Any service that processes the data of under-18s is bound by Section 9, the sharpest DPDP-specific requirement there is.
In short
Under the DPDP Act, anyone under 18 is a child. Section 9 requires verifiable parental consent (Rule 10, via a government- or law-authorised identity/age or virtual-token mechanism) and bans tracking, behavioural monitoring and targeted ads at children outright. Rule 12 and the Fourth Schedule give only narrow, purpose-bound exemptions. Children-data penalties reach ₹200 crore.
What changes for this niche, and the specific rule it turns on.
Rule 10 requires verifiable consent from a parent or guardian, verified using reliable identity and age details or a virtual token issued by a government- or law-authorised entity, before processing a child's data.
Section 9(3) bans behavioural tracking, monitoring and targeted advertising at children, regardless of consent.
Rule 12 and the Fourth Schedule give narrow, conditional exemptions to certain fiduciary classes (clinical and mental-health establishments, healthcare and allied professionals, educational institutions, creche and child-transport providers) and defined purposes (child safety, state benefits, age assurance), disapplying only s9(1) and s9(3), never s9(2).
Gate accounts by age so you know when Section 9 applies, and treat not-aimed-at-children cautiously if children use it in practice.
Even where exempt, you must not process a child data in a way likely to harm their well-being (s9(2)).
Short, cite-able answers, mirrored in FAQPage schema.
Stand up age assurance and verifiable consent first.
The readiness check flags age-assurance, consent and tracking gaps.
Take the readiness check →