Children’s Data Protection Under The DPDP Act, 2023: A Legislative Analysis
Archi Ghiya, LL.M. (Technology & Law), Hidayatullah National Law University, Nava Raipur, Chhattisgarh, India
Introduction
India’s digital infrastructure has expanded rapidly, fundamentally changing how children interact with the online ecosystem. As digital learning, online gaming, social media platforms and e-commerce become deeply embedded in everyday routines, massive quantities of minors’ personal information are constantly generated, collected and commercialized. To counter the increasing risks of online exploitation, dynamic behavioral profiling, and algorithmic steering, India passed the “Digital Personal Data Protection Act, 2023 (DPDP Act)”. This landmark legislation, primarily focusing on Section 9 of the legislation, provides a specific legal regime for dealing with children’s personal data and is operationalized by the Digital Personal Data Protection Rules, 2025.
India’s legal framework imposes a mandatory “triple lock” system to protect young users: mandatory verifiable parental consent, harm-centric restrictions on processing data that adversely impacts the well-being of a child, and a strict prohibition on tracking, behavioral surveillance and targeted advertising to minors. Although these safeguards reflect a strong legislative commitment to protect children online, they also present complex operational, constitutional and normative challenges. The statute contravenes international human rights standards that recognize the evolving capacities of growing children by imposing an unflexible age threshold of eighteen years for adulthood, and thus subjecting adolescents to the same restrictions as toddlers.
This report details the legal analysis of privacy of children’s data under the DPDP Act, 2023 and the DPDP Rules, 2025. It looks at the governing statutory provisions, procedural rules, relevant constitutional case law, major structural constraints, and key opportunities for policy change.
