SCHEDULE IV - FOURTH SCHEDULE - EXEMPTIONS FROM SECTION 9(1) AND 9(3)

Fourth Schedule - Exemptions from section 9(1) and 9(3)

Official text

See rule 12

Part A - Classes of Data Fiduciaries in respect of whom provisions of sub-sections (1) and (3) of section 9 shall not apply

S. No.(1)Class of Data Fiduciaries(2)Conditions(3)
1.A Data Fiduciary who is a clinical establishment, mental health establishment or healthcare professional.Processing is restricted to provision of health services to the child by such establishment or professional, to the extent necessary for the protection of her health.
2.A Data Fiduciary who is an allied healthcare professional.Processing is restricted to supporting implementation of any healthcare treatment and referral plan recommended by such professional for the child, to the extent necessary for the protection of her health.
3.A Data Fiduciary who is an educational institution.
Processing is restricted to tracking and behavioural monitoring
(a)for the educational activities of such institution; or
(b)in the interests of safety of children enrolled with such institution.
4.A Data Fiduciary who is an individual in whose care infants and children in a crèche or child day care centre are entrusted.Processing is restricted to tracking and behavioural monitoring in the interests of safety of children entrusted in the care of such institution, crèche or centre.
5.A Data Fiduciary who is engaged by an educational institution, crèche or child care centre for transport of children enrolled with such institution, crèche or centre.Processing is restricted to tracking the location of such children, in the interests of their safety, during the course of their travel to and from such institution, crèche or centre.

S. No. 1.

Class of Data Fiduciaries (2)A Data Fiduciary who is a clinical establishment, mental health establishment or healthcare professional.
Conditions (3)Processing is restricted to provision of health services to the child by such establishment or professional, to the extent necessary for the protection of her health.

S. No. 2.

Class of Data Fiduciaries (2)A Data Fiduciary who is an allied healthcare professional.
Conditions (3)Processing is restricted to supporting implementation of any healthcare treatment and referral plan recommended by such professional for the child, to the extent necessary for the protection of her health.

S. No. 3.

Class of Data Fiduciaries (2)A Data Fiduciary who is an educational institution.
Conditions (3)
Processing is restricted to tracking and behavioural monitoring
(a)for the educational activities of such institution; or
(b)in the interests of safety of children enrolled with such institution.

S. No. 4.

Class of Data Fiduciaries (2)A Data Fiduciary who is an individual in whose care infants and children in a crèche or child day care centre are entrusted.
Conditions (3)Processing is restricted to tracking and behavioural monitoring in the interests of safety of children entrusted in the care of such institution, crèche or centre.

S. No. 5.

Class of Data Fiduciaries (2)A Data Fiduciary who is engaged by an educational institution, crèche or child care centre for transport of children enrolled with such institution, crèche or centre.
Conditions (3)Processing is restricted to tracking the location of such children, in the interests of their safety, during the course of their travel to and from such institution, crèche or centre.

Part B - Purposes for which provisions of sub-sections (1) and (3) of section 9 shall not apply

S. No.(1)Purposes(2)Conditions(3)
1.For the exercise of any power, performance of any function or discharge of any duties in the interests of a child, under any law for the time being in force in India.Processing is restricted to the extent necessary for such exercise, performance or discharge.
2.For providing or issuing of any subsidy, benefit, service, certificate, licence or permit, by whatever name called, under law or policy or using public funds, in the interests of a child, under clause (b) of section 7 of the Act.Processing is restricted to the extent necessary for such provision or issuance.
3.For the creation of a user account for communicating by email.Processing is restricted to the extent necessary for creating such user account, the use of which is limited to communication by email.
4.For the determination of real-time location of a child.Processing is restricted to the tracking of real-time location of such child, in the interest of her safety and protection or security.
5.For ensuring that any information, service or advertisement likely to cause any detrimental effect on the well-being of a child is not accessible to her.Processing is restricted to the extent necessary to ensure that such information, service or advertisement is not accessible to the child.
6.For confirmation by the Data Fiduciary that the Data Principal is not a child and observance of due diligence under rule 10.Processing is restricted to the extent necessary for such confirmation or observance.

