How is a child's personal data protected under the DPDP Rules, 2025?
Answer:
Before processing a child's personal data (a child is anyone under 18), a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian, and confirm the adult is identifiable using reliable identity and age details or a virtual token. The Act prohibits tracking, behavioural monitoring of children and targeted advertising directed at them. Certain classes such as healthcare and educational institutions may be exempted for specified purposes.
children verifiable parental consent age 18 tracking targeted advertising
Related Questions:
- By when do organizations need to technically integrate with Board-registered Consent Managers?
- Is the consent notice required to give contact details?
- What makes consent valid under Section 6 of the DPDP Act?
- Must a Data Fiduciary maintain data accuracy?
- What is the right to correction and erasure?
- How are DPDP penalties determined by the Board?