{GyaanGRID}
17. Understanding Child Data Rules
ISSUE #100Published: 9/27/2026

17. Understanding Child Data Rules

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

Under DPDPA Sections 9(1) and 9(3), any company processing data of a child under 18 must obtain verifiable parental consent and is strictly prohibited from tracking, behavior monitoring, targeting, or serving individualized advertising to the child.

The Fourth Schedule provides narrow exemptions for specific organizations—hospitals, schools, daycare centers, and caregivers—that must process child data for health or safety purposes, but only within those limited use cases.

Ankur Technology avoided this complexity entirely by declaring all services 18+ and refusing to collect children's data—a smart compliance strategy for most businesses.

If you ever expand to training minors, you must follow Section 9: verifiable parental consent, zero behavior tracking, and no targeted advertising to children.