Verifiable parental consent under DPDP: an educator's guide
Under DPDP, students under 18 are children. How to verify a parent under Rule 10, which tracking and ads are barred, the exemption for educational institutions, and a sign-up flow.
On this page 9 sections
Under India's DPDP Act, every student below 18 is a child, so before an institute processes that student's personal data it must get a parent's consent and check that the person consenting is an identifiable adult. Rule 10 of the DPDP Rules, 2025 sets out how to do that check, and it applies from May 2027. This guide covers who counts as a child, the ways to verify a parent, the ban on tracking and targeted ads, the exemption for educational institutions, and an onboarding flow for coaching apps.
Who counts as a child under DPDP
Section 2(f) of the Act defines a child as an individual who has not completed 18 years. That line is higher than many global products assume. The US children's privacy rule (COPPA) protects children under 13, and the EU's GDPR sets 16 as the age of consent for online services, which member states may lower to 13. A tool built for those markets may treat a 15-year-old as an ordinary user. In India, that student is a child.
How much this affects you depends on what you teach:
| Course type | Students under 18? |
|---|---|
| Foundation, Olympiad and school boards (Classes 6 to 10) | All |
| JEE and NEET (Classes 11 and 12) | Almost all |
| JEE and NEET droppers, CUET | Some, until their 18th birthday |
| Sainik school entrance | All |
| NDA | Many |
| UPSC, state PSC, SSC and banking | Rarely |
For a child, the Act treats the parent or lawful guardian as part of the "Data Principal" (Section 2(j)). So notices, consent and rights requests run through the parent.
What verifiable consent requires
Section 9(1) requires the parent's verifiable consent before you process any personal data of a child. Rule 10 turns that into two duties:
- Put technical and organisational measures in place so that a parent's consent is obtained before any processing.
- Do due diligence to check that the person who says they are the parent is an adult (18 or over) who can be identified if that is ever needed under law.
Rule 10 lets you base that check on:
- reliable identity and age details you already hold, for example because the parent is a registered user who shared them earlier;
- identity and age details the parent provides voluntarily; or
- a virtual token mapped to identity and age details, issued by an entity entrusted by law or government with those details. This includes details made available and verified through a Digital Locker service provider, such as DigiLocker.
The consent itself must still pass the Act's normal test in Section 6: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. The parent gets the full notice, and must be able to withdraw as easily as they consented. The full text is in the DPDP Rules, 2025.
The Rules illustrate four cases. Applied to a coaching app, they look like this:
| Who starts sign-up | Is the parent already your user? | What you check |
|---|---|---|
| The student, who names a parent | Yes, with identity and age details on record | That your records show an identifiable adult |
| The student, who names a parent | No | The parent's identity and age, from government-issued details or a virtual token, for example through DigiLocker |
| The parent, for the student | Yes | Your records, as above |
| The parent, for the student | No | Government-issued details or a virtual token, as above |
Notice what the Rule's text asks you to verify: that the person consenting is an identifiable adult. It does not set out a separate test of the parent-child relationship. Your admission records usually establish that anyway, so keep them accurate.
Ways to verify a parent
| Method | What it shows | Friction | Best used for |
|---|---|---|---|
| Parent already verified in your system | Identity and age, if your records are reliable | Very low | Siblings and returning families |
| DigiLocker or another authorised token | Identity and age from a government-backed source | Low to medium; the parent needs an account | App and website sign-ups |
| Government ID checked at your centre | Identity and age, checked by your staff | Medium; needs a visit | Offline and hybrid admissions |
| Government ID uploaded online | Identity and age, if someone checks it properly | Medium; you now hold sensitive copies | A fallback when nothing else works |
| OTP to the parent's phone | Only that someone controls that number | Very low | A supporting step, not the check itself |
| Fee paid from the parent's card or UPI | A signal that an adult is involved | Low | A supporting signal only |
Two practical points. First, keep the result, not the document. Record "verified through DigiLocker on 12 June 2027, reference 4821" rather than storing a scan of an ID card; a folder of ID scans is a breach waiting to happen. Second, an OTP feels like verification but proves only that someone has the phone, which in many homes is also the student's phone. Pair it with an identity and age check.
Tracking and targeted advertising restrictions
Section 9(3) says a Data Fiduciary shall not undertake "tracking or behavioural monitoring of children or targeted advertising directed at children". Section 9(2) separately bars processing likely to harm a child's well-being. In a coaching business, review:
- ad pixels and SDKs on web pages and app screens used by under-18 students, which build retargeting audiences;
- custom audiences created by uploading student or lead phone numbers to an ad platform;
- behaviour-based sales nudges, such as "you watched three organic chemistry videos, buy the crash course";
- analytics that profile individual children for marketing rather than teaching.
Marketing to parents is a different matter. A campaign aimed at adults, using adults' data with proper consent, is not advertising directed at children. A practical approach is to aim campaigns at parents, with age targeting set to adults, and keep marketing tools out of the student side of your app.
Remote proctoring of under-18 students is also a form of monitoring. If you rely on the educational-institution exemption below for it, keep it tied to the exam, and see our guide to preventing cheating in online exams for lighter alternatives.
