Children's Data Protection

Section 9 Compliance for Children's Data Protection

The DPDP Act places the highest obligations on organizations that process personal data of children (under 18). Section 9 mandates verifiable parental consent, bans profiling of minors, prohibits behavioural advertising targeting children, and restricts tracking. dcomply's module helps you register every system processing children's data, enforce all five Section 9 requirements, and maintain an audit-ready compliance register.

Try the live product
Age Gate
Parental Consent
No Profiling
No Ads
No Tracking
The Problem

Five Section 9 Obligations. Most Organizations Miss Several

Section 9 is not a single rule but five stacked obligations. Missing any one is a separate violation with up to ₹200 Crore penalty

Five Distinct Section 9 Obligations

Section 9 is not a single rule but five stacked obligations: (1) verifiable parental consent, (2) age verification, (3) no profiling, (4) no behavioural advertising, (5) no tracking. Missing any one is a separate violation with up to ₹200 Crore penalty.

Age Verification Is Technically Challenging

Simply asking "Are you over 18?" is not "verifiable." The DPDP Act requires actual verification. Aadhaar-linked, school ID, parental confirmation, or AI-based age estimation. Most organizations have no compliant mechanism.

No Centralised Children's Data Register

Organizations don't know which of their systems process children's data. Without a register, you cannot demonstrate compliance, and regulators will assume non-compliance if you cannot show evidence.

Capabilities

Complete Section 9 Compliance Across All Your Systems

Children's Data Register

Register every system or product that processes data from users under 18. Track data categories, estimated minor user count, and system-level compliance status.

Age Verification Tracking

Document the age verification method used for each system: self-declaration, Aadhaar-based verification, school ID, AI-based age estimation, or parental confirmation. Know exactly how you verify age across all products.

Parental Consent Management

Track whether verifiable parental consent has been obtained, the consent method used (email verification, signed form, digital signature, in-app), and when consent was given. Linked to the Parental Consent module in your consent widget.

Section 9 Safeguards Checklist

Per-system checklist confirming all five Section 9 requirements: age gate active, parental consent obtained, profiling disabled, behavioural ads blocked, tracking restricted. Visual compliance score per system.

Compliance Score per System

Each registered system gets a Section 9 compliance score (0–100%) based on how many of the five requirements are met. Instantly see which systems need attention.

Section 9 Compliance Register

Export a complete Children's Data Protection Register as PDF, showing all systems, age verification methods, parental consent status, and safeguard implementation. Essential for DPB inspections.

How It Works

Section 9 Compliance in 4 Steps

From registering your systems to a DPB-ready compliance register, structured and audit-proof.

Register each system processing children's data

For each app, website, or service that has under-18 users, create a record with the data categories collected, estimated minor count, and age verification method.

Document parental consent

Record how parental consent is obtained and verified. Link to the consent widget's parental verification flow for automatic tracking of verified consents.

Confirm all 5 Section 9 safeguards

Mark each safeguard as implemented: age gate, parental consent, profiling restriction, behavioural ad block, tracking restriction. Get DPO review sign-off per system.

Monitor and maintain

Get alerts for systems due for review. Mark systems as Compliant once all safeguards are verified. Export your register for regulatory inspections.

FAQ

Frequently Asked Questions

Section 9 of the DPDP Act prohibits processing personal data of children without: (1) verifiable parental or guardian consent, (2) appropriate age verification. It also prohibits (3) profiling of minors, (4) behavioural advertising targeting minors, and (5) tracking or monitoring children without parental consent. The maximum penalty for Section 9 violations is ₹200 Crore. Importantly, Section 9(4) provides an exemption for healthcare providers and educational institutions processing children's data for legitimate purposes without commercial intent.

The DPDP Act requires consent that can be verified, not just a checkbox clicked by a child. Acceptable methods include: Aadhaar-linked age verification (where the parent's Aadhaar is used to confirm the child's age), email-based parental confirmation (parent receives and clicks a verification link), signed consent forms, digital signatures, and in-app parental confirmation flows. Simple "I am over 18" checkboxes are not considered verifiable.

Section 9 applies to all Data Fiduciaries who knowingly process personal data of children, or those where it is reasonably foreseeable that children may use their service. Organizations offering consumer-facing apps, games, educational platforms, social media, or any service without strict 18+ enforcement are likely covered. Section 9(4) provides an exemption for healthcare providers and educational institutions acting in the legitimate interest of children.

Build Your Children's Data Compliance Register

Section 9 compliance, the DPDP Act's most penalized provision

View All Features