S. No. 1.

Purposes (2)For the exercise of any power, performance of any function or discharge of any duties in the interests of a child, under any law for the time being in force in India.
Conditions (3)Processing is restricted to the extent necessary for such exercise, performance or discharge.

S. No. 2.

Purposes (2)For providing or issuing of any subsidy, benefit, service, certificate, licence or permit, by whatever name called, under law or policy or using public funds, in the interests of a child, under clause (b) of section 7 of the Act.
Conditions (3)Processing is restricted to the extent necessary for such provision or issuance.

S. No. 3.

Purposes (2)For the creation of a user account for communicating by email.
Conditions (3)Processing is restricted to the extent necessary for creating such user account, the use of which is limited to communication by email.

S. No. 4.

Purposes (2)For the determination of real-time location of a child.
Conditions (3)Processing is restricted to the tracking of real-time location of such child, in the interest of her safety and protection or security.

S. No. 5.

Purposes (2)For ensuring that any information, service or advertisement likely to cause any detrimental effect on the well-being of a child is not accessible to her.
Conditions (3)Processing is restricted to the extent necessary to ensure that such information, service or advertisement is not accessible to the child.

S. No. 6.

Purposes (2)For confirmation by the Data Fiduciary that the Data Principal is not a child and observance of due diligence under rule 10.
Conditions (3)Processing is restricted to the extent necessary for such confirmation or observance.

Note

In this Schedule, -

(a)“advertisement” shall have the same meaning as is assigned to it in the Consumer Protection Act, 2019 (35 of 2019).
(a)“allied healthcare professional” shall have the same meaning as is assigned to it in the clause (d) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021);
(b)“clinical establishment” shall have the same meaning as assigned to it in the clause (c) of section 2 of the Clinical Establishments (Registration and Regulation) Act, 2010 (23 of 2010);
(c)“educational institution” shall mean and include an institution of learning that imparts education, including vocational education;
(d)“healthcare professional” shall have the same meaning as is assigned to it in clause (j) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021);
(e)“health services” shall mean the services required to be provided by a healthcare professional as referred to in clause (j) of section 2 of the National Commission for Allied and Healthcare Professions Act, 2021 (14 of 2021); and
(f)“mental health establishment” shall have the same meaning as is assigned to it in clause (p) of sub-section (1) of section 2 of the Mental Healthcare Act, 2017 (10 of 2017).

Cross-references

Fourth Schedule

Commentary

Fourth Schedule: Exemptions Relating to Processing of Personal Data of Children

Commentary

The Fourth Schedule is one of the most important parts of the DPDP Rules because it creates the principal regulatory exceptions to the otherwise stringent protections contained in Section 9 of the DPDP Act.

Section 9 adopts a deliberately protective approach towards children. Before processing a child's personal data, the Data Fiduciary must obtain verifiable consent of the parent or lawful guardian. The provision also prohibits processing likely to cause a detrimental effect on the well-being of a child and prohibits tracking, behavioural monitoring and targeted advertising directed at children.

Section 9(4), however, recognises that these requirements cannot necessarily operate identically in every context. It therefore permits the prescribed exemption of certain classes of Data Fiduciaries or certain purposes, subject to prescribed conditions.

The Fourth Schedule is the instrument through which that power is operationalised.

Rule 12 expressly provides that Sections 9(1) and 9(3) shall not apply to processing of children's personal data by the classes of Data Fiduciaries specified in Part A, subject to the conditions stated there. It creates a parallel exemption for specified purposes listed in Part B, again subject to their conditions.

The Schedule therefore has to be read as a conditional exception, not as a general relaxation of children's privacy protections.

1. The starting point: Section 9 is the rule

The first interpretive mistake would be to begin with the Fourth Schedule.

The correct starting point is Section 9.

