16.  Record of Processing Activites
ISSUE #99Published: 9/27/2026

16. Record of Processing Activites

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

A Record of Processing Activities (RoPA) documents what data you collect, why, where it's stored, and who accesses it—but child data under 18 comes with strict default rules: verifiable parental consent, no tracking, no behavior monitoring, and no targeted advertising.

The Fourth Schedule of DPDPA provides narrow exemptions for specific organizations (hospitals, schools, daycare, caregivers) that must process child data for health or safety purposes—Sections 9(1) and 9(3) don't apply to them within those limited use cases.

Ankur Technology avoided this complexity entirely by declaring all services 18+ and refusing to collect children's data—a smart compliance strategy for most businesses.

If you ever start training minors, you must follow Section 9: obtain verifiable parental consent, avoid behavior tracking, and never target children with advertising.