How is a child's personal data protected under the DPDP Rules, 2025?

Reviewed by: Santosh Raut
Senior IT Architect & Privacy Technology Consultant
Last Updated: 05 June 2026

Answer:

Before processing a child's personal data (a child is anyone under 18), a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian, and confirm the adult is identifiable using reliable identity and age details or a virtual token. The Act prohibits tracking, behavioural monitoring of children and targeted advertising directed at them. Certain classes such as healthcare and educational institutions may be exempted for specified purposes.
children verifiable parental consent age 18 tracking targeted advertising