Section 9(1) establishes the parental-consent requirement.

Section 9(2) prohibits processing likely to cause detrimental effects on the well-being of a child.

Section 9(3) prohibits:

  • tracking;
  • behavioural monitoring; and
  • targeted advertising directed at children.

Section 9(4) then creates an exception specifically in relation to sub-sections (1) and (3).

This drafting is critical.

The Fourth Schedule does not create an exemption from Section 9 as a whole.

It operates only against the provisions expressly identified in Rule 12, namely Sections 9(1) and 9(3).

Section 9(2) is not included.

This means that even where a Data Fiduciary falls within Part A or a processing activity falls within Part B, the organisation cannot conclude that all child-data restrictions disappear.

The prohibition against processing likely to cause a detrimental effect on the child's well-being remains a separate statutory requirement.

This is perhaps the single most important structural point concerning the Schedule.

2. The Schedule is conditional, not absolute

Both Part A and Part B use a two-part structure:

exempted activity + condition

The condition is therefore not ancillary drafting.

It is part of the exemption.

For example, Part A does not simply say:

healthcare establishments are exempt.

It says, in substance, that processing is exempt where it is restricted to the provision of health services to the child to the extent necessary for protection of her health.

The same architecture appears throughout the Schedule.

This produces an important principle:

A Data Fiduciary does not qualify for the exemption merely because it belongs to an exempt class. The particular processing must also remain within the condition attached to that exemption.

Thus, the Schedule is not class-based alone.

It is class-and-purpose based in Part A and purpose-and-condition based in Part B.

Part A: Classes of Data Fiduciaries

3. Healthcare establishments and healthcare professionals

The first category covers a Data Fiduciary that is:

  • a clinical establishment;
  • a mental health establishment; or
  • a healthcare professional.

The exemption applies where processing is restricted to providing health services to the child, to the extent necessary for protection of the child's health.

The logic is straightforward.

A healthcare provider cannot realistically provide many services to a child without processing the child's personal data.

Consider a ten-year-old admitted to a hospital.

The hospital may need to process:

name;

age;

medical history;

diagnostic information;

medication information;

emergency contact information;

treatment records; and

information concerning the child's condition.

Requiring a separate parental-consent architecture for every necessary processing operation could interfere with the provision of healthcare.

The Schedule therefore creates an exemption from Section 9(1) and Section 9(3) in this context.

But the condition is deliberately restrictive.

The processing must be:

for health services

and

necessary for protection of the child's health.

The exemption cannot therefore automatically cover unrelated processing.

Suppose a hospital uses a child's medical data to provide healthcare. That may fall within the exemption.

Suppose the same hospital uses the child's information to construct a commercial advertising profile for unrelated products.

The fact that the organisation is a healthcare establishment does not logically extend the exemption to that activity.

The exemption follows the purpose and necessity of processing, not merely the identity of the Data Fiduciary.

4. Allied healthcare professionals

The second category concerns allied healthcare professionals.

The Schedule restricts the exemption to processing necessary for supporting implementation of a healthcare treatment and referral plan recommended by the professional for the child, and further limits it to what is necessary for protecting the child's health.

The narrower language is significant.

Unlike the first category, the provision is tied specifically to the implementation of a treatment or referral plan.

This prevents the category from being interpreted as a broad exemption for every form of data processing carried out by an allied healthcare professional.

For example, where an allied healthcare professional needs to process a child's information to implement a recommended treatment plan, the exemption may apply.

But if the same information is subsequently used for an unrelated commercial purpose, the connection with the treatment plan becomes difficult to establish.

Again, the operative concept is necessity.

5. Educational institutions

The third category is considerably more controversial because it expressly permits activities that Section 9(3) otherwise prohibits.

An educational institution may process children's personal data for:

tracking and behavioural monitoring for its educational activities; or

tracking and behavioural monitoring in the interests of safety of children enrolled with the institution.

This creates an important exception to the statutory prohibition.

The Act's general position is:

no tracking or behavioural monitoring of children.

