiduciary may need to process limited identity or age information before it knows whether the person is a child and whether parental consent is necessary.

17.1 Age-assurance token

A user supplies a verified token confirming that she has completed eighteen years.

The Data Fiduciary processes:

  • token authenticity;

  • issuer information;

  • verification result;

  • and a limited compliance record.

The processing may fall within the exemption.

The exemption does not authorise the Data Fiduciary to retrieve or retain every underlying identity detail if a limited adulthood confirmation is sufficient.

17.2 Parent verification

A person identifies herself as the parent of a child. The Data Fiduciary verifies, under Rule 10, that she is an identifiable adult.

The identity and age processing required for that check may fall within this Part B exemption.

The parent’s verification information should not automatically be used to:

  • market products;

  • create an independent commercial account;

  • build a household profile;

  • enrich the child’s advertising profile;

  • or disclose the parent’s identity to unrelated parties.

17.3 Age verification should remain proportionate

Part B does not require every Data Fiduciary to collect a government identity document from every visitor.

The method should correspond to:

  • the likelihood that children use the service;

  • the service’s intended audience;

  • the nature of the data;

  • the consequences of misclassifying a child as an adult;

  • and the intrusiveness of the processing.

A child-oriented social platform will ordinarily require a stronger age-assurance model than a specialised enterprise portal accessible only to verified employees of corporate customers.

18. The continuing effect of Section 9(2)

The exemptions in Rule 12 do not apply to Section 9(2). No class of Data Fiduciary and no Part B purpose may rely on Rule 12 to undertake processing likely to cause a detrimental effect on a child’s well-being.

This has significant consequences.

A school may be permitted to monitor educational participation, but it must not implement that monitoring in a harmful manner.

A transport provider may track a child during a school journey, but it must protect the information against misuse that could endanger the child.

A healthcare professional may process data without ordinary parental verification where necessary for health, but it must not use a system that predictably exposes or harms the child.

A platform may conduct age assurance to protect children from harmful information, but it must not design the process in a manner that exploits, humiliates or unjustifiably excludes children.

18.1 Detrimental effect as a substantive boundary

The DPDPA does not provide an exhaustive list of detrimental effects. The assessment should consider the nature of the processing and its likely consequences for the child.

Possible detrimental effects may include:

  • physical danger;

  • psychological distress;

  • humiliation;

  • discrimination;

  • exclusion from education or services;

  • manipulation;

  • exposure of confidential information;

  • unjustified labelling;

  • financial exploitation;

  • unsafe contact;

  • reputational harm;

  • or loss of future opportunities.

The focus is on processing likely to cause harm, not only processing that has already produced documented harm.

18.2 Illustration: Educational ranking

A school uses permitted educational monitoring to identify learning needs. It then publicly ranks children by inferred intelligence and behavioural compliance.

The initial collection may have an educational connection, but the public ranking may create humiliation, labelling and discriminatory effects. Rule 12 does not excuse processing likely to harm the child’s well-being.

18.3 Illustration: Transport-location breach

A school-bus service lawfully tracks children for safety but publishes a live, unauthenticated location feed.

The original purpose is safety, but insecure implementation may expose children to physical risk. The exemption does not remove Section 9(2) or Rule 6 security obligations.

19. Targeted advertising remains restricted

Section 9(3) prohibits both:

  • tracking or behavioural monitoring of children; and

  • targeted advertising directed at children.

The Fourth Schedule permits certain processing that would otherwise fall within Section 9(3), but its classes and purposes are tightly defined.

None of the listed exemptions should be treated as a general permission for targeted advertising to children.

Example

For example:

  • a hospital cannot use health data to target wellness advertisements;

  • a school cannot use academic behaviour to target coaching advertisements;

  • a crèche cannot use family information to market consumer products;

  • a bus operator cannot use location to serve nearby advertisements;

  • an email provider cannot rely on the email-account exemption to profile message content for child-directed advertising;

  • and an age-assurance provider cannot commercialise verification data for advertising.

Even where some tracking is exempt, targeted advertising requires its own analysis and will ordinarily remain outside the Schedule’s narrow conditions.

20. Necessity is the recurring condition

The Fourth Schedule repeatedly limits processing to what is necessary for the listed function or purpose.

Necessity requires more than convenience. The Data Fiduciary should be able to explain:

  • how the personal data contributes to the permitted purpose;

  • why each data field is required;

  • whether a less intrusive method would work;

  • why the frequency and duration of monitoring are appropriate;

  • who needs access;

  • and when the information will be erased.

20.1 Illustration: School attendance

A school needs to know whether a child attended class. Recording attendance may be necessary.

Continuous recording of the child’s face, home environment, private conversations, device activity and browsing history is not automatically necessary merely because the lesson occurs online.

20.2 Illustration: Bus safety

Tracking the location of the school bus during the route may be necessary for safety.

Tracking the child’s personal device all day, including weekends and holidays, is not necessary for travel to and from the school.

20.3 Illustration: Healthcare

A doctor may need symptoms, diagnoses and test results to treat the child.

The doctor does not necessarily need the child’s unrelated social-media history, family purchasing patterns or complete school behavioural profile.

The Schedule’s conditions are therefore not formal descriptions. They are substantive limits on data quantity, monitoring intensity, recipients, retention and further use.

21. Reliance on Rule 12 must be documented

A Data Fiduciary relying on an exemption should maintain a defensible record explaining:

  • the precise processing operation;

  • the child-data categories involved;

  • whether Part A or Part B is relied upon;

  • the applicable entry;

  • how the stated condition is satisfied;

  • why the data is necessary;

  • whether tracking or behavioural monitoring occurs;

  • whether any advertising is involved;

  • why Section 9(2) is satisfied;

  • the persons and Processors receiving the data;

  • security measures;

  • and the retention period.

A statement that “the Fourth Schedule applies” is insufficient.

Example

For example, an educational institution should document:

  • the educational or safety activity;

  • the nature of the monitoring;

  • where it occurs;

  • which children are affected;

  • how the output is used;

  • who can see it;

  • how long it is retained;

  • whether it affects decisions;

  • and why it is not likely to cause a detrimental effect.

This documentation should be revisited if:

  • the purpose changes;

  • monitoring becomes more intrusive;

  • a new vendor is added;

  • an AI feature is activated;

  • the data is shared more widely;

  • or retention is extended.

22. Notices and transparency

Exemption from parental consent does not necessarily mean secrecy.

Where the DPDPA requires a notice or intimation, the Data Fiduciary must provide it. Even where a formal consent request is unnecessary, transparency may remain essential to questioning the processing, exercising rights and maintaining accountability.

The communication should accurately state the basis on which processing occurs.

A Data Fiduciary should not present an optional-looking consent request if it intends to process the data under an exemption regardless of the parent’s answer. That creates confusion concerning the legal basis and effect of refusal.

22.1 Illustration: School safety tracking

A school may rely on the educational-safety exemption for bus tracking. It should explain:

  • what is tracked;

  • when tracking begins and ends;

  • whether the bus or child device is tracked;

  • who can access the location;

  • whether parents receive access;

  • how long records are retained;

  • who the Processor is;

  • and how concerns may be raised.

The communication should not falsely state that tracking is based on revocable consent if the school actually relies on the Schedule exemption.

23. Rights and grievances continue

Rule 12 does not generally extinguish Data Principal rights.

Subject to the Act and the circumstances, the child’s parent, lawful guardian or later the child acting directly may seek:

  • information about processing;

  • correction of inaccurate data;

  • completion or updating;

  • erasure where retention is no longer justified;

  • grievance redressal;

  • and nomination.

An exemption from parental consent does not mean that inaccurate or obsolete child data may be retained indefinitely.

23.1 Illustration: Incorrect school behaviour record

A school’s monitoring system incorrectly records that a child repeatedly left class without permission.

The parent challenges the record. The school cannot refuse correction merely by saying the monitoring was exempt under Rule 12. The exemption concerns the applicability of Sections 9(1) and 9(3), not the accuracy and correction framework.

23.2 Illustration: Route history

A transport provider retains years of individual child-location history after the safety purpose and legal retention period have ended.

The safety exemption does not create indefinite retention authority. Erasure obligations continue to apply.

24. Data Processors and third-party vendors

A Data Fiduciary may use third parties to perform exempt processing, but it remains responsible for processing undertaken on its behalf.

Contracts and technical arrangements should ensure that the Processor:

  • acts only on documented instructions;

  • processes only the necessary child data;

  • does not create independent commercial purposes;

  • does not use the data for targeted advertising;

  • maintains reasonable security safeguards;

  • reports breaches promptly;

  • applies retention and erasure instructions;

  • and controls subprocessors.

