Verifiable consent for processing of personal data of child
10. (1) A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable... by reference toΓÇö
(a) reliable details of identity and age of the individual available with the Data Fiduciary; or
(b) details of identity and age, voluntarily provided ΓÇö
(i) by the individual; or
(ii) through a virtual token mapped to such details, which is issued by an authorised entity.
Illustration.
C informs DF that she is a child and declares P as her parent. DF shall enable P to identify herself through its website... by reference to identity and age details issued by an entity entrusted by law... P may voluntarily make such details available using the services of a Digital Locker service provider.
What this means: Apps must verify that a parent actually gave permission for a child to use the app.
The safest way for a company to verify a parent's age without hoarding sensitive ID cards (like Aadhaar) is by allowing the parent to prove their age using an authorized "virtual token" provider, such as the government's DigiLocker service.
Key Practical Takeaways for Compliance Teams
-
•
Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
-
•
Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 10.
-
•
Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.