What does DPDP require for processing a child's personal data? Section 9 of the DPDP Act 2023 sets a strict regime for anyone whose service may be used by children (defined as under 18 in India). Before processing a child's personal data, the Data Fiduciary must obtain verifiable consent from a parent or lawful guardian — not the child's own consent. The Act also expressly prohibits processing that is likely to cause any detrimental effect on a child's wellbeing, and bans tracking, behavioural monitoring and targeted advertising directed at children. This means an age-appropriate service needs a real age-gate, a verifiable parental-consent mechanism, and a data-use design that switches off the behavioural tracking and ad targeting used for adults. A children consent DPDP India minor flow built around Section 9 is one of the highest-risk areas of the Act — violations sit in the up-to-₹200-crore penalty band. This generator produces that Section 9 flow tailored to your service.
Generate a DPDP Section 9 consent flow for services that may be used by minors — age-gating, verifiable parental consent, and a data design that switches off behavioural tracking and targeted ads for children.
Section 9 of the DPDP Act 2023 imposes three core obligations on any Data Fiduciary whose service may be used by a child — defined in India as anyone under 18. First, before processing a child's personal data, you must obtain verifiable consent from a parent or lawful guardian; the child's own consent is not sufficient. Second, you must not undertake processing likely to cause a detrimental effect on the wellbeing of a child. Third, you are prohibited from tracking, behavioural monitoring, and targeted advertising directed at children. This section maps each obligation to your specific service based on whether children are a primary, mixed or incidental audience.
Crucially, Section 9 can apply even where children are not your intended audience — if minors may use the service and you have no reliable way to keep them out, the obligations can attach. That is why the map treats age-gating as the gateway control: without knowing which users are minors, you cannot apply the different rules Section 9 requires for them. Because violations involving children's data sit in the highest penalty band (up to ₹200 crore), and because a Data Fiduciary handling children's data at scale may also be designated a Significant Data Fiduciary with extra obligations, this section flags exactly where your service carries elevated risk.
Everything in a Section 9 flow depends on first knowing whether a user is a child, so age determination is the foundation. A bare self-declared date of birth is weak — a child can enter any date — so this section sets out a proportionate, layered approach: a neutral age-gate that does not encourage under-age users to lie, escalating verification signals where the risk is higher, and a clear branch in the flow so that any user who indicates they are under 18 is routed into the parental-consent path rather than the standard adult sign-up. The right level of verification is proportionate to your service: a general app with incidental minors needs less than a platform built for children.
The design also covers what happens at the branch point: for a user identified as a minor, the service must pause standard onboarding and seek verifiable parental consent (section 3) before processing beyond what is strictly necessary, and must switch the account into a mode where behavioural tracking and targeted ads are off (section 4). This section gives you the age-gate copy, the decision logic, and the handling for edge cases — a user who changes their date of birth, an existing account later found to belong to a minor, and mixed family accounts — so the gate is robust rather than a checkbox a child clicks past.
Data uses selected for Section 9 review:
The children consent DPDP India minor regime lives in Section 9 of the DPDP Act 2023, and it is among the strictest parts of the law. A child in India is anyone under 18. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian — the child cannot consent for themselves. The Act separately prohibits any processing likely to cause a detrimental effect on a child's wellbeing, and bars tracking, behavioural monitoring and targeted advertising directed at children. These are not consent-can-cure rules: even with parental consent, you cannot behaviourally track or target ads at a minor.
Because the obligations can attach wherever minors may use a service, the practical starting point for almost every consumer product is a reliable way to tell adults and children apart — age-gating — followed by a parental-consent path and a data-use mode for minors that switches off the profiling and advertising machinery used for adults. Violations involving children's data fall in the up-to-₹200-crore penalty band, and a Fiduciary processing children's data at scale may be designated a Significant Data Fiduciary with additional obligations, so Section 9 is a compliance area to get right early, especially with enforcement expected around May 2027 under the DPDP Rules 2025.
The fear with Section 9 is that verifiable parental consent and a no-tracking design will make a product unusable — but the Act allows a proportionate response scaled to risk. A general app where minors are incidental needs a neutral age-gate and a clear parental-consent branch; a platform built for children needs stronger verification and a fully non-personalised experience by default. This generator produces the whole flow — obligations map, age-gate, parental-consent mechanism, tracking/ads switch-off, age-appropriate copy and records — scoped to whether children are your primary, mixed or incidental audience, so the design fits your actual risk rather than over-engineering.
Children's data is one of the two highest-penalty areas of the DPDP Act, so it is worth getting right with expert input rather than guesswork. Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) for EdTech, gaming and consumer platforms that need a defensible Section 9 flow — verifiable parental consent, a compliant data-use design, and the records to prove it — built and documented against how your specific service actually works.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.