India's DPDP Act treats anyone under 18 as a child. DPDP Comply age-gates your consent banner, verifies a parent or guardian through an email one-time code, and blocks tracking and targeted ads for minors — the way Section 9 requires.
Age gate on demand · A per-project threshold you control
What Section 9 requires
Under India's DPDP Act 2023, a child is anyone under 18. Before processing a child's personal data, a data fiduciary must obtain the verifiable consent of a parent or lawful guardian — and the same protection extends to a person with a disability who has a lawful guardian. Section 9 also forbids any processing likely to have a detrimental effect on a child, and specifically bars tracking, behavioural monitoring, and targeted advertising directed at children. DPDP Comply is built to satisfy each of those duties out of the box.
Children's data, handled
The same widget that collects everyday consent handles minors correctly — from the age gate to the guardian verification to the day the child comes of age.
Before the consent banner appears, the widget asks the visitor whether they meet your age threshold — a per-project setting, defaulting to 18, the age the DPDP Act treats as a child.
A visitor under the threshold cannot self-consent. A parent or legal guardian is emailed a one-time code, and consent is only recorded once that code is verified — the verifiable consent Section 9(1) requires.
When a child's date of birth is captured, their consent is automatically expired the moment they reach your age threshold, with the guardian notified — no manual clean-up needed.
Purposes flagged as tracking, behavioural monitoring, or targeted advertising can never be granted for a minor. It is enforced in the widget and again as a server-side backstop, per Section 9.
How it works
When a visitor says they're under your threshold, the widget walks them through verifying a parent or guardian — and refuses to record consent until that verification succeeds.
A short screen asks whether the visitor is at or above your threshold. Answer yes and the normal banner appears; answer no and the guardian flow begins.
The child enters a parent or legal guardian's email and relationship. A six-digit one-time code is sent to that inbox — nothing is recorded yet.
Entering the code proves the guardian authorized this. Verification issues a short-lived, project-bound session — the only way a minor's consent can be written.
The consent is stored as a minor record naming the verified guardian, and a guardian portal token lets that parent review or revoke it at any time.
Every step is evidenced. A verified guardian is named on the consent record, a blocked tracking purpose is logged for compliance reporting, and an aged-out expiry is written to the audit trail — so you can prove how a child's data was handled at each stage.
Why it matters
For adults, consent under the DPDP Act must be free, specific, informed and unambiguous (Section 6). For children, the bar is higher: the consent must come from a parent or lawful guardian and be verifiable, and whole categories of processing — tracking, behavioural monitoring and targeted advertising directed at children — are simply off the table. Getting this wrong is one of the Act's clearest lines to cross.
DPDP Comply turns those duties into product behaviour: the age gate, the guardian OTP, the tracking backstop, and the automatic aged-out expiry all run without you writing a line of code. The exact procedural details of “verifiable” consent are being set by the DPDP Rules (draft Rules published in 2025) and may change. This is general information about the DPDP Act, not legal advice.
FAQ
Section 9 of India's Digital Personal Data Protection Act 2023 requires a data fiduciary to obtain the verifiable consent of a parent or lawful guardian before processing the personal data of a child (a person under 18), and of a person with a disability who has a lawful guardian. It also prohibits processing that is likely to cause a detrimental effect on a child, and prohibits tracking, behavioural monitoring, and targeted advertising directed at children.
Through a guardian email OTP flow. The consent widget shows an age gate; a visitor under your threshold enters a parent or legal guardian's email, and a six-digit one-time code is sent to that inbox. Only after the code is verified does the platform issue a short-lived, project-bound guardian session that authorizes recording the child's consent. Without a verified guardian session, the consent is refused — so a minor cannot self-consent, whether through the widget or a direct API call.
Yes. The age threshold is a per-project setting. It defaults to 18 — the age the DPDP Act treats as a child — and you can adjust it for each project from the banner configuration.
When a child's date of birth has been captured, DPDP Comply automatically expires that consent once they reach your project's age threshold, records the expiry event in the audit trail, and notifies the guardian. If no date of birth was captured, the consent simply persists until it is withdrawn.
Yes. Any purpose flagged as tracking, behavioural monitoring, or targeted advertising cannot be granted for a minor. The widget hides these options, and the consent service enforces the same rule server-side as a backstop, so they can never be recorded for a child — as Section 9 requires.
Yes. A minor's consent record carries a guardian portal token. Using it, the parent or guardian can view every consent under that token and revoke them all in one action. A withdrawal propagates a cease-processing signal to your systems, consistent with the withdrawal obligation in Section 6(6).
Add the DPDP Comply widget and Section 9 is handled — age-gating, verifiable parental consent, and no tracking for minors, all with a defensible audit trail behind every decision.
Get Started — It's FreeNo credit card required · Setup in under 10 minutes