The DPDP Act's Hardest Test: 450 Million Children by 2027
Date Published
.png&w=3840&q=75)
India has more than 450 million people under the age of 18. The European Union, the bloc whose roughly 449 million people the GDPR was designed to protect, is approximately the same size. Europe built an entire regulatory apparatus to protect that population. India must protect a comparable number of children alone, under a single domestic law, the Digital Personal Data Protection Act, in the 18 months before enforcement begins on 13 May 2027.
That comparison is not rhetorical. It frames the scale of what Indian enterprises are being asked to get right, for a population larger than almost any country on earth, on infrastructure that was not built for it.
Why Children's Data Is the Hardest Part of DPDP Compliance
The DPDP Rules, 2025, notified on 13 November 2025, place children's data in the highest obligation tier. A data fiduciary processing the data of a child must obtain verifiable parental or guardian consent before doing so. No consent from the child. Not a self-declared age checkbox. Verifiable consent from an adult who is confirmed to be the child's parent or guardian. IDfy's detailed guide on protecting children's data under the DPDP Rules covers the specific legal requirements enterprises need to map against.
This is harder than it sounds, and the difficulty is structural, not technical. Western consent models assume one person, one device, one account, one language. India is different in every one of those dimensions. A SIM registered to an adult is frequently shared across a household, so the account holder's age tells a platform nothing about who is actually using it. Nearly 90 percent of children aged 14 to 16 already have smartphone access at home, according to a 2024 government-backed survey. The DPDP Act requires consent notices in English or any of India's 22 scheduled languages, yet most platforms publish only in English, which means parents are being asked to consent to terms they cannot read.
And parents are not always the vigilant gatekeepers consent frameworks assume. Policy research finds parents are often aware their children misrepresent their age online, and sometimes help them do it.

What the Evidence Already Shows
The compliance gap is not theoretical. An independent assessment of 14 widely used platforms against 14 DPDP-derived criteria, covering 196 separate evaluations, found 71 percent outright non-compliant. Tracking and parental consent failures appeared at or near 100 percent across every risk tier assessed. This is a structural, industry-wide gap, not a handful of bad actors.
Social platforms and general purpose AI tools carried the highest average risk score in that assessment, at 88 percent. Private edtech platforms averaged 65 percent, driven by learning analytics, gamified tracking, and weak consent flows. Edtech is particularly exposed because K-8 students show engagement rates 3 to 5 times higher with gamified content, which is exactly why the tracking exists in the first place, and exactly why the consent obligations attach to it.
The breach record reinforces the picture. One Indian edtech provider left the records of more than 50,000 schoolchildren, parents, and teachers exposed on unsecured servers, reportedly without acting for days after being notified. A separate 2024 incident exposed more than 2 million student records, including academic performance and psychological assessments, through misconfigured cloud storage. A 2025 disclosure alleged a breach affecting 426,000 users, with a seller claiming 22 terabytes of exfiltrated data.
Because India's breach visibility infrastructure is still maturing, the National Human Rights Commission estimates roughly 40 percent of identity theft cases go unreported. Any public count of children's data harm in India is a floor, not the real figure.
What GDPR Enforcement Tells Indian Enterprises About What Is Coming
European enforcement offers a preview. A third of all GDPR fines levied on social media platforms, 4 out of 13, relate specifically to mishandling children's data, totalling roughly 765 million euros. Individual penalties in that category have run into the hundreds of millions of euros for issues as specific as child accounts defaulting to public visibility or family pairing transparency failures. The largest children's data breach on record anywhere sits in the United States, where a single incident exposed more than 62 million student records, traced to one missing baseline control, and produced 55 consolidated lawsuits.
India's own penalty ceiling for children's data violations under the DPDP Act is ₹200 crore, with platform blocking available in extreme cases. That ceiling was set at a scale comparable to GDPR level enforcement, not a fraction of it. The National Human Rights Commission has already opened a probe based on the independent platform assessment cited above and directed MeitY to pursue enforcement action, before enforcement formally begins.
The Two Technical Problems Enterprises Have Not Solved Yet
Parental consent for a child's data involves two separate, difficult problems. Most compliance programmes treat them as one.
The age problem. Proving how old a user actually is, without demanding identity documents from every child for every use case, is genuinely hard. The more reliable the age check, the more sensitive the data it collects from a minor. Self-declared age is not proof. A checkbox that asks a user to confirm they are 18 or older is not age verification. Under the DPDP Act's significant data fiduciary obligations, the standard expected from high-risk platforms is meaningfully higher than a declaration.
The relationship problem. Even once an adult is confirmed, almost no framework anywhere has solved how to confirm that this specific adult is the parent or guardian of this specific child. Verifying that someone is an adult is fairly routine for any enterprise with KYC infrastructure. Verifying that they are the right adult for a particular child is not. That gap sits between current practice and what verifiable parental consent actually means under the DPDP Act.