The Fourth Schedule creates a limited exception:

educational tracking or behavioural monitoring may occur where it falls within the specified educational or safety purposes.

The exemption therefore reflects the practical reality of modern education.

Schools increasingly use digital systems to monitor:

attendance;

academic engagement;

classroom participation;

access to educational platforms;

transportation;

safety systems;

examination activity; and

online learning.

Some of these activities could technically involve tracking or behavioural monitoring.

The Schedule recognises this.

But the condition is critical.

The monitoring must be:

for educational activities

or

in the interests of safety.

The school therefore cannot simply rely on its institutional status.

For example:

A school monitors whether a student attends online classes and interacts with assigned educational material.

This could fall within the educational-activity limb.

But:

The school uses behavioural data to create commercial advertising profiles for third-party advertisers.

That activity is difficult to reconcile with either of the specified purposes.

The distinction is therefore between institutional necessity and commercial opportunity.

The exemption is designed for the former, not the latter.

6. Crèches and child day-care centres

The fourth category applies to an individual in whose care infants and children in a crèche or child day-care centre are entrusted.

The exemption concerns tracking and behavioural monitoring in the interests of the safety of the children entrusted to the care of the institution, crèche or centre.

This could accommodate technologies such as:

child-location systems;

attendance monitoring;

controlled-access systems;

safety alerts;

movement monitoring within a facility; and

systems designed to identify when a child leaves an authorised area.

Again, the drafting does not create a general permission to monitor children.

The monitoring must be connected to safety.

This is particularly important because behavioural monitoring is an extremely broad concept.

A system that determines whether a child has entered an unauthorised area for safety purposes is conceptually different from a system that analyses the child's behaviour to predict purchasing preferences or advertising interests.

The former has a direct connection with the Schedule's objective.

The latter does not.

7. Child transport providers

The fifth category applies to a Data Fiduciary engaged by an educational institution, crèche or child care centre to transport children.

The exemption permits tracking the location of children during the course of travel to and from the institution, where the tracking is in the interests of their safety.

This is a particularly clear example of purpose limitation through geographical and temporal limitation.

The exemption does not simply say:

transport providers may track children.

It effectively limits the processing to:

location tracking

during:

the course of travel

to and from:

the relevant institution

for:

safety.

Each element narrows the exemption.

Suppose a school bus operator tracks a child's location while the child is travelling from home to school. That is precisely the type of processing contemplated.

But suppose the operator continues tracking the child's location throughout the day after the child reaches school, without a separate lawful basis.

The Schedule does not automatically justify that continued tracking.

The exemption therefore illustrates a broader principle running through the Fourth Schedule:

An exemption should be mapped to the precise processing activity rather than to the organisation as a whole.

Part B: Purposes

Part B takes a different approach.

Part A asks:

Who is the Data Fiduciary?

Part B asks:

Why is the personal data being processed?

This is an important distinction.

The exemption can apply because of the purpose of processing, even where the Data Fiduciary does not fall into one of the institutional categories in Part A.

The first purpose concerns the exercise of a power, performance of a function or discharge of duties in the interests of a child under any law in force in India.

The condition is that processing must be restricted to what is necessary for that exercise, performance or discharge.

This accommodates situations where public authorities and other legally empowered bodies need to process children's data pursuant to statutory functions.

For example, a child-protection authority may need to process information about a child to discharge a statutory duty concerning the child's welfare.

Requiring ordinary commercial-style parental consent in such circumstances could conflict with the legal function being performed.

The exemption therefore recognises that there are circumstances in which the law itself places responsibility upon an institution to act in the child's interests.

But the processing must remain necessary.

The phrase "in the interests of a child" is therefore significant.

A statutory function involving children does not automatically make every processing activity legitimate under this exemption. The processing must have a genuine connection with the child's interests and the statutory function.

9. Subsidies, benefits, services, certificates, licences and permits

The second purpose relates to providing or issuing a subsidy, benefit, service, certificate, licence or permit under law or policy or using public funds, in the interests of a child, under Section 7(b) of the Act.

