Children’s Data Under DPDP: Why Your Onboarding Flow is Now a Liability

Children’s Data Under DPDP: Why Your Onboarding Flow is Now a Liability

Digital products can no longer treat kids like adults. See how the new rules for children data protection india force companies to rethink UX and consent.

Priyanka Choudhury

Written by

Priyanka Choudhury

Date

Read time

5 min

A child downloads a game on a parent’s phone.

It asks for a name. Then a phone number. Then permission to access contacts.

Within minutes, the child is playing. The parent assumes it is harmless. But behind the scenes, the app has just ingested a surprising amount of personal information.

Until recently, many digital products treated children and adults exactly the same when it came to data collection. A user was a user. A data point was a data point. The Digital Personal Data Protection Act (DPDP Act), 2023, ends that illusion.

Under the new rules for children’s data protection India is enforcing, companies building digital products can no longer hide behind a generic Terms of Service link. They must fundamentally rethink onboarding, consent, and data collection.

Who Is Considered a Child Under DPDP

Under the DPDP Act, a child is defined as anyone under 18 years of age.

This definition, found in Section 2(f) of the Act, is a massive operational shift.

This is important because many global privacy laws set the threshold differently. For example, the EU’s GDPR sets the default age at 16, with member states permitted to lower it to a minimum of 13. The United States COPPA law applies only to children under 13.

India’s privacy law sets a much harder bar: anyone under 18.

That means platforms that spent years assuming teenagers could independently use services must now rethink how accounts are created, managed, and verified.

Section 9 of the DPDP Act contains the principal obligations relating to children’s personal data, including parental consent requirements and restrictions on certain forms of processing.

It states that before processing the personal data of a child, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian.

The word verifiable is doing a lot of heavy lifting here.

No flimsy checkbox.

Companies cannot simply rely on a flimsy checkbox that says “I confirm I am over 18” if they reasonably expect children to use the service. A checkbox is not verification. It is a well-written lie.

They must implement mechanisms that reasonably verify parental consent.

What This Means for Real Products

Many popular digital products collect children’s data in subtle, frictionless ways. Frictionless is great for growth. It is terrible for compliance.

Consider how this breaks down in practice.

Example 1: Gaming Apps

A mobile gaming app allows users to create accounts using:

  • a username
  • email address
  • device identifiers
  • gameplay data

If children under 18 are likely to use the game, the company must ensure parental consent is obtained before collecting and processing this data.

That may require changes such as parental email verification, guardian approval workflows, and actual age verification during signup.

Without these mechanisms, the platform is not just risking a poor user experience. It risks violating the Act.

Example 2: Online Learning Platforms

An EdTech platform may collect the following:

  • student names
  • school information
  • performance analytics
  • behavioral learning data

Since many users are minors, the platform must ensure that parents or guardians approve data collection and usage.

The system cannot rely on a student clicking “Accept”. It might need to route consent requests directly to parents.

Example 3: Social Platforms Used by Teenagers

Social media platforms frequently collect large amounts of data, including:

  • profile information
  • location data
  • browsing behavior
  • content interaction patterns

If teenagers under 18 are using the platform, companies must ensure compliance with the parental consent requirement.

This is not a minor tweak to the privacy policy. It has major implications for account creation flows and identity verification.

Restrictions on Harmful Processing

The DPDP Act children provisions do not just care about how you collect data. They care about what you do with it.

Under Section 9, Data Fiduciaries must not process children’s personal data in ways that are likely to cause detrimental effects on the well-being of the child.

The law also restricts behavioral monitoring and targeted advertising directed at children.

Example:

Suppose a video platform analyses children’s viewing habits to serve highly targeted advertisements.

If those ads rely on profiling or behavioral tracking of children, the practice may violate the Act’s restrictions.

This means companies must carefully examine how recommendation algorithms and advertising systems interact with child users.

Why This Matters to Parents

Parents often assume that when their children use apps, those apps are designed with children’s safety in mind.

But historically, many digital services were built primarily for adults and simply extended to younger users.

The DPDP Act is pushing companies to change that.

For parents, this means greater expectations that

  • children’s data will not be collected casually
  • platforms will seek parental approval before processing data
  • products will avoid practices that could harm children

In short, the law shifts the responsibility toward the companies building these digital environments.

A Major UX Shift for Digital Products

For product teams, the implications of Data Protection India are significant.

Age verification, parental consent workflows, and restricted data practices may require redesigning user journeys.

Need of parental approval systems

Signup flows may need to detect and route minors to parental approval systems. Certain personalisation or advertising features may need to be disabled for younger users.

This is not just a legal change. It is a product design challenge.

Teams that treat privacy and child protection as part of the user experience will adapt more easily than those treating compliance as an afterthought bolted onto the end of a sprint.

A Reminder of Who Data Laws Are Ultimately For

At its core, the DPDP Act recognises something simple.

Children often do not fully understand the consequences of sharing personal information online.

That is why the India data privacy law places responsibility on organisations to act more carefully when handling their data.

For parents, the goal is reassurance.

For companies, the message is clear.

If your product reaches young users, protecting their data is not optional. It is a legal obligation and an ethical one.

The precise implementation of children’s-data obligations depends on the DPDP Act, the Rules issued under it, and any exemptions or relaxations notified by the Government from time to time.

If your product reaches young users, protecting their data is a legal obligation. Regodit helps you meet it.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →