A Record of Processing Activities (RoPA) documents what data you collect, why, where it's stored, and who accesses it—but child data under 18 comes with strict default rules: verifiable parental consent, no tracking, no behavior monitoring, and no targeted advertising.
The Fourth Schedule of DPDPA provides narrow exemptions for specific organizations (hospitals, schools, daycare, caregivers) that must process child data for health or safety purposes—Sections 9(1) and 9(3) don't apply to them within those limited use cases.
Ankur Technology avoided this complexity entirely by declaring all services 18+ and refusing to collect children's data—a smart compliance strategy for most businesses.
If you ever start training minors, you must follow Section 9: obtain verifiable parental consent, avoid behavior tracking, and never target children with advertising.