"A checkbox proves a click happened," as Privy by IDfy frames it. "It does not prove the clicker was an adult, was the parent of that child, understood what they were agreeing to, or can withdraw it later. That is the gap between what most platforms have today and what the DPDP Act actually requires."
What the Law Specifically Requires Before May 2027
The DPDP Rules place children's data at the top of the obligation hierarchy. Before a data fiduciary processes any personal data of a child, it must:
- Obtain verifiable consent from the child's parent or guardian, not the child.
- Deliver the consent notice in a language the parent can actually read.
- Not use that data for behavioural tracking, targeted advertising, or profiling the child.
- Maintain an auditable consent record showing who consented, when, for what specific purpose, and how the parental relationship was established.
- Enable withdrawal that is as easy as the original consent capture.
Platforms that currently run behavioural analytics, personalisation engines, or ad targeting against user accounts that could belong to children need to treat the under-18 threshold as a hard segmentation boundary, not a best-effort filter. A platform that cannot distinguish a child's account from an adult's account cannot satisfy these obligations.
What "Verifiable Parental Consent" Requires as Infrastructure
Privy by IDfy's view is that the industry's instinct to treat parental consent as a UX detail, a checkbox or a pop-up to be designed once and forgotten, will not survive scrutiny under the DPDP Act. Verifiable consent is a system, not a screen.
That system requires several capabilities working together. Consent governance that treats every child's data differently from an adult's by default. Age gating that is proportionate to risk rather than uniform. Parent-linked consent records that capture who consented, when, for what purpose, and how the relationship was established. Multilingual notices that actually reach non-English-speaking parents. Consent withdrawal that is as easy as consent capture. Clear segmentation of child data from adult data pipelines. And an audit trail immutable enough to answer a regulator's question about any single child's consent on demand.
"India is being asked to build the largest child data protection system in the world, for more children than the entire European Union has people, on infrastructure built for a single-person, single device world," as Privy by IDfy frames the challenge. "That mismatch is the real story here, not the regulation itself."
How Privy by IDfy Supports Children's Data Compliance
Privy by IDfy is a full-stack DPDPA compliance platform with 30+ live implementations across BFSI, fintech, ecommerce, and digital services. The consent governance platform handles consent lifecycle management natively, including the purpose-linked, parent-attributed, multilingual, and audit-ready consent records that children's data obligations require.
Data Compass discovers and classifies personal data across systems, enabling enterprises to identify where child-attributed data currently sits, which pipelines it flows through, and whether the right consent records exist for each processing purpose. Privacy Impact Assessments built into the platform include a specific trigger for child data processing, since this is one of the high-risk activities the Act's obligations attach to most firmly.
Conclusion
May 2027 is not a grace period. It is a build deadline. Enterprises that collect data from users who could be children need to treat the under-18 threshold correctly, build real age gates that route into a genuine consent flow, stand up parent-linked and auditable consent records, localise notices into the languages parents actually read, and switch off behavioural tracking and ad personalisation for any account flagged as a child's.
The companies that start now will have a working system by the time the law requires one. The ones that wait will be building it under regulatory scrutiny, in public, with 450 million children's worth of obligations to account for. If you want to discuss how Privy can help your enterprise build verifiable parental consent infrastructure ahead of the May 2027 deadline, write to shivani@idfy.com.
FAQ's
What does the DPDP Act require for children's data?
The DPDP Act requires data fiduciaries to obtain verifiable parental or guardian consent before processing any personal data of a child under 18. The consent notice must be in a language the parent can read. Behavioural tracking, targeted advertising, and profiling of children are prohibited.
How many children in India are protected under the DPDP Act?
More than 450 million people in India are under 18, including over 260 million school-going children. This is the largest child data protection mandate by population in the world, comparable in scale to the entire EU population protected under GDPR.
What is verifiable parental consent under the DPDP Act?
Verifiable parental consent means consent obtained from the child's parent or guardian, confirmed through a mechanism that goes beyond self-declaration. The consent record must be auditable, purpose-linked, and as easy to withdraw as it was to give.
When does children's data enforcement begin under the DPDP Act?
The DPDP Rules, 2025 were notified on 13 November 2025. Substantive obligations, including children's data protections, take effect on 13 May 2027.
What are the penalties for mishandling children's data under the DPDP Act?
The DPDP Act sets a penalty ceiling of ₹200 crore for violations related to children's data, with platform blocking available as an additional consequence in extreme cases.
How compliant are Indian platforms with children's data obligations today?
An independent assessment of 14 widely used platforms against DPDP-derived criteria found 71 percent outright non-compliant, with tracking and parental consent failures at or near 100 percent across every risk tier.
.png&w=3840&q=75)
How Indian marketing teams meet DPDPA in 2026: consent management for marketing, email marketing compliance, cookie consent, and data strategy.
India's first DPDP penalty may come from an AI workflow, not a breach. Here's why consent, purpose limitation, and AI governance are now your biggest compliance risks.