Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Rule 10 of the Digital Personal Data Protection Rules, 2025: verifiable consent of a parent for processing a child's personal data

Rule 10 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. Before processing any personal data of a child, a...

Published
Updated
Reading time
8 min
Views
7
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Data Protection
Published
October 2, 2026
Last updated
Oct 8, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Rule 10 says how a Data Fiduciary makes sure a parent's consent to processing a child's personal data is verifiable. It must adopt technical and organisational measures and check, by reference to reliable identity and age details, that the person who says she is the parent is an identifiable adult.

Rule 10 and the Act

Section 9(1) of the Act requires verifiable consent of the parent or lawful guardian before processing a child's personal data, in the manner prescribed. Rule 10 is that manner for parents; rule 11 is the manner for the lawful guardian of a person with disability. The Act's text is covered in Section 9 of the DPDP Act: verifiable parental consent. Exemptions from section 9(1) and (3) are in rule 12; see rule 12 and the Fourth Schedule, Part A.

Rule 1(4) places rule 10 in the group that comes into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. The "verifiable consent" label itself is defined in rule 2(1)(d) as consent "as specified in rule 10 or 11"; see rules 1 and 2.

Apps for children, schools' online services and gaming platforms often ask how this rule fits their sign-up flow, and a legal consultation can walk through it.

Rule 10(1): measures and due diligence

"A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to" two sources:

SourceText
(a)"reliable details of identity and age of the individual available with the Data Fiduciary"
(b)(i)"details of identity and age, voluntarily provided ... by the individual"
(b)(ii)details provided "through a virtual token mapped to such details, which is issued by an authorised entity"

Notice what the rule asks for and what it does not. It asks for two things: measures so that verifiable consent is obtained before processing, and due diligence that the claimed parent is an identifiable adult. It does not fix a method. The Data Fiduciary may rely on details it already holds (a), or take details the individual gives voluntarily (b), including through a token. The phrase "if required in connection with compliance with any law for the time being in force in India" qualifies the identifiability of the adult. The rule does not say how the relationship between parent and child is proved; it speaks of the individual "identifying herself as the parent" and of due diligence about adulthood and identifiability.

Rule 10(2): the defined words

TermMeaning in rule 10(2)
"adult"An individual who has completed the age of eighteen years
"authorised entity"(i) an entity entrusted by law or by the Central Government or a State Government with the issuance of details of identity and age or a virtual token mapped to such details; or (ii) a person appointed or permitted by that entity for such issuance; the definition "also includes details of identity and age or token made available and verified by a Digital Locker Service Provider"
"Digital Locker service provider"Such intermediary, including a body corporate or an agency of the appropriate Government, as may be notified by the Central Government, in accordance with the rules made in this regard under the Information Technology Act, 2000 (21 of 2000)

Drafting notes: the definition of "authorised entity" ends with a hanging limb ("and also includes details of identity and age or token made available and verified by a Digital Locker Service Provider"), which is not an entity but details; clause (c) ends with a semicolon and nothing follows it; and the term is printed both as "Digital Locker Service Provider" and "Digital Locker service provider". All are quoted as printed. A list of notified Digital Locker service providers is not in the Rules.

The Rules' own Illustration

C is a child, P is a parent and DF is a Data Fiduciary. A user account of C is sought to be created on DF's online platform, by processing C's personal data.

  • Case 1: C tells DF she is a child and declares P as her parent. DF enables P to identify herself through its website, app or other appropriate means. P says she is a registered user who has previously made her identity and age details available to DF. Before processing C's data to create her account, DF checks that it holds reliable identity and age details of P and that P is an identifiable adult.
  • Case 2: Same start, but P says she is not a registered user. Before processing, DF checks that P is an identifiable adult by reference to identity and age details issued by an entity entrusted by law or the Government with maintaining those details, or to a virtual token mapped to them. P may voluntarily make such details available using the services of a Digital Locker service provider.
  • Case 3: P is opening an account for C, identifies herself as the parent and says she is a registered user who previously gave DF her identity and age details. DF checks that it holds reliable details and that P is an identifiable adult.
  • Case 4: P is opening an account for C and says she is not a registered user. DF checks as in Case 2.

The four cases turn on two facts: who starts (the child or the parent), and whether the parent is already a registered user. Where she is registered, DF relies on the details it holds. Where she is not, DF goes to an outside source or a token.

Our own example, separate from the Illustration: LearnLoop (invented) offers a reading app. A ten-year-old, Arjun, tries to sign up. LearnLoop asks him to name a parent. His mother, Kavita, is not a registered user. LearnLoop asks her to verify through a government-issued identity token; once it confirms she is an identifiable adult, it processes Arjun's data to create the account.

What rule 10 does not say

  • It does not define "child"; the Act's meaning applies under rule 2(2).
  • It does not name a particular document, app or portal.
  • It does not state a penalty. For penalties see the Schedule to the Act.
  • The Act bars tracking and targeted advertising directed at children in section 9(3); see that section. Rule 12 gives exemptions.

For a plain-language overview written before the Rules, see children's data protection under section 9.

Need help with child sign-up flows?

If your product can be used by children, the sign-up flow, token checks and records are what a regulator would read. Speak to our legal team to map your flow to rule 10 before launch.

Key takeaways

  • Rule 10 starts eighteen months after the date of publication of the Gazette (rule 1(4)).
  • Verifiable consent of the parent must be obtained before processing any personal data of a child.
  • The Data Fiduciary observes due diligence that the individual is an adult who is identifiable, against reliable details it holds or details given voluntarily, including through a virtual token from an authorised entity.
  • "Adult" means completed eighteen years.
  • The text of rule 10(2) has several printing slips.
  • Later amendments and notifications should be checked.

Read next

Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Rule 10

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who is an adult for rule 10?

An individual who has completed the age of eighteen years (rule 10(2)(a)).

What counts as proof of the parent's identity and age?

Reliable details already with the Data Fiduciary, details given voluntarily by the individual, or details through a virtual token mapped to them and issued by an authorised entity.

If a rule seems to have changed, check the date of what you are reading before you act on it.

— TaxClue Compliance Desk

Rule 10: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

An individual who has completed the age of eighteen years (rule 10(2)(a)).

Reliable details already with the Data Fiduciary, details given voluntarily by the individual, or details through a virtual token mapped to them and issued by an authorised entity.

No. The Illustration says the parent "may" make details available using a Digital Locker service provider.

Yes, "before the processing of any personal data of a child".

The Data Fiduciary checks that it holds reliable identity and age details and that she is an identifiable adult (Cases 1 and 3).

No, rule 11 does.