March 20, 2026 · DPDP Rules 2025, Rule 10
Protecting Children's Data: How Verifiable Parental Consent Works
Before processing a child's data, fiduciaries must verify a parent's identity using reliable details, a virtual token or DigiLocker, and must not track or target children.
Rule 10 requires Data Fiduciaries to obtain verifiable parental consent before processing the personal data of a child (under 18). Acceptable verification methods include reliable identity details already held by the fiduciary, a virtual token mapped to verified identity, or a Digital Locker (DigiLocker) / authorised identity verification service.
The rules also prohibit tracking, behavioural monitoring and targeted advertising directed at children. Limited exemptions apply to specified healthcare, educational and child-safety activities under Schedule IV.
children, verifiable parental consent, digilocker, rule 10, age verification