24.1 Illustration: School analytics vendor

A school engages a provider to measure assignment completion and attendance.

The provider may process the information on the school’s behalf for the educational purpose. It should not independently:

  • combine the information across clients;

  • build commercial student profiles;

  • train an unrelated product;

  • advertise to children;

  • or retain the information after the school’s purpose ends.

If it determines those independent purposes, it may become a separate Data Fiduciary for that processing and cannot simply borrow the school’s exemption.

25. Artificial intelligence and automated monitoring

AI systems may be used in several Fourth Schedule contexts, including:

  • educational analytics;

  • safety monitoring;

  • health assessment;

  • age assurance;

  • content filtering;

  • and transport tracking.

The presence of AI does not remove or automatically defeat the exemption. The legality depends on the processing purpose, necessity, likely effect and safeguards.

However, AI can increase risk through:

  • inaccurate inferences;

  • opaque behavioural scores;

  • false age classification;

  • bias;

  • excessive surveillance;

  • automated adverse decisions;

  • model memorisation;

  • and reuse of input data for vendor training.

25.1 Illustration: AI-based classroom monitoring

A school uses an AI tool to analyse participation during online classes. The tool infers attention and emotional state from facial movement and generates behavioural scores.

The school must ask more than whether the tool is marketed for education. It must examine:

  • whether the inferences are reliable;

  • whether the processing is necessary for education;

  • whether less intrusive methods exist;

  • whether children are unfairly labelled;

  • whether the data affects grades or discipline;

  • whether the vendor trains its model on student recordings;

  • and whether the processing is likely to harm well-being.

An educational purpose does not automatically validate every technology chosen to pursue it.

25.2 Illustration: Age-estimation AI

A platform uses facial age-estimation technology to prevent children from accessing harmful content.

The child-protection and age-confirmation exemptions may be relevant. But the platform must still examine:

  • accuracy;

  • bias;

  • false classification;

  • retention of facial images;

  • whether biometric templates are created;

  • vendor reuse;

  • security;

  • and whether a less intrusive age token would achieve the same result.

The Schedule permits necessary processing, not unnecessary collection of high-risk data.

26. Mixed-purpose systems

Many systems process the same data for multiple purposes. Rule 12 must be applied purpose by purpose.

Consider a school application that uses student information for:

  1. recording attendance;

  2. monitoring bus safety;

  3. recommending learning material;

  4. advertising commercial courses;

  5. training the vendor’s commercial AI model; and

  6. producing promotional success stories.

The possible application of Rule 12 to attendance or safety does not automatically extend to advertising, AI training or promotion.

The Data Fiduciary must separate:

  • purposes;

  • data fields;

  • user permissions;

  • access;

  • retention periods;

  • Processor instructions;

  • and legal grounds.

Where the same dataset contains information needed for both exempt and non-exempt purposes, technical and organisational controls should prevent the exempt collection from becoming a general-purpose child-data repository.

27. Changes in purpose

A processing operation may begin within the Fourth Schedule but later change.

Example

For example:

  • school attendance data is later used for commercial predictions;

  • bus-location data is later used for urban marketing analytics;

  • health records are later used to develop a commercial product;

  • age-verification data is later used for identity profiling;

  • email content is later scanned for targeted advertising.

The original exemption does not automatically continue.

The Data Fiduciary must reassess:

  • the new purpose;

  • whether the Schedule still applies;

  • whether parental consent is required;

  • whether Section 9(3) prohibits the activity;

  • whether the processing could harm the child’s well-being;

  • and whether fresh notice or other action is needed.

An exempt origin does not cleanse every later use.

28. Relationship with Rule 10

Rule 10 governs how verifiable parental consent is obtained. Rule 12 determines when Section 9(1), and therefore the Rule 10 consent process, does not apply to a particular child-data operation.

The correct order of analysis is:

  1. identify the child-data processing;

  2. determine whether Part A or Part B of the Fourth Schedule applies;

  3. verify that every stated condition is satisfied;

  4. if the exemption applies to Section 9(1), Rule 10 verification is not required for that specific processing;

  5. if the processing falls outside the exemption, complete the Rule 10 process before processing;

  6. separately assess Section 9(3);

  7. continue applying Section 9(2) and all other applicable duties.

