Verifiable parental consent under DPDP: an educator's guide

Under DPDP, students under 18 are children. How to verify a parent under Rule 10, which tracking and ads are barred, the exemption for educational institutions, and a sign-up flow.

10 min read
On this page 9 sections
  1. Who counts as a child under DPDP
  2. What verifiable consent requires
  3. Ways to verify a parent
  4. Tracking and targeted advertising restrictions
  5. Exemptions for educational institutions
  6. An onboarding flow for coaching apps
  7. Key takeaways
  8. Where Upclass fits
  9. Frequently asked questions

Under India's DPDP Act, every student below 18 is a child, so before an institute processes that student's personal data it must get a parent's consent and check that the person consenting is an identifiable adult. Rule 10 of the DPDP Rules, 2025 sets out how to do that check, and it applies from May 2027. This guide covers who counts as a child, the ways to verify a parent, the ban on tracking and targeted ads, the exemption for educational institutions, and an onboarding flow for coaching apps.

Who counts as a child under DPDP

Section 2(f) of the Act defines a child as an individual who has not completed 18 years. That line is higher than many global products assume. The US children's privacy rule (COPPA) protects children under 13, and the EU's GDPR sets 16 as the age of consent for online services, which member states may lower to 13. A tool built for those markets may treat a 15-year-old as an ordinary user. In India, that student is a child.

How much this affects you depends on what you teach:

Course typeStudents under 18?
Foundation, Olympiad and school boards (Classes 6 to 10)All
JEE and NEET (Classes 11 and 12)Almost all
JEE and NEET droppers, CUETSome, until their 18th birthday
Sainik school entranceAll
NDAMany
UPSC, state PSC, SSC and bankingRarely

For a child, the Act treats the parent or lawful guardian as part of the "Data Principal" (Section 2(j)). So notices, consent and rights requests run through the parent.

Section 9(1) requires the parent's verifiable consent before you process any personal data of a child. Rule 10 turns that into two duties:

  1. Put technical and organisational measures in place so that a parent's consent is obtained before any processing.

  2. Do due diligence to check that the person who says they are the parent is an adult (18 or over) who can be identified if that is ever needed under law.

Rule 10 lets you base that check on:

  • reliable identity and age details you already hold, for example because the parent is a registered user who shared them earlier;

  • identity and age details the parent provides voluntarily; or

  • a virtual token mapped to identity and age details, issued by an entity entrusted by law or government with those details. This includes details made available and verified through a Digital Locker service provider, such as DigiLocker.

The consent itself must still pass the Act's normal test in Section 6: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. The parent gets the full notice, and must be able to withdraw as easily as they consented. The full text is in the DPDP Rules, 2025.

The Rules illustrate four cases. Applied to a coaching app, they look like this:

Who starts sign-upIs the parent already your user?What you check
The student, who names a parentYes, with identity and age details on recordThat your records show an identifiable adult
The student, who names a parentNoThe parent's identity and age, from government-issued details or a virtual token, for example through DigiLocker
The parent, for the studentYesYour records, as above
The parent, for the studentNoGovernment-issued details or a virtual token, as above

Notice what the Rule's text asks you to verify: that the person consenting is an identifiable adult. It does not set out a separate test of the parent-child relationship. Your admission records usually establish that anyway, so keep them accurate.

Ways to verify a parent

MethodWhat it showsFrictionBest used for
Parent already verified in your systemIdentity and age, if your records are reliableVery lowSiblings and returning families
DigiLocker or another authorised tokenIdentity and age from a government-backed sourceLow to medium; the parent needs an accountApp and website sign-ups
Government ID checked at your centreIdentity and age, checked by your staffMedium; needs a visitOffline and hybrid admissions
Government ID uploaded onlineIdentity and age, if someone checks it properlyMedium; you now hold sensitive copiesA fallback when nothing else works
OTP to the parent's phoneOnly that someone controls that numberVery lowA supporting step, not the check itself
Fee paid from the parent's card or UPIA signal that an adult is involvedLowA supporting signal only

Two practical points. First, keep the result, not the document. Record "verified through DigiLocker on 12 June 2027, reference 4821" rather than storing a scan of an ID card; a folder of ID scans is a breach waiting to happen. Second, an OTP feels like verification but proves only that someone has the phone, which in many homes is also the student's phone. Pair it with an identity and age check.

Tracking and targeted advertising restrictions

Section 9(3) says a Data Fiduciary shall not undertake "tracking or behavioural monitoring of children or targeted advertising directed at children". Section 9(2) separately bars processing likely to harm a child's well-being. In a coaching business, review:

  • ad pixels and SDKs on web pages and app screens used by under-18 students, which build retargeting audiences;

  • custom audiences created by uploading student or lead phone numbers to an ad platform;

  • behaviour-based sales nudges, such as "you watched three organic chemistry videos, buy the crash course";

  • analytics that profile individual children for marketing rather than teaching.

Marketing to parents is a different matter. A campaign aimed at adults, using adults' data with proper consent, is not advertising directed at children. A practical approach is to aim campaigns at parents, with age targeting set to adults, and keep marketing tools out of the student side of your app.