This provision recognises that the State may need to process children's information to provide public benefits.

Examples

may include:

  • educational benefits;
  • child welfare schemes;
  • scholarships;
  • certificates;
  • licences;
  • public services; or
  • other benefits funded through public resources. The condition again imposes necessity. Processing must be restricted to what is necessary for providing or issuing the relevant benefit, service, certificate, licence or permit. This prevents the exemption from becoming a general authorisation for governmental data collection. If a government department requires a child's age and identity to determine eligibility for a scholarship, that processing may fall within the exemption. But unrelated collection or reuse of the child's information would require separate justification.

10. Creation of an email-only user account

The third purpose is particularly interesting.

The Fourth Schedule permits processing for the creation of a user account for communicating by email, provided processing is restricted to what is necessary to create that account and the account's use is limited to email communication.

This appears designed to accommodate relatively low-risk digital services that require an account solely to communicate with the child by email.

The condition is again doing substantial legal work.

The exemption does not apply simply because an organisation creates a user account.

It applies where:

the purpose is communication by email

and

the account is limited to that function.

Consider an educational organisation creating an account for a child solely so that it can send course-related email communications.

That may fall within the provision.

But if the account also enables:

behavioural profiling;

personalised advertising;

social interaction;

recommendation systems; or

extensive platform tracking,

the processing may move beyond the narrowly defined purpose.

The exemption therefore does not create a general exemption for "child accounts."

It creates a narrow exemption for email communication accounts.

11. Real-time location determination

The fourth purpose concerns determining the real-time location of a child.

This is permitted where tracking is in the interest of the child's safety and protection or security.

This provision must be read carefully because real-time location is inherently intrusive.

Location data can reveal:

where a child lives;

where she studies;

whom she visits;

what activities she attends;

her daily routines; and

patterns of movement.

The Schedule nevertheless recognises that real-time location can be necessary for safety.

For example, a child-safety application may need real-time location to enable a parent or authorised caregiver to locate the child during an emergency.

The exemption therefore reflects a balancing exercise built into the Schedule itself.

But the limiting words remain:

real-time

tracking

safety and protection or security.

The provision should not readily support indefinite location surveillance for unrelated purposes.

12. Preventing access to harmful information, services or advertisements

The fifth purpose is particularly significant because it concerns the protection of the child from harmful digital content.

The Schedule permits processing for ensuring that information, services or advertisements likely to cause a detrimental effect on a child's well-being are not accessible to the child. The processing must be restricted to what is necessary to achieve that objective.

This creates an important conceptual distinction.

Section 9(2) prohibits processing likely to cause detrimental effects on a child's well-being.

Part B allows processing that is designed to prevent the child from accessing information, services or advertisements likely to cause such detrimental effects.

The latter is therefore protective processing.

For example, an online platform may need to process age-related information to prevent a child from accessing certain services or advertisements.

The processing is not undertaken to exploit the child's behavioural information.

It is undertaken to prevent exposure to harmful material.

This illustrates that the DPDP framework does not treat all processing concerning children as inherently harmful. Instead, it distinguishes between processing that exploits children's vulnerabilities and processing that protects children from harmful environments.

13. Confirming that the Data Principal is not a child

The sixth purpose is perhaps the most technically interesting.

The Schedule permits processing for confirming that the Data Principal is not a child and for observing due diligence under Rule 10, with processing restricted to what is necessary for that confirmation or due diligence.

This provision addresses a fundamental problem created by the age threshold in Section 9.

If a platform must obtain verifiable parental consent whenever a user is a child, it must first determine whether the user is a child.

But age assurance itself may require processing personal data.

The Schedule therefore creates an exemption that facilitates the very act of determining whether Section 9 applies.

This is a logical necessity.

A Data Fiduciary cannot determine whether parental consent is required without some mechanism for age assurance, unless it simply assumes every user is a child.

The provision therefore creates a narrow legal space for age verification.