Exemptions for educational institutions
Rule 12 and the Fourth Schedule switch off Section 9(1), the parental consent rule, and Section 9(3), the tracking ban, for certain Data Fiduciaries and purposes, each with conditions. The ones that matter in education:
| Who or what | Exempt only for |
|---|---|
| An educational institution | Tracking and behavioural monitoring for its educational activities, or for the safety of children enrolled with it |
| A transport provider engaged by an educational institution | Tracking children's location for their safety while travelling to and from the institution |
| Any Data Fiduciary confirming a user is not a child | Processing needed for that confirmation and for the Rule 10 checks |
| Any Data Fiduciary locating a child in real time | Tracking location in the interest of the child's safety |
| Any Data Fiduciary keeping harmful content or ads away from a child | Processing needed to ensure the child can't access them |
The Schedule defines an "educational institution" as an institution of learning that imparts education, including vocational education. On a plain reading, many coaching institutes may fit, but the point hasn't been tested, so take advice before you rely on it.
Read the condition closely. The exemption covers tracking and monitoring for educational activities: attendance, watch progress, test analytics and doubt history used to teach. A cautious reading is that it does not cover:
- targeted advertising at children;
- using learning data to sell other courses;
- other processing, such as enrolment, publicity or sharing data with third parties, which still needs a parent's consent;
- the ban on harmful processing, or any other DPDP duty, such as notice, security, breach reporting and erasure.
An onboarding flow for coaching apps
- Ask for the date of birth first. Use a neutral date field, not a yes/no "Are you over 18?" button, and don't hint at the answer that skips steps.
- 18 or over: show the normal notice and take the student's own consent.
- Under 18: collect only what you need to reach a parent, such as the parent's name and mobile number. Don't build the full profile yet.
- Send the parent a link to the notice, in plain language and a language of their choice, listing the data you'll collect and why.
- Verify the parent with an existing verified account, a DigiLocker or other authorised token, or an ID check at your centre.
- Take consent with separate choices: first the processing the course needs, then optional items such as promotional messages or using the student's result and photo in publicity.
- Record everything (see the table below).
- Activate the student's account with ad pixels, retargeting and marketing SDKs switched off for under-18 users.
- Give the parent a way to review or withdraw consent, such as a link in the app or a named contact.
- When the student turns 18, show them the notice and ask for their own consent. The Act doesn't spell this out, but it keeps your consent records current.
| Consent record field | Example |
|---|---|
| Student | Enrolment ID JEE27-0192 |
| Parent | Name, relationship, mobile number |
| Verification | Method, reference and date, not a copy of the document |
| Notice | Version number and language shown |
| Choices | Course processing: yes; promotional messages: no; publicity: yes |
| Evidence | Time, channel, device or IP address |
| Changes | Every withdrawal or update, with its date |
For walk-in admissions, the same logic works on paper: a printed notice with the admission form, an ID check by your staff at the desk, the parent's signature, and a note of who checked it and when, entered into your system the same day.
If you are comparing platforms, ask each vendor to show you its age gate, its parental consent records and which trackers load for under-18 users. The broader duties, from notices to breach reporting, are in our DPDP Act compliance checklist.
Key takeaways
- Under DPDP, a child is anyone below 18, which covers most school-level, JEE and NEET students.
- Rule 10 requires a parent's consent before processing, and a check that the parent is an identifiable adult using records you hold, details the parent provides, or a virtual token such as DigiLocker.
- Don't track children for marketing or target ads at them. Aim campaigns at parents instead.
- Educational institutions have a narrow exemption for tracking and monitoring used to teach or keep children safe. It isn't a blanket waiver.
- Build the flow into sign-up and admissions now; Rule 10 applies from May 2027.
This is general information, not legal advice. For your situation, speak to a lawyer.
Where Upclass fits
Upclass gives coaching institutes and schools a course website, live classes, tests, a lead CRM and branded apps on Android, iOS, Windows and macOS. See LMS for coaching institutes and LMS for schools.
Frequently asked questions
What is verifiable parental consent?
It is consent given by a parent or lawful guardian before an organisation processes a child's personal data, where the organisation has taken reasonable steps to check that the person consenting is an identifiable adult. Under Rule 10 of India's DPDP Rules, 2025, that check can rely on reliable records the organisation already holds, identity and age details the parent provides, or a virtual token, such as one made available through DigiLocker.
Who is considered a child under DPDP Act?
Any individual who has not completed 18 years of age (Section 2(f)). For a child, the Act treats the parent or lawful guardian as part of the Data Principal, so the parent receives the notice, gives consent and exercises rights on the child's behalf. For a coaching institute, that covers almost every school-level, JEE and NEET student, and some droppers until their 18th birthday.
What age is considered a child under DPDP?
Below 18. That is higher than the thresholds many global apps are built around: COPPA in the US protects under-13s, and the EU's GDPR sets 16, which member states may lower to 13. Section 9(5) lets the Indian government notify an age above which a specific organisation, whose processing it finds verifiably safe, is exempt from the consent and tracking rules. Otherwise, 18 applies to everyone.