Remote proctoring of under-18 students is also a form of monitoring. If you rely on the educational-institution exemption below for it, keep it tied to the exam, and see our guide to preventing cheating in online exams for lighter alternatives.

Exemptions for educational institutions

Rule 12 and the Fourth Schedule switch off Section 9(1), the parental consent rule, and Section 9(3), the tracking ban, for certain Data Fiduciaries and purposes, each with conditions. The ones that matter in education:

Who or whatExempt only for
An educational institutionTracking and behavioural monitoring for its educational activities, or for the safety of children enrolled with it
A transport provider engaged by an educational institutionTracking children's location for their safety while travelling to and from the institution
Any Data Fiduciary confirming a user is not a childProcessing needed for that confirmation and for the Rule 10 checks
Any Data Fiduciary locating a child in real timeTracking location in the interest of the child's safety
Any Data Fiduciary keeping harmful content or ads away from a childProcessing needed to ensure the child can't access them

The Schedule defines an "educational institution" as an institution of learning that imparts education, including vocational education. On a plain reading, many coaching institutes may fit, but the point hasn't been tested, so take advice before you rely on it.

Read the condition closely. The exemption covers tracking and monitoring for educational activities: attendance, watch progress, test analytics and doubt history used to teach. A cautious reading is that it does not cover:

  • targeted advertising at children;

  • using learning data to sell other courses;

  • other processing, such as enrolment, publicity or sharing data with third parties, which still needs a parent's consent;

  • the ban on harmful processing, or any other DPDP duty, such as notice, security, breach reporting and erasure.

An onboarding flow for coaching apps

  1. Ask for the date of birth first. Use a neutral date field, not a yes/no "Are you over 18?" button, and don't hint at the answer that skips steps.

  2. 18 or over: show the normal notice and take the student's own consent.

  3. Under 18: collect only what you need to reach a parent, such as the parent's name and mobile number. Don't build the full profile yet.

  4. Send the parent a link to the notice, in plain language and a language of their choice, listing the data you'll collect and why.

  5. Verify the parent with an existing verified account, a DigiLocker or other authorised token, or an ID check at your centre.

  6. Take consent with separate choices: first the processing the course needs, then optional items such as promotional messages or using the student's result and photo in publicity.

  7. Record everything (see the table below).

  8. Activate the student's account with ad pixels, retargeting and marketing SDKs switched off for under-18 users.

  9. Give the parent a way to review or withdraw consent, such as a link in the app or a named contact.

  10. When the student turns 18, show them the notice and ask for their own consent. The Act doesn't spell this out, but it keeps your consent records current.

Consent record fieldExample
StudentEnrolment ID JEE27-0192
ParentName, relationship, mobile number
VerificationMethod, reference and date, not a copy of the document
NoticeVersion number and language shown
ChoicesCourse processing: yes; promotional messages: no; publicity: yes
EvidenceTime, channel, device or IP address
ChangesEvery withdrawal or update, with its date

For walk-in admissions, the same logic works on paper: a printed notice with the admission form, an ID check by your staff at the desk, the parent's signature, and a note of who checked it and when, entered into your system the same day.

If you are comparing platforms, ask each vendor to show you its age gate, its parental consent records and which trackers load for under-18 users. The broader duties, from notices to breach reporting, are in our DPDP Act compliance checklist.

Key takeaways

  • Under DPDP, a child is anyone below 18, which covers most school-level, JEE and NEET students.

  • Rule 10 requires a parent's consent before processing, and a check that the parent is an identifiable adult using records you hold, details the parent provides, or a virtual token such as DigiLocker.

  • Don't track children for marketing or target ads at them. Aim campaigns at parents instead.

  • Educational institutions have a narrow exemption for tracking and monitoring used to teach or keep children safe. It isn't a blanket waiver.

  • Build the flow into sign-up and admissions now; Rule 10 applies from May 2027.

This is general information, not legal advice. For your situation, speak to a lawyer.

Where Upclass fits

Upclass gives coaching institutes and schools a course website, live classes, tests, a lead CRM and branded apps on Android, iOS, Windows and macOS. See LMS for coaching institutes and LMS for schools.

Frequently asked questions

It is consent given by a parent or lawful guardian before an organisation processes a child's personal data, where the organisation has taken reasonable steps to check that the person consenting is an identifiable adult. Under Rule 10 of India's DPDP Rules, 2025, that check can rely on reliable records the organisation already holds, identity and age details the parent provides, or a virtual token, such as one made available through DigiLocker.

Who is considered a child under DPDP Act?

Any individual who has not completed 18 years of age (Section 2(f)). For a child, the Act treats the parent or lawful guardian as part of the Data Principal, so the parent receives the notice, gives consent and exercises rights on the child's behalf. For a coaching institute, that covers almost every school-level, JEE and NEET student, and some droppers until their 18th birthday.

What age is considered a child under DPDP?

Below 18. That is higher than the thresholds many global apps are built around: COPPA in the US protects under-13s, and the EU's GDPR sets 16, which member states may lower to 13. Section 9(5) lets the Indian government notify an age above which a specific organisation, whose processing it finds verifiably safe, is exempt from the consent and tracking rules. Otherwise, 18 applies to everyone.

Share this article

Looking for something else?

Talk to Us