The restriction is crucial:

processing must be limited to what is necessary for confirmation or observance of due diligence under Rule 10.

The organisation therefore cannot use the age-verification process as an opportunity to collect additional information unrelated to age assurance.

14. The Fourth Schedule and Rule 10

The final entry in Part B expressly refers to Rule 10.

Rule 10 requires the Data Fiduciary to adopt appropriate technical and organisational measures to ensure that verifiable parental consent is obtained before processing a child's personal data and to observe due diligence in checking that the person identifying herself as the parent is an adult and, where required, identifiable for compliance with law. The Rule provides mechanisms involving reliable identity and age information, voluntarily provided details, and virtual tokens issued by authorised entities.

The Fourth Schedule therefore cannot be properly understood without Rule 10.

There is a sequence:

  1. Determine whether user is a child
  2. If child, determine parent/lawful guardian
  3. Verify parent or guardian
  4. Obtain verifiable consent
  5. Process subject to Section 9

The Schedule's sixth Part B entry provides the legal room necessary for the first stage.

This also demonstrates why the definition of "user account" in Rule 2 is relevant. The Rules contemplate digital interactions through which accounts are created and managed, while Rule 10 provides a technical and organisational framework for age and parental verification.

15. Why Section 9(2) remains outside the Schedule

The omission of Section 9(2) from Rule 12 is deliberate in legal effect, even if the Rules do not separately explain the policy choice.

Section 9(4) itself refers to sub-sections (1) and (3).

Rule 12 follows that statutory limitation.

Consequently, the Fourth Schedule does not provide an exemption from the prohibition on processing likely to cause a detrimental effect on the well-being of a child.

This produces an important distinction:

Situation Fourth Schedule effect

Parental consent under Section 9(1) May be exempted

Tracking/behavioural monitoring/targeted advertising under Section 9(3) May be exempted in specified cases

Detrimental processing under Section 9(2) Not exempted by Rule 12/Fourth Schedule

Thus, even a school, hospital, transport provider or other listed entity must consider whether its processing could cause a detrimental effect on the child's well-being.

The Schedule should therefore not be described as a "child-data exemption" without qualification.

It is more accurately a limited exemption from specified components of Section 9.

16. The necessity condition is the central safeguard

Across both Parts A and B, the most important recurring expression is necessity.

The Schedule repeatedly limits processing to what is necessary:

necessary for protection of health;

necessary to implement a treatment plan;

necessary for educational activities or safety;

necessary for child safety during transportation;

necessary for statutory functions;

necessary for benefits or services;

necessary for email account creation;

necessary for real-time safety tracking;

necessary to block harmful content; and

necessary for age confirmation and due diligence.

This is not accidental repetition.

It is the mechanism through which the Schedule prevents an exemption from becoming an unrestricted authorisation.

The legal question is therefore not simply:

"Does this organisation fall within Part A?"

It is:

"Is this particular processing necessary for the particular purpose for which the exemption has been created?"

That distinction will likely become central to enforcement.

17. The risk of over-reading institutional exemptions

Consider an educational institution.

It falls squarely within Part A.

But that does not mean:

"All processing of children's data by a school is exempt."

The exemption is confined to tracking and behavioural monitoring for educational activities or safety.

Similarly, a hospital does not receive a general exemption from Section 9 merely because it is a healthcare provider.

The processing must be connected to health services and necessary for protecting the child's health.

Likewise, a transport provider cannot argue that all location processing is exempt merely because it transports children.

The location tracking must occur during travel and be for their safety.

The Schedule therefore establishes a functional nexus test:

Institution or purpose

specified activity

specified objective

necessity

=

exemption

Remove one of those elements and the exemption becomes difficult to sustain.

18. The relationship between child protection and surveillance

The Schedule raises a deeper regulatory question.

Section 9(3) adopts a strong anti-surveillance position by prohibiting tracking and behavioural monitoring of children.

The Fourth Schedule recognises that some forms of tracking and monitoring may actually be necessary to protect children.

