Children’s data: the strictest obligations in Indian data protection law.
Under Section 9 of the DPDP Act, anyone under 18 is treated as a child, a uniform national threshold, stricter than GDPR’s 16 or the US COPPA standard of 13. If your platform processes a child’s personal data, name, academic records, attendance, learning patterns, or anything else, you need verifiable parental consent before you process it at all.
Three restrictions apply absolutely, regardless of what parents consent to and regardless of whether it’s core to your product: no behavioural tracking or monitoring of children, no targeted advertising directed at children, and no processing likely to cause detrimental effect to a child’s wellbeing. A learning app that personalises ads based on a child’s activity, or a gamified product using engagement-maximising design on minors, sits directly in the zone regulators are watching. Penalty exposure for violations runs up to ₹200 crore.
If you work through schools
Where you provide services to students through a school, the school is generally the Data Fiduciary and your platform sits as the Data Processor, with the school responsible for consent and your platform contractually bound to process data only within DPDP-compliant limits. Getting this contractual allocation right with your school partners is not optional paperwork, it’s the thing that determines who’s actually liable if something goes wrong.