28.1 Illustration: School with two processing purposes

A school monitors attendance for educational activities and also wishes to use photographs of children in targeted promotional campaigns.

Attendance monitoring may fall within Part A.

The advertising purpose does not. It must be separately assessed, and targeted advertising directed at children remains restricted under Section 9(3).

The school cannot use an exemption applicable to the first operation as a basis for the second.

29. Scope of the two exemptions

Rule 12 states that both Section 9(1) and Section 9(3) do not apply to the qualifying processing.

This wording requires caution because some Schedule entries naturally relate more strongly to one obligation than the other.

Example

For example:

  • healthcare exemptions are particularly important for avoiding delay caused by parental verification;

  • educational and transport exemptions are particularly important because they permit defined tracking or monitoring;

  • age-confirmation processing helps determine whether parental consent is required;

  • content-protection processing may itself involve age checking or monitoring.

The fact that the Rule removes both subsections does not expand the permitted purpose. The Schedule’s condition remains the controlling boundary.

A hospital exempt from Section 9(3) for necessary treatment processing does not thereby obtain general authority to track children for advertising. Such tracking would not satisfy the health-service condition in the first place.

Likewise, a school exempt from Section 9(1) and Section 9(3) for educational monitoring cannot use the same exemption for an unrelated commercial purpose.

30. Enforcement implications

A Data Fiduciary that falls outside the Fourth Schedule but processes a child’s data without verifiable parental consent may breach Section 9(1). A Data Fiduciary that exceeds the Schedule’s limits through tracking, behavioural monitoring or targeted advertising may breach Section 9(3). Processing likely to harm a child’s well-being may independently breach Section 9(2).

The DPDPA Schedule permits a maximum monetary penalty of up to ₹200 crore for breach of the additional obligations concerning children.

The maximum is not automatic. The Board must conduct the statutory inquiry, determine that a significant breach occurred, provide an opportunity of hearing and apply the Section 33 factors.

A contravention may be particularly serious where the Data Fiduciary:

  • knowingly relies on an exemption that does not apply;

  • treats institutional status as blanket immunity;

  • processes substantially more information than necessary;

  • uses educational, health or safety data for advertising;

  • conducts intrusive monitoring outside the permitted setting;

  • processes data in a manner likely to harm the child;

  • allows a Processor to use child data independently;

  • conceals the real purpose;

  • retains information indefinitely;

  • or continues the activity after complaints or warnings.

Other penalty categories may also become relevant. For example:

  • a breach of child-location or health data may involve inadequate security;

  • failure to notify the breach may involve Section 8(6);

  • misleading notices may affect consent validity;

  • and failure to erase data after the purpose ends may constitute a separate violation.

Conclusion

Rule 12 does not weaken the DPDPA’s general protection of children. It prevents two specific obligations from obstructing narrowly defined activities that are necessary for healthcare, education, safety, statutory child protection, public benefits, email communication, protection from harmful content and age assurance.

The exemption analysis must remain disciplined.

A Data Fiduciary should ask:

  1. Is the processing covered by a class in Part A or a purpose in Part B?

  2. Does the particular processing satisfy the stated condition?

  3. Is every category of personal data necessary for that limited purpose?

  4. Does the exemption apply to this operation rather than merely to the organisation generally?

  5. Is tracking or behavioural monitoring confined to the permitted setting?

  6. Is targeted advertising involved?

  7. Could the processing cause a detrimental effect on the child’s well-being?

  8. Are security, accuracy, retention, rights and Processor obligations being observed?

  9. Has any later use moved beyond the exemption?

The Schedule must be applied to the actual data operation. A hospital is not exempt for all uses of child data because it provides healthcare. A school is not exempt for all monitoring because it provides education. A transport provider is not exempt for all location processing because it operates a school bus. An email provider is not exempt for every digital service because it issues an email address. An age-verification system is not exempt for every use of identity information because it once checked age.

Key point

Rule 12 creates necessity-bound exemptions, not organisation-wide immunity. The permitted processing must remain confined to the health, educational, safety, legal, public-benefit, email, content-protection or age-assurance function identified in the Fourth Schedule. Section 9(2) continues to prohibit processing likely to cause a detrimental effect on the child’s well-being, and the rest of the DPDPA continues to govern the collection, use, security, retention, sharing and erasure of the child’s personal data.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.