This creates a distinction between:

surveillance for exploitation

and

monitoring for protection.

For example:

An app tracks a child's location to send behavioural advertisements.

This is fundamentally different from:

A school bus tracks a child's location while travelling to school to ensure that the child has safely reached the institution.

Both involve location data.

Both involve tracking.

But the purpose, context and potential harm are different.

The Schedule therefore introduces a more contextual approach without abandoning the protective architecture of Section 9.

19. Practical case study: school surveillance

Assume a school uses a digital learning platform that records: login time; duration of participation; assignments completed; classroom attendance; interaction with educational content. The school also uses a location system for its school buses. Under Part A, educational tracking and behavioural monitoring may fall within the exemption where used for educational activities or safety. The school bus operator may separately rely on the transport exemption for location tracking during travel. But imagine that the school begins analysing the same behavioural data to predict which commercial products the child is likely to purchase and shares those profiles with advertisers. The processing has moved outside the stated purposes. The institutional exemption does not provide a general safe harbour. The case illustrates why purpose mapping will become particularly important for child-data processing.

20. Practical case study: healthcare

Consider a child receiving treatment at a mental health establishment. The establishment processes information concerning the child's condition, treatment history and clinical interactions. The first Part A category is potentially engaged because the entity is a mental health establishment. The processing is nevertheless confined to health services and what is necessary to protect the child's health. Now suppose the establishment proposes to use the child's treatment history to identify commercially valuable behavioural patterns and provide those patterns to an unrelated marketing company. The fact that the organisation is a mental health establishment does not make the latter processing fall within the exemption. Indeed, the sensitivity of the information makes the distinction even more important. The Schedule is therefore not an institutional immunity. It is a conditional functional exemption.

21. Practical case study: age assurance

Consider a social platform where a user seeks to create an account. The platform needs to determine whether the user is a child. It therefore processes an age-related identifier or uses an authorised virtual token. Part B, item 6, accommodates processing necessary to confirm that the Data Principal is not a child and to conduct due diligence under Rule 10. But once the platform has completed the age-assurance exercise, it cannot automatically assume that all subsequent processing is covered by the exemption. Age verification is one purpose. Advertising, profiling, recommendation and behavioural analytics are other purposes. The exemption for age confirmation cannot simply be carried forward into those activities. This is another manifestation of the principle that the exemption follows the purpose, not the data subject alone.

22. The importance of the definitions in the Note

The Note to the Fourth Schedule contains definitions of expressions including:

  • advertisement;
  • allied healthcare professional;
  • clinical establishment;
  • educational institution;
  • healthcare professional;
  • health services; and
  • mental health establishment.

The corrigendum G.S.R. 892(E) corrected the lettering of these definitions, moving the definitions after "advertisement" to the appropriate sequence.

These definitions matter because the Schedule uses sector-specific terminology.

For example, "educational institution" is expressly described to include an institution of learning that imparts education, including vocational education.

This means that the institutional exemption should not be confined only to conventional schools in the narrow colloquial sense.

The inclusion of vocational education indicates a broader functional conception of educational institutions.

At the same time, an organisation should not assume that any organisation that provides information to children is automatically an "educational institution."

The statutory definition in the Schedule should be applied according to its language and context.

23. Overall interpretation of the Fourth Schedule

The Fourth Schedule is best understood as a controlled exception mechanism embedded within a highly protective child-data regime.

Its architecture can be represented as follows:

  1. Section 9 establishes the child-data regime through three limbs:
  • 9(1): verifiable parental or lawful guardian consent;
  • 9(2): no processing likely to cause detrimental effects on a child's well-being;
  • 9(3): no tracking, behavioural monitoring or targeted advertising.
  1. Section 9(4) creates the power to exempt specified processing from Sections 9(1) and 9(3).
  2. Rule 12 gives effect to that power through theFourth Schedule.
  3. The Fourth Schedule operates in two Parts: Part A (classes of Data Fiduciary) andPart B (purposes of processing).
  4. Each Part attaches conditions, and every exemption remains limited bynecessity for the protected purpose.

The structure reveals something important.

The Fourth Schedule does not dismantle Section 9.

It creates carefully bounded departures from Sections 9(1) and 9(3).

24. Final assessment

The Fourth Schedule represents an attempt to reconcile child protection with the practical necessities of healthcare, education, childcare, transportation, public administration, public benefits, safety mechanisms and age assurance.

Its central regulatory technique is not to declare certain sectors completely exempt.

Instead, it identifies particular situations in which otherwise prohibited processing may occur and then attaches a condition limiting the processing to the relevant purpose.

This distinction is critical.

A hospital is not exempt because it is a hospital.

It is exempt for specified processing connected with health services.

A school is not exempt because it is a school.

It is exempt for specified tracking and behavioural monitoring connected with education or safety.

A transport provider is not exempt from all location tracking.

It is exempt for specified tracking during travel and for safety.

A platform is not exempt from all age-related processing.

It may process information necessary to determine whether a Data Principal is a child and to conduct the due diligence contemplated by Rule 10.

The better formulation is therefore:

The Fourth Schedule does not create categories of organisations that are generally outside the child-data regime. It creates narrowly conditioned circumstances in which specified obligations under Section 9 do not apply to specified processing.

That reading is reinforced by Rule 12 itself, which expressly limits the exemption to Sections 9(1) and 9(3) and makes every exemption subject to the conditions contained in the relevant Part of the Fourth Schedule.

The Schedule consequently establishes a regulatory balance between two competing concerns.

On one side is the need to protect children from unnecessary consent collection, surveillance, profiling and targeted commercial exploitation.

On the other is the reality that some forms of processing are themselves necessary to protect, educate, treat, transport or otherwise serve children.

The law therefore does not treat every instance of child tracking or monitoring identically.

It asks a more precise question:

What is the purpose of the processing, who is carrying it out, what precisely is being processed, and is the processing confined to what is necessary for the protected purpose?

That is the question on which the availability of the Fourth Schedule exemption ultimately turns.

Core statutory mapping

DPDP Act / RulesFunction in the framework
Section 2(f)Defines a child as an individual who has not completed eighteen years
Section 5Establishes the notice obligation
Section 6Establishes requirements for valid consent and withdrawal
Section 7Provides certain legitimate uses, including specified State/public-benefit processing
Section 9(1)Requires verifiable parental/lawful guardian consent
Section 9(2)Prohibits processing likely to cause detrimental effects on a child's well-being
Section 9(3)Prohibits tracking, behavioural monitoring and targeted advertising
Section 9(4)Creates the statutory power for exemptions from 9(1) and 9(3)
Rule 3Operationalises the notice requirements
Rule 10Operationalises verifiable parental consent and due diligence
Rule 12Gives effect to the Fourth Schedule
Fourth ScheduleSpecifies exempt classes, purposes and conditions

The DPDP Act's child-data framework is therefore not a simple "parental consent" regime. It is a layered framework comprising consent, substantive protection against harmful processing, restrictions on surveillance and advertising, age assurance, parental verification and narrowly defined exemptions. Section 9 provides the substantive architecture, while Rules 10 to 12 provide the mechanisms through which that architecture becomes operational.

In short:

Rule 3 regulates how a Data Fiduciary must communicate before seeking consent. The Fourth Schedule regulates when certain child-data protections may be displaced. The former is principally a transparency mechanism; the latter is an exception mechanism. But both are governed by the same underlying idea: a Data Fiduciary should not be permitted to rely on formal compliance while defeating the substantive purpose of the Act.

Currentness note: Rule 3 and Rule 12, and therefore the Fourth Schedule, are in the eighteen-month commencement group under Rule 1(4), whereas Rules 1 and 2 are already in force. The Rules were notified on 13 November 2025 and the commencement structure is therefore materially relevant when describing these provisions as